|  | @@ -235,7 +235,7 @@ ENCRYPT_BACKUPS="yes"
 | 
	
		
			
			| 235 | 235 |  #list of encryption protocols
 | 
	
		
			
			| 236 | 236 |  SSL_PROTOCOLS="TLSv1 TLSv1.1 TLSv1.2"
 | 
	
		
			
			| 237 | 237 |  
 | 
	
		
			
			| 238 |  | -# list of ciphers to use
 | 
	
		
			
			|  | 238 | +# list of ciphers to use.  See bettercrypto.org recommendations
 | 
	
		
			
			| 239 | 239 |  SSL_CIPHERS="EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA"
 | 
	
		
			
			| 240 | 240 |  
 | 
	
		
			
			| 241 | 241 |  export DEBIAN_FRONTEND=noninteractive
 | 
	
	
		
			
			|  | @@ -302,6 +302,15 @@ function argument_checks {
 | 
	
		
			
			| 302 | 302 |            exit 30
 | 
	
		
			
			| 303 | 303 |        fi
 | 
	
		
			
			| 304 | 304 |    fi
 | 
	
		
			
			|  | 305 | +  # make sure you don't use the default user account
 | 
	
		
			
			|  | 306 | +  if [[ $MY_USERNAME == "debian" ]]; then
 | 
	
		
			
			|  | 307 | +      echo 'Do not use the default debian user account. Create a different user with: adduser [username]'
 | 
	
		
			
			|  | 308 | +      exit 68
 | 
	
		
			
			|  | 309 | +  fi
 | 
	
		
			
			|  | 310 | +  # remove the default debian user to prevent it from becoming an attack vector
 | 
	
		
			
			|  | 311 | +  if [ -d /home/debian ]; then
 | 
	
		
			
			|  | 312 | +      userdel -r debian
 | 
	
		
			
			|  | 313 | +  fi
 | 
	
		
			
			| 305 | 314 |  }
 | 
	
		
			
			| 306 | 315 |  
 | 
	
		
			
			| 307 | 316 |  function change_login_message {
 |