From 7c4b6e29b1d48847aedbc6da5316c5a30fb5ede2 Mon Sep 17 00:00:00 2001 From: Lars Wirzenius Date: Fri, 8 Apr 2022 17:15:39 +0300 Subject: feat: add script to configure ssh on installer accept an SSH CA Sponsored-by: author --- set-user-ca-pubkey | 32 ++++++++++++++++++++++++++++++++ 1 file changed, 32 insertions(+) create mode 100755 set-user-ca-pubkey diff --git a/set-user-ca-pubkey b/set-user-ca-pubkey new file mode 100755 index 0000000..0bac587 --- /dev/null +++ b/set-user-ca-pubkey @@ -0,0 +1,32 @@ +#!/bin/bash + +set -eu -o pipefail + +die() { + echo "ERROR: $*" 1>&2 + exit 1 +} + +cleanup() { + umount "$drive" || true + rmdir "$mnt" +} + +trap cleanup EXIT + +drive="$1" +pubkey="$2" + +[ -e "$drive" ] || die "$drive does not exist" +[ -e "$pubkey" ] || die "$pubkey does not exist" + +mnt="$(mktemp -d)" +mount "$drive" "$mnt" + +include="$mnt/etc/ssh/sshd_config.d/userca.conf" +echo "TrustedUserCAKeys /etc/ssh/user_ca_keys" >"$include" +chown root:root "$include" +chmod 0644 "$include" + +cakeys="$mnt/etc/ssh/user_ca_keys" +install -m 0600 "$pubkey" "$cakeys" -- cgit v1.2.1