diff --git a/debian.cfg b/debian.cfg index c0e9296..0b9812f 100644 --- a/debian.cfg +++ b/debian.cfg @@ -351,6 +351,17 @@ d-i partman/early_command string true; \ # 另一种方法处理 cloudcone # if [ "$link_grub_dir" = 1 ]; then mkdir /target/boot/grub2; echo 'chainloader (hd0)+1' >/target/boot/grub2/grub.cfg; fi; \ # debian 9 tar 不支持 --strip-components + +# sshd_config 里自带的值 9-11 12+/kali +# ChallengeResponseAuthentication no 没有此项 +# kbdinteractiveauthentication 没有此项 no + +# sshd -T 得到 9-11 12+/kali +# ChallengeResponseAuthentication no 没有此项 +# kbdinteractiveauthentication no no + +# 因此不需要自行设置 ChallengeResponseAuthentication 和 kbdinteractiveauthentication + d-i preseed/late_command string true; \ for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \ username=${username:-root}; \ @@ -381,23 +392,18 @@ d-i preseed/late_command string true; \ in-target chown "$username:$username" "$user_home/.ssh/authorized_keys"; \ echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \ - echo "PasswordAuthentication no" >>/target/etc/ssh/sshd_config; \ - - if (. /target/etc/os-release && [ "$VERSION_ID" -le 11 ]); then \ - echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config.d/01-challengeresponseauthentication.conf || \ - echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config; \ - fi; \ + sed -Ei "s|^#? *PasswordAuthentication .*|PasswordAuthentication no|i" /target/etc/ssh/sshd_config; \ else \ if [ "$username" = root ]; then \ echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \ - echo "PermitRootLogin yes" >>/target/etc/ssh/sshd_config; \ + sed -Ei "s|^#? *PermitRootLogin .*|PermitRootLogin yes|i" /target/etc/ssh/sshd_config; \ fi; \ fi; \ if ! [ "$ssh_port" = 22 ]; then \ echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-port.conf || \ - echo "Port $ssh_port" >>/target/etc/ssh/sshd_config; \ + sed -Ei "s|^#? *Port .*|Port $ssh_port|i" /target/etc/ssh/sshd_config; \ fi; \ if ! [ "$username" = root ]; then \