diff options
Diffstat (limited to 'templates/sshd_config/Gentoo.erb')
| -rw-r--r-- | templates/sshd_config/Gentoo.erb | 12 | 
1 files changed, 7 insertions, 5 deletions
diff --git a/templates/sshd_config/Gentoo.erb b/templates/sshd_config/Gentoo.erb index 2112f0d..f9f5b23 100644 --- a/templates/sshd_config/Gentoo.erb +++ b/templates/sshd_config/Gentoo.erb @@ -14,14 +14,12 @@  <%= sshd_head_additional_options %>  <%- end %> -<%- unless sshd_port.to_s.empty? then -%> -<%- if sshd_port.to_s == 'off' then -%> +<%- sshd_ports.each do |port| -%> +<%- if port.to_s == 'off' then -%>  #Port -- disabled by puppet  <% else -%> -Port <%= sshd_port -%> +Port <%= port %>  <% end -%> -<%- else -%> -Port 22  <%- end -%>  # Use these options to restrict which interfaces/protocols sshd will bind to @@ -210,6 +208,10 @@ AllowUsers <%= sshd_allowed_users %>  AllowGroups <%= sshd_allowed_groups %>  <%- end %> +<%- if sshd_hardened_ssl.to_s == 'yes' then -%> +Ciphers aes256-ctr +MACs hmac-sha1 +<%- end -%>  <%- unless sshd_tail_additional_options.to_s.empty? then %>  <%= sshd_tail_additional_options %>  | 
