Skip to content
This repository was archived by the owner on Dec 26, 2020. It is now read-only.

Defaults: Remove DSA from SSH host keys to match ssh-baseline profile #92

Merged
merged 1 commit into from
Jan 25, 2017

Conversation

techraf
Copy link
Contributor

@techraf techraf commented Jan 24, 2017

This is a change in the default values, for consistency between dev-sec's repos.

Currently Ansible SSH hardening role configures DSA host key which does not pass InSpec's sshd-14.

Both: the ssh-baseline profile and the Chef recipe specify only RSA and ECDSA, so I assume the intention was to exclude the DSA key and convergence should be achieved by removing it from Ansible's role.

@techraf techraf changed the title Remove DSA from SSH host keys to match ssh-baseline profile Defaults: Remove DSA from SSH host keys to match ssh-baseline profile Jan 25, 2017
@rndmh3ro rndmh3ro self-requested a review January 25, 2017 13:44
@rndmh3ro rndmh3ro added this to the ansible-ssh-hardening 4.0.0 milestone Jan 25, 2017
@rndmh3ro rndmh3ro merged commit 45a464b into dev-sec:master Jan 25, 2017
@rndmh3ro
Copy link
Member

Thanks!

# for free to subscribe to this conversation on GitHub. Already have an account? #.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants