Disable password/root/GSSAPI/Kerberos SSH auth now that public keys are served by Kanidm.
17 lines
630 B
Plaintext
17 lines
630 B
Plaintext
# Fetch authorized SSH public keys from Kanidm (uploaded to the account).
|
|
# Name this 10-* so it is read before systemd-userdbd's AuthorizedKeysCommand
|
|
# drop-in, since sshd honours the first directive it sees.
|
|
PubkeyAuthentication yes
|
|
UsePAM yes
|
|
AuthorizedKeysCommand /usr/bin/kanidm_ssh_authorizedkeys %u
|
|
AuthorizedKeysCommandUser nobody
|
|
|
|
# Hardening: key-only auth through Kanidm. Make sure you have uploaded an SSH
|
|
# public key to your account before relying on this, or you can lock yourself
|
|
# out of SSH.
|
|
PermitRootLogin no
|
|
PasswordAuthentication no
|
|
PermitEmptyPasswords no
|
|
GSSAPIAuthentication no
|
|
KerberosAuthentication no
|