debian: 对于低版本 debian,直接修改 sshd_config 而不是追加

debian: 不需要手动设置 ChallengeResponseAuthentication
This commit is contained in:
bin456789
2026-09-07 19:21:10 +08:00
parent 6a0a2c9b3c
commit 86b88f5b71
+14 -8
View File
@@ -351,6 +351,17 @@ d-i partman/early_command string true; \
# 另一种方法处理 cloudcone # 另一种方法处理 cloudcone
# if [ "$link_grub_dir" = 1 ]; then mkdir /target/boot/grub2; echo 'chainloader (hd0)+1' >/target/boot/grub2/grub.cfg; fi; \ # if [ "$link_grub_dir" = 1 ]; then mkdir /target/boot/grub2; echo 'chainloader (hd0)+1' >/target/boot/grub2/grub.cfg; fi; \
# debian 9 tar 不支持 --strip-components # debian 9 tar 不支持 --strip-components
# sshd_config 里自带的值 9-11 12+/kali
# ChallengeResponseAuthentication no 没有此项
# kbdinteractiveauthentication 没有此项 no
# sshd -T 得到 9-11 12+/kali
# ChallengeResponseAuthentication no 没有此项
# kbdinteractiveauthentication no no
# 因此不需要自行设置 ChallengeResponseAuthentication 和 kbdinteractiveauthentication
d-i preseed/late_command string true; \ d-i preseed/late_command string true; \
for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \ for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \
username=${username:-root}; \ username=${username:-root}; \
@@ -381,23 +392,18 @@ d-i preseed/late_command string true; \
in-target chown "$username:$username" "$user_home/.ssh/authorized_keys"; \ in-target chown "$username:$username" "$user_home/.ssh/authorized_keys"; \
echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \ echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \
echo "PasswordAuthentication no" >>/target/etc/ssh/sshd_config; \ sed -Ei "s|^#? *PasswordAuthentication .*|PasswordAuthentication no|i" /target/etc/ssh/sshd_config; \
if (. /target/etc/os-release && [ "$VERSION_ID" -le 11 ]); then \
echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config.d/01-challengeresponseauthentication.conf || \
echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config; \
fi; \
else \ else \
if [ "$username" = root ]; then \ if [ "$username" = root ]; then \
echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \ echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \
echo "PermitRootLogin yes" >>/target/etc/ssh/sshd_config; \ sed -Ei "s|^#? *PermitRootLogin .*|PermitRootLogin yes|i" /target/etc/ssh/sshd_config; \
fi; \ fi; \
fi; \ fi; \
if ! [ "$ssh_port" = 22 ]; then \ if ! [ "$ssh_port" = 22 ]; then \
echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-port.conf || \ echo "Port $ssh_port" >/target/etc/ssh/sshd_config.d/01-port.conf || \
echo "Port $ssh_port" >>/target/etc/ssh/sshd_config; \ sed -Ei "s|^#? *Port .*|Port $ssh_port|i" /target/etc/ssh/sshd_config; \
fi; \ fi; \
if ! [ "$username" = root ]; then \ if ! [ "$username" = root ]; then \