You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

关于sshd_config忽略AuthorizedKeysFile指令及LDAP公钥脚本重复调用的问题求助

求助:sshd_config忽略AuthorizedKeysFile指令及LDAP公钥脚本重复调用问题

大家好,我遇到两个关于OpenSSH服务器配置的问题,折腾了好久没解决,希望能得到大家的帮助:

问题一:sshd似乎忽略了AuthorizedKeysFile配置,用户仍能通过ssh-copy-id生成个人authorized_keys

我想阻止用户用ssh-copy-id往服务器添加自己的公钥,于是做了以下配置:

  • 在sshd_config里指定全局的授权密钥文件:
    AuthorizedKeysFile /etc/ssh/global_authorized_keys
    
  • 用sshd -T | grep -i authorizedkey确认sshd已经加载了这个配置,输出结果是:
    authorizedkeysfile /etc/ssh/global_authorized_keys
    
  • 创建了对应的只读文件:
    ls -l /etc/ssh/global_authorized_keys
    -r--r--r-- 1 root root 0 Sep 15 10:38 /etc/ssh/global_authorized_keys
    

但重启sshd服务后,客户端依然可以执行ssh-copy-id client@server,执行过程输出如下:

/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed
/usr/bin/ssh-copy-id: INFO: 2 key(s) remain to be installed -- if you are prompted now it is to install the new keys
Number of key(s) added: 2

Now try logging into the machine, with:   "ssh 'client@server'"
and check to make sure that only the key(s) you wanted were added.

之后我在客户端的~/.ssh目录下发现生成了个人的authorized_keys文件:

ls -l ~/.ssh/authorized_keys
-rw------- 1 client client 1312 Sep 15 10:42 authorized_keys

看起来sshd完全没理会AuthorizedKeysFile的配置?我的服务器版本是OpenSSH_8.4p1 Debian-5+deb11u1, OpenSSL 1.1.1n 15 Mar 2022

另外补充:我还尝试把用户个人的authorized_keys改成指向全局只读文件的软链接:

lrwxrwxrwx 1 root   root    31 Sep 15 11:15 ~client/.ssh/authorized_keys -> /etc/ssh/global_authorized_keys

问题二:LDAP公钥查询脚本每次连接被调用两次

我用LDAP作为用户公钥的来源,sshd_config里相关配置:

AuthenticationMethods publickey keyboard-interactive
AuthorizedKeysCommand /usr/local/bin/ldap-ssh-keys.py %u
AuthorizedKeysCommandUser nobody

最初我用shell脚本实现LDAP查询,后来改成了Python版本(做了一些安全优化,比如用LDAP过滤防止注入),脚本内容如下:

#!/usr/bin/env python3

import argparse
import ldap
import ldap.filter
import syslog

def main():
    parser = argparse.ArgumentParser()
    parser.add_argument("username")
    args = parser.parse_args()

    # Use filter_format() to avoid LDAP filter injection
    filter_str = ldap.filter.filter_format("(&(objectClass=posixAccount)(uid=%s))",
                                          [args.username])

    conn = ldap.initialize("ldaps://ldap.example.com")
    try:
        conn.simple_bind_s()
        res = conn.search_s("dc=example,dc=com",
                            ldap.SCOPE_SUBTREE,
                            filter_str,
                            ["sshPublicKey"])

        if len(res) == 0:
            syslog.syslog(syslog.LOG_WARNING, f"No LDAP entry found for {args.username}")
            exit(2)
        elif len(res) > 1:
            syslog.syslog(syslog.LOG_ALERT, f"More than one LDAP entry for {args.username}")
            exit(1)

        for dn, attrs in res:
            keys = attrs.get("sshPublicKey", [])
            syslog.syslog(syslog.LOG_INFO, f"Found {len(keys)} keys for {args.username}")
            for val in keys:
                syslog.syslog(syslog.LOG_DEBUG, f"Found key: {val}")
                print(val.decode().strip())

    except ldap.LDAPError as e:
        syslog.syslog(syslog.LOG_ERR, f"LDAP error: {e}")
        exit(3)
    finally:
        conn.unbind_s()

if __name__ == "__main__":
    main()

现在发现每次用户连接服务器时,这个Python脚本会被调用两次,从日志里能看到:

Sep 16 06:58:16 egde ldap-ssh-keys.py: Found 1 keys for jeremy
Sep 16 06:58:18 egde ldap-ssh-keys.py: Found 1 keys for jeremy
Sep 16 06:58:18 egde systemd[1]: Started Session 742 of user jeremy.
Sep 16 06:58:21 egde systemd[1]: session-742.scope: Succeeded.

请问这两个问题该怎么解决呢?麻烦大家帮忙看看,谢谢!

备注:内容来源于stack exchange,提问作者Jeremy Ardley

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 13:13:10