关于sshd_config忽略AuthorizedKeysFile指令及LDAP公钥脚本重复调用的问题求助
大家好,我遇到两个关于OpenSSH服务器配置的问题,折腾了好久没解决,希望能得到大家的帮助:
问题一:sshd似乎忽略了AuthorizedKeysFile配置,用户仍能通过ssh-copy-id生成个人authorized_keys
我想阻止用户用ssh-copy-id往服务器添加自己的公钥,于是做了以下配置:
- 在
sshd_config里指定全局的授权密钥文件:AuthorizedKeysFile /etc/ssh/global_authorized_keys - 用
sshd -T | grep -i authorizedkey确认sshd已经加载了这个配置,输出结果是:authorizedkeysfile /etc/ssh/global_authorized_keys - 创建了对应的只读文件:
ls -l /etc/ssh/global_authorized_keys -r--r--r-- 1 root root 0 Sep 15 10:38 /etc/ssh/global_authorized_keys
但重启sshd服务后,客户端依然可以执行ssh-copy-id client@server,执行过程输出如下:
/usr/bin/ssh-copy-id: INFO: attempting to log in with the new key(s), to filter out any that are already installed /usr/bin/ssh-copy-id: INFO: 2 key(s) remain to be installed -- if you are prompted now it is to install the new keys Number of key(s) added: 2 Now try logging into the machine, with: "ssh 'client@server'" and check to make sure that only the key(s) you wanted were added.
之后我在客户端的~/.ssh目录下发现生成了个人的authorized_keys文件:
ls -l ~/.ssh/authorized_keys -rw------- 1 client client 1312 Sep 15 10:42 authorized_keys
看起来sshd完全没理会AuthorizedKeysFile的配置?我的服务器版本是OpenSSH_8.4p1 Debian-5+deb11u1, OpenSSL 1.1.1n 15 Mar 2022
另外补充:我还尝试把用户个人的authorized_keys改成指向全局只读文件的软链接:
lrwxrwxrwx 1 root root 31 Sep 15 11:15 ~client/.ssh/authorized_keys -> /etc/ssh/global_authorized_keys
问题二:LDAP公钥查询脚本每次连接被调用两次
我用LDAP作为用户公钥的来源,sshd_config里相关配置:
AuthenticationMethods publickey keyboard-interactive AuthorizedKeysCommand /usr/local/bin/ldap-ssh-keys.py %u AuthorizedKeysCommandUser nobody
最初我用shell脚本实现LDAP查询,后来改成了Python版本(做了一些安全优化,比如用LDAP过滤防止注入),脚本内容如下:
#!/usr/bin/env python3 import argparse import ldap import ldap.filter import syslog def main(): parser = argparse.ArgumentParser() parser.add_argument("username") args = parser.parse_args() # Use filter_format() to avoid LDAP filter injection filter_str = ldap.filter.filter_format("(&(objectClass=posixAccount)(uid=%s))", [args.username]) conn = ldap.initialize("ldaps://ldap.example.com") try: conn.simple_bind_s() res = conn.search_s("dc=example,dc=com", ldap.SCOPE_SUBTREE, filter_str, ["sshPublicKey"]) if len(res) == 0: syslog.syslog(syslog.LOG_WARNING, f"No LDAP entry found for {args.username}") exit(2) elif len(res) > 1: syslog.syslog(syslog.LOG_ALERT, f"More than one LDAP entry for {args.username}") exit(1) for dn, attrs in res: keys = attrs.get("sshPublicKey", []) syslog.syslog(syslog.LOG_INFO, f"Found {len(keys)} keys for {args.username}") for val in keys: syslog.syslog(syslog.LOG_DEBUG, f"Found key: {val}") print(val.decode().strip()) except ldap.LDAPError as e: syslog.syslog(syslog.LOG_ERR, f"LDAP error: {e}") exit(3) finally: conn.unbind_s() if __name__ == "__main__": main()
现在发现每次用户连接服务器时,这个Python脚本会被调用两次,从日志里能看到:
Sep 16 06:58:16 egde ldap-ssh-keys.py: Found 1 keys for jeremy Sep 16 06:58:18 egde ldap-ssh-keys.py: Found 1 keys for jeremy Sep 16 06:58:18 egde systemd[1]: Started Session 742 of user jeremy. Sep 16 06:58:21 egde systemd[1]: session-742.scope: Succeeded.
请问这两个问题该怎么解决呢?麻烦大家帮忙看看,谢谢!
备注:内容来源于stack exchange,提问作者Jeremy Ardley
相关产品推荐
相关产品推荐

