Skip to main content

about sshd settings

ssh (secure shell)

- service name : sshd

- log file
/var/log/secure*
/var/log/audit/audit.log

- default configuration files and ssh ports
/etc/ssh/sshd_config     --> openssh server configuration file
/etc/ssh/ssh_config     --> openssh client configuration file
~/.ssh/     --> user ssh configuration directory
~/.ssh/authorized_keys    ---> lists public key (RSA or DSA) that can be used to log into the user's account
/etc/nologin     --> if the file exists, sshd refuses to let anyone except root log in
/etc/hosts.allow  
/etc/hosts.deny     --> these two file are access control list that should be enforced by tcp-wrappers defined here

- ssh default port    ---> tcp:22

- examples of using tcp wrappers for sshd
allow ssh only from 192.168.1.2 172.16.23.12
put the line in /etc/hosts.allow
sshd : 192.168.1.2 172.16.23.12
vsftpd : ALL

put the line in /etc/hosts.deny
ALL : ALL

- enable warning banner
put the line in /etc/ssh/sshd_config
Banner /etc/banner      (the file name banner must exists in /etc)

Comments

Popular posts from this blog

about gigabyte NIC onboard not detected on enterprise linux distribution

on several gigabyte motherboard, onboard network interface card  will not be detected on enterprise linux distribution (e.g. scientific linux, oracle linux server, etc). alternatively you must supply add-on card. or if you insist to use the onboard card, you must install the unofficial nic driver. this is tutorial how to install driver for onboard network interface card GIGABYTE first of all prepare your system. make sure it has package group "Development Tools" installed. if it has not, install it # yum groupinstall “Development Tools” download the source code : https://www.dropbox.com/s/na91bu4az4p9827/AR81Family-linux-v1.0.1.14.tar.gz extract the source code : # tar zxvf AR81Family-linux1.0.1.14.tar.gz the extraction process will make the new directory "AR81Family*", change to the directory # cd AR81Family* compile the source by type on terminal : # make then, # make install wait until the compiling process finish. next make the new scrip...

about getsebool and setsebool

The setsebool is used to set SELinux boolean value i.e. various configurations can be enabled or disabled using this tool. In other words, the setsebool command switches on and off the protection of SELinux. Type getsebool -a to see all such options which can be enabled or disabled at run time: e.g. # getsebool -a The following should give you a complete listing of all the vsftpd switches: e.g.  # getsebool -a | grep ftp  For example, if httpd_disable_trans set to 1, it will disable SELinux protection for  Apache web server. To disable it, enter:  # setsebool -P httpd_can_network_connect=1 To enable it, enter:    # setsebool -P httpd_can_network_connect=0

All certification