From ce243e5e3e7d07f75665ce18f854a2c38cc7f43c Mon Sep 17 00:00:00 2001 From: unitexe Date: Sun, 30 Aug 2026 00:30:56 -0500 Subject: Use SSH certificate based authentication --- .../openssh-client-ca-pubkey/files/ssh-client-ca.pub | 1 + .../openssh-client-ca-pubkey/openssh-client-ca-pubkey.bb | 13 +++++++++++++ .../recipes-connectivity/openssh/openssh_%.bbappend | 8 ++++++++ 3 files changed, 22 insertions(+) create mode 100644 meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/files/ssh-client-ca.pub create mode 100644 meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/openssh-client-ca-pubkey.bb (limited to 'meta-unit-core/recipes-connectivity') diff --git a/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/files/ssh-client-ca.pub b/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/files/ssh-client-ca.pub new file mode 100644 index 0000000..2f41ca3 --- /dev/null +++ b/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/files/ssh-client-ca.pub @@ -0,0 +1 @@ +ecdsa-sha2-nistp256 AAAAE2VjZHNhLXNoYTItbmlzdHAyNTYAAAAIbmlzdHAyNTYAAABBBF4vwnl8xt6Q2pL2UI0ly2s4tEZ4Vrt5VlTgVSiLp9DBVId8ePwMKuo0zYe8/3UzqMqHexMhLMf35dPr2hKifzg= ssh-client-ca-key diff --git a/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/openssh-client-ca-pubkey.bb b/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/openssh-client-ca-pubkey.bb new file mode 100644 index 0000000..3112e80 --- /dev/null +++ b/meta-unit-core/recipes-connectivity/openssh-client-ca-pubkey/openssh-client-ca-pubkey.bb @@ -0,0 +1,13 @@ +SUMMARY = "Add SSH client CA public key" +LICENSE = "MIT" +LIC_FILES_CHKSUM = "file://${UNIT_CORE_LAYERDIR}/LICENSE;md5=38bf13be5d6979b28bd8adddb2f2f9b3" + +SRC_URI = "file://ssh-client-ca.pub" + +S = "${UNPACKDIR}" + +do_install() { + install -D -m 0644 ${UNPACKDIR}/ssh-client-ca.pub ${D}${sysconfdir}/ssh/ssh-client-ca.pub +} + +FILES:${PN} = "${sysconfdir}/ssh/ssh-client-ca.pub" diff --git a/meta-unit-core/recipes-connectivity/openssh/openssh_%.bbappend b/meta-unit-core/recipes-connectivity/openssh/openssh_%.bbappend index d520f4a..ce77f4d 100644 --- a/meta-unit-core/recipes-connectivity/openssh/openssh_%.bbappend +++ b/meta-unit-core/recipes-connectivity/openssh/openssh_%.bbappend @@ -9,6 +9,9 @@ do_install:append () { # Add global authorized_keys file to AuthorizedKeysFile sed -i -e 's:^AuthorizedKeysFile.*:AuthorizedKeysFile\t.ssh/authorized_keys /etc/ssh/authorized_keys:' ${D}${sysconfdir}/ssh/sshd_config + + # Disable authorized keys file + sed -i -E 's/^AuthorizedKeysFile[[:blank:]]+\.ssh\/authorized_keys$/#&/' ${D}${sysconfdir}/ssh/sshd_config # Disable password authentication sed -i -e 's:#PasswordAuthentication yes:PasswordAuthentication no:' ${D}${sysconfdir}/ssh/sshd_config @@ -20,4 +23,9 @@ do_install:append () { echo "" >> ${D}${sysconfdir}/ssh/sshd_config echo "# Allow only the unitexe user" >> ${D}${sysconfdir}/ssh/sshd_config echo "AllowUsers unitexe" >> ${D}${sysconfdir}/ssh/sshd_config + + # Restrict SSH access to keys that have been signed by CA only + echo "" >> ${D}${sysconfdir}/ssh/sshd_config + echo "# Allow only keys signed by CA" >> ${D}${sysconfdir}/ssh/sshd_config + echo "TrustedUserCAKeys /etc/ssh/ssh-client-ca.pub" >> ${D}${sysconfdir}/ssh/sshd_config } -- cgit v1.2.3