From mboxrd@z Thu Jan 1 00:00:00 1970 Return-path: Received: from mail.pqgruber.com ([178.189.19.235]) by metis.ext.pengutronix.de with esmtps (TLS1.2:DHE_RSA_AES_256_CBC_SHA256:256) (Exim 4.80) (envelope-from ) id 1ZtLWL-00088p-OK for ptxdist@pengutronix.de; Mon, 02 Nov 2015 21:16:01 +0100 From: Clemens Gruber Date: Mon, 2 Nov 2015 21:15:35 +0100 Message-Id: <1446495335-22071-1-git-send-email-clemens.gruber@pqgruber.com> Subject: [ptxdist] [PATCH v2] openssh: harden security options and host keys List-Id: PTXdist Development Mailing List List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: ptxdist@pengutronix.de MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: ptxdist-bounces@pengutronix.de Sender: "ptxdist" To: ptxdist@pengutronix.de Cc: Clemens Gruber VGhlIHJjLm9uY2UuZCBzY3JpcHQgZ2VuZXJhdGVzIHRoZSBob3N0IGtleXMgd2hpY2ggYXJlIGVu YWJsZWQgaW4KdGhlIHNzZF9jb25maWcgZmlsZS4KRWQyNTUxOSBhbmQgUlNBIGFyZSB0aGUgZGVm YXVsdCBob3N0IGtleSBzaWduYXR1cmUgYWxnb3JpdGhtcyBhcwpib3RoIGRvIG5vdCBzb2xlbHkg cmVseSB1cG9uIGdvb2QgZW50cm9weSBzb3VyY2VzLgpEU0EgYW5kIEVDRFNBIGFyZSBub3QgcmVj b21tZW5kZWQgb24gZW1iZWRkZWQgc3lzdGVtcy4KVGhlIFNTSCBjb25maWd1cmF0aW9uIGlzIGhh cmRlbmVkOiBFbmFibGVkIHNhbmRib3hpbmcsIHJlZHVjZWQKbG9naW4gZ3JhY2UgdGltZSwgc3Ry aWN0IG1vZGUsIGV0Yy4KClNpZ25lZC1vZmYtYnk6IENsZW1lbnMgR3J1YmVyIDxjbGVtZW5zLmdy dWJlckBwcWdydWJlci5jb20+Ci0tLQoKQ2hhbmdlcyBmcm9tIHYxOgpDb3JyZWN0ZWQgYSBtaXN0 YWtlIGluIHRoZSBzZnRwIHBhdGguCgotLS0KIHByb2plY3Ryb290L2V0Yy9yYy5vbmNlLmQvb3Bl bnNzaCB8IDY4ICsrKysrKysrKysrKysrKysrKy0tLS0tLS0tLS0KIHByb2plY3Ryb290L2V0Yy9z c2gvc3NoZF9jb25maWcgICB8IDk1ICsrKysrKysrKysrKysrKysrKysrKystLS0tLS0tLS0tLS0t LS0tLQogMiBmaWxlcyBjaGFuZ2VkLCA5NyBpbnNlcnRpb25zKCspLCA2NiBkZWxldGlvbnMoLSkK CmRpZmYgLS1naXQgYS9wcm9qZWN0cm9vdC9ldGMvcmMub25jZS5kL29wZW5zc2ggYi9wcm9qZWN0 cm9vdC9ldGMvcmMub25jZS5kL29wZW5zc2gKaW5kZXggODNlNmUzNy4uNmVkM2IyMyAxMDA2NDQK