fedora-cosmic: enable Kanidm SSH public key auth
Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
This commit is contained in:
@@ -47,6 +47,7 @@ add-files:
|
|||||||
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
|
- ["kanidm-nsswitch.conf", "/usr/share/fedora-cosmic/authselect/nsswitch.conf"]
|
||||||
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
- ["50-kanidm.preset", "/usr/lib/systemd/system-preset/50-kanidm.preset"]
|
||||||
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
|
- ["kanidm-unixd.cil", "/usr/share/fedora-cosmic/kanidm-unixd.cil"]
|
||||||
|
- ["10-kanidm.conf", "/etc/ssh/sshd_config.d/10-kanidm.conf"]
|
||||||
|
|
||||||
postprocess:
|
postprocess:
|
||||||
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
# The upstream fedora.yaml removes the Google Chrome repo from the Fedora
|
||||||
|
|||||||
@@ -0,0 +1,7 @@
|
|||||||
|
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
||||||
|
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
||||||
|
# drop-in, since sshd honours the first directive it sees.
|
||||||
|
PubkeyAuthentication yes
|
||||||
|
UsePAM yes
|
||||||
|
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
||||||
|
AuthorizedKeysCommandUser nobody
|
||||||
Reference in New Issue
Block a user