Ubuntu环境下通过SSSD从Windows AD获取SSH密钥的配置问题咨询
Ubuntu环境下通过SSSD从Windows AD获取SSH密钥的配置问题咨询
Hey there! I’ve helped several folks troubleshoot exactly this issue, so let’s break down the necessary configurations to get your AD-stored SSH public keys working on your Ubuntu servers with SSSD.
第一步:配置SSSD读取AD中的SSH公钥
First, we need to make sure SSSD is set up to pull the sshPublicKey attribute from your AD users:
- Open the SSSD configuration file with your favorite editor (e.g.,
sudo nano /etc/sssd/sssd.conf). - Navigate to your AD domain section (it’ll look like
[domain/your-ad-domain-name]). - Add or modify these lines:
ldap_user_ssh_public_key = sshPublicKey cache_credentials = Trueldap_user_ssh_public_keytells SSSD which AD attribute holds the SSH public key (this is the standard attribute most AD environments use).cache_credentialsensures the key is stored locally after the first successful fetch, which speeds up future logins.
- Save the file and restart the SSSD service to apply changes:
sudo systemctl restart sssd sudo systemctl status sssd # Verify the service starts without errors
第二步:配置sshd使用SSSD获取授权密钥
Next, we need to configure the SSH daemon to use SSSD to retrieve authorized keys instead of relying on the local ~/.ssh/authorized_keys file:
- Edit the sshd config file:
sudo nano /etc/ssh/sshd_config - Ensure these settings are present and uncommented:
PubkeyAuthentication yes AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys AuthorizedKeysCommandUser nobodyAuthorizedKeysCommandpoints to the SSSD utility that fetches the user’s public key from AD.AuthorizedKeysCommandUserruns the command as thenobodyuser for security purposes.
- Save the file and restart the SSH daemon:
sudo systemctl restart sshd
第三步:验证配置是否生效
Let’s test if everything is working before you try logging in:
- Run this command on your Ubuntu server to fetch the public key for your AD user:
If this returns your public key string, SSSD is correctly pulling the key from AD.sss_ssh_authorizedkeys your-ad-username - Try logging in from another machine using SSH:
ssh your-ad-username@your-ubuntu-server-ip— you should be able to authenticate without a password using your private key.
常见问题排查
If it’s still not working, here are a few things to check:
- AD Attribute Confirmation: Ask your Windows team to verify that the public key was added to the
sshPublicKeyattribute of your AD account. They can use PowerShell to check:Get-ADUser -Identity your-username -Properties sshPublicKey | Select-Object -ExpandProperty sshPublicKey - Log Analysis: Check the SSSD logs (
/var/log/sssd/sssd_your-ad-domain.log) and SSH logs (/var/log/auth.log) for errors. Common issues include permission problems on config files or incorrect AD attribute names. - SSSD Permissions: Ensure the
sssd.conffile has strict permissions (sudo chmod 600 /etc/sssd/sssd.conf) — SSSD will refuse to load the config if permissions are too open.
备注:内容来源于stack exchange,提问作者HBtools
相关产品推荐
相关产品推荐