LS0tIGEvcHJvamVjdHJvb3QvZXRjL3JjLm9uY2UuZC9vcGVuc3NoCisrKyBiL3Byb2plY3Ryb290 L2V0Yy9yYy5vbmNlLmQvb3BlbnNzaApAQCAtMSwzMyArMSw1MyBAQAogIyEvYmluL3NoCiAKLVBB VEg9L3Vzci9sb2NhbC9zYmluOi91c3IvbG9jYWwvYmluOi9zYmluOi9iaW46L3Vzci9zYmluOi91 c3IvYmluCitQQVRIPS9zYmluOi9iaW46L3Vzci9zYmluOi91c3IvYmluCiAKLU9QRU5TU0hfUlNB S0VZX0RFRkFVTFQ9Ii9ldGMvc3NoL3NzaF9ob3N0X3JzYV9rZXkiCi1PUEVOU1NIX0RTQUtFWV9E RUZBVUxUPSIvZXRjL3NzaC9zc2hfaG9zdF9kc2Ffa2V5IgotCi10ZXN0IC1uICIkT1BFTlNTSF9S U0FLRVkiIHx8IFwKLQlPUEVOU1NIX1JTQUtFWT0kT1BFTlNTSF9SU0FLRVlfREVGQVVMVAotdGVz dCAtbiAiJE9QRU5TU0hfRFNBS0VZIiB8fCBcCi0JT1BFTlNTSF9EU0FLRVk9JE9QRU5TU0hfRFNB S0VZX0RFRkFVTFQKLQotZ2VuX2tleSgpIHsKLQotCWtleV90eXBlPSQxCi0Ja2V5X2ZpbGU9JDIK LQotCXJtIC1mICRrZXlfZmlsZSA+IC9kZXYvbnVsbCAyPiYxCi0KLQllY2hvIC1uICJnZW5lcmF0 aW5nICRrZXlfdHlwZSBrZXkuLi4iCi0Jc3NoLWtleWdlbiAtdCAka2V5X3R5cGUgLWYgJGtleV9m aWxlIC1OICIiID4gL2Rldi9udWxsIDI+JjEKK2dldF9ob3N0a2V5cygpIHsKKwlbIC1mIC9ldGMv c3NoL3NzaGRfY29uZmlnIF0gfHwgcmV0dXJuCisJc2VkIC1uICdzL15Ib3N0S2V5WyBcdF1bIFx0 XSpcKC4qXCkvXDEvcCcgL2V0Yy9zc2gvc3NoZF9jb25maWcKK30KIAotCWlmIFsgIiQ/IiA9ICIw IiBdOyB0aGVuCi0JCWVjaG8gImRvbmUiCitob3N0X2tleXNfcmVxdWlyZWQoKSB7CisJaG9zdGtl eXM9IiQoZ2V0X2hvc3RrZXlzKSIKKwlpZiBbICIkaG9zdGtleXMiIF07IHRoZW4KKwkJZWNobyAi JGhvc3RrZXlzIgogCWVsc2UKLQkJZWNobyAiZmFpbGVkIgotCQlleGl0IDEKKwkJIyBObyBIb3N0 S2V5IGRpcmVjdGl2ZXMgZm91bmQsIHNvIHdlIHBpY2sgc2VjdXJlIGRlZmF1bHRzCisJCWVjaG8g L2V0Yy9zc2gvc3NoX2hvc3RfZWQyNTUxOV9rZXkKKwkJZWNobyAvZXRjL3NzaC9zc2hfaG9zdF9y c2Ffa2V5CiAJZmkKIH0KIAotZ2VuX2tleSByc2EgIiRPUEVOU1NIX1JTQUtFWSIKLWdlbl9rZXkg ZHNhICIkT1BFTlNTSF9EU0FLRVkiCitjcmVhdGVfa2V5KCkgeworCW1zZz0iJDEiCisJc2hpZnQK Kwlob3N0a2V5cz0iJDEiCisJc2hpZnQKKwlmaWxlPSIkMSIKKwlzaGlmdAorCisJaWYgZWNobyAi JGhvc3RrZXlzIiB8IGdyZXAgLXggIiRmaWxlIiA+L2Rldi9udWxsOyB0aGVuCisJCWVjaG8gIiRt