fedora-cosmic: harden sshd for Kanidm key-only auth
Disable password/root/GSSAPI/Kerberos SSH auth now that public keys are served by Kanidm.
This commit is contained in:
@@ -5,3 +5,12 @@ PubkeyAuthentication yes
|
|||||||
UsePAM yes
|
UsePAM yes
|
||||||
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
||||||
AuthorizedKeysCommandUser nobody
|
AuthorizedKeysCommandUser nobody
|
||||||
|
|
||||||
|
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
|
||||||
|
# public key to your account before relying on this, or you can lock yourself
|
||||||
|
# out of SSH.
|
||||||
|
PermitRootLogin no
|
||||||
|
PasswordAuthentication no
|
||||||
|
PermitEmptyPasswords no
|
||||||
|
GSSAPIAuthentication no
|
||||||
|
KerberosAuthentication no
|
||||||
|
|||||||
Reference in New Issue
Block a user