From fa083565409bba7215dfb7249a77559c33ec20ee Mon Sep 17 00:00:00 2001 From: macmpi Date: Fri, 12 May 2023 08:41:41 +0200 Subject: [PATCH] re-order ssh config code and add log info about temp key use --- headless.apkovl.tar.gz | Bin 4822 -> 4827 bytes overlay/etc/local.d/headless.start | 34 +++++++++++++++-------------- 2 files changed, 18 insertions(+), 16 deletions(-) diff --git a/headless.apkovl.tar.gz b/headless.apkovl.tar.gz index 4c076e0d2a109934956cc81139c0e478825fc463..72fd7185160840783e156183eb46692ca6426bdf 100644 GIT binary patch delta 4685 zcmV-T60+^qCEF#C9XzXaQiBj6v>*g%fu2-~eP6^X$mF{ZlI^tPB<)!o&vcbf)q8-> z;hx_;>%D;Ay6`7|Fd;M1B>6bb^!AZiGJk_J&+&)Gulv~boA;;V?qG@_{u}-$C>s9+ zMBX2S-=~lMhnpt)LuO1P# zj3)*i2yd&&-G<}ViR_O0VRhN_Jbz7leO*guUbt*dYqdv^WS{J@&7L1N%&jx3sKCy| zL7NaUf}|~(EF;aoN|@2gg}6rJ2uX4QUazj?!u1-Z4?9@E!*1iCGN$hj&K}()^8Ql$ zo1WWv*Mflkg|_Z{YSr*59OZH8ZBADysM2nsE6V=JYOB>LWFU-0ZtKAN|a6uu0$SCff3SulJ17k+X9X zo&pgH)E3!O=wgkyqCp=Pdxs@&n$Qc(+Fj>#RQiVv)R5Pk2xYu;^Fw(P^W>6QFP&UZ z&gm5naJSFT3}PmhTHjIxxqn&ZkeQqG6m_^Gw9LxcZpWlC@a9|a9{>MlXH{JIPmynX zncpPMv^Fd?*Z>i$D{uLy6*qn|0x`QtNs%dhJ395AA+9lv=Ag& z0r#q)==us&HTlFD0=N;(2N!VgMdlQb-cVbYwDpolf8Z7p**p31et#-BIonwW?ls-} z2DcmT|J%vM!qz$ihfy((xBXp+UmVC~)Jqe?;ih_8VJM^Vrq?$UW!7B1yg8b;gAQc~ zx&D2Ob-dFn#ZQE*0bIg2NBy4;3fw{Sd6zBRT_A?H>%8s zs9P3B;+W|M%_{O#PHmio4d3q^Af-%;%{oDF*@YQIF=P(J@p6sYl-Acb-7`y1CL?v! zsP1rCIZKDw_BVyt#yP7iX_87)tCu6N%qTpr2fnZ?NPoq{qwdg9M01r&Smkx4XLeLj z);2sQhLNd9?S`7F+IF6qU6!^?VNIP`P7nd))pNMYGV2vd#te$F6lHg|ck44> ziKf$Hw{5V%#*ry$fu--urC3pq1GF;Gof`e}Sp;woHfh1_M46GU=jEYWCT=wET-Ug( z!15X9F~`@djjM%1a%g;ML+;s&u12eZT%1oaFMn*~<)pS5Nn$LzkDB;okBbv?AsGli(DhL$ z0Bty_EhmsYUWkIu7(+JXPA5eqS5s473m59R?nR0Vuktokhg9jTjbiIH3wtAEIg=JE zDbxd!VHjeb@Tc&qoh909bbRodrr+#us{g1dySctR!h$<{_?bw9713eG6l0coV1K)} z3rn{UFkaWT#M&Fkw?