mirror of
https://github.com/imthenachoman/How-To-Secure-A-Linux-Server.git
synced 2026-10-02 20:44:47 +02:00
Update SSH Compression recommendation to reflect modern OpenSSH behavior
OpenSSH moved to delayed (post-authentication) compression by default in 6.7, and removed pre-authentication compression support entirely in 7.4 (2016). The compression-oracle attack surface that motivated the original `Compression no` recommendation no longer exists on any currently supported OpenSSH version, so `Compression yes` is safe. Fixes #117
This commit is contained in:
1 parent
21492c2507
commit
aa9160adc9
1 file changed
+5
-1
@@ -573,7 +573,11 @@ SSH is a door into your server. This is especially true if you are opening ports
|
||||
# verify hostname matches IP
|
||||
UseDNS yes
|
||||
|
||||
Compression no
|
||||
# OpenSSH only supports delayed (post-authentication) compression since
|
||||
# 6.7, and removed pre-auth compression support entirely in 7.4 (2016),
|
||||
# so the old compression-oracle attack surface this setting guarded
|
||||
# against no longer exists on any currently supported OpenSSH version
|
||||
Compression yes
|
||||
|
||||
# TCP keepalive is spoofable (runs outside the encrypted channel)
|
||||
# Use ClientAlive instead (runs inside the encrypted channel)
|
||||
|
||||
Reference in new issue
Block a user