Use ~/.ssh/config

Stephan Verbücheln <[email protected]> Tue, 13 May 2025 12:11:24 +0000
Newsgroups gmane.linux.debian.devel.security
Message-ID <[email protected]>
On Tue, 2025-05-13 at 11:39 +0100, Chris Boot wrote:
> I don't think that your software _should_ offer cipher selection
> options to override SSH defaults at all, instead just using the
> default options.

I second this. This way, the secure defaults will evolve over time with
future releases of OpenSSH and Debian.

If necessary, I recommend to define non-default settings on a per-host
basis in:

  ~/.ssh/config

This is out of scope for rsync and Back in Time.

Regards
Stephan
signature.asc (application/pgp-signature, 228 B)
-----BEGIN PGP SIGNATURE-----

iHUEABYKAB0WIQRB1rjSpCJd8a7h6mNgNUJZCjx8YgUCaCM27AAKCRBgNUJZCjx8
Yv7hAQDOFtWmFwhgdiANk+OQTQvAruLKyLeVOYTFwwuGFgAn5wD+OBjaznTDdeMy
m86FSTYCuDQ2tUky5MvRq48Vf4l62Ac=
=CbEJ
-----END PGP SIGNATURE-----