diff --git a/security.conf b/security.conf index 30b9f54d4ce6631c6872f4f9853b02d83e1f2538..65b9f671f9c837243c85bbcf2af88f293143fb9f 100644 --- a/security.conf +++ b/security.conf @@ -97,6 +97,10 @@ #CVE-2015-4000 121@m@/etc/ssh/sshd_config@KexAlgorithms@ curve25519-sha256,curve25519-sha256@@libssh.org,diffie-hellman-group-exchange-sha256 +122@m@/etc/ssh/sshd_config@HostbasedAcceptedKeytypes@ ssh-ed25519,ssh-ed25519-cert-v01@@openssh.com,rsa-sha2-256,rsa-sha2-512 +122@m@/etc/ssh/sshd_config@GSSAPIKexAlgorithms@ gss-group14-sha256-,gss-group16-sha512-,gss-curve25519-sha256- +122@m@/etc/ssh/sshd_config@CASignatureAlgorithms@ ssh-ed25519,sk-ssh-ed25519@@openssh.com,rsa-sha2-512,rsa-sha2-256 + 130@systemctl@sshd.service@restart ########################################################################