From 7dddf2186ba05ba1260da4fa4873034d3362164c Mon Sep 17 00:00:00 2001 From: Stefan <57448158+root360-StefanHeitmueller@users.noreply.github.com> Date: Sat, 30 Jan 2021 20:57:31 +0100 Subject: [PATCH] configure internal ssh server w/ macs and ciphers, backport of #14523 (#14530) --- modules/ssh/ssh.go | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/modules/ssh/ssh.go b/modules/ssh/ssh.go index 7a449dd41..13e69a0f3 100644 --- a/modules/ssh/ssh.go +++ b/modules/ssh/ssh.go @@ -196,13 +196,17 @@ func publicKeyHandler(ctx ssh.Context, key ssh.PublicKey) bool { // Listen starts a SSH server listens on given port. func Listen(host string, port int, ciphers []string, keyExchanges []string, macs []string) { - // TODO: Handle ciphers, keyExchanges, and macs - srv := ssh.Server{ Addr: fmt.Sprintf("%s:%d", host, port), PublicKeyHandler: publicKeyHandler, Handler: sessionHandler, - + ServerConfigCallback: func(ctx ssh.Context) *gossh.ServerConfig { + config := &gossh.ServerConfig{} + config.KeyExchanges = keyExchanges + config.MACs = macs + config.Ciphers = ciphers + return config + }, // We need to explicitly disable the PtyCallback so text displays // properly. PtyCallback: func(ctx ssh.Context, pty ssh.Pty) bool {