fedora-cosmic: enable Kanidm SSH public key auth
Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
This commit is contained in:
@@ -47,6 +47,7 @@ add-files:
|
||||
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
|
||||
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
||||
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
|
||||
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
||||
|
||||
postprocess:
|
||||
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
||||
|
||||
@@ -0,0 +1,7 @@
|
||||
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
||||
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
||||
# drop-in, since sshd honours the first directive it sees.
|
||||
PubkeyAuthentication yes
|
||||
UsePAM yes
|
||||
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
||||
AuthorizedKeysCommandUser nobody
|
||||
Reference in New Issue
Block a user