Bug#522745: [security] debian/openssh-server.postinst improved sshd_config

2009-04-06 Thread Jari Aalto
Package: openssh-server Version: 1:5.1p1-5 Severity: normal Tags: security The following patch improves security in default /etc/ssh/sshd_config file: - PermitRootLogin cha¨nge: from 'yes' to 'no' - Add 'Match Address 192.168.1.0/26' exmaple to limit root logins insode LAN (in comments; for

Bug#522745: [security] debian/openssh-server.postinst improved sshd_config

2009-04-06 Thread Colin Watson
On Mon, Apr 06, 2009 at 11:37:47AM +0300, Jari Aalto wrote: - PermitRootLogin cha¨nge: from 'yes' to 'no' No. See README.Debian. - Add 'Match Address 192.168.1.0/26' exmaple to limit root logins insode LAN (in comments; for sysadm to enable it) Wouldn't this be better as an example in the

Bug#522745: [security] debian/openssh-server.postinst improved sshd_config

2009-04-06 Thread Jari Aalto
Colin Watson cjwat...@debian.org writes: On Mon, Apr 06, 2009 at 11:37:47AM +0300, Jari Aalto wrote: - PermitRootLogin cha¨nge: from 'yes' to 'no' No. See README.Debian. This wasn't obvious. Please add at least a comment to the default conffile for people to consult

Bug#522745: [security] debian/openssh-server.postinst improved sshd_config

2009-04-06 Thread Colin Watson
On Mon, Apr 06, 2009 at 10:15:08PM +0300, Jari Aalto wrote: Colin Watson cjwat...@debian.org writes: On Mon, Apr 06, 2009 at 11:37:47AM +0300, Jari Aalto wrote: - PermitRootLogin cha¨nge: from 'yes' to 'no' No. See README.Debian. This wasn't obvious. Please add at least a comment to