scripts/ssh-config.sh

119 lines
3 KiB
Bash
Executable file

#!/bin/sh
UNAME=$(uname)
case ${UNAME} in
Linux)
if [ ${EUID} -ne 0 ]; then
echo "error: this script must be run as root" 1>&2
exit 1
fi
;;
OpenBSD|FreeBSD)
if [ $(id -u) -ne 0 ]; then
echo "error: this script must be run as root" 1>&2
exit 1
fi
;;
esac
echo "warning: this script will disable ssh password authentication"
read -p "continue? [y/N] " answer
if [ "${answer}" != "y" ]; then
exit 0
fi
echo "generating safe moduli"
if [ -f /etc/ssh/moduli ]; then
awk '$5 > 2000' /etc/ssh/moduli > /tmp/moduli
mv /tmp/moduli /etc/ssh/moduli
else
ssh-keygen -G /etc/ssh/moduli.all -b 4096
ssh-keygen -T /etc/ssh/moduli.safe -f /etc/ssh/moduli.all
mv /etc/ssh/moduli.safe /etc/ssh/moduli
rm /etc/ssh/moduli.all
fi
echo "cleaning ssh host keys"
rm /etc/ssh/ssh_host_*key*
ssh-keygen -t ed25519 -f /etc/ssh/ssh_host_ed25519_key < /dev/null
ssh-keygen -t rsa -b 4096 -f /etc/ssh/ssh_host_rsa_key < /dev/null
echo "writing ssh config"
if [ -f /etc/ssh/sshd_config ]; then
mv /etc/ssh/sshd_config /etc/ssh/sshd_config.bak
fi
cat << EOF > /etc/ssh/sshd_config
Port 22
Protocol 2
HostKey /etc/ssh/ssh_host_ed25519_key
HostKey /etc/ssh/ssh_host_rsa_key
KexAlgorithms curve25519-sha256@libssh.org,diffie-hellman-group-exchange-sha256
Ciphers chacha20-poly1305@openssh.com,aes256-gcm@openssh.com,aes128-gcm@openssh.com,aes256-ctr,aes192-ctr,aes128-ctr
MACs hmac-sha2-512-etm@openssh.com,hmac-sha2-256-etm@openssh.com,hmac-ripemd160-etm@openssh.com,umac-128-etm@openssh.com,hmac-sha2-512,hmac-sha2-256,hmac-ripemd160,umac-128@openssh.com
UsePrivilegeSeparation sandbox
PermitRootLogin no
RSAAuthentication no
PubkeyAuthentication yes
ChallengeResponseAuthentication no
PasswordAuthentication no
PrintMotd no
EOF
case ${UNAME} in
Linux)
cat << EOF >> /etc/ssh/sshd_config
AuthorizedKeysFile %h/.ssh/authorized_keys
Subsystem sftp /usr/lib/openssh/sftp-server
UsePAM yes
EOF
;;
OpenBSD|FreeBSD)
cat << EOF >> /etc/ssh/sshd_config
Subsystem sftp /usr/libexec/sftp-server
AuthorizedKeysFile .ssh/authorized_keys
EOF
;;
esac
read -p "enter your username " user
if [ -z "${user}" ]; then
echo "error: no user submitted" 1>&2
mv /etc/ssh/sshd_config.bak /etc/ssh/sshd_config
exit 1
fi
if [ ! -d /home/${user}/.ssh ]; then
mkdir /home/${user}/.ssh
fi
chmod 700 /home/${user}/.ssh
chown ${user}: /home/${user}/.ssh
read -p "paste your ssh public key " sshkey
if [ -z "${sshkey}" ]; then
echo "error: no ssh key submitted" 1>&2
mv /etc/ssh/sshd_config.bak /etc/ssh/sshd_config
exit 1
fi
echo "${sshkey}" > /home/${user}/.ssh/authorized_keys
chmod 600 /home/${user}/.ssh/authorized_keys
chown ${user}:root /home/${user}/.ssh/authorized_keys
case ${UNAME} in
Linux)
service ssh restart
;;
OpenBSD|FreeBSD)
/etc/rc.d/sshd restart
;;
esac
if [ -z "$(ps aux | awk '/\/usr\/s?bin\/sshd/')" ]; then
echo "error: ssh service failed to restart" 1>&2
echo "please check for sshd config errors manually" 1>&2
exit 1
fi