diff --git a/roles/ovzdb/templates/openvz-diff-backups.conf.j2 b/roles/ovzdb/templates/openvz-diff-backups.conf.j2 index 375185e..83aa069 100644 --- a/roles/ovzdb/templates/openvz-diff-backups.conf.j2 +++ b/roles/ovzdb/templates/openvz-diff-backups.conf.j2 @@ -11,12 +11,16 @@ SERVER_TMPFS_SIZE="auto" BACKUP_SSH_PATH="root@{{ backup_server }}:{{ backup_dir }}" #compatibilite ovzdb > 0.9.3 MASTER_SSH_PATH="root@{{ backup_server }}:{{ backup_dir }}" +#changement du cypher SSH vers chacha pour plus de secu +MASTER_SSH_OPTIONS="ssh -p 22 -c chacha20-poly1305@openssh.com -o Compression=no -o ConnectTimeout=60 -o ControlMaster=auto -o ControlPath=/root/openvz-diff-backups_%r@%h:%p -o ControlPersist=3600 -o ForwardX11=no -o PasswordAuthentication=no -o PreferredAuthentications=publickey -o StrictHostKeyChecking=ask" BACKUP_SKIP_STOPPED_CONTAINERS="all" UPLOAD_SKIP_HOSTS=other #compatibilite ovzdb < 0.9.2 UPLOAD_SSH_PATH="root@{{ upload_server }}:{{ upload_dir }}" #compatibilite ovzdb > 0.9.3 REMOTE_SSH_PATH="root@{{ upload_server }}:{{ upload_dir }}" +#Changement du cyper ssh pour plus de secu +REMOTE_SSH_OPTIONS="ssh -p 22 -c chacha20-poly1305@openssh.com -o Compression=no -o ConnectTimeout=60 -o ControlMaster=auto -o ControlPath=/root/openvz-diff-backups_%r@%h:%p -o ControlPersist=3600 -o ForwardX11=no -o PasswordAuthentication=no -o PreferredAuthentications=publickey -o StrictHostKeyChecking=ask" #possibilite de restaurer des backups de n'importe quel host RESTORE_SKIP_HOSTS="" #decommenter pour supprimer les backup de n'importe quel host