Skip to content

Commit 1a07d1e

Browse files
Allow login grace time to be configurable
1 parent 5d58452 commit 1a07d1e

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

attributes/default.rb

+1
Original file line numberDiff line numberDiff line change
@@ -78,6 +78,7 @@
7878
default['ssh']['use_dns'] = nil # sshd
7979
# set this to nil to let us detect the attribute based on the node platform
8080
default['ssh']['use_privilege_separation'] = nil
81+
default['ssh']['login_grace_time'] = '30s' # sshd
8182
default['ssh']['max_auth_tries'] = 2 # sshd
8283
default['ssh']['max_sessions'] = 10 # sshd
8384
default['ssh']['client']['password_authentication'] = false # ssh

templates/default/opensshd.conf.erb

+1-1
Original file line numberDiff line numberDiff line change
@@ -88,7 +88,7 @@ KexAlgorithms <%= @kex %>
8888
UseLogin no
8989
UsePrivilegeSeparation <%= @use_priv_sep %>
9090
PermitUserEnvironment no
91-
LoginGraceTime 30s
91+
LoginGraceTime <%= @node['ssh']['login_grace_time'] %>
9292
MaxAuthTries <%= @node['ssh']['max_auth_tries'] %>
9393
MaxSessions <%= @node['ssh']['max_sessions'] %>
9494
MaxStartups 10:30:100

0 commit comments

Comments
 (0)