~vcs-imports/ipfire/ipfire-2.x

  • Committer: Peter Müller
  • Date: 2022-04-23 14:27:56 UTC
  • Revision ID: git-v1:7a981d94cb2c3e48ecaf07c506c8353a2c839d79
SSH: do not send spoofable TCP keep alive messages

By default, both SSH server and client rely on TCP-based keep alive
messages to detect broken sessions, which can be spoofed rather easily
in order to keep a broken session opened (and vice versa).

Since we rely on SSH-based keep alive messages, which are not vulnerable
to this kind of tampering, there is no need to double-check connections
via TCP keep alive as well.

This patch thereof disables using TCP keep alive for both SSH client and
server scenario. For usability reasons, a timeout of 5 minutes (10
seconds * 30 keep alive messages = 300 seconds) will be used for both
client and server configuration, as 60 seconds were found to be too
short for unstable connectivity scenarios.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Filename Latest Rev Last Changed Committer Comment Size
..
acpid 3315 12 years ago Michael Tremer acpid: Forgot to commit config data. Diff
avahi 6491 6 years ago Michael Tremer Revert "avahi: Drop package" This reverts commit Diff
backup 637 17 years ago maniacikarus Korrekturen im IDS System Division by 0 in den gra Diff
bash 3433 12 years ago Michael Tremer Import bash startfiles from IPFire 3.x. Diff
bind 4428 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
ca-certificates 4742 9 years ago Arne Fitzenreiter Merge branch 'master' into next Diff
calamaris 471 17 years ago ms Calamaris-Proxy-Logdatei-Analyzer eingebaut. git Diff
cdrom 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
cfgroot 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
clamav 505 17 years ago ms Einige Fixes fuer den Paketmanager. ISA PnP aus Ke Diff
client175 2701 14 years ago Arne Fitzenreiter Merge branch 'master' of ssh://arne_f@git.ipfire.o Diff
collectd 1004 17 years ago maniacikarus Corrected guardian build lcd4linux startet integra Diff
cron 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
cups 976 17 years ago ms Made cups accessable. git-svn-id: http://svn.ipf Diff
cyrus-sasl 963 17 years ago ms Typo in compilation commands of postfix. Now it wo Diff
dehydrated 6674 6 years ago Michael Tremer dehydrated: New package This is a light client fo Diff
dhcpc 4937 9 years ago Arne Fitzenreiter Merge branch 'master' into next Diff
dma 4801 9 years ago Michael Tremer dma: Add script that cleans up stale emails in the Diff
dracut 4436 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
elinks 1058 16 years ago arne_f Addon: elinks (www-browser for textconsole) git- Diff
etc 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
etc-aarch64 8767 3 years ago Michael Tremer Install sysctl.conf only on those architectures wh Diff
etc-armv6l 8893 3 years ago Arne Fitzenreiter switch arm 32 bit arch from armv5tel to armv6l we Diff
etc-x86_64 8767 3 years ago Michael Tremer Install sysctl.conf only on those architectures wh Diff
extrahd 395 18 years ago ms ExtraHD! Die Erweiterung um Festplatten schnell ei Diff
findutils 4431 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
firewall 3989 11 years ago Alexander Marx Firewall: renamed /config/forwardfw to config/fire Diff
flash-images 6214 6 years ago Arne Fitzenreiter Merge branch 'kernel-4.14' into next Diff
freeradius 7338 5 years ago Arne Fitzenreiter Merge branch 'next' Diff
fstrim 3552 12 years ago Arne Fitzenreiter fstrim: add daily cronjob. Diff
fwhosts 3884 11 years ago Michael Tremer Merge remote-tracking branch 'amarx/firewall' into Diff
gnump3d 946 17 years ago ms Made the gnump3d working out of the box... git-s Diff
grub2 4436 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
guardian 691 17 years ago maniacikarus Guardian Paket angefangen, zum Testen muss Snort f Diff
haproxy 4482 9 years ago Michael Tremer haproxy: New package Diff
hostapd 1182 16 years ago Christian Schmidt Merge branch 'rspezial' Conflicts: config/rootf Diff
httpd 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
icinga 4419 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
include 3442 12 years ago Arne Fitzenreiter linux-headers: use kernel 3.2.x headers. Diff
initrd 2701 14 years ago Arne Fitzenreiter Merge branch 'master' of ssh://arne_f@git.ipfire.o Diff
iptraf-ng 8363 4 years ago Arne Fitzenreiter Merge branch 'next' Diff
