In a lot of environments, having sftp enabled by default runs afoul of security audit scans. The current state of the cookbook doesn't seem to provide the ability to disable sftp on the platforms it supports. It enables it by default. It would make more sense to enable the sftp subsystem only if an attribute in the cookbook was set to true.
In a lot of environments, having sftp enabled by default runs afoul of security audit scans. The current state of the cookbook doesn't seem to provide the ability to disable sftp on the platforms it supports. It enables it by default. It would make more sense to enable the sftp subsystem only if an attribute in the cookbook was set to true.