diff --git a/INSTALL/install_env.sh b/INSTALL/install_env.sh index 9a2ac552..1f1974b8 100755 --- a/INSTALL/install_env.sh +++ b/INSTALL/install_env.sh @@ -9,32 +9,8 @@ then fi USER="tmuser" -ADMIN_EMAIL="ENTER_ADMIN_EMAIL" OPEN_PORTS=(46656 46657 46658 46659 46660 46661 46662 46663 46664 46665 46666 46667 46668 46669 46670 46671) SSH_PORT=20 -SSH_CONFIG="Port 20 -Protocol 2 -HostKey /etc/ssh/ssh_host_rsa_key -HostKey /etc/ssh/ssh_host_dsa_key -HostKey /etc/ssh/ssh_host_ecdsa_key -HostKey /etc/ssh/ssh_host_ed25519_key -UsePrivilegeSeparation yes -KeyRegenerationInterval 3600 -ServerKeyBits 1024 -SyslogFacility AUTH -LogLevel INFO -LoginGraceTime 120 -PermitRootLogin no -StrictModes yes -RSAAuthentication yes -PubkeyAuthentication yes -IgnoreRhosts yes -RhostsRSAAuthentication no -HostbasedAuthentication no -PermitEmptyPasswords no -ChallengeResponseAuthentication no -PasswordAuthentication no -" WHITELIST=() # update and upgrade @@ -52,13 +28,6 @@ apt-get install -y make screen gcc git mercurial libc6-dev pkg-config libgmp-dev # set up firewall echo "ENABLE FIREWALL ..." -# copy in the ssh config with locked down settings -if [ "$SSH_CONFIG" != "" ]; then - echo "$SSH_CONFIG" > /etc/ssh/sshd_config - service ssh restart -else - echo "Skipping over sshd_config rewrite" -fi # white list ssh access for ip in "${WHITELIST[@]}"; do ufw allow from $ip to any port $SSH_PORT @@ -74,8 +43,8 @@ done ufw enable # watch the logs and have them emailed to me -apt-get install -y logwatch -echo "/usr/sbin/logwatch --output mail --mailto $ADMIN_EMAIL --detail high" >> /etc/cron.daily/00logwatch +# apt-get install -y logwatch +# echo "/usr/sbin/logwatch --output mail --mailto $ADMIN_EMAIL --detail high" >> /etc/cron.daily/00logwatch # set up user account echo "CREATE USER $USER ..."