=8?@rk#DV}DXEQ-n(Taeo#dWEgXpKk2Nj`-nFC`LE zMz^%QGD-u`Io{?{;og>$kJ7#v2sb1-be&>)GCGFo0`E9V#hMEVTclrPqGD5-<2D7k zudXzOY=p^^M&8Zi8HUM1LL-alg%LeZz?;ik50C%R<{PcI0;0yT(erZW&_4 zm}@*S$%2qQC^ZjWGyx1=$VGnImdpjcI)UdORK1W94kQ}USVqnAewz^#8 z0+Cd87stU_L~cRK#)yB!bpRGR!r@j!y;FC?fDX8@L>AV`5Gi%j;#V);>VK_#s&;A! zdn$G4@GaRzeW+iSxZo9VbZ|DIr31GjJs+UGpPbB2~h60{5n=0e>BN=Y%7 z?5uKW?6bIQw^6<};tpACPf^Gdd9ER$;ish$YI2!dESs#D)(1Eh>2psqE0Ta6dc|H# zjyNsg$ms2mW2l9<=5E_6+`HK>?aD`kJuKONWgO0%h^=d7FjhGMNP2MyLIJOvle5VA z{pqME=ng*kP;1IHbbo`+P&JPu?_^nBurziNe3aOdTR{uk!#RSu%Q_(mfOhOlKyo)( z&dZ6u4!)1?b%j*AX&DFkX@w3Z-dK$((F{tV$QT{v{X`!Z@S3f9M@A0Jn3y$Ch#Ad7 zqr$;vRLVz^>l^Q|-%=XAV*Cr~!E4e`%$05I9VZyJ2F5X|<$oNm>z#04PAZ|}7(wY4IP$*P8(j1WmFWKn4<&&(x( zaUj&tNgP>$O;RDhn*N1$4h@N47e1uGR9^LLHSt13`i^%Bs>-zH2=%AbYP4M#vEgmC zt_pPrtUP$C;(x)ODx+8(mYdSNmJK;H3}+P6z!+rXE~#9DngrDjg^;Hlhhalaoca7L zbLZ>wVljyfRBL=KbKym%j}%kGYi(Z9=qzoVuFZyGvDRJ%^rF&CyB9*XX?EULWt7X9 zWz33nv}#@$QQ{E?4x_L>6jXq(;rnW9p^Xm4A_qxqTz@I+EFCSavzR*4X>y1EKaV3m z(g&vd{x2(CJA3y2uy??Z_rLG_{)511oSelT?|&)kTWZ&U` z8mG{={7;a?$M?S$ z(68&VZj<~AD>C(6*mqx|05FS%ehoe~E%@R`;{h0a zLcy{#X{>V`#9;GK5|rIM%g;UsKAmxbf41j=zZ?(vG%n^~&$8JB z6oR~4Gkh-&zvTRuAmC?>|898qu=p8b5CeA$d?uWZb3;ykIPr_aVzx(d@tnyOS?&chQF%S0gGJeeX#Y+_a zJweOLvE3AS$(~1idGgIS_oLrN?_Hx8xz%rL8#23if2Hn`692`x1HT8q{1W^S0K3L{ z@8+1pzKz|NJaDEtU+a6FLy>0!dq$oy7$g3{4eiz+?D1zV`UcQnBYO#K9npf!vAt}aO=Kt83dlpRXweohy69VhK$d8k zyOO9poNi7;$*#aOTVzO15pAKK<3F^yyRzPhF1;H|E-zxwn#R z{3RtfSjsSz8~PTvaL*ZAw9-D!72`CXAC1c`(Gv<&axHw6{?E5MJiBWtd=~JSE0-EEXk7yx zMe)>KbCwCHs|*z~;c<$f=_N)Z#WNxQnl>+j&cYL^M6l~YWgwAM-zqRItq$*L3~7yC zf8>Pea1FicPe3B+6Q_WkjpkfMB6|}h*>+xNCuLi5I8*Z(`};@=G=(qS7`v}>g1;BK z$TEJ@v7E}9t&v`rFH(0Aa(X5PWnSrlb?*nv45p)jRd>JkjM&)yX^pj?syOq#<>+&E z6=#uLqXK*W{Nj_I8CF7ZamzL`euP8ke>%2tAH!?