]> git.madduck.net Git - etc/ssh.git/commitdiff

madduck's git repository

Every one of the projects in this repository is available at the canonical URL git://git.madduck.net/madduck/pub/<projectpath> — see each project's metadata for the exact URL.

All patches and comments are welcome. Please squash your changes to logical commits before using git-format-patch and git-send-email to patches@git.madduck.net. If you'd read over the Git project's submission guidelines and adhered to them, I'd be especially grateful.

SSH access, as well as push access can be individually arranged.

If you use my repositories frequently, consider adding the following snippet to ~/.gitconfig and using the third clone URL listed for each project:

[url "git://git.madduck.net/madduck/"]
  insteadOf = madduck:

config file cleanup
authormartin f. krafft <madduck@madduck.net>
Thu, 12 Nov 2015 04:07:12 +0000 (17:07 +1300)
committermartin f. krafft <madduck@madduck.net>
Thu, 12 Nov 2015 04:07:12 +0000 (17:07 +1300)
.ssh/config.in

index c0322cd595c6b7dfe240504d9eec9144986e02c1..034ae113d4d4d080cb8bec2417cdbc2b9de4545d 100644 (file)
@@ -4,6 +4,10 @@ Host 127.0.0.1 | localhost
   ForwardX11Trusted yes
   NoHostAuthenticationForLocalhost yes
 
   ForwardX11Trusted yes
   NoHostAuthenticationForLocalhost yes
 
+Match host *.madduck.net
+  StrictHostKeyChecking ask
+  VerifyHostKeyDNS ask
+
 ### CHARADE KVM HOST
 
 Host charade.madduck.net | charade
 ### CHARADE KVM HOST
 
 Host charade.madduck.net | charade
@@ -276,6 +280,10 @@ Host *.virt | 192.168.122.* | red | green | blue | yellow | black | white | oran
 
 ### DEBIAN
 
 
 ### DEBIAN
 
+Match host *.debian.org
+  StrictHostKeyChecking ask
+  VerifyHostKeyDNS ask
+
 Host scm.alioth.debian.org
   HostKeyAlias moszumanska.debian.org
   User madduck
 Host scm.alioth.debian.org
   HostKeyAlias moszumanska.debian.org
   User madduck
@@ -924,63 +932,21 @@ Host github.com | github
 ### DEFAULTS
 
 Host *
 ### DEFAULTS
 
 Host *
-# AddressFamily any
-# BatchMode no
-# CheckHostIP yes
-  Cipher blowfish
-# Ciphers aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc,arcfour128,arcfour256,arcfour,aes192-cbc,aes256-cbc,aes128-ctr,aes192-ctr,aes256-ctr
-# ClearAllForwardings no
-# Compression no
-# CompressionLevel 6
-# ConnectionAttempts 1
+  IgnoreUnknown *
   ConnectTimeout 10
   ControlPath ~/.var/ssh/ssh_control_%l_%h_%p_%r
   ControlMaster auto
   ControlPersist 30
   ConnectTimeout 10
   ControlPath ~/.var/ssh/ssh_control_%l_%h_%p_%r
   ControlMaster auto
   ControlPersist 30
-## DSAAuthentication no
-# DynamicForward off
-# EnableSSHKeysign no
-# EscapeChar ~
   ExitOnForwardFailure yes
   ForwardAgent no
   ForwardX11 no
   ExitOnForwardFailure yes
   ForwardAgent no
   ForwardX11 no
-# ForwardX11Trusted yes
-# GatewayPorts no
-# GlobalKnownHostsFile /etc/ssh/ssh_known_hosts
+  ForwardX11Trusted no
   HashKnownHosts no
   HashKnownHosts no
-# HostbasedAuthentication no
-  HostKeyAlgorithms ssh-rsa
-# IdentityFile ~/.ssh/identity
-  IdentityFile2 ~/.ssh/id_rsa
-  IPQoS lowdelay throughput
-# KbdInteractiveDevices pam
-# LocalCommand none
-# LocalForward none
-# LogLevel INFO
-  MACs hmac-sha1,umac-64@openssh.com,hmac-ripemd160,hmac-sha1-96,hmac-md5,hmac-md5-96
-# NoHostAuthenticationForLocalhost no
   NumberOfPasswordPrompts 2
   PasswordAuthentication yes
   NumberOfPasswordPrompts 2
   PasswordAuthentication yes
-# PermitLocalCommand no
-# Port 22
-# PreferredAuthentications gssapi-with-mic,hostbased,publickey,keyboard-interactive,password
   Protocol 2
   Protocol 2
-# ProxyCommand
-# PubkeyAuthentication yes
-# RekeyLimit 1G-4G #depends on cipher
-# RemoteForward
-# RhostsRSAAuthentication no
-# RSAAuthentication no
-# ServerAliveCountMax 3
   ServerAliveInterval 45
   ServerAliveInterval 45
-  SetupTimeOut 10
-# SmartcardDevice off
   StrictHostKeyChecking yes
   StrictHostKeyChecking yes
-# TCPKeepAlive yes
-# Tunnel no
-# TunnelDevice any:any
-# UsePrivilegedPort no
-# UserKnownHostsFile ~/.ssh/known_hosts
-# VerifyHostKeyDNS no
+  UpdateHostKeys ask
+  VerifyHostKeyDNS ask
   VisualHostKey no
   VisualHostKey no
-# XAuthLocation /usr/X11R6/bin/xauth