The wholesale sshd_config replacement is intentional, but two side effects were not: - The template had no Include line, so reinstalling dropped the `Include /etc/ssh/sshd_config.d/*.conf` that update_ssh_banners_config appends, leaving the per-user banner drop-in on disk but inert. Add it as the last line: OpenSSH uses the first value it obtains for a keyword, so the template's own settings still take precedence over any drop-in and only the Match blocks become effective. - The template hardcoded the Debian path for sftp-server. sshd -t does not verify that the binary exists, so SFTP broke silently on distributions that ship it elsewhere. install.sh now probes the common locations and rewrites the Subsystem line. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
36 lines
886 B
Plaintext
36 lines
886 B
Plaintext
# TNS243-GLOBAL
|
|
#
|
|
Port 22
|
|
Protocol 2
|
|
KeyRegenerationInterval 3600
|
|
ServerKeyBits 1024
|
|
SyslogFacility AUTH
|
|
LogLevel INFO
|
|
LoginGraceTime 120
|
|
PermitRootLogin yes
|
|
StrictModes yes
|
|
RSAAuthentication yes
|
|
PubkeyAuthentication yes
|
|
IgnoreRhosts yes
|
|
RhostsRSAAuthentication no
|
|
HostbasedAuthentication no
|
|
PermitEmptyPasswords no
|
|
PermitTunnel yes
|
|
ChallengeResponseAuthentication no
|
|
PasswordAuthentication yes
|
|
X11Forwarding yes
|
|
X11DisplayOffset 10
|
|
PrintMotd no
|
|
PrintLastLog yes
|
|
TCPKeepAlive yes
|
|
#UseLogin no
|
|
AcceptEnv LANG LC_*
|
|
Subsystem sftp /usr/lib/openssh/sftp-server
|
|
UsePAM yes
|
|
Banner /etc/bannerssh
|
|
|
|
# Kept last on purpose. OpenSSH uses the first value it obtains for a keyword,
|
|
# so everything above still wins over any drop-in; this only lets the Match
|
|
# blocks that menu.sh writes to sshd_config.d (per-user banners) take effect.
|
|
Include /etc/ssh/sshd_config.d/*.conf
|