preseed/jessie: install fail2ban by default
authorClinton Ebadi <clinton@unknownlamer.org>
Wed, 15 Apr 2015 05:24:49 +0000 (01:24 -0400)
committerClinton Ebadi <clinton@unknownlamer.org>
Wed, 15 Apr 2015 05:24:49 +0000 (01:24 -0400)
Default config looks good enough to protect ssh about as well as
denyhosts did.

preseed/preseed-jessie.cfg

index faae421..db941e3 100644 (file)
@@ -367,7 +367,7 @@ tasksel     tasksel/first   multiselect     SSH server, Standard system utilities
 #tasksel tasksel/desktop multiselect kde, xfce
 
 # Individual additional packages to install
-d-i pkgsel/include string build-essential less sudo vim emacs24-nox etckeeper changetrack openssh-server debsums logcheck bzip2 rkhunter openafs-client openafs-modules-dkms ntp nscd krb5-user libpam-krb5 kstart ssmtp libpam-afs-session openafs-krb5 dnscache-run ferm libnss-afs hcoop-nsswitch-config hcoop-common-config hcoop-firewall-config hcoop-krb5-config hcoop-openssh-server-config irqbalance \
+d-i pkgsel/include string build-essential less sudo vim emacs24-nox etckeeper changetrack openssh-server debsums logcheck bzip2 rkhunter openafs-client openafs-modules-dkms ntp nscd krb5-user libpam-krb5 kstart ssmtp libpam-afs-session openafs-krb5 dnscache-run ferm libnss-afs hcoop-nsswitch-config hcoop-common-config hcoop-firewall-config hcoop-krb5-config hcoop-openssh-server-config irqbalance fail2ban \
     mlton-compiler mlton-tools libssl-dev libpcre3-dev # domtool deps, a metapackage would be useful here
 # Whether to upgrade packages after debootstrap.
 # Allowed values: none, safe-upgrade, full-upgrade