Files
bootc-images/images/shared/files/10-kanidm.conf
T
Misthios 5bea16bc01
Build containers / fedora-remote (44) (push) Failing after 36s
Build containers / fedora-cosmic (rawhide) (push) Failing after 51s
Build containers / fedora-cosmic (44) (push) Successful in 12m34s
Build containers / Prune old releases (push) Failing after 28s
refactor: share common files between images; trim fedora-remote for a VM
- Move Kanidm/flatpak/finalize.d/sshd files to images/shared/{files,repos}
  and have build.sh overlay them for every image.
- fedora-remote: aggressive hardware trim (no firmware, no kernel-modules-extra,
  no non-QEMU guest agents), keep + enable qemu-guest-agent (Proxmox).
- Fixes the missing package-list (release step) for fedora-remote.
2026-09-27 22:44:10 +02:00

17 lines
630 B
Plaintext

# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
# drop-in, since sshd honours the first directive it sees.
PubkeyAuthentication yes
UsePAM yes
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
AuthorizedKeysCommandUser nobody
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
# public key to your account before relying on this, or you can lock yourself
# out of SSH.
PermitRootLogin no
PasswordAuthentication no
PermitEmptyPasswords no
GSSAPIAuthentication no
KerberosAuthentication no