3 ms·
no, there might even be detriment Because of the way FreeBSD modifes openssh. OpenBSD might be an improvement to Ubuntu security wise.
by normaler 4y ago
no, there might even be detriment Because of the way FreeBSD modifes openssh. OpenBSD might be an improvement to Ubuntu security wise.
- nix23 4y agoNo openssl: https://www.wireguard.com/papers/zinzindohoue-bhargavan-protzenko-beurdouche-hacl-2017.pdf https://www.wireguard.com/papers/zinzindohoue-bhargavan-prot...
- normaler 4y agoI meant in the context of a Bastion ssh server, which is what the patent meant i think.
- nix23 4y agoThen just exchange the ssh-server with one in the ports, compile it with wolfssl, openssl-(devel?), libressl or mbed TLS, whatever you want. The stuff in base is meant to be compatible and as slim as possible (for example the kerberos-server in base). Or define the runtime options from the base-ssh-server in rc.conf (that's what i normally do): sshd_enable="YES" sshd_dsa_enable="NO" sshd_ecdsa_enable="NO" sshd_ed25519_enable="YES" sshd_rsa_enable="NO" If you want RSA=YES then you probably/maybe want to delete all moduli less then 4096. https://github.com/bsdlabs/ssh-hardening https://github.com/bsdlabs/ssh-hardening