Update debian/debian-secure.sh
This commit is contained in:
		
					parent
					
						
							
								46f5277c8b
							
						
					
				
			
			
				commit
				
					
						e83720f4a5
					
				
			
		
					 1 changed files with 4 additions and 0 deletions
				
			
		
							
								
								
									
										4
									
								
								debian/debian-secure.sh
									
										
									
									
										vendored
									
									
								
							
							
						
						
									
										4
									
								
								debian/debian-secure.sh
									
										
									
									
										vendored
									
									
								
							| 
						 | 
				
			
			@ -26,6 +26,7 @@ Address = $WG_SUBNET::1/64
 | 
			
		|||
PublicKey = $WIREGUARD_PUBKEY
 | 
			
		||||
AllowedIPs = $WG_SUBNET::2/128
 | 
			
		||||
EOF
 | 
			
		||||
chmod -R 700 /etc/wireguard
 | 
			
		||||
 | 
			
		||||
systemctl enable --now wg-quick@vmh-ssh-vpn
 | 
			
		||||
 | 
			
		||||
| 
						 | 
				
			
			@ -33,6 +34,8 @@ systemctl enable --now wg-quick@vmh-ssh-vpn
 | 
			
		|||
echo "Configuring ssh..."
 | 
			
		||||
mkdir /home/$USERNAME/.ssh
 | 
			
		||||
echo $MY_SSH_KEY > /home/$USERNAME/.ssh/authorized_keys
 | 
			
		||||
chmod 600 /home/$USERNAME/.ssh/authorized_keys
 | 
			
		||||
chmod 700 /home/$USERNAME/.ssh
 | 
			
		||||
 | 
			
		||||
cat <<EOF > /etc/ssh/sshd_config.d/10-vmh_ssh.conf
 | 
			
		||||
X11Forwarding no
 | 
			
		||||
| 
						 | 
				
			
			@ -56,6 +59,7 @@ echo "Configuring sudo..."
 | 
			
		|||
cat <<EOF > /etc/sudoers.d/99-vmh-newuser
 | 
			
		||||
$USERNAME    ALL=(ALL:ALL)   NOPASSWD:ALL
 | 
			
		||||
EOF
 | 
			
		||||
chmod 440 /etc/sudoers.d/99-vmh-newuser
 | 
			
		||||
 | 
			
		||||
echo
 | 
			
		||||
echo "BEFORE DISCONNECTING, FOLLOW THE FOLLOWING STEPS"
 | 
			
		||||
| 
						 | 
				
			
			
 | 
			
		|||
		Loading…
	
	Add table
		Add a link
		
	
		Reference in a new issue