FreeBSD src
Go to file
Conrad Meyer 858178a142 Remove insecure ciphers from GCE sshd configuration
They were added for unclear reasons in r277263.  The current OpenSSH
defaults (7.5+) are reasonable, and do not include the insecure rc4 cipher:

                   chacha20-poly1305@openssh.com,
                   aes128-ctr,aes192-ctr,aes256-ctr,
                   aes128-gcm@openssh.com,aes256-gcm@openssh.com,
                   aes128-cbc,aes192-cbc,aes256-cbc

I think I recall there being a reason for a specific list of ciphers on GCE
at the time, but I do not recall what it was, and cannot find any
current GCE documentation of such a list.

So, just revert the explicit configuration and use sane openssh defaults.

PR:		230092
Submitted by:	Gustavo Scalet <gustavo.scalet AT collabora.com>
MFC after:	3 days
Security:	yes
2018-07-28 19:35:49 +00:00
bin Describe how to prevent *.core files from being created using ulimit. 2018-07-19 13:09:29 +00:00
cddl Improve TCP related tests for dtrace. 2018-07-22 10:50:59 +00:00
contrib MFV r336800: libarchive: Cherry-pick upstream 2c8c83b9 2018-07-28 00:59:59 +00:00
crypto Merge upstream patch to unbreak tunnel forwarding. 2018-05-16 14:04:39 +00:00
etc Move apmd.conf to CONFS in usr.sbin/apmd which simplifies this nicely. 2018-07-26 16:51:23 +00:00
gnu Update libstdc++ configuration. 2018-07-16 18:53:28 +00:00
include msun: add ld80/ld128 powl, cpow, cpowf, cpowl from openbsd 2018-07-15 00:23:10 +00:00
kerberos5 Remove redundant space. 2018-07-10 00:26:13 +00:00
lib Clean up execl*(3) manual page prototype formatting 2018-07-28 19:08:00 +00:00
libexec Fix several Coverity warnings in tftp 2018-07-22 17:10:12 +00:00
release Remove insecure ciphers from GCE sshd configuration 2018-07-28 19:35:49 +00:00
rescue Avoid referencing private lib names directly. 2017-11-10 07:53:02 +00:00
sbin Convert bsd.files.mk to support DIRS and simplify by only having one install 2018-07-26 17:05:33 +00:00
secure Upgrade to OpenSSH 7.7p1. 2018-05-11 13:22:43 +00:00
share Remove npe.4. It was removed as part of the xscale removal. 2018-07-27 23:28:35 +00:00
stand Use % for printf, not a dollar sign 2018-07-27 22:35:07 +00:00
sys Use the cp15 functions to read cp15 registers rather than using assembly 2018-07-28 17:21:34 +00:00
targets Remove special cases for armeb in the build. 2018-07-17 23:23:54 +00:00
tests Fix compilation error on some arches after r336761 & r336781. 2018-07-28 02:53:36 +00:00
tools tools/build/beinstall.sh: Use some slightly better shell syntax; reduce duplication 2018-07-28 00:33:40 +00:00
usr.bin top(1): fix a buffer overflow copying states to display while they were incremented 2018-07-27 07:05:50 +00:00
usr.sbin Update nfsd.8 for support of IPv6 addresses for hosts in the "-p" option. 2018-07-27 23:38:31 +00:00
.arcconfig callsign isn't required anymore 2016-09-29 06:19:45 +00:00
.arclint arc lint: ignore /tests/ in chmod 2017-12-19 03:38:06 +00:00
.gitattributes .git*: add gitattributes and gitignore 2017-12-25 21:07:54 +00:00
.gitignore Ignore _.universe-toolchain file. 2018-07-01 13:50:37 +00:00
COPYRIGHT Remove 'All Rights Reserved' from the collection copyright and templates. 2018-05-09 02:02:49 +00:00
LOCKS LOCKS: update current locks 2018-06-09 03:08:04 +00:00
MAINTAINERS Add pointer to freebsd-numerics for libm. 2018-07-16 15:29:32 +00:00
Makefile As discussed several times on freebsd-arch, start to decommission armeb. 2018-07-17 23:23:34 +00:00
Makefile.inc1 Alpha-sort the list of user/group IDs to check at install time. 2018-07-22 16:51:11 +00:00
Makefile.libcompat Don't change directory owner to root when building with -DNO_ROOT 2018-06-29 21:15:26 +00:00
Makefile.sys.inc AUTO_OBJ: For all top-level targets enforce using an OBJDIR. 2017-12-05 21:29:47 +00:00
ObsoleteFiles.inc Add a few forgotten files to ObsoleteFiles.inc: 2018-07-25 17:14:05 +00:00
README README: add generic notes about GENERIC and NOTES 2018-06-17 19:44:24 +00:00
README.md README: add generic notes about GENERIC and NOTES 2018-06-17 19:44:24 +00:00
UPDATING Note ARM Atmel, Cavlium and XScale removal. 2018-07-27 21:40:05 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory. This file was last revised on: FreeBSD

FreeBSD is an operating system used to power modern servers, desktops, and embedded platforms. A large community has continually developed it for more than thirty years. Its advanced networking, security, and storage features have made FreeBSD the platform of choice for many of the busiest web sites and most pervasive embedded networking and storage devices.

For copyright information, please see the file COPYRIGHT in this directory. Additional copyright information also exists for some sources in this tree - please see the specific source directories for more information.

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7), config(8), https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html, and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html for more information, including setting make(1) variables.

Source Roadmap:

bin		System/user commands.

cddl		Various commands and libraries under the Common Development
		and Distribution License.

contrib		Packages contributed by 3rd parties.

crypto		Cryptography stuff (see crypto/README).

etc		Template files for /etc.

gnu		Various commands and libraries under the GNU Public License.
		Please see gnu/COPYING* for more information.

include		System include files.

kerberos5	Kerberos5 (Heimdal) package.

lib		System libraries.

libexec		System daemons.

release		Release building Makefile & associated tools.

rescue		Build system for statically linked /rescue utilities.

sbin		System commands.

secure		Cryptographic libraries and commands.

share		Shared resources.

stand		Boot loader sources.

sys		Kernel sources.

sys/<arch>/conf Kernel configuration files. GENERIC is the configuration
		used in release builds. NOTES contains documentation of
		all possible entries.

tests		Regression tests which can be run by Kyua.  See tests/README
		for additional information.

tools		Utilities for regression testing and miscellaneous tasks.

usr.bin		User commands.

usr.sbin	System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see:

https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/current-stable.html