Skip to content

Repository files navigation

Build Status Code Climate

SSH keyreader with authorization via LDAP

Features

  • Reads standard PosixAccount and PosixGroup object classes
  • Uses GoSa authorization scheme (trustModel and accessTo attributes)
  • Can read authorization not only from user entries but from groups too
  • Support NIS netgroups in accessTo attributes with sudo-compatible syntax, netgroups are distinguished by prepending 'plus' sign (accessTo: hostname, accessTo: +netgroup)
  • Netgroups are received via libnss (you can back it to ldap by libnss-ldap or sssd)
  • Keyreader can ignore keys without "from" option

How authorization works

  1. keyreader is launched by sshd with user login in argv[1]
  2. keyreader looks for PosixGroup objects where user is member
  3. keyreader validates if found posix groups have this host in accessTo
  4. keyreader gets all netgroups which found posix groups have in accessTo
  5. keyreader checks if any netgroup has this host in members
  6. if keyreader founds granted access, it looks for user with uid same as login and print their ssh pubkeys to stdout, otherwise it does 3-5 steps, but for PosixAccount instead of PosixGroup
  7. sshd reads ssh keys (if there're any) and uses them to authenticate user

About

SSH keyreader with authz via LDAP

Topics

Resources

Stars

6 stars

Watchers

5 watching

Forks

Releases

Packages

Used by

Contributors

Languages