Put ssh keys on configured path in sshd_config (AuthorizedKeysFile)

Signed-off-by: POTIER Mathieu <mathieu.potier@onzeway.eu>
This commit is contained in:
POTIER Mathieu 2015-11-17 11:09:37 +01:00
parent 67e500fb11
commit dda1fb5128
2 changed files with 7 additions and 1 deletions

View File

@ -38,12 +38,14 @@ include:
{{ print_name(identifier, key) }}: {{ print_name(identifier, key) }}:
ssh_auth.present: ssh_auth.present:
{{ print_ssh_auth(identifier, key) }} {{ print_ssh_auth(identifier, key) }}
- config: {{ pillar['sshd_config']['AuthorizedKeysFile'] }}
- require: - require:
- service: {{ openssh.service }} - service: {{ openssh.service }}
{%- else %} {%- else %}
{{ print_name(identifier, key) }}: {{ print_name(identifier, key) }}:
ssh_auth.absent: ssh_auth.absent:
{{ print_ssh_auth(identifier, key) }} {{ print_ssh_auth(identifier, key) }}
- config: {{ pillar['sshd_config']['AuthorizedKeysFile'] }}
{%- endif -%} {%- endif -%}
{%- endfor -%} {%- endfor -%}
{%- endfor -%} {%- endfor -%}

View File

@ -23,6 +23,7 @@ sshd_config:
PermitEmptyPasswords: 'no' PermitEmptyPasswords: 'no'
ChallengeResponseAuthentication: 'no' ChallengeResponseAuthentication: 'no'
AuthenticationMethods: 'publickey,keyboard-interactive' AuthenticationMethods: 'publickey,keyboard-interactive'
AuthorizedKeysFile: '%h/.ssh/authorized_keys'
X11Forwarding: 'yes' X11Forwarding: 'yes'
X11DisplayOffset: 10 X11DisplayOffset: 10
PrintMotd: 'no' PrintMotd: 'no'
@ -80,16 +81,19 @@ openssh:
present: True present: True
enc: ssh-rsa enc: ssh-rsa
comment: main key - desktop comment: main key - desktop
source: salt://ssh_keys/joe.desktop.pub
joe-valid-ssh-key-notebook: joe-valid-ssh-key-notebook:
- user: joe - user: joe
present: True present: True
enc: ssh-rsa enc: ssh-rsa
comment: main key - notebook comment: main key - notebook
source: salt://ssh_keys/joe.netbook.pub
joe-non-valid-ssh-key: joe-non-valid-ssh-key:
- user: joe - user: joe
present: False present: False
enc: ssh-rsa enc: ssh-rsa
comment: obsolete key - removed comment: obsolete key - removed
source: salt://ssh_keys/joe.no-valid.pub
generate_dsa_keys: False generate_dsa_keys: False
absent_dsa_keys: False absent_dsa_keys: False