+# Disable authentication methods I don't use.
+ ChallengeResponseAuthentication no
+ GSSAPIAuthentication no
+ HostbasedAuthentication no
+ KbdInteractiveAuthentication no
+# Only enable those I need.
+ PasswordAuthentication yes
+ PubkeyAuthentication yes
+
+# Use only authentication identity files configured in ~/.ssh/config even if
+# ssh-agent offers more identities.
+ IdentitiesOnly yes
+
+# Bind local forwardings to loopback only. This way no remote hosts can access
+# them (default).
+ GatewayPorts no
+# Abort if not all requested port forwardings can be set up.
+ ExitOnForwardFailure yes
+