fedora-cosmic: enable Kanidm SSH public key auth
Build containers / fedora-cosmic (rawhide) (push) Failing after 46s
Build containers / Prune old releases (push) Canceled after 0s
Build containers / fedora-cosmic (44) (push) Canceled after 4m17s

Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via
kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
This commit is contained in:
2026-09-27 22:09:56 +02:00
parent b9fe183da1
commit 0e4ea86f22
2 changed files with 8 additions and 0 deletions
+1
View File
@@ -47,6 +47,7 @@ add-files:
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
postprocess:
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
@@ -0,0 +1,7 @@
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
# drop-in, since sshd honours the first directive it sees.
PubkeyAuthentication yes
UsePAM yes
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
AuthorizedKeysCommandUser nobody