Ship an sshd_config.d drop-in so sshd fetches authorized keys from Kanidm via kanidm_ssh_authorizedkeys. Named 10-* to take precedence over systemd-userdbd.
8 lines
340 B
Plaintext
8 lines
340 B
Plaintext
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
|
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
|
# drop-in, since sshd honours the first directive it sees.
|
|
PubkeyAuthentication yes
|
|
UsePAM yes
|
|
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
|
AuthorizedKeysCommandUser nobody
|