From 2e5a4fd7079f3343410570b856959be7e80cbe27 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Wed, 30 Sep 2026 17:26:58 +0200 Subject: [PATCH] fedora-remote: add openssl for grd-firstboot TLS, enable sshd grd-firstboot aborts before enabling RDP because it shells out to openssl to generate the TLS certificate, and the minimal image did not include the openssl CLI. Add it. Also enable sshd so the headless host is reachable without RDP. --- images/fedora-remote/custom.yaml | 3 +++ images/fedora-remote/files/50-grd.preset | 3 +++ 2 files changed, 6 insertions(+) diff --git a/images/fedora-remote/custom.yaml b/images/fedora-remote/custom.yaml index a84450a..a9925c9 100644 --- a/images/fedora-remote/custom.yaml +++ b/images/fedora-remote/custom.yaml @@ -23,6 +23,9 @@ packages: # Proxmox guest integration. - qemu-guest-agent + # grd-firstboot generates the RDP TLS certificate with the openssl CLI. + - openssl + # Kanidm Unix authentication (kanidm-unixd-clients pulls kanidm-clients). - kanidm-unixd-clients diff --git a/images/fedora-remote/files/50-grd.preset b/images/fedora-remote/files/50-grd.preset index 98187bc..e2d1222 100644 --- a/images/fedora-remote/files/50-grd.preset +++ b/images/fedora-remote/files/50-grd.preset @@ -3,3 +3,6 @@ enable gdm.service enable gnome-remote-desktop.service enable grd-firstboot.service enable qemu-guest-agent.service + +# Headless host: SSH (Kanidm key auth via 10-kanidm.conf) is the other way in. +enable sshd.service