diff --git a/etc/ssh/sshd_config b/etc/ssh/sshd_config index 169a87b..7285407 100644 --- a/etc/ssh/sshd_config +++ b/etc/ssh/sshd_config @@ -60,18 +60,6 @@ MaxAuthTries 3 # some PAM modules and threads) ChallengeResponseAuthentication no -# Kerberos options -#KerberosAuthentication no -#KerberosOrLocalPasswd yes -#KerberosTicketCleanup yes -#KerberosGetAFSToken no - -# GSSAPI options -#GSSAPIAuthentication no -#GSSAPICleanupCredentials yes -#GSSAPIStrictAcceptorCheck yes -#GSSAPIKeyExchange no - # Set this to 'yes' to enable PAM authentication, account processing, # and session processing. If this is enabled, PAM authentication will # be allowed through the ChallengeResponseAuthentication and @@ -83,12 +71,7 @@ ChallengeResponseAuthentication no # and ChallengeResponseAuthentication to 'no'. UsePAM yes -#AllowAgentForwarding yes -#AllowTcpForwarding yes -#GatewayPorts no -X11Forwarding no -#X11DisplayOffset 10 -#X11UseLocalhost yes +DisableForwarding yes #PermitTTY yes PrintMotd no #PrintLastLog yes @@ -101,7 +84,6 @@ PrintMotd no UseDNS no #PidFile /var/run/sshd.pid #MaxStartups 10:30:100 -#PermitTunnel no #ChrootDirectory none #VersionAddendum none @@ -123,16 +105,6 @@ MACs hmac-sha2-256-etm@openssh.com,hmac-sha2-512-etm@openssh.com,umac-128-etm@op Match User root AuthenticationMethods publickey -# Example of overriding settings on a per-user basis -#Match User anoncvs -# X11Forwarding no -# AllowTcpForwarding no -# PermitTTY no -# ForceCommand cvs server - Match Group www-data ChrootDirectory %h ForceCommand internal-sftp - AllowTcpForwarding no - X11Forwarding no - DisableForwarding yes