diff --git a/vars/Ubuntu_12.yml b/vars/Ubuntu_12.yml new file mode 100644 index 0000000..2e120ce --- /dev/null +++ b/vars/Ubuntu_12.yml @@ -0,0 +1,35 @@ +--- +sshd_service: ssh +sshd_packages: + - openssh-server +sshd_config_mode: "0644" +sshd_defaults: + Port: 22 + Protocol: 2 + HostKey: + - /etc/ssh/ssh_host_rsa_key + - /etc/ssh/ssh_host_dsa_key + - /etc/ssh/ssh_host_ecdsa_key + UsePrivilegeSeparation: yes + KeyRegenerationInterval: 3600 + ServerKeyBits: 768 + SyslogFacility: AUTH + LogLevel: INFO + LoginGraceTime: 120 + PermitRootLogin: yes + StrictModes: yes + RSAAuthentication: yes + PubkeyAuthentication: yes + IgnoreRhosts: yes + RhostsRSAAuthentication: no + HostbaseAuthentication: no + PermitEmptyPasswords: no + ChallengeResponseAuthentication: no + X11Forwarding: yes + X11DisplayOffset: 10 + PrintMotd: no + PrintLastLog: yes + TCPKeepAlive: yes + AcceptEnv: LANG LC_* + Subsystem: "sftp {{ sshd_sftp_server }}" + UsePAM: yes diff --git a/vars/Ubuntu.yml b/vars/Ubuntu_14.yml similarity index 97% rename from vars/Ubuntu.yml rename to vars/Ubuntu_14.yml index f485ab4..9e46d78 100644 --- a/vars/Ubuntu.yml +++ b/vars/Ubuntu_14.yml @@ -5,6 +5,7 @@ sshd_packages: - openssh-blacklist - openssh-blacklist-extra - openssh-sftp-server +sshd_config_mode: "0644" sshd_defaults: Port: 22 Protocol: 2