blob: 1bc8a330893702ad03ae8ebbdda18d20e4555ec1 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
|
Template: openssh-server/permit-root-login
Type: boolean
Default: false
_Description: Disable SSH password authentication for root?
Previous versions of openssh-server permitted logging in as root over SSH
using password authentication. The default for new installations is now
"PermitRootLogin prohibit-password", which disables password authentication
for root without breaking systems that have explicitly configured SSH
public key authentication for root.
.
This change makes systems more secure against brute-force password
dictionary attacks on the root user (a very common target for such
attacks). However, it may break systems that are set up with the
expectation of being able to SSH as root using password authentication. You
should only make this change if you do not need to do that.
|