DHEat Attack: DoS attack by enforcing the Diffie-Hellman key exchange
dheatattack.com
dheatattack.com
If hardening SSH it may be safest to first harden the SSH client and ensure one can still connect. Then harden the ssh daemon of a local machine using the same version of openssh used on ones servers to minimize the risk of locking one out of their own machine and having to use a rescue console or ILO. This may be counter-intuitive but going through the hardening process significantly speeds up SSH handshake time which may be most useful to those using Ansible.
[1] - https://www.ssh-audit.com/
There are another tools (open source and SaaS) on OWASP Transport Layer Protection Cheat Sheet page[2].
[1] https://gitlab.com/coroner/cryptolyzer
[2] https://cheatsheetseries.owasp.org/cheatsheets/Transport_Lay...