From 6822bc3061626b58f0d1ebea78c2d3a2f341cf26 Mon Sep 17 00:00:00 2001 From: Wesley van Tilburg Date: Sun, 27 Sep 2026 22:11:55 +0200 Subject: [PATCH] fedora-cosmic: harden sshd for Kanidm key-only auth Disable password/root/GSSAPI/Kerberos SSH auth now that public keys are served by Kanidm. --- images/fedora-cosmic/files/10-kanidm.conf | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/images/fedora-cosmic/files/10-kanidm.conf b/images/fedora-cosmic/files/10-kanidm.conf index dc7c9e4..77f85b1 100644 --- a/images/fedora-cosmic/files/10-kanidm.conf +++ b/images/fedora-cosmic/files/10-kanidm.conf @@ -5,3 +5,12 @@ PubkeyAuthentication yes UsePAM yes AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u AuthorizedKeysCommandUser nobody + +# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH +# public key to your account before relying on this, or you can lock yourself +# out of SSH. +PermitRootLogin no +PasswordAuthentication no +PermitEmptyPasswords no +GSSAPIAuthentication no +KerberosAuthentication no