harden sshd
More details:
- require keys to login
- don’t allow login as root
That should be plenty, but you could go a bit further and restrict the types of algorithms allowed (e.g. disallow RSA if you’re worried about quantum attacks). For this, I recommend a subtractive config (e.g. HostbasedAcceptedAlgorithms=-rsa-*
). This is way over the top since an attacker is unlikely to attack the cipher directly, but it could be part of an attack.
om1k@sopuli.xyz 1 week ago
did you mean crowdsec instead of crowdstrike?
zr0@lemmy.dbzer0.com 1 week ago
Fml… yes, I meant CrowdSec. Thanks for the hint
whodatdair@lemmy.blahaj.zone 1 week ago
Vietnam stare