Skip to content

Commit a7590e2

Browse files
author
Alexandros
committed
Reduce SSL login grace time
1 parent a35cf46 commit a7590e2

File tree

3 files changed

+12
-0
lines changed

3 files changed

+12
-0
lines changed

install/hst-install-debian.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -926,6 +926,10 @@ if [ ! -z "$sftp_subsys_enabled" ]; then
926926
sed -i -E "s/^#?.*Subsystem.+(sftp )?sftp-server/Subsystem sftp internal-sftp/g" /etc/ssh/sshd_config
927927
fi
928928

929+
# Reduce SSH login grace time
930+
sed -i "s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
931+
sed -i "s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
932+
929933
# Disable SSH suffix broadcast
930934
if [ -z "$(grep "^DebianBanner no" /etc/ssh/sshd_config)" ]; then
931935
echo '' >> /etc/ssh/sshd_config

install/hst-install-ubuntu.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -898,6 +898,10 @@ if [ ! -z "$sftp_subsys_enabled" ]; then
898898
sed -i -E "s/^#?.*Subsystem.+(sftp )?sftp-server/Subsystem sftp internal-sftp/g" /etc/ssh/sshd_config
899899
fi
900900

901+
# Reduce SSH login grace time
902+
sed -i "s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
903+
sed -i "s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
904+
901905
# Disable SSH suffix broadcast
902906
if [ -z "$(grep "^DebianBanner no" /etc/ssh/sshd_config)" ]; then
903907
echo '' >> /etc/ssh/sshd_config

install/upgrade/versions/latest.sh

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -18,6 +18,10 @@ mv /etc/ssl/dhparam.pem $HESTIA_BACKUP/conf/
1818
cp -f $HESTIA_INSTALL_DIR/ssl/dhparam.pem /etc/ssl/
1919
chmod 600 /etc/ssl/dhparam.pem
2020

21+
# Reduce SSH login grace time
22+
sed -i "s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
23+
sed -i "s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
24+
2125
# Enhance Vsftpd security
2226
echo "(*) Hardening Vsftpd SSL configuration..."
2327
cp -f /etc/vsftpd.conf $HESTIA_BACKUP/conf/

0 commit comments

Comments
 (0)