Browse Source

ovzdb: par defaut le cipher ssh est force a rsa, on le passe sur chacha20 pour plus de securite

master
victor héry 6 years ago
parent
commit
1676c900f0
1 changed files with 4 additions and 0 deletions
  1. +4
    -0
      roles/ovzdb/templates/openvz-diff-backups.conf.j2

+ 4
- 0
roles/ovzdb/templates/openvz-diff-backups.conf.j2 View File

@ -11,12 +11,16 @@ SERVER_TMPFS_SIZE="auto"
BACKUP_SSH_PATH="root@{{ backup_server }}:{{ backup_dir }}"
#compatibilite ovzdb > 0.9.3
MASTER_SSH_PATH="root@{{ backup_server }}:{{ backup_dir }}"
#changement du cypher SSH vers chacha pour plus de secu
MASTER_SSH_OPTIONS="ssh -p 22 -c chacha20-poly1305@openssh.com -o Compression=no -o ConnectTimeout=60 -o ControlMaster=auto -o ControlPath=/root/openvz-diff-backups_%r@%h:%p -o ControlPersist=3600 -o ForwardX11=no -o PasswordAuthentication=no -o PreferredAuthentications=publickey -o StrictHostKeyChecking=ask"
BACKUP_SKIP_STOPPED_CONTAINERS="all"
UPLOAD_SKIP_HOSTS=other
#compatibilite ovzdb < 0.9.2
UPLOAD_SSH_PATH="root@{{ upload_server }}:{{ upload_dir }}"
#compatibilite ovzdb > 0.9.3
REMOTE_SSH_PATH="root@{{ upload_server }}:{{ upload_dir }}"
#Changement du cyper ssh pour plus de secu
REMOTE_SSH_OPTIONS="ssh -p 22 -c chacha20-poly1305@openssh.com -o Compression=no -o ConnectTimeout=60 -o ControlMaster=auto -o ControlPath=/root/openvz-diff-backups_%r@%h:%p -o ControlPersist=3600 -o ForwardX11=no -o PasswordAuthentication=no -o PreferredAuthentications=publickey -o StrictHostKeyChecking=ask"
#possibilite de restaurer des backups de n'importe quel host
RESTORE_SKIP_HOSTS=""
#decommenter pour supprimer les backup de n'importe quel host

Loading…
Cancel
Save