base_common is a role that provisions sensible defaults for Centos 7.
- The openssh-server is hardened to ssh-audit standards.
- This config removes the deprecated ssh-rsa host key
RHEL- like system
server:
install: true
packages:
- policycoreutils-python
- libsemanage-python
- postfix
# sshd
Ciphers: [email protected],[email protected],[email protected],aes256-ctr,aes192-ctr,aes128-ctr
HostKeyAlgorithms: [email protected],ssh-ed25519
KexAlgorithms: [email protected],diffie-hellman-group18-sha512,diffie-hellman-group16-sha512,diffie-hellman-group14-sha256
MACs: [email protected],[email protected],[email protected]
base_common is a role that other base roles can depend on.
Refer to a complete build server https://github.com/bbaassssiiee/buildserver
MIT
Bas Meijer @bbaassssiiee