c2c7IHRoaXMgbWF5IHRha2Ugc29tZSB0aW1lIC4uLiIKKwkJcm0gLWYgJGZpbGUgJiYKKwkJc3No LWtleWdlbiAtcSAtZiAiJGZpbGUiIC1OICcnICIkQCIgfHwgcmV0dXJuCisJCWVjaG8gIiRtc2c7 IGRvbmUuIgorCWZpCit9CisKK2NyZWF0ZV9rZXlzKCkgeworCWhvc3RrZXlzPSIkKGhvc3Rfa2V5 c19yZXF1aXJlZCkiCisKKwljcmVhdGVfa2V5ICJDcmVhdGluZyBEU0Ega2V5IiBcCisJCSIkaG9z dGtleXMiIC9ldGMvc3NoL3NzaF9ob3N0X2RzYV9rZXkgLXQgZHNhICYmCisJY3JlYXRlX2tleSAi Q3JlYXRpbmcgRUNEU0Ega2V5IiBcCisJCSIkaG9zdGtleXMiIC9ldGMvc3NoL3NzaF9ob3N0X2Vj ZHNhX2tleSAtdCBlY2RzYSAmJgorCWNyZWF0ZV9rZXkgIkNyZWF0aW5nIEVEMjU1MTkga2V5IiBc CisJCSIkaG9zdGtleXMiIC9ldGMvc3NoL3NzaF9ob3N0X2VkMjU1MTlfa2V5IC10IGVkMjU1MTkg JiYKKwljcmVhdGVfa2V5ICJDcmVhdGluZyBSU0Ega2V5IiBcCisJCSIkaG9zdGtleXMiIC9ldGMv c3NoL3NzaF9ob3N0X3JzYV9rZXkgLXQgcnNhCit9CiAKK2lmICEgY3JlYXRlX2tleXM7IHRoZW4K KwllY2hvICJHZW5lcmF0aW5nIFNTSCBrZXlzIGZhaWxlZCEiCisJZXhpdCAxCitmaQpkaWZmIC0t Z2l0IGEvcHJvamVjdHJvb3QvZXRjL3NzaC9zc2hkX2NvbmZpZyBiL3Byb2plY3Ryb290L2V0Yy9z c2gvc3NoZF9jb25maWcKaW5kZXggN2NkNzg5Ny4uODBjZTU4MCAxMDA2NDQKLS0tIGEvcHJvamVj dHJvb3QvZXRjL3NzaC9zc2hkX2NvbmZpZworKysgYi9wcm9qZWN0cm9vdC9ldGMvc3NoL3NzaGRf Y29uZmlnCkBAIC0xLDUzICsxLDUyIEBACi0jCSRPcGVuQlNEOiBzc2hkX2NvbmZpZyx2IDEuNzMg MjAwNS8xMi8wNiAyMjozODoyOCByZXlrIEV4cCAkCi0KLSMgVGhpcyBpcyB0aGUgc3NoZCBzZXJ2 ZXIgc3lzdGVtLXdpZGUgY29uZmlndXJhdGlvbiBmaWxlLiAgU2VlCi0jIHNzaGRfY29uZmlnKDUp IGZvciBtb3JlIGluZm9ybWF0aW9uLgotCi0jIFRoaXMgc3NoZCB3YXMgY29tcGlsZWQgd2l0aCBQ QVRIPS91c3IvYmluOi9iaW46L3Vzci9zYmluOi9zYmluCisjIFRoaXMgaXMgdGhlIHNzaGQgc2Vy dmVyIHN5c3RlbS13aWRlIGNvbmZpZ3VyYXRpb24gZmlsZS4KIAogIyBUaGUgc3RyYXRlZ3kgdXNl ZCBmb3Igb3B0aW9ucyBpbiB0aGUgZGVmYXVsdCBzc2hkX2NvbmZpZyBzaGlwcGVkIHdpdGgKICMg T3BlblNTSCBpcyB0byBzcGVjaWZ5IG9wdGlvbnMgd2l0aCB0aGVpciBkZWZhdWx0IHZhbHVlIHdo ZXJlCi0jIHBvc3NpYmxlLCBidXQgbGVhdmUgdGhlbSBjb21tZW50ZWQuICBVbmNvbW1lbnRlZCBv cHRpb25zIGNoYW5nZSBhCisjIHBvc3NpYmxlLCBidXQgbGVhdmUgdGhlbSBjb21tZW50ZWQuIFVu