diff options
author | Micah Anderson <micah@riseup.net> | 2008-09-26 17:30:28 -0400 |
---|---|---|
committer | Micah Anderson <micah@riseup.net> | 2008-09-26 17:30:28 -0400 |
commit | 9edd2705d4c59ac8cb75a67b587d06d32cb5e6c6 (patch) | |
tree | ec918ac2f13b7bc7c76fba7662ce6c708ae8f0d8 /templates/sshd_config/Debian_normal.erb | |
parent | ba8d788f89e2e8676985b40553a9f6794a322217 (diff) | |
download | puppet-sshd-9edd2705d4c59ac8cb75a67b587d06d32cb5e6c6.tar.gz puppet-sshd-9edd2705d4c59ac8cb75a67b587d06d32cb5e6c6.tar.bz2 |
add sshd_ignore_rhosts option, default set to yes
Diffstat (limited to 'templates/sshd_config/Debian_normal.erb')
-rw-r--r-- | templates/sshd_config/Debian_normal.erb | 6 |
1 files changed, 6 insertions, 0 deletions
diff --git a/templates/sshd_config/Debian_normal.erb b/templates/sshd_config/Debian_normal.erb index 7105dfd..155c4da 100644 --- a/templates/sshd_config/Debian_normal.erb +++ b/templates/sshd_config/Debian_normal.erb @@ -55,8 +55,14 @@ PubkeyAuthentication no # rhosts authentication should not be used #RhostsAuthentication no + # Don't read the user's ~/.rhosts and ~/.shosts files +<%- if real_sshd_pubkey_authentication.to_s == 'yes' then %> IgnoreRhosts yes +<%- else %> +IgnoreRhosts no +<% end -%> + # For this to work you will also need host keys in /etc/ssh_known_hosts RhostsRSAAuthentication no # similar for protocol version 2 |