fedora-cosmic: harden sshd for Kanidm key-only auth
Build containers / fedora-cosmic (rawhide) (push) Failing after 54s
Build containers / fedora-cosmic (44) (push) Successful in 12m1s
Build containers / Prune old releases (push) Successful in 22s

Disable password/root/GSSAPI/Kerberos SSH auth now that public keys are
served by Kanidm.
This commit is contained in:
2026-09-27 22:11:55 +02:00
parent 0e4ea86f22
commit 6822bc3061
@@ -5,3 +5,12 @@ PubkeyAuthentication yes
UsePAM yes
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
AuthorizedKeysCommandUser nobody
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
# public key to your account before relying on this, or you can lock yourself
# out of SSH.
PermitRootLogin no
PasswordAuthentication no
PermitEmptyPasswords no
GSSAPIAuthentication no
KerberosAuthentication no