testing: Configure curve25519-sha256 as key exchange for SSH
With Debian bookworm, the PQC KE sntrup761x25519-sha512 is negotiated, by default. This increases the overhead significantly, in particular, the size of the KE message, which wouldn't get through IPsec tunnels without MSS clamping.
This commit is contained in:
@@ -1,6 +1,7 @@
|
||||
Port 22
|
||||
Protocol 2
|
||||
Ciphers [email protected]
|
||||
KexAlgorithms curve25519-sha256
|
||||
HostKey /etc/ssh/ssh_host_rsa_key
|
||||
HostKey /etc/ssh/ssh_host_ecdsa_key
|
||||
PermitRootLogin yes
|
||||
|
||||
Reference in New Issue
Block a user