STIG合规的RHEL 8系统SSH超时后tmux会话被终止的问题求助
STIG合规的RHEL 8系统SSH超时后tmux会话被终止的问题求助
我现在在一台应用了DISA STIG(通过OpenSCAP)的RHEL 8机器上工作。STIG要求用户登录后自动进入tmux会话,tmux会话在闲置一段时间后锁定屏幕,同时SSH在另一段闲置时间后断开连接。
现在遇到的问题是:我们会启动一些长时间运行的命令,然后离开。先是tmux锁定屏幕,最后SSH断开连接。我们期望的行为是,当重新通过SSH连接时,要么能重新连接到旧的tmux会话,要么新建一个tmux会话而旧会话在后台继续运行。总之,我们不希望SSH断开时tmux会话也跟着终止。
相关STIG要求及我们的配置
V-230349(用户登录自动进入tmux会话)
我们的配置文件/etc/profile.d/tmux.sh内容如下:
if [ "$PS1" ]; then parent=$(ps -o ppid= -p $$) name=$(ps -o comm= -p $parent) case "$name" in (sshd|login) tmux ;; esac fi if [ -n "$TMUX" ]; then # render /etc/issue or else fall back to kernel/system info agetty --show-issue 2>/dev/null || uname -a # message of the day for motd in /run/motd.dynamic /etc/motd; do if [ -s "$motd" ]; then cat "$motd"; break; fi done # last login last $USER |awk 'NR==2 { if (NF==10) { i=1; if ($3!~/^:/) from = " from " $3 } printf("Last login: %s %s %s %s%s on %s\n", $(3+i), $(4+i), $(5+i), $(6+i), from, $2); exit }' # mail check if [ -s "/var/mail/$USER" ] # may need to change to /var/spool/mail/$USER then echo "You have mails." else echo "You have no mail." fi fi
V-230353(tmux会话闲置锁定)
我们的/etc/tmux.conf配置:
set -g lock-after-time 300 set -g lock-command vlock bind X lock-session
V-244525(SSH闲置断开)
/etc/ssh/sshd_config相关配置段:
... Compression no ClientAliveInterval 600 ClientAliveCountMax 1 #UseDNS no ...
我还怀疑systemd-logind与此有关,参考过相关讨论。我们的/etc/systemd/logind.conf相关配置:
# This file is part of systemd. # # systemd is free software; you can redistribute it and/or modify it # under the terms of the GNU Lesser General Public License as published by # the Free Software Foundation; either version 2.1 of the License, or # (at your option) any later version. # # Entries in this file show the compile time defaults. # You can change settings by editing this file. # Defaults can be restored by simply deleting this file. # # See logind.conf(5) for details. [Login] StopIdleSessionSec=900 #NAutoVTs=6 #ReserveVT=6 KillUserProcesses=no #KillOnlyUsers= #KillExcludeUsers=root #InhibitDelayMaxSec=5 #HandlePowerKey=poweroff #HandleSuspendKey=suspend #HandleHibernateKey=hibernate #HandleLidSwitch=suspend #HandleLidSwitchExternalPower=suspend #HandleLidSwitchDocked=ignore #PowerKeyIgnoreInhibited=no #SuspendKeyIgnoreInhibited=no #HibernateKeyIgnoreInhibited=no #LidSwitchIgnoreInhibited=yes #HoldoffTimeoutSec=30s #IdleAction=ignore #IdleActionSec=30min #RuntimeDirectorySize=10% #RemoveIPC=no #InhibitorsMax=8192 #SessionsMax=8192 #StopIdleSessionSec=infinity
(注:较长的文件我只截取了相关部分)
我已经尝试过以下方法,但都没得到理想的结果:
- 修改profile.d里的启动脚本,参考过自动在SSH会话启动tmux的相关方案
- 修改SSH的ClientAliveInterval为60和10,并且重启了sshd服务
- 在logind.conf里取消注释
KillUserProcesses=no,并重启systemd-logind甚至重启系统 - 在登录默认的tmux会话(session 0)之外新建另一个tmux会话(session 1),但SSH断开时两个会话都会被终止
有没有其他人遇到过这个问题,并且找到了解决方案?
备注:内容来源于stack exchange,提问作者Andrew Laramore
相关产品推荐
相关产品推荐