kernel 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
lcdproc 3696 11 years ago Arne Fitzenreiter Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
lib 4450 10 years ago Michael Tremer Merge branch 'master' into next Conflicts: make. Diff
libid3tag 8775 3 years ago Michael Tremer Merge branch 'next' Diff
libvirt 7536 5 years ago Arne Fitzenreiter Merge branch 'next' Signed-off-by: Arne Fitzenrei Diff
logwatch 388 18 years ago ms MoBlock hinzugefuegt (fuer Outgoing Firewall) gi Diff
lua 8775 3 years ago Michael Tremer Merge branch 'next' Diff
menu 393 18 years ago ms Credits ueberarbeitet. Menue Rewrite Connectionche Diff
minidlna 3292 12 years ago Michael Tremer Merge remote-tracking branch 'origin/next' into gl Diff
monit 4448 10 years ago Alexander Marx Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
mpfire 625 17 years ago maniacikarus MPFire hinzugefügt - CGI mpg123 Frontend Hardwareg Diff
netpbm 1071 16 years ago arne_f deleted empty collectd rootfile added netpbm (pnmt Diff
netsnmpd 1989 15 years ago Peter Pfeiffer add new changed files for netsnmpd Diff
nginx 3614 12 years ago Michael Tremer Merge remote-tracking branch 'trikolon/next' into Diff
ntp 8381 4 years ago Arne Fitzenreiter Merge branch 'next' into master Signed-off-by: Ar Diff
oinkmaster 7005 5 years ago Michael Tremer Merge remote-tracking branch 'stevee/next-suricata Diff
ovpn 128 18 years ago ms Hinzugefügt: * OpenVPN GUI Alpha7 Geändert: * Diff
pmacct 8775 3 years ago Michael Tremer Merge branch 'next' Diff
profile.d 373 18 years ago ms Bashpromt erweitert und FTP Upload wieder funktion Diff
proxy 524 17 years ago maniacikarus Proxy.cgi von den IPCop Error Pages befreit, da ni Diff
qemu 4610 9 years ago Arne Fitzenreiter qemu: update to 2.3.0 Diff
qos 173 18 years ago ms Hinzugefügt: * Fehlende Grafik. * QoS-Script, Diff
rootfiles 292 18 years ago ms Hinzugefuegt: * Net-Tools * Inetutils * Ed Diff
rpi-firmware 3342 12 years ago Arne Fitzenreiter rpi: updated firmware and patchset. Diff
samba 438 17 years ago maniacikarus colours.txt ins Theme Verzeichnis geschoben, daher Diff
sarg 3498 12 years ago Arne Fitzenreiter Merge remote-tracking branch 'origin/next' into th Diff
shadow 5353 8 years ago Michael Tremer shadow-utils: Create standard set of configuration Diff
squidclamav 1099 16 years ago Maniacikarus Fixed authentication not working when using proxy Diff
ssh 6574 6 years ago Michael Tremer add hardened SSH client configuration Introduce a Diff
ssl 2 19 years ago ipfire git-svn-id: http://svn.ipfire.org/svn/ipfire/IPF Diff
strongswan 4455 10 years ago Michael Tremer strongswan: Create configuration for better intero Diff
stunnel 4415 10 years ago Dirk Wagner Merge branch 'next' of ssh://git.ipfire.org/pub/gi Diff
suricata 7005 5 years ago Michael Tremer Merge remote-tracking branch 'stevee/next-suricata Diff
syslinux 344 18 years ago ms Graphen gefixt. Bootlogo zur Iso hinzugefuegt. Mem Diff
sysstat 459 17 years ago ms Wir kehren zurueck zu Kudzu, da hwinfo noch mehr A Diff
time 2717 14 years ago Arne Fitzenreiter ntp: new enabled at default Fix ipfire ntp server Diff
tor 3805 11 years ago Michael Tremer tor: New package. Diff
transmission 3045 13 years ago Arne Fitzenreiter transmission: New package. Diff
u-boot 3136 12 years ago Arne Fitzenreiter u-boot: update to 2011.12 and build MLO + bin for Diff
udev 1088 16 years ago arne_f added DVB Hardware modules to core12 added VideoDi Diff
unbound 5297 8 years ago Michael Tremer Merge branch 'unbound' into next Diff
updxlrator 396 18 years ago ms Updatexlrator (not tested yet) git-svn-id: http: Diff
urlfilter 161 18 years ago ms Hinzugefügt: * URL-Filter git-svn-id: http://s Diff
vdr 1091 16 years ago arne_f add vdr streamdev-plugin git-svn-id: http://svn. Diff
vdradmin 1618 15 years ago Arne Fitzenreiter Change vdradmin istallation part 1 Diff
vim 3962 11 years ago Michael Tremer vim: Update to 7.4. Diff
w_scan 3448 12 years ago Arne Fitzenreiter w_scan: add new w_scan_start skript. Diff
wpa_supplicant 1182 16 years ago Christian Schmidt Merge branch 'rspezial' Conflicts: config/rootf Diff
xinetd 3850 11 years ago Michael Tremer xinetd: New package. Diff
xtables-addons 4549 9 years ago Michael Tremer Merge remote-tracking branch 'stevee/core-90-geoip Diff
zabbix_agentd 6977 5 years ago Michael Tremer zabbix_agentd: New addon New addon for monitoring Diff