Andy Ning 62ed634825 Remove sha1 based kex algorithms
This patch hardened server configuration including removing sha1 based
kex algorithms from the manifest template that puppet uses to generate
the configuration file sshd_config.

It also removed hardcoded sshd_config and ssh_config from repo, replaced
them with patches to openssh that harden both server and client
configuration.
This is particularly to address the requirements that the system should
be hardened from the very first boot up (before it is configured by
manifest apply)

It also removed old obsolete patch files in openssh directory to avoid
confusions.

Change-Id: I293d233c0ed12fef0c1d180cf357100d4aabc2ed
Signed-off-by: Andy Ning <andy.ning@windriver.com>
2018-06-28 15:21:33 -04:00

10 lines
359 B
Plaintext

spec-include-TiS-config-files.patch
sshd-pam-use-common-includes.patch
openssh-service-file.patch
openssh-spec-file-add-init.patch
0001-Update-package-versioning-for-TIS-format.patch
openssh-init-script-kill-old-instances-on-start.patch
0001-Further-parallelize-openssh-build.patch
spec-remove-TC-config-files.patch
spec-harden-server-and-client-config.patch