}F*24wTW$<3v*L6^zzZxe<{QLA zILAgHB-1%i@4|*SEHPTwPR%?qd`h}`THEvq<`VIL#2rf$WgeKejLfpaL`C`g6iFVh|v)P-BAr6EEa$oF`OGUqQ%0woAofj|n0>$V_USoo5*o zkoMbXZOqX=CFoY?D{6=VCwXF2*RYBjJoIR??9#-D4lg8x@_D#Js9iym-KvO9R41V8 zy53-2*6l*bt|XFv4lkXA()F>Pf8ZKu#8nYdD~$lY3*K(vK|?+qN3XU>kPJiI_wLTU z;rLzoK_0tV#$&+zNxG_J1{GqD1p1~f`qXP>=-n=4?PQJpX^pz=p`&~1DUl$Uxq0lZ z3_4+@j0k6-bPhmB#OCi`v#$>+V<8vl9{n`{iTy!s3}&yOZ}!*se*4u~e_3zsaE)1) zh6VqWIrJsZt-t@M{{F|F4)=e@ksA=~U~}mAe=hpp|Fh4gt>1sm&WHQIW5@$y|3oaM zzR-{=V_*J#Ie9}?Kxt~=`T_pHMEEX)ATlx+bfY13&SofH$_nG5ifc+|uej@6%p7~^ z@PC}M=g#vP)9gprEiasle@n;X&SL6#rw(@qWd0S>L30j1$NlktdN!L5_kKR+ArOaB;BKmX!-;=p!r z|MQ;`T^P>)2-1E2`c~>-a~S@2dH3_TPfv;e+4_b|#3BPLIqZ`5@|&OkAcG7t$RL9Z P^83jT-w5Oj08jt`&u&{k delta 4631 zcmV+y66o#QCDtX79XwH`lNy8op#>p8LeP_PvG0pm1(|&JL9(58w)QNJXS&L#>ODZ` zaL@0a^pph<=KbloJD4Jf|AzkwipDHZ_fBIedj}thKqZmTX{zp-a{FwhAg5LOl{(BjfP5ZKL?3bxO zK3ARdzI41J|51dde&K)ee)yRGAAn}RKg})&*_oEOJlPyNx)^`IT(L)XdH*>)u78%A zvb<&?vI_}Zy6nieV5b{L0s@Sbv;6?9(H^5T}zJEOgw`;Iy_ zTwe|xM}N~^U)Q3+@t5s+qx1-p9FhaJJ#fR8xpjIK6_`OB z)d>+INZgUhDpLKci0Q3V2pcqxkR<2f&H73%U9XY*u!DI#?6wXnVcOy79MEkd9WJ%M z?b)q&EeP0Os++#2)(w}!Q687x_IwqCD(#kZp8uEG*pp0{Fekg5Yj$ARDm6L0U zkzU~dcl+F65Hqoq`j#Td&3`I~%-p8usKXt;W!BDaHztjaH{XKy`2ROMtK!0cihSG4 z{H6i^ucP-P{cq`4_22g}l0+Bx9`L?&JnH|i>;6yupThB9)PI7)kdO8ML(tQmmb@s* z;6dSKOmpC=@!M~KhiQ3v_4{W3ApZYn`TxGwfbZJ>&FTKj^&f!}AM^i1(0%>) z+U1WmAopqwm{}_cm35xH|0W5)9sIu)`ybZ{|625W`@i?8<9{9fpF~LPm;IkW=#TmT zA?Oe6|I6&r|Gh`2b_+m`9;{)$`7UVk>~Km3yE0{tILMN)IqS?+6Hvs6lninM=uWW!N2I?ue0TiB{VlU*N!w%z9arFr8v7S>7A=eq(Tz zU^*>!+XYK(9GQ~l7xaC(6wAtKfYv&?SE8RkivaGyCN9~%ATi?ASRK1n;zsk%b%VPy zEEzC|IlfkHT{YyBW8;fk^02sQO0+J>rE!iqVSl>}Ar;sx_Bkm@w_KB_W{2?Jh1no; z1PRS4q*x*sRZ$l`X}b|d+T7VRGgafDkf)%*aZ#D81TGj54OH5+xlET;gtUB2lq{R? zqiM5YJ(rMneTzX|W0{ibR;Lt#b!|`WX|p7DY(0tOAr}M7iI!