Skip to content

Commit

Permalink
Harden the SSH service with strong encryption (#547)
Browse files Browse the repository at this point in the history
Co-authored-by: Giacomo Sanchietti <giacomo.sanchietti@nethesis.it>
  • Loading branch information
stephdl and gsanchietti committed Nov 23, 2020
1 parent 1d634e0 commit 600970d
Showing 1 changed file with 6 additions and 0 deletions.
6 changes: 6 additions & 0 deletions administrator-manual/en/base_system2.rst
Original file line number Diff line number Diff line change
Expand Up @@ -112,6 +112,12 @@ administrative group (``Domain Admins``).
It is possible to selectively grant SSH and :index:`SFTP` access to some groups,
while administrators are always granted access to SSH and SFTP.

The administrator can harden SSH by restricting the usage of weak ciphers, algorythms and macs.
After enabling the :guilabel:`Disable weak ciphers` option, the host key will change and clients
will have to accept the new one.
Also, note that big files transfer can be slower with the strong encryption and very old SSH clients
may not be able to connect to the server.

.. note::

For |product| up to version 7.7:
Expand Down

0 comments on commit 600970d

Please sign in to comment.