[pve-devel] PATH V1: central cipher config

Stefan Priebe - Profihost AG s.priebe at profihost.ag
Wed Oct 31 10:13:32 CET 2012


Am 31.10.2012 09:47, schrieb Dietmar Maurer:
> Many thanks for that patch. But I am still unsure if we should go that way.
>
> I just found another option - /root/.ssh/config
>
> # man ssh_config
>
> What if we simply create that file if it does not exist?
>
>   - create /.ssh/config with reasonable value for Chiphers (blowfish first)
>   - remove hardcoded chiphers
>
> What do you think?

Good idea - i want to extent your idea. What about providing 
/etc/pve/ssh_config and then pass
-F /etc/pve/ssh_config to every ssh / scp command?

So we have a custom default ssh config only for pve.

Greets,
Stefan



More information about the pve-devel mailing list