Advertisement
Dijit

DS remote access guidelines for UNIX servers.

Mar 27th, 2017
181
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.65 KB | None | 0 0
  1. DarkScience remote access information:
  2.  
  3. Guidelines follow;
  4. * sshd will listen on port 22 and 2222
  5. * firewall will allow all connections to 2222
  6. * global inbound connections on 2222 will have a rate limit
  7. * firewall will allow connections to 22 from -ONLY- other DS hosts.
  8. * mandatory allowed hosts are: phobos.drk.sc and deimos.drk.sc ; you may add more as you wish, but those are required.
  9. * sshd will have a hardcoded list of AllowUsers.
  10. * only staff may be contained in AllowUsers.
  11. * sshd will only accept public-keys
  12. * ssh version 2 will be required, version 1 is deprecated.
  13. * where possible sshd will be configured to allow ed25519 in liu of RSA
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement