diff --git a/images/fedora-cosmic/custom.yaml b/images/fedora-cosmic/custom.yaml index 87377c4..be41aa1 100644 --- a/images/fedora-cosmic/custom.yaml +++ b/images/fedora-cosmic/custom.yaml @@ -47,6 +47,7 @@ add-files: - ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"] - ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"] - ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"] + - ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"] postprocess: # The upstream fedora.yaml removes the Google Chrome repo from the Fedora diff --git a/images/fedora-cosmic/files/10-kanidm.conf b/images/fedora-cosmic/files/10-kanidm.conf new file mode 100644 index 0000000..dc7c9e4 --- /dev/null +++ b/images/fedora-cosmic/files/10-kanidm.conf @@ -0,0 +1,7 @@ +# Fetch authorized SSH public keys from Kanidm (uploaded to the account). +# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand +# drop-in, since sshd honours the first directive it sees. +PubkeyAuthentication yes +UsePAM yes +AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u +AuthorizedKeysCommandUser nobody