Y29tbWVudGVkIG9wdGlvbnMgb3ZlcnJpZGUgdGhlCiAjIGRlZmF1bHQgdmFsdWUuCisjIEFsdGVy bmF0aXZlIG9wdGlvbnMgd2hpY2ggYXJlIG5vdCBvbiBieSBkZWZhdWx0IGFyZSBjb21tZW50ZWQg b3V0IHdpdGggIyMuCisKKyMgTm90ZTogT25seSBTU0ggcHJvdG9jb2wgdmVyc2lvbiAyIGlzIHN1 cHBvcnRlZC4KIAotUG9ydCAyMgotUHJvdG9jb2wgMgorI1BvcnQgMjIKICNBZGRyZXNzRmFtaWx5 IGFueQogI0xpc3RlbkFkZHJlc3MgMC4wLjAuMAogI0xpc3RlbkFkZHJlc3MgOjoKIAotIyBIb3N0 S2V5IGZvciBwcm90b2NvbCB2ZXJzaW9uIDEKLSNIb3N0S2V5IC9ldGMvc3NoL3NzaF9ob3N0X2tl eQotIyBIb3N0S2V5cyBmb3IgcHJvdG9jb2wgdmVyc2lvbiAyCisjIEhvc3Qga2V5cwogSG9zdEtl eSAvZXRjL3NzaC9zc2hfaG9zdF9yc2Ffa2V5Ci1Ib3N0S2V5IC9ldGMvc3NoL3NzaF9ob3N0X2Rz YV9rZXkKK0hvc3RLZXkgL2V0Yy9zc2gvc3NoX2hvc3RfZWQyNTUxOV9rZXkKIAotIyBMaWZldGlt ZSBhbmQgc2l6ZSBvZiBlcGhlbWVyYWwgdmVyc2lvbiAxIHNlcnZlciBrZXkKLSNLZXlSZWdlbmVy YXRpb25JbnRlcnZhbCAxaAotI1NlcnZlcktleUJpdHMgNzY4CisjIERTQSBhbmQgRUNEU0EgaG9z dCBrZXlzIChOb3QgcmVjb21tZW5kZWQpCisjI0hvc3RLZXkgL2V0Yy9zc2gvc3NoX2hvc3RfZHNh X2tleQorIyNIb3N0S2V5IC9ldGMvc3NoL3NzaF9ob3N0X2VjZHNhX2tleQorCisjIENpcGhlcnMg YW5kIGtleWluZworI1Jla2V5TGltaXQgZGVmYXVsdCBub25lCiAKICMgTG9nZ2luZwotIyBvYnNv bGV0ZXMgUXVpZXRNb2RlIGFuZCBGYXNjaXN0TG9nZ2luZwogI1N5c2xvZ0ZhY2lsaXR5IEFVVEgK ICNMb2dMZXZlbCBJTkZPCiAKICMgQXV0aGVudGljYXRpb246Ci0KLSNMb2dpbkdyYWNlVGltZSAy bQorTG9naW5HcmFjZVRpbWUgMW0KIFBlcm1pdFJvb3RMb2dpbiB5ZXMKLSNTdHJpY3RNb2RlcyB5 ZXMKK1N0cmljdE1vZGVzIHllcwogI01heEF1dGhUcmllcyA2CisjTWF4U2Vzc2lvbnMgMTAKIAog I1JTQUF1dGhlbnRpY2F0aW9uIHllcwogI1B1YmtleUF1dGhlbnRpY2F0aW9uIHllcwotI0F1dGhv cml6ZWRLZXlzRmlsZQkuc3NoL2F1dGhvcml6ZWRfa2V5cworCitBdXRob3JpemVkS2V5c0ZpbGUg LnNzaC9hdXRob3JpemVkX2tleXMKKyNBdXRob3JpemVkS2V5c0NvbW1hbmQgbm9uZQorI0F1dGhv cml6ZWRLZXlzQ29tbWFuZFVzZXIgbm9ib2R5CisjQXV0aG9yaXplZFByaW5jaXBhbHNGaWxlIG5v bmUKIAogIyBGb3IgdGhpcyB0byB3b3JrIHlvdSB3aWxsIGFsc28gbmVlZCBob3N0IGtleXMgaW4g L2V0Yy9zc2gvc3NoX2tub3duX2hvc3RzCi0jUmhvc3RzUlNBQXV0aGVudGljYXRpb24gbm8KLSMg