ansible-bootstrap-rocky9/roles/linux_ssh_hardening_rhel9
2026-05-12 00:21:37 +03:00
..
defaults update 2026-05-12 00:21:37 +03:00
handlers update 2026-05-12 00:21:37 +03:00
tasks update 2026-05-12 00:21:37 +03:00
templates update 2026-05-12 00:21:37 +03:00
README.md update 2026-05-12 00:21:37 +03:00

linux_ssh_hardening_rhel9

Purpose

Applies deep SSH server hardening by enforcing strong ciphers, MACs, key exchange algorithms, authentication restrictions, and login banners to minimize SSH attack exposure.

Targeted OS

RHEL 9 / AlmaLinux 9 / Rocky Linux 9

CIS Alignment

CIS Section 5.1 — Configure SSH Server

Key Variables

linux_ssh_hardening_rhel9_disabled: false   # set to true to skip this role

See defaults/main.yml for all tunable parameters.