mirror of
https://github.com/bin456789/reinstall.git
synced 2026-10-06 15:37:47 +08:00
core: 使用证书登录时设置 KbdInteractiveAuthentication / ChallengeResponseAuthentication
This commit is contained in:
+16
@@ -139,6 +139,11 @@ d-i grub-installer/force-efi-extra-removable boolean true
|
||||
# https://salsa.debian.org/installer-team/network-console/-/blob/master/debian/network-console.postinst?ref_type=heads
|
||||
# https://salsa.debian.org/installer-team/user-setup/-/blob/master/user-setup-apply?ref_type=heads
|
||||
|
||||
# debian 安装后 sshd_config 显式设置了 KbdInteractiveAuthentication no
|
||||
# 但 debian 11 和以下
|
||||
# 如果没有显式设置 ChallengeResponseAuthentication no
|
||||
# 则 KbdInteractiveAuthentication no 不会生效 (sshd -G/-T 显示 KbdInteractiveAuthentication yes)
|
||||
|
||||
# 此时还没有配置源,anna-install 会在配置完源后再安装
|
||||
d-i preseed/early_command string true; \
|
||||
for str in $(grep -wo "extra_[^ ]*" /proc/cmdline | sed 's/^extra_//'); do eval "$str"; done; \
|
||||
@@ -246,6 +251,12 @@ d-i preseed/early_command string true; \
|
||||
chown "$username:$username" "$user_home/.ssh"; \
|
||||
chown "$username:$username" "$user_home/.ssh/authorized_keys"; \
|
||||
echo "PasswordAuthentication no" >>/etc/ssh/sshd_config; \
|
||||
|
||||
if grep -Eiq 'stretch|buster|bullseye' /etc/default-release; then \
|
||||
echo "ChallengeResponseAuthentication no" >>/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
echo "KbdInteractiveAuthentication no" >>/etc/ssh/sshd_config; \
|
||||
|
||||
else \
|
||||
if [ "$username" = root ]; then \
|
||||
echo "PermitRootLogin yes" >>/etc/ssh/sshd_config; \
|
||||
@@ -366,6 +377,11 @@ d-i preseed/late_command string true; \
|
||||
echo "PasswordAuthentication no" >/target/etc/ssh/sshd_config.d/01-passwordauthentication.conf || \
|
||||
echo "PasswordAuthentication no" >>/target/etc/ssh/sshd_config; \
|
||||
|
||||
if (. /target/etc/os-release && [ "$VERSION_ID" -le 11 ]); then \
|
||||
echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config.d/01-challengeresponseauthentication.conf || \
|
||||
echo "ChallengeResponseAuthentication no" >>/target/etc/ssh/sshd_config; \
|
||||
fi; \
|
||||
|
||||
else \
|
||||
if [ "$username" = root ]; then \
|
||||
echo "PermitRootLogin yes" >/target/etc/ssh/sshd_config.d/01-permitrootlogin.conf || \
|
||||
|
||||
Reference in New Issue
Block a user