Port 22
ListenAddress 0.0.0.0
-HostKey /etc/openssh/ssh_host_key
+HostKey /etc/ssh/ssh_host_key
ServerKeyBits 768
LoginGraceTime 600
KeyRegenerationInterval 3600
PermitRootLogin yes
-#
-# Don't read ~/.rhosts and ~/.shosts files
-IgnoreRhosts yes
StrictModes yes
-QuietMode no
-X11Forwarding yes
+X11Forwarding no
X11DisplayOffset 10
-FascistLogging no
PrintMotd yes
KeepAlive yes
+CheckMail no
+UseLogin no
+
+#
+# Loglevel replaces QuietMode and FascistLogging
+#
SyslogFacility AUTH
-RhostsAuthentication no
+LogLevel INFO
+
+#
+# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
#
-# For this to work you will also need host keys in /etc/openssh/ssh_known_hosts
RhostsRSAAuthentication no
+
#
+# Don't read ~/.rhosts and ~/.shosts files
+#
+IgnoreRhosts yes
+RhostsAuthentication no
+
+#
+# Uncomment if you don't trust ~/.ssh/known_hosts for RhostsRSAAuthentication
+#
+#IgnoreUserKnownHosts yes
+
RSAAuthentication yes
# To disable tunneled clear text passwords, change to no here!
PasswordAuthentication yes
PermitEmptyPasswords no
-# Uncomment to disable s/key passwords
+
+#
+# Uncomment to disable s/key passwords (must be compiled with s/key support)
+#
#SkeyAuthentication no
-# To change Kerberos options
+#
+# To change Kerberos options (must be compiled with Kerberos support)
+#
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#AFSTokenPassing no
#KerberosTicketCleanup no
-
# Kerberos TGT Passing does only work with the AFS kaserver
#KerberosTgtPassing yes
-
-#CheckMail yes
-#UseLogin no