Created
May 30, 2019 02:34
-
-
Save MatthewVance/b87bb3809ec0c600b845ef60ac4fcf71 to your computer and use it in GitHub Desktop.
OpenSSH SSH client configuration example for Raspberry Pi, customized to improve security.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
# This is the ssh client system-wide configuration file. See | |
# ssh_config(5) for more information. This file provides defaults for | |
# users, and the values can be changed in per-user configuration files | |
# or on the command line. | |
# Configuration data is parsed as follows: | |
# 1. command line options | |
# 2. user-specific file | |
# 3. system-wide file | |
# Any configuration value is only changed the first time it is set. | |
# Thus, host-specific definitions should be at the beginning of the | |
# configuration file, and defaults at the end. | |
# Site-wide defaults for some commonly used options. For a comprehensive | |
# list of available options, their meanings and defaults, please see the | |
# ssh_config(5) man page. | |
Host * | |
# ForwardAgent no | |
# ForwardX11 no | |
# ForwardX11Trusted yes | |
# RhostsRSAAuthentication no | |
# RSAAuthentication yes | |
# PasswordAuthentication yes | |
# HostbasedAuthentication no | |
# GSSAPIAuthentication no | |
# GSSAPIDelegateCredentials no | |
# GSSAPIKeyExchange no | |
# GSSAPITrustDNS no | |
# BatchMode no | |
# CheckHostIP yes | |
# AddressFamily any | |
# ConnectTimeout 0 | |
# StrictHostKeyChecking ask | |
# IdentityFile ~/.ssh/identity | |
# IdentityFile ~/.ssh/id_rsa | |
# IdentityFile ~/.ssh/id_dsa | |
# Port 22 | |
# Protocol 2,1 | |
# Cipher 3des | |
# Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc | |
# MACs hmac-md5,hmac-sha1,[email protected],hmac-ripemd160 | |
# EscapeChar ~ | |
# Tunnel no | |
# TunnelDevice any:any | |
# PermitLocalCommand no | |
# VisualHostKey no | |
# ProxyCommand ssh -q -W %h:%p gateway.example.com | |
# RekeyLimit 1G 1h | |
## SendEnv LANG LC_* | |
## HashKnownHosts yes | |
## GSSAPIAuthentication yes | |
## GSSAPIDelegateCredentials no | |
AddressFamily inet | |
Ciphers [email protected],[email protected] | |
ForwardX11 no | |
ForwardX11Trusted no | |
KexAlgorithms [email protected] | |
MACs [email protected],[email protected],[email protected] | |
Protocol 2 | |
VisualHostKey yes | |
HashKnownHosts yes |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment