File: //etc/ssh/sshd_config.bak
# $OpenBSD: sshd_config,v 1.103 2018/04/09 20:41:22 tj Exp $
# This is the sshd server system-wide configuration file. See
# sshd_config(5) for more information.
# This sshd was compiled with PATH=/usr/local/bin:/usr/bin:/usr/local/sbin:/usr/sbin
# The strategy used for options in the default sshd_config shipped with
# OpenSSH is to specify options with their default value where
# possible, but leave them commented. Uncommented options override the
# default value.
# If you want to change the port on a SELinux system, you have to tell
# SELinux about this change.
# semanage port -a -t ssh_port_t -p tcp #PORTNUMBER
#
#Port 22
#AddressFamily any
#ListenAddress 0.0.0.0
#ListenAddress ::
HostKey /etc/ssh/ssh_host_rsa_key
HostKey /etc/ssh/ssh_host_ecdsa_key
HostKey /etc/ssh/ssh_host_ed25519_key
# Ciphers and keying
#RekeyLimit default none
# Logging
#SyslogFacility AUTH
SyslogFacility AUTHPRIV
#LogLevel INFO
# Authentication:
#LoginGraceTime 2m
PermitRootLogin yes
#StrictModes yes
#MaxAuthTries 6
#MaxSessions 10
PubkeyAuthentication yes
# The default is to check both .ssh/authorized_keys and .ssh/authorized_keys2
# but this is overridden so installations will only check .ssh/authorized_keys
AuthorizedKeysFile .ssh/authorized_keys
#AuthorizedPrincipalsFile none
#AuthorizedKeysCommand none
#AuthorizedKeysCommandUser nobody
# For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
#HostbasedAuthentication no
# Change to yes if you don't trust ~/.ssh/known_hosts for
# HostbasedAuthentication
#IgnoreUserKnownHosts no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes
# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication yes
#PermitEmptyPasswords no
PasswordAuthentication yes
# Change to no to disable s/key passwords
#ChallengeResponseAuthentication yes
ChallengeResponseAuthentication no
# Kerberos options
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no
#KerberosUseKuserok yes
# GSSAPI options
GSSAPIAuthentication no
GSSAPICleanupCredentials no
#GSSAPIStrictAcceptorCheck yes
#GSSAPIKeyExchange no
#GSSAPIEnablek5users no
# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication and
# PasswordAuthentication. Depending on your PAM configuration,
# PAM authentication via ChallengeResponseAuthentication may bypass
# the setting of "PermitRootLogin without-password".
# If you just want the PAM account and session checks to run without
# PAM authentication, then enable this but set PasswordAuthentication
# and ChallengeResponseAuthentication to 'no'.
# WARNING: 'UsePAM no' is not supported in openEuler and may cause several
# problems.
UsePAM yes
#AllowAgentForwarding yes
#AllowTcpForwarding yes
#GatewayPorts no
X11Forwarding yes
#X11DisplayOffset 10
#X11UseLocalhost yes
#PermitTTY yes
PrintMotd no
#PrintLastLog yes
#TCPKeepAlive yes
#PermitUserEnvironment no
#Compression delayed
#ClientAliveInterval 0
#ClientAliveCountMax 3
UseDNS no
#PidFile /var/run/sshd.pid
#MaxStartups 10:30:100
#PermitTunnel no
#ChrootDirectory none
#VersionAddendum none
# no default banner path
#Banner none
AcceptEnv LANG LC_CTYPE LC_NUMERIC LC_TIME LC_COLLATE LC_MONETARY LC_MESSAGES
AcceptEnv LC_PAPER LC_NAME LC_ADDRESS LC_TELEPHONE LC_MEASUREMENT
AcceptEnv LC_IDENTIFICATION LC_ALL LANGUAGE
AcceptEnv XMODIFIERS
# override default of no subsystems
Subsystem sftp /usr/libexec/openssh/sftp-server
# Example of overriding settings on a per-user basis
#Match User anoncvs
# X11Forwarding no
# AllowTcpForwarding no
# PermitTTY no
# ForceCommand cvs server
#CheckUserSplash yes
# To modify the system-wide ssh configuration, create a *.conf file under
# /etc/ssh/sshd_config.d/ which will be automatically included below
#Include /etc/ssh/sshd_config.d/*.conf
Protocol 2
DenyUsers root@43.155.166.220
DenyUsers root@43.153.85.172
DenyUsers root@119.96.158.238
DenyUsers root@113.142.30.225
DenyUsers root@223.113.121.94
DenyUsers root@50.187.52.54
DenyUsers root@150.158.11.43
DenyUsers root@62.234.220.16
DenyUsers root@209.38.228.147
DenyUsers root@43.139.14.57
DenyUsers root@106.52.33.34
DenyUsers root@106.54.217.227
DenyUsers root@45.95.146.33
DenyUsers root@101.43.123.18
DenyUsers root@111.229.10.88
DenyUsers root@82.157.196.31
DenyUsers root@81.69.233.69
DenyUsers root@80.249.113.114
DenyUsers root@210.91.154.187
DenyUsers root@150.158.143.188
DenyUsers root@14.116.146.20
DenyUsers root@124.220.83.13
DenyUsers root@43.138.59.170
DenyUsers root@117.34.71.28
DenyUsers root@119.96.143.51
DenyUsers root@118.25.178.157
DenyUsers root@119.29.84.119
DenyUsers root@111.229.99.168
DenyUsers root@180.112.114.189
DenyUsers root@101.35.23.90
DenyUsers root@113.134.212.85
DenyUsers root@82.196.1.167
DenyUsers root@121.4.175.99
DenyUsers root@120.48.242.12
DenyUsers root@103.119.3.178
DenyUsers root@168.167.228.123
DenyUsers root@59.12.160.91
DenyUsers root@49.247.198.162
DenyUsers root@43.156.33.78
DenyUsers root@39.109.117.37
DenyUsers root@43.153.64.49
DenyUsers root@43.133.157.49
DenyUsers root@14.225.206.98
DenyUsers root@165.232.124.31
DenyUsers root@14.116.200.5
DenyUsers root@35.219.62.194
DenyUsers root@139.150.69.56
DenyUsers root@188.226.207.26
DenyUsers root@209.97.163.130
DenyUsers root@95.130.227.116
DenyUsers root@162.240.98.245
DenyUsers root@101.34.148.151
DenyUsers root@150.109.254.239
DenyUsers root@43.153.112.182
DenyUsers root@104.168.100.175
DenyUsers root@43.129.244.195
DenyUsers root@152.136.175.162
DenyUsers root@114.218.158.118
DenyUsers root@187.216.84.197
DenyUsers root@103.236.192.222
DenyUsers root@106.51.169.25
DenyUsers root@43.153.68.27
DenyUsers root@43.153.75.83
DenyUsers root@101.43.34.82
DenyUsers root@103.112.213.103
DenyUsers root@218.78.63.36
DenyUsers root@43.134.190.106
DenyUsers root@104.248.145.46
DenyUsers root@124.222.239.189
DenyUsers root@43.156.71.12
DenyUsers root@58.40.199.162
DenyUsers root@163.228.248.90
DenyUsers root@119.4.250.94
DenyUsers root@51.15.56.154
DenyUsers root@203.195.195.147
DenyUsers root@209.141.41.166
DenyUsers root@139.59.46.97
DenyUsers root@124.223.81.105
DenyUsers root@1.117.147.119
DenyUsers root@14.116.189.74
DenyUsers root@118.25.51.102
DenyUsers root@43.163.245.246
DenyUsers root@10.191.147.59