V8.00.000.2025.06.17
Signed-off-by: Marc S. Weidner <msw@coresecret.dev>
This commit is contained in:
@@ -372,13 +372,20 @@ ntp:
|
||||
################################################################################################################################
|
||||
user:
|
||||
allow_policies: true # For additional hardening of SSH connections '/etc/hosts.allow'.
|
||||
# If "allow_policies" = "true", at least one IP MUST be provided:
|
||||
allow_ipv4:
|
||||
# If "allow_policies" = "true", at least one 'bastion_ipv4' MUST be provided.
|
||||
# One or multiple Domains could be provided as well 'allow_domain'.
|
||||
bastion_enable: false # In case 'bastion_ipv4' and 'bastion_ipv6' are SSH Bastion IPs set this to "true".
|
||||
# If these are Jump Server and / or static VPN-Exit-Nodes, set this to "false".
|
||||
bastion_ipv4: # Provide Bastion / Jump-Server / static VPN-Exit-Nodes IPv4.
|
||||
- 202.61.246.50
|
||||
allow_ipv6:
|
||||
bastion_ipv6: # Provide Bastion / Jump-Server / static VPN-Exit-Nodes IPv6.
|
||||
- 2a03:4000:53:f:abcd:9494:0:2
|
||||
allow_domain: # Provide Bastion / Jump-Server / static VPN-Exit-Nodes Domains.
|
||||
- vpn00.x448.eu
|
||||
dropbear_boot: true # Dropbear initramfs integration.
|
||||
dropbear_dhcp: true # Whether the '/etc/initramfs-tools/conf.d/ip' file should be configured statically or via DHCP.
|
||||
dropbear_fw: true # Additional ultra hardening of the dropbear initramfs environment via firewall.
|
||||
# The "bastion_ipv4" MUST be provided.
|
||||
ssh_port: 42137 # SSH Port. In case "dropbear_boot" = "true" the same SSH Port will be used.
|
||||
ssh_rootca: "/.preseed/ssh_root_ca.pub"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user