Created
September 17, 2018 03:20
-
-
Save lovejavaee/042fc07811aa27cb8fdc1160850b116d to your computer and use it in GitHub Desktop.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Host * | |
# ForwardAgent no | |
ForwardX11 yes | |
ForwardX11Trusted yes | |
# RhostsRSAAuthentication no | |
# RSAAuthentication yes | |
# PasswordAuthentication yes | |
# HostbasedAuthentication no | |
# GSSAPIAuthentication no | |
# GSSAPIDelegateCredentials no | |
# GSSAPIKeyExchange no | |
# GSSAPITrustDNS no | |
# BatchMode no | |
# CheckHostIP yes | |
# AddressFamily any | |
# ConnectTimeout 0 | |
# StrictHostKeyChecking ask | |
# IdentityFile ~/.ssh/identity | |
# IdentityFile ~/.ssh/id_rsa | |
# IdentityFile ~/.ssh/id_dsa | |
# Port 22 | |
# Protocol 2,1 | |
# Cipher 3des | |
# Ciphers aes128-ctr,aes192-ctr,aes256-ctr,arcfour256,arcfour128,aes128-cbc,3des-cbc | |
# MACs hmac-md5,hmac-sha1,[email protected],hmac-ripemd160 | |
# EscapeChar ~ | |
# Tunnel no | |
# TunnelDevice any:any | |
# PermitLocalCommand no | |
VisualHostKey yes | |
SendEnv LANG LC_* | |
HashKnownHosts yes | |
GSSAPIAuthentication yes | |
GSSAPIDelegateCredentials no | |
Compression yes | |
CompressionLevel 6 | |
ControlMaster auto | |
ControlPath ~/.ssh/master-%r@%h:%p |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Host *
-This means the configuration applies to any host. In
some cases options can be given that will allow different
configurations depending on what host the user would like to
connect to. Under normal circumstances, all machines are treated
the same.
Network Settings
Port 22
AddressFamily inet
ConnectTimeout 4
CheckHostIP yes
TCPKeepAlive no
We are using ServerAliveInterval and ServerAliveCountMax
ServerAliveInterval 10
ServerAliveCountMax 5
Identifcation
IdentitiesOnly yes
IdentityFile ~/.ssh/identity
IdentityFile ~/.ssh/id_rsa
IdentityFile ~/.ssh/id_dsa
RhostsAuthentication no
RhostsRSAAuthentication no
HostbasedAuthentication no
RSAAuthentication yes
PubkeyAuthentication yes
PasswordAuthentication yes
NoHostAuthenticationForLocalhost no
Home directories are not on NFS
Forwarding
ForwardAgent yes
ForwardX11 yes
ForwardX11Trusted yes
We always enable X11 forwarding. Invariably our users will
want to use an X-Windows System from somewhere, and we would
rather it be over an encrypted connection than the standard X11-
type connections.
System Settings
Protocol 2
GlobalKnownHostsFile /etc/ssh/ssh_known_hosts
BatchMode no
StrictHostKeyChecking ask
EscapeChar ~
SendEnv PATH
LogLevel Verbose
Verbose Logging provides nice amounts of logs.
Encryption
Ciphers aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour,aes192-cbc,aes256-cbc