c2ltaWxhciBmb3IgcHJvdG9jb2wgdmVyc2lvbiAyCiAjSG9zdGJhc2VkQXV0aGVudGljYXRpb24g bm8KICMgQ2hhbmdlIHRvIHllcyBpZiB5b3UgZG9uJ3QgdHJ1c3Qgfi8uc3NoL2tub3duX2hvc3Rz IGZvcgotIyBSaG9zdHNSU0FBdXRoZW50aWNhdGlvbiBhbmQgSG9zdGJhc2VkQXV0aGVudGljYXRp b24KKyMgSG9zdGJhc2VkQXV0aGVudGljYXRpb24KICNJZ25vcmVVc2VyS25vd25Ib3N0cyBubwog IyBEb24ndCByZWFkIHRoZSB1c2VyJ3Mgfi8ucmhvc3RzIGFuZCB+Ly5zaG9zdHMgZmlsZXMKICNJ Z25vcmVSaG9zdHMgeWVzCkBAIC02OCwzOCArNjcsNTAgQEAgUGVybWl0Um9vdExvZ2luIHllcwog IyBHU1NBUEkgb3B0aW9ucwogI0dTU0FQSUF1dGhlbnRpY2F0aW9uIG5vCiAjR1NTQVBJQ2xlYW51 cENyZWRlbnRpYWxzIHllcwotCi0jIFNldCB0aGlzIHRvICd5ZXMnIHRvIGVuYWJsZSBQQU0gYXV0 aGVudGljYXRpb24sIGFjY291bnQgcHJvY2Vzc2luZywgCi0jIGFuZCBzZXNzaW9uIHByb2Nlc3Np bmcuIElmIHRoaXMgaXMgZW5hYmxlZCwgUEFNIGF1dGhlbnRpY2F0aW9uIHdpbGwgCi0jIGJlIGFs bG93ZWQgdGhyb3VnaCB0aGUgQ2hhbGxlbmdlUmVzcG9uc2VBdXRoZW50aWNhdGlvbiBtZWNoYW5p c20uIAotIyBEZXBlbmRpbmcgb24geW91ciBQQU0gY29uZmlndXJhdGlvbiwgdGhpcyBtYXkgYnlw YXNzIHRoZSBzZXR0aW5nIG9mIAotIyBQYXNzd29yZEF1dGhlbnRpY2F0aW9uLCBQZXJtaXRFbXB0 eVBhc3N3b3JkcywgYW5kIAotIyAiUGVybWl0Um9vdExvZ2luIHdpdGhvdXQtcGFzc3dvcmQiLiBJ ZiB5b3UganVzdCB3YW50IHRoZSBQQU0gYWNjb3VudCBhbmQgCi0jIHNlc3Npb24gY2hlY2tzIHRv IHJ1biB3aXRob3V0IFBBTSBhdXRoZW50aWNhdGlvbiwgdGhlbiBlbmFibGUgdGhpcyBidXQgc2V0 IAotIyBDaGFsbGVuZ2VSZXNwb25zZUF1dGhlbnRpY2F0aW9uPW5vCisjR1NTQVBJU3RyaWN0QWNj ZXB0b3JDaGVjayB5ZXMKKyNHU1NBUElLZXlFeGNoYW5nZSBubworCisjIFNldCB0aGlzIHRvICd5 ZXMnIHRvIGVuYWJsZSBQQU0gYXV0aGVudGljYXRpb24sIGFjY291bnQgcHJvY2Vzc2luZywKKyMg YW5kIHNlc3Npb24gcHJvY2Vzc2luZy4gSWYgdGhpcyBpcyBlbmFibGVkLCBQQU0gYXV0aGVudGlj YXRpb24gd2lsbAorIyBiZSBhbGxvd2VkIHRocm91Z2ggdGhlIENoYWxsZW5nZVJlc3BvbnNlQXV0 aGVudGljYXRpb24gYW5kCisjIFBhc3N3b3JkQXV0aGVudGljYXRpb24uICBEZXBlbmRpbmcgb24g eW91ciBQQU0gY29uZmlndXJhdGlvbiwKKyMgUEFNIGF1dGhlbnRpY2F0aW9uIHZpYSBDaGFsbGVu Z2VSZXNwb25zZUF1dGhlbnRpY2F0aW9uIG1heSBieXBhc3MKKyMgdGhlIHNldHRpbmcgb2YgIlBl