commit 13445d6433ac51374c640fe3eb3dc136f533ed0e Author: ston1th Date: Wed Jun 24 19:56:05 2015 +0200 initial commit diff --git a/README.md b/README.md new file mode 100644 index 0000000..410ee56 --- /dev/null +++ b/README.md @@ -0,0 +1,3 @@ +# GiftFish Scripts + +A collection of some useful scripts diff --git a/ssh-config.sh b/ssh-config.sh new file mode 100755 index 0000000..5c46f55 --- /dev/null +++ b/ssh-config.sh @@ -0,0 +1,97 @@ +#!/bin/bash + +if [ ${EUID} -ne 0 ]; then + echo "this script must be run as root" 1>&2 + exit 1 +fi + +echo "warning: this script will disable ssh password authentication" +echo -n "contine? [y/N] " +read answer + +if [ "${answer}" != "y" ]; then + exit 0 +fi + +echo "generating safe moduli" +if [ -f /etc/ssh/moduli ]; then + awk '$5 > 2000' /etc/ssh/moduli > /tmp/moduli + mv /tmp/moduli /etc/ssh/moduli +else + ssh-keygen -G /etc/ssh/moduli.all -b 4096 + ssh-keygen -T /etc/ssh/moduli.safe -f /etc/ssh/moduli.all + mv /etc/ssh/moduli.safe /etc/ssh/moduli + rm /etc/ssh/moduli.all +fi + +echo "cleaning ssh host keys" +rm /etc/ssh/ssh_host_*key* +ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key < /dev/null +ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key < /dev/null + +echo "writing ssh config" +if [ -f /etc/ssh/sshd_config ]; then + mv /etc/ssh/sshd_config /etc/ssh/sshd_config.bak +fi + +cat < /etc/ssh/sshd_config +Port 22 +Protocol 2 +HostKey /etc/ssh/ssh_host_ed25519_key +HostKey /etc/ssh/ssh_host_rsa_key +KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256 +Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr +MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-ripemd160-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160,umac-128@openssh.com +UsePrivilegeSeparation yes +SyslogFacility AUTH +LogLevel INFO +LoginGraceTime 120 +PermitRootLogin no +StrictModes yes +RSAAuthentication no +PubkeyAuthentication yes +AuthorizedKeysFile %h/.ssh/authorized_keys +IgnoreRhosts yes +RhostsRSAAuthentication no +HostbasedAuthentication no +PermitEmptyPasswords no +ChallengeResponseAuthentication no +PasswordAuthentication no +X11Forwarding no +PrintMotd no +PrintLastLog yes +TCPKeepAlive yes +AcceptEnv LANG LC_* +Subsystem sftp /usr/lib/openssh/sftp-server +UsePAM yes +EOF + +echo "enter your username" +read user + +if [ -z ${user} ]; then + echo "error: no user submitted" 1>&2 + mv /etc/ssh/sshd_config.bak /etc/ssh/sshd_config + exit 1 +fi + +if [ ! -d /home/${user}/.ssh ]; then + mkdir /home/${user}/.ssh +fi +chmod 700 /home/${user}/.ssh +chown ${user}: /home/${user}/.ssh + +echo "paste your ssh public key" +read sshkey + +if [ -z ${sshkey} ]; then + echo "error: no ssh key submitted" 1>&2 + mv /etc/ssh/sshd_config.bak /etc/ssh/sshd_config + exit 1 +fi + +echo "${sshkey}" > /home/${user}/.ssh/authorized_keys +chmod 600 /home/${user}/.ssh/authorized_keys +chown ${user}:root /home/${user}/.ssh/authorized_keys + +service ssh restart