File tree Expand file tree Collapse file tree 3 files changed +12
-0
lines changed
Expand file tree Collapse file tree 3 files changed +12
-0
lines changed Original file line number Diff line number Diff line change @@ -926,6 +926,10 @@ if [ ! -z "$sftp_subsys_enabled" ]; then
926926 sed -i -E " s/^#?.*Subsystem.+(sftp )?sftp-server/Subsystem sftp internal-sftp/g" /etc/ssh/sshd_config
927927fi
928928
929+ # Reduce SSH login grace time
930+ sed -i " s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
931+ sed -i " s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
932+
929933# Disable SSH suffix broadcast
930934if [ -z " $( grep " ^DebianBanner no" /etc/ssh/sshd_config) " ]; then
931935 echo ' ' >> /etc/ssh/sshd_config
Original file line number Diff line number Diff line change @@ -898,6 +898,10 @@ if [ ! -z "$sftp_subsys_enabled" ]; then
898898 sed -i -E " s/^#?.*Subsystem.+(sftp )?sftp-server/Subsystem sftp internal-sftp/g" /etc/ssh/sshd_config
899899fi
900900
901+ # Reduce SSH login grace time
902+ sed -i " s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
903+ sed -i " s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
904+
901905# Disable SSH suffix broadcast
902906if [ -z " $( grep " ^DebianBanner no" /etc/ssh/sshd_config) " ]; then
903907 echo ' ' >> /etc/ssh/sshd_config
Original file line number Diff line number Diff line change @@ -18,6 +18,10 @@ mv /etc/ssl/dhparam.pem $HESTIA_BACKUP/conf/
1818cp -f $HESTIA_INSTALL_DIR /ssl/dhparam.pem /etc/ssl/
1919chmod 600 /etc/ssl/dhparam.pem
2020
21+ # Reduce SSH login grace time
22+ sed -i " s/LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
23+ sed -i " s/#LoginGraceTime 2m/LoginGraceTime 1m/g" /etc/ssh/sshd_config
24+
2125# Enhance Vsftpd security
2226echo " (*) Hardening Vsftpd SSL configuration..."
2327cp -f /etc/vsftpd.conf $HESTIA_BACKUP /conf/
You can’t perform that action at this time.
0 commit comments