
このAnsibleロールは、セキュリティ関連のssh設定を多数提供し、全体的な基本保護を実現します。
注意: このロールは hardening-collection に移行されました:
問題やプルリクエストはそちらでお願いします!
network_ipv6_enable
ssh_listen_to も IPv6 アドレス (例: [::]) をリッスンするように設定する必要があります。ssh_server_ports
ssh_client_port
ssh_listen_to
ssh_host_key_files
ssh_host_key_algorithms
ssh_client_alive_interval
ssh_client_alive_count
ssh_permit_tunnel
ssh_remote_hosts
defaults/main.yml を参照してください。ssh_permit_root_login
without-password または yes に設定します。ssh_allow_tcp_forwarding
'no'。TCP フォワーディングを許可するには 'yes' に設定します。OpenSSH >= 6.2 バージョンを使用している場合は、'yes'、'no'、'all'、または 'local' を指定できます。 'yes' および 'no' の値は引用符で囲んで渡す必要があります。ssh_gateway_ports
falsefalse。ワイルドカードアドレスへのバインドを強制するには true に設定します。クライアントがバインドするアドレスを指定できるようにするには clientspecified に設定します。ssh_allow_agent_forwarding
ssh_x11_forwarding
ssh_pam_support
ssh_use_pam
ssh_gssapi_support
ssh_kerberos_support
ssh_deny_users
ssh_allow_users
ssh_deny_groups
ssh_allow_groups
ssh_authorized_keys_file
ssh_trusted_user_ca_keys_file
ssh_trusted_user_ca_keys
ssh_trusted_user_ca_keys_file が設定されている場合のみ使用されます。ssh_authorized_principals_file
ssh_trusted_user_ca_keys_file が設定されている場合のみ使用されます。ssh_authorized_principals
default_custom.yml を参照してください。ssh_authorized_principals_file が設定されている場合のみ使用されます。ssh_print_motd
ssh_print_pam_motd
ssh_print_last_log
sftp_enabled
sftp_umask
sftp_chroot
sftp_chroot_dir
ssh_client_roaming
sshd_moduli_file
sshd_moduli_minimum
ssh_challengeresponseauthentication
ssh_client_password_login
truessh_server_password_login
truessh_banner
falsetruessh_banner_path
ssh_client_hardening
truefalsessh_client_port
'22'ssh_client_compression
falsessh_compression
falsessh_login_grace_time
30sssh_max_auth_retries
2ssh_max_sessions
10ssh_print_debian_banner
falsetruessh_server_enabled
truefalsessh_server_hardening
truefalsessh_server_match_address
ssh_server_match_group
ssh_server_match_user
ssh_server_match_local_port
ssh_server_permit_environment_vars
noyes。openssh バージョン 7.8 以降では、グローバルな "yes" または "no" 設定に加えて、環境変数名のホワイトリストを指定できます。ssh_server_accept_env_vars
ssh_use_dns
falsessh_server_revoked_keys
ssh_max_startups
ssh_macs
defaults/main.yml にあります。ssh_kex
defaults/main.yml にあります。ssh_ciphers
defaults/main.yml にあります。ssh_custom_options
sshd_custom_options
sshd_syslog_facility
sshd_log_level
sshd_strict_modes
sshd_authenticationmethods
publickeydefaults/main.yml にあります。上記にリストされていない ssh オプションを設定する場合は、ssh_custom_options (/etc/ssh/ssh_config 用) または sshd_custom_options (/etc/ssh/sshd_config 用) を使用して設定できます。これらのオプションはファイルの先頭に設定されるため、ファイルの後半でオプションを上書きできます。
プレイブックの例: