File tree Expand file tree Collapse file tree 2 files changed +2
-1
lines changed Expand file tree Collapse file tree 2 files changed +2
-1
lines changed Original file line number Diff line number Diff line change 6666default [ 'ssh' ] [ 'allow_groups' ] = [ ] # sshd
6767default [ 'ssh' ] [ 'print_motd' ] = false # sshd
6868default [ 'ssh' ] [ 'print_last_log' ] = false # sshd
69+ default [ 'ssh' ] [ 'password_authentication' ] = false # sshd
6970# set this to nil to let us use the default OpenSSH in case it's not set by the user
7071default [ 'ssh' ] [ 'use_dns' ] = nil # sshd
7172# set this to nil to let us detect the attribute based on the node platform
Original file line number Diff line number Diff line change @@ -104,7 +104,7 @@ HostbasedAuthentication no
104104# Enable PAM to enforce system wide rules
105105UsePAM <%= ((@node['ssh']['use_pam']) ? "yes" : "no" ) %>
106106# Disable password-based authentication, it can allow for potentially easier brute-force attacks.
107- PasswordAuthentication no
107+ PasswordAuthentication <%= ((@node['ssh']['password_authentication']) ? "yes" : "no" ) %>
108108PermitEmptyPasswords no
109109ChallengeResponseAuthentication no
110110
You can’t perform that action at this time.
0 commit comments