From 86b88f5b715c5ff6fba1cc84a70d7a03ed04a4ef Mon Sep 17 00:00:00 2001 From: bin456789 Date: Mon, 7 Sep 2026 19:21:10 +0800 Subject: [PATCH] =?UTF-8?q?debian:=20=E5=AF=B9=E4=BA=8E=E4=BD=8E=E7=89=88?= =?UTF-8?q?=E6=9C=AC=20debian=EF=BC=8C=E7=9B=B4=E6=8E=A5=E4=BF=AE=E6=94=B9?= =?UTF-8?q?=20sshd=5Fconfig=20=E8=80=8C=E4=B8=8D=E6=98=AF=E8=BF=BD?= =?UTF-8?q?=E5=8A=A0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit debian: 不需要手动设置 ChallengeResponseAuthentication --- debian.cfg | 22 ++++++++++++++-------- 1 file changed, 14 insertions(+), 8 deletions(-) diff --git a/debian.cfg b/debian.cfg index c0e9296..0b9812f 100644 --- a/debian.cfg +++ b/debian.cfg @@ -351,6 +351,17 @@ d-i partman/early_command string true; \ # 另一种方法处理 cloudcone # if [ "$link_grub_dir" = 1 ]; then mkdir /target/boot/grub2; echo 'chainloader (hd0)+1' >/target/boot/grub2/grub.cfg; fi; \ # debian 9 tar 不支持 --strip-components + +# sshd_config 里自带的值 9-11 12+/kali +# ChallengeResponseAuthentication no 没有此项 +# kbdinteractiveauthentication 没有此项 no + +# sshd -T 得到 9-11 12+/kali +# ChallengeResponseAuthentication no 没有此项 +# kbdinteractiveauthentication no no + +# 因此不需要自行设置 ChallengeResponseAuthentication 和 kbdinteractiveauthentication + d-i preseed/late_command string true; \ for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \ username=${username:-root}; \ @@ -381,23 +392,18 @@ d-i preseed/late_command string true; \ in-target chown "$username:$username" "$user_home/.ssh/authorized_keys"; \ echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \ - echo "PasswordAuthentication no" >>/target/etc/ssh/sshd_config; \ - - if (. /target/etc/os-release && [ "$VERSION_ID" -le 11 ]); then \ - echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config.d/01-challengeresponseauthentication.conf || \ - echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config; \ - fi; \ + sed -Ei "s|^#? *PasswordAuthentication .*|PasswordAuthentication no|i" /target/etc/ssh/sshd_config; \ else \ if [ "$username" = root ]; then \ echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \ - echo "PermitRootLogin yes" >>/target/etc/ssh/sshd_config; \ + sed -Ei "s|^#? *PermitRootLogin .*|PermitRootLogin yes|i" /target/etc/ssh/sshd_config; \ fi; \ fi; \ if ! [ "$ssh_port" = 22 ]; then \ echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-port.conf || \ - echo "Port $ssh_port" >>/target/etc/ssh/sshd_config; \ + sed -Ei "s|^#? *Port .*|Port $ssh_port|i" /target/etc/ssh/sshd_config; \ fi; \ if ! [ "$username" = root ]; then \