Merge pull request #9225 from omacom/fix/sshd-hardening-verification-case
Match sshd -T keywords case-insensitively when verifying SSH hardening
This commit is contained in:
@@ -172,9 +172,11 @@ CONF
|
|||||||
|
|
||||||
# Syntax alone is insufficient because sshd uses the first value it reads for
|
# Syntax alone is insufficient because sshd uses the first value it reads for
|
||||||
# these settings. An earlier administrator rule could leave passwords enabled.
|
# these settings. An earlier administrator rule could leave passwords enabled.
|
||||||
|
# Match keywords case-insensitively: OpenSSH 9.x dumps them lowercase, 10.x
|
||||||
|
# in CamelCase.
|
||||||
if ! effective_config=$(sudo sshd -T) ||
|
if ! effective_config=$(sudo sshd -T) ||
|
||||||
! grep -qxF "passwordauthentication no" <<<"$effective_config" ||
|
! grep -qixF "passwordauthentication no" <<<"$effective_config" ||
|
||||||
! grep -qxF "kbdinteractiveauthentication no" <<<"$effective_config"; then
|
! grep -qixF "kbdinteractiveauthentication no" <<<"$effective_config"; then
|
||||||
echo -e "\e[31msshd did not apply the password-authentication restrictions; removing the ineffective config.\e[0m" >&2
|
echo -e "\e[31msshd did not apply the password-authentication restrictions; removing the ineffective config.\e[0m" >&2
|
||||||
sudo rm -f "$config"
|
sudo rm -f "$config"
|
||||||
return 1
|
return 1
|
||||||
|
|||||||
@@ -29,8 +29,14 @@ case $1 in
|
|||||||
[[ ${SSHD_SYNTAX_VALID:-1} == 1 ]]
|
[[ ${SSHD_SYNTAX_VALID:-1} == 1 ]]
|
||||||
;;
|
;;
|
||||||
-T)
|
-T)
|
||||||
printf 'passwordauthentication %s\n' "${SSHD_PASSWORD_AUTH:-no}"
|
# OpenSSH 10.x dumps keywords in CamelCase; 9.x dumped them lowercase.
|
||||||
printf 'kbdinteractiveauthentication %s\n' "${SSHD_KBD_AUTH:-no}"
|
if [[ ${SSHD_DUMP_LOWERCASE:-0} == 1 ]]; then
|
||||||
|
printf 'passwordauthentication %s\n' "${SSHD_PASSWORD_AUTH:-no}"
|
||||||
|
printf 'kbdinteractiveauthentication %s\n' "${SSHD_KBD_AUTH:-no}"
|
||||||
|
else
|
||||||
|
printf 'PasswordAuthentication %s\n' "${SSHD_PASSWORD_AUTH:-no}"
|
||||||
|
printf 'KbdInteractiveAuthentication %s\n' "${SSHD_KBD_AUTH:-no}"
|
||||||
|
fi
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
exit 2
|
exit 2
|
||||||
@@ -82,6 +88,12 @@ grep -qxF "systemctl reload sshd.service" "$test_dir/success.calls" || fail "SSH
|
|||||||
grep -q "Password logins are off" <<<"$output" || fail "SSH setup reports hardening after it succeeds"
|
grep -q "Password logins are off" <<<"$output" || fail "SSH setup reports hardening after it succeeds"
|
||||||
pass "SSH setup authorizes a key and disables password logins"
|
pass "SSH setup authorizes a key and disables password logins"
|
||||||
|
|
||||||
|
output=$(SSHD_DUMP_LOWERCASE=1 run_setup success-legacy)
|
||||||
|
config="$test_dir/success-legacy/root/etc/ssh/sshd_config.d/10-omarchy-hardening.conf"
|
||||||
|
[[ -e $config ]] || fail "SSH setup accepts the lowercase sshd -T dump of OpenSSH 9.x"
|
||||||
|
grep -q "Password logins are off" <<<"$output" || fail "SSH setup reports hardening on OpenSSH 9.x"
|
||||||
|
pass "SSH setup verifies settings across sshd -T keyword casings"
|
||||||
|
|
||||||
if SSHD_PASSWORD_AUTH=yes run_setup ineffective >"$test_dir/ineffective.output" 2>&1; then
|
if SSHD_PASSWORD_AUTH=yes run_setup ineffective >"$test_dir/ineffective.output" 2>&1; then
|
||||||
fail "SSH setup must fail when password authentication remains effective"
|
fail "SSH setup must fail when password authentication remains effective"
|
||||||
fi
|
fi
|
||||||
|
|||||||
Reference in New Issue
Block a user