cm1pdFJvb3RMb2dpbiB3aXRob3V0LXBhc3N3b3JkIi4KKyMgSWYgeW91IGp1c3Qgd2FudCB0aGUg UEFNIGFjY291bnQgYW5kIHNlc3Npb24gY2hlY2tzIHRvIHJ1biB3aXRob3V0CisjIFBBTSBhdXRo ZW50aWNhdGlvbiwgdGhlbiBlbmFibGUgdGhpcyBidXQgc2V0IFBhc3N3b3JkQXV0aGVudGljYXRp b24KKyMgYW5kIENoYWxsZW5nZVJlc3BvbnNlQXV0aGVudGljYXRpb24gdG8gJ25vJy4KICNVc2VQ QU0gbm8KIAorI0FsbG93QWdlbnRGb3J3YXJkaW5nIHllcwogI0FsbG93VGNwRm9yd2FyZGluZyB5 ZXMKICNHYXRld2F5UG9ydHMgbm8KICNYMTFGb3J3YXJkaW5nIG5vCiAjWDExRGlzcGxheU9mZnNl dCAxMAogI1gxMVVzZUxvY2FsaG9zdCB5ZXMKKyNQZXJtaXRUVFkgeWVzCiAjUHJpbnRNb3RkIHll cwogI1ByaW50TGFzdExvZyB5ZXMKICNUQ1BLZWVwQWxpdmUgeWVzCiAjVXNlTG9naW4gbm8KLSNV c2VQcml2aWxlZ2VTZXBhcmF0aW9uIHllcworVXNlUHJpdmlsZWdlU2VwYXJhdGlvbiBzYW5kYm94 CiAjUGVybWl0VXNlckVudmlyb25tZW50IG5vCiAjQ29tcHJlc3Npb24gZGVsYXllZAogI0NsaWVu dEFsaXZlSW50ZXJ2YWwgMAogI0NsaWVudEFsaXZlQ291bnRNYXggMwotI1VzZUROUyB5ZXMKKyNV c2VETlMgbm8KICNQaWRGaWxlIC92YXIvcnVuL3NzaGQucGlkCi0jTWF4U3RhcnR1cHMgMTAKK01h eFN0YXJ0dXBzIDEwOjMwOjYwCiAjUGVybWl0VHVubmVsIG5vCi0KLSMgbm8gZGVmYXVsdCBiYW5u ZXIgcGF0aAotI0Jhbm5lciAvc29tZS9wYXRoCi0KLSMgb3ZlcnJpZGUgZGVmYXVsdCBvZiBubyBz dWJzeXN0ZW1zCi1TdWJzeXN0ZW0Jc2Z0cAkvdXNyL3NiaW4vc2Z0cC1zZXJ2ZXIKKyNDaHJvb3RE aXJlY3Rvcnkgbm9uZQorI1ZlcnNpb25BZGRlbmR1bSBub25lCisjQmFubmVyIG5vbmUKKworIyBE aXNhYmxlIFRDUEtlZXBBbGl2ZSB0byBwcmV2ZW50IFRDUCBzcG9vZmluZyBhdHRhY2tzLiBJdCBp cyByZXBsYWNlZCBieQorIyBDbGllbnRBbGl2ZUludGVydmFsLCB3aGljaCBzZW5kcyBhIG51bGwg cGFja2V0IGV2ZXJ5IDYwIHNlY29uZHMgb3ZlciB0aGUKKyMgZW5jcnlwdGVkIGNoYW5uZWwuIFVu cmVzcG9uc2l2ZSBjbGllbnRzIGFyZSBkaXNjb25uZWN0ZWQgYWZ0ZXIgMyBtaW51dGVzLgorIyNU Q1BLZWVwQWxpdmUgbm8KKyMjQ2xpZW50QWxpdmVJbnRlcnZhbCA2MAorIyNDbGllbnRBbGl2ZUNv dW50TWF4IDMKKworIyBFbmFibGUgdGhlIFNTSCBGaWxlIFRyYW5zZmVyIFByb3RvY29sCitTdWJz eXN0ZW0gc2Z0cCAvdXNyL3NiaW4vc2Z0cC1zZXJ2ZXIKLS0gCjIuNi4yCgoKLS0gCnB0eGRpc3Qg bWFpbGluZyBsaXN0CnB0eGRpc3RAcGVuZ3V0cm9uaXguZGUK