Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update sshd config for Focal #5660

Closed
emkll opened this issue Dec 1, 2020 · 0 comments · Fixed by #5666
Closed

Update sshd config for Focal #5660

emkll opened this issue Dec 1, 2020 · 0 comments · Fixed by #5666
Assignees

Comments

@emkll
Copy link
Contributor

emkll commented Dec 1, 2020

Description

In the current sshd configuration, we specify a path to a host dsa key for the server, but that has been deprecated/disabled. This was uncovered by an ossec alert while reviewing #5638

The alert is as follows:

Dec 1 15:08:22 app-staging sshd[3302]: error: Unable to load host key: /etc/ssh/ssh_host_dsa_key

The server sshd config is

and removing the line should suffice. We should also review and audit the current configuration to ensure we adhere to current best practices.

@emkll emkll added this to Next up in SecureDrop Team Board Dec 1, 2020
@emkll emkll self-assigned this Dec 2, 2020
@emkll emkll moved this from Next up to In Development in SecureDrop Team Board Dec 2, 2020
@eloquence eloquence removed this from In Development in SecureDrop Team Board Dec 15, 2020
@kushaldas kushaldas mentioned this issue Feb 26, 2021
27 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants