User Tools

Site Tools


computing:ssh

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
computing:ssh [2019/03/25 04:33] oemb1905computing:ssh [2026/09/11 17:39] (current) oemb1905
Line 39: Line 39:
      
 config options for /etc/ssh/sshd_config config options for /etc/ssh/sshd_config
 +   
 +  Port 53535 
 +  PubkeyAuthentication yes 
 +  PasswordAuthentication no 
 +  PermitRootLogin prohibit-password
   Protocol 2   Protocol 2
-  AllowUsers user +  AllowUsers sally 
-  PermitRootLogin no+  AllowUsers johnny 
 +  PermitEmptyPasswords no 
 +  X11Forwarding yes 
 +  PrintMotd yes 
 +  ChallengeResponseAuthentication no 
 +  UsePAM yes 
 +   
 +Then, always restart the service
      
   sudo systemctl restart sshd.service   sudo systemctl restart sshd.service
      
 +Debian 14 changes to ssh. The kex packets are so large they may not traverse on vpn connections, etc. On the box you connect to open ''sudo nano /etc/ssh/sshd_config''"
 +
 +  KexAlgorithms curve25519-sha256,ecdh-sha2-nistp256,diffie-hellman-group14-sha256
 +  
 +On the box reaching out or from which you are connecting, open ''sudo nano /etc/ssh/ssh_config'' and enter these two lines at the end with the same indentation:
 +
 +  KexAlgorithms curve25519-sha256
 +  IPQoS none
 +
 +If you have not yet noticed, nor made any changes and need to connect quickly, use the following:
  
 +  ssh -o KexAlgorithms=curve25519-sha256 -o IPQoS=none root@10.13.13.20
  
 +Then, if you use git across a vpn, you will now need to accept those environment variables. So on the git server's sshd_config file, add the git protocol as an allowance:
  
- --- //[[netcmnd@jonathanhaack.com|oemb1905]] 2018/05/19 20:03//+  AcceptEnv LANG LC_* GIT_PROTOCOL
  
 + --- //[[alerts@haacksnetworking.org|oemb1905]] 2026/09/11 17:38//
computing/ssh.1553488436.txt.gz · Last modified: by oemb1905