You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

AWS Simple AD是否支持SSH密钥上传及Linux实例认证?

AWS Simple AD & SSH Key Authentication for EC2 Linux Instances

Great question—let's break this down clearly for you:

Core Answer

AWS Simple AD does NOT natively support storing or managing user SSH keys for authentication to EC2 Linux instances. Unlike OpenLDAP (where you can easily define custom attributes to hold SSH public keys), Simple AD is a lightweight, Samba-based directory service that only supports basic Active Directory-compatible features. It doesn't include built-in attributes or functionality for storing SSH key data, nor does it integrate directly with EC2's SSH authentication workflow for keys stored in the directory.

Workarounds to Achieve Similar Functionality

Since you're migrating from OpenLDAP and need to maintain SSH key-based access, here are practical alternatives:

  • Use AWS Systems Manager (SSM) Parameter Store/Secrets Manager:
    Store each user's SSH public key in Parameter Store (as a plaintext parameter) or Secrets Manager. Then, configure your EC2 Linux instances to pull the corresponding key for an authenticated AD user (via PAM integration with Simple AD) and add it to the user's ~/.ssh/authorized_keys file on-demand, using a custom script or SSM Automation document.

  • Upgrade to AWS Managed Microsoft AD:
    If your use case allows, upgrading to Managed AD lets you extend the Active Directory schema to add a custom attribute (e.g., sshPublicKey) for storing SSH keys. You can then configure your EC2 instances' SSH daemon (sshd) to query this attribute during authentication, mirroring the exact workflow you used with OpenLDAP. This is the closest drop-in replacement for your existing setup.

  • Leverage IAM Identity Center with EC2 Instance Connect:
    For a more AWS-native approach, use IAM Identity Center to manage users/groups, then grant access to EC2 instances via EC2 Instance Connect. This eliminates the need to store keys in a directory entirely—users authenticate via their Identity Center credentials and get temporary access to the instance without managing SSH keys directly.

Additional Note

If you stick with Simple AD, you can still enable password-based SSH authentication to EC2 instances by configuring PAM to authenticate against Simple AD. But for key-based auth, you'll need to implement one of the workarounds above since native support doesn't exist.

内容的提问来源于stack exchange,提问作者Aun Muhammad Raza

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.20 12:20:29