2015-08-20 08:37:43 +02:00
|
|
|
# My SSH config. This does leak existense of some hosts where I have
|
|
|
|
# access, but they should require SSH key authentication anyway.
|
|
|
|
|
|
|
|
Host *
|
2015-09-06 07:15:17 +02:00
|
|
|
# Path for the control socket.
|
2015-08-20 08:37:43 +02:00
|
|
|
ControlPath /tmp/SSH_%u-%r.%h.%p
|
2015-08-30 16:17:12 +02:00
|
|
|
# Multiple sessions over single connection
|
|
|
|
ControlMaster yes
|
2015-08-30 16:08:29 +02:00
|
|
|
# Keep connection open in the background even after connection has been
|
|
|
|
# closed.
|
2015-08-20 08:37:43 +02:00
|
|
|
ControlPersist yes
|
2015-08-30 16:08:29 +02:00
|
|
|
|
2015-08-20 08:37:43 +02:00
|
|
|
ForwardAgent no
|
|
|
|
ForwardX11 no
|
2015-08-30 16:08:29 +02:00
|
|
|
|
2015-08-30 16:17:12 +02:00
|
|
|
# Ensure KnownHosts are unreadable if leaked.
|
|
|
|
HashKnownHosts yes
|
|
|
|
|
2015-08-20 08:37:43 +02:00
|
|
|
LogLevel VERBOSE
|
|
|
|
Protocol 2
|
2015-08-30 16:08:29 +02:00
|
|
|
|
2015-09-06 07:15:17 +02:00
|
|
|
# Always try public key authentication.
|
2015-08-20 08:37:43 +02:00
|
|
|
PubkeyAuthentication yes
|
2015-08-30 16:08:29 +02:00
|
|
|
|
2015-09-06 06:30:11 +02:00
|
|
|
# Send LANG, LANGUAGE and LC_* environment variables to the server.
|
|
|
|
SendEnv LANG LANGUAGE LC_*
|
2015-09-05 22:46:00 +02:00
|
|
|
|
2015-09-01 14:54:05 +02:00
|
|
|
# If the server doesn't reply in "three" pings, connection is dead.
|
|
|
|
# Defaults to 3 anyway, but I add it here for clearity and
|
|
|
|
# in case it decides to change in the future.
|
|
|
|
ServerAliveCountMax 3
|
|
|
|
|
|
|
|
# "ping" the server every minute.
|
2015-08-20 08:37:43 +02:00
|
|
|
ServerAliveInterval 60
|
|
|
|
|
2015-09-02 07:15:16 +02:00
|
|
|
# OpenSSH 6.8+ - ask all host keys from servers.
|
|
|
|
# I trust the server admins and ways to identify the keys (DNSSEC,
|
2015-09-06 07:15:17 +02:00
|
|
|
# manual).
|
2015-09-02 07:15:16 +02:00
|
|
|
UpdateHostKeys yes
|
|
|
|
|
2015-08-30 16:17:12 +02:00
|
|
|
# Verify SSHFP records. In case DNSSEC is used this skips the
|
|
|
|
# question on whether you trust the fingerprint or not.
|
2015-09-02 07:15:16 +02:00
|
|
|
# All my hosts run DNSSEC validating Unbound on localhost and use it
|
|
|
|
# for all DNS queries. Yours should too.
|
|
|
|
VerifyHostKeyDNS yes
|
2015-08-30 16:17:12 +02:00
|
|
|
|
2015-08-20 08:37:43 +02:00
|
|
|
Host hilla
|
|
|
|
HostName hilla.kapsi.fi
|
2015-08-23 05:53:48 +02:00
|
|
|
User mikaela
|
2015-08-20 08:37:43 +02:00
|
|
|
|
|
|
|
Host lakka
|
|
|
|
HostName lakka.kapsi.fi
|
2015-08-23 05:53:48 +02:00
|
|
|
User mikaela
|
2015-08-20 08:37:43 +02:00
|
|
|
|
2015-09-01 16:14:06 +02:00
|
|
|
Host meetingology
|
|
|
|
HostName ubottu.com
|
|
|
|
User meetingology
|
|
|
|
|
2015-08-20 08:37:43 +02:00
|
|
|
Host synvaler
|
|
|
|
AddressFamily inet6
|
2015-08-30 16:17:12 +02:00
|
|
|
HostName synvaler.mikaela.info
|
2015-08-20 19:48:28 +02:00
|
|
|
User nemo
|
2015-08-23 05:53:48 +02:00
|
|
|
|
|
|
|
Host tezagm
|
|
|
|
HostName tezagm.mikaela.info
|
|
|
|
User mikaela
|
2015-08-30 16:17:12 +02:00
|
|
|
|
|
|
|
Host verdarik
|
|
|
|
HostName verdarik.mikaela.info
|
|
|
|
User mikaela
|