aboutsummaryrefslogtreecommitdiff
path: root/templates/sshd_config/Debian_sid.erb
diff options
context:
space:
mode:
authorSilvio Rhatto <rhatto@riseup.net>2014-08-19 13:40:41 -0300
committerSilvio Rhatto <rhatto@riseup.net>2014-08-19 13:40:41 -0300
commit0b3b27b577de7daf6c0259bd2190b33d8f624cb1 (patch)
tree7c6de76de467bb0a6ee56d18a12334180d6d0a24 /templates/sshd_config/Debian_sid.erb
parentad030e74efe9249b59ef6fdb58fca8d9d562cc11 (diff)
downloadpuppet-sshd-0b3b27b577de7daf6c0259bd2190b33d8f624cb1.tar.gz
puppet-sshd-0b3b27b577de7daf6c0259bd2190b33d8f624cb1.tar.bz2
Back to OpenSSH HMAC: SHA1 -> SHA2-512 (suggested by duraconf)
Diffstat (limited to 'templates/sshd_config/Debian_sid.erb')
-rw-r--r--templates/sshd_config/Debian_sid.erb2
1 files changed, 1 insertions, 1 deletions
diff --git a/templates/sshd_config/Debian_sid.erb b/templates/sshd_config/Debian_sid.erb
index 70bb4bf..60c15fa 100644
--- a/templates/sshd_config/Debian_sid.erb
+++ b/templates/sshd_config/Debian_sid.erb
@@ -115,7 +115,7 @@ AllowGroups <%= s %>
<% if scope.lookupvar('sshd::hardened_ssl') == 'yes' -%>
Ciphers aes256-ctr
-MACs hmac-sha1
+MACs hmac-sha2-512
<% end -%>
<% unless (s=scope.lookupvar('sshd::tail_additional_options')).empty? -%>