You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu环境下通过SSSD从Windows AD获取SSH密钥的配置问题咨询

Ubuntu环境下通过SSSD从Windows AD获取SSH密钥的配置问题咨询

Hey there! I’ve helped several folks troubleshoot exactly this issue, so let’s break down the necessary configurations to get your AD-stored SSH public keys working on your Ubuntu servers with SSSD.

第一步:配置SSSD读取AD中的SSH公钥

First, we need to make sure SSSD is set up to pull the sshPublicKey attribute from your AD users:

  1. Open the SSSD configuration file with your favorite editor (e.g., sudo nano /etc/sssd/sssd.conf).
  2. Navigate to your AD domain section (it’ll look like [domain/your-ad-domain-name]).
  3. Add or modify these lines:
    ldap_user_ssh_public_key = sshPublicKey
    cache_credentials = True
    
    • ldap_user_ssh_public_key tells SSSD which AD attribute holds the SSH public key (this is the standard attribute most AD environments use).
    • cache_credentials ensures the key is stored locally after the first successful fetch, which speeds up future logins.
  4. Save the file and restart the SSSD service to apply changes:
    sudo systemctl restart sssd
    sudo systemctl status sssd  # Verify the service starts without errors
    

第二步:配置sshd使用SSSD获取授权密钥

Next, we need to configure the SSH daemon to use SSSD to retrieve authorized keys instead of relying on the local ~/.ssh/authorized_keys file:

  1. Edit the sshd config file: sudo nano /etc/ssh/sshd_config
  2. Ensure these settings are present and uncommented:
    PubkeyAuthentication yes
    AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys
    AuthorizedKeysCommandUser nobody
    
    • AuthorizedKeysCommand points to the SSSD utility that fetches the user’s public key from AD.
    • AuthorizedKeysCommandUser runs the command as the nobody user for security purposes.
  3. Save the file and restart the SSH daemon:
    sudo systemctl restart sshd
    

第三步:验证配置是否生效

Let’s test if everything is working before you try logging in:

  • Run this command on your Ubuntu server to fetch the public key for your AD user:
    sss_ssh_authorizedkeys your-ad-username
    
    If this returns your public key string, SSSD is correctly pulling the key from AD.
  • Try logging in from another machine using SSH: ssh your-ad-username@your-ubuntu-server-ip — you should be able to authenticate without a password using your private key.

常见问题排查

If it’s still not working, here are a few things to check:

  • AD Attribute Confirmation: Ask your Windows team to verify that the public key was added to the sshPublicKey attribute of your AD account. They can use PowerShell to check:
    Get-ADUser -Identity your-username -Properties sshPublicKey | Select-Object -ExpandProperty sshPublicKey
    
  • Log Analysis: Check the SSSD logs (/var/log/sssd/sssd_your-ad-domain.log) and SSH logs (/var/log/auth.log) for errors. Common issues include permission problems on config files or incorrect AD attribute names.
  • SSSD Permissions: Ensure the sssd.conf file has strict permissions (sudo chmod 600 /etc/sssd/sssd.conf) — SSSD will refuse to load the config if permissions are too open.

备注:内容来源于stack exchange,提问作者HBtools

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 13:29:38