^xI2voh?DPFW5UA3z z4u44Oo(f~T)()o5q<)H$&Lbs&6xr_7?K3Q5-pZ;w=8upXJLGp`y0hE(LiMd&8vIE>#k>@rXFdr;y~tL`2Hy zmX=pWZU8#R+gvQ%+iLPr+7|-;h9t+XlTA-T$1q*u9ZM-#b0J}i^ovZ8Z7OrzrXUa1 zm8Os_KiN?P92jLWj#IkdB9|VK27g32?DAUMvI2^trP4|g-}cKrxf>3yzE-X~h8QvC z8c$5JBqR??&7&7h0D~7&k)L-Zb3w0;?kCoy{j_{cNx*fa^T}&!@*=FlO>_c zI;2lMatwVlu;|t1fTPb2W(E30~t3*BY!a(lPgiOeabC6 zt6b@aEbiJ}lyCI7LzcU96mmqKt4OH(X{m>*ROZ%Vk*t~42UrE^b5ArYl7Jn0y||Vv zabCia-rFI|P)l#a-gZ@ZaI<~dm5&B{TrK*wel)hxqORpZU*`lMYQ-@KdAx4U&NAl? z=aVd>d-&)>ttr*e4SzDAY92@0OOmo&(Ab6dQDR5#cr|Q~Mg*~!O+pd??bw%qWN(s` zmlJ&*d>=n(GAVb{Dh~4V8XZi$u^LmP8I(eiF*-?yi9Rji&7$fZ2{|%jV%9(*Wb^_W zWfnH0QaX`r-+0Hvj#BA0<6lS*-jKR%u5JC`IKi;fF_uX!=YM$J?D_kG!lPnVzEuD$ zvnIR4_I1ssSwD^tWc8CM$m+0`-TM>lxohk>`=EBItrl5KRyFKogg}bn0u`syU@i%a z1EGpe!noiUNy_I})4$Npu_5v6(uZW2%By}+O&lMQzT=&PsxqxPLj5VV8g(B=i}1GI zRE4q!)*d`n@qb`Xm0qlmt8Hms%Z3~phSiH{V05x^S5&S-O@gY&g3nWy#jv3!3@$e$ z*0`=N7L!OowZS(M8(t*(L@_nIQRfwnwxIR%wb@b&thLtxy{uHz?)h-hG<$ESF!E*0 zGGyY!|Cg1nojrSh*gN3I``>qd|3S=U62}pgyubgwKQ8+C{`UjW+x~y^xaRq8lJ_{- zcle*4cl~etkI@u;-~W^N$M?Sz8YNATaj0srFx7<@v(uYlQvUx1q5b`>c5lhF(pf8jOI zAK{_0Up8G;WwC1)?elD_;B)Z%Z@@P43*gh=G?ozuG1xqm1Z6kR^0Uu@PiLH8{R!Eeu5apz}*6$fp0+~h@V0Fhpk>C zDP9@zEyf$md~sI+zW$2sEhB@oe~P=>rt;kxi0|Da<|p}h##Ur%l7%yu({JnX| z<=ewPZhU10-}@`*baCd*f&Lo^o}Zs*e*|Sc^ZNOB@Wo%U285fjf!)k*n){@_0zUOh z;L}fCyYXk0v*4fp^mpWG@%`67&Ueg=8PZqx!(F5W|Ms^h{vd$gefN7-e|aTpcXN)u zm3+S(r zy#h85S7!aI6n%)?>(u@0f6h6&F@$-h{uuYHqR-K<;GCgryV*-*$5{pBVf`33 zYz2%CeH#$a5+ieyNR^W8`rr3lO0p$cYLdeB9;yojb@|PEFV8)flCCGN>(XC;^#%QP zDn+E+C&yL79%kXMG#kB7=@{JUDAF7Hr4De<8#%PnKFyWmw4NW0f2u9f6AD_UQ~hA$ z-&!?JXhg!sAJ~Z8suw!Qbsq0*#vhlj$F{JQS<2+p>dPrf3q@Tm9AqL+fHr2!DAOu+ z{*)L71x~4c0&1}Y@PHA5XVh;aSPpbZHMYD2hDN|LfQn8ssTGg5EHQd51C;(Jwl+NT zwUz-3g%XBSBL=Nof1sl%p7OO|nS{EkP@xl{Qepw;Y{?ZmS&(y@UbPRdKNpSQ8D9{s z(aZYn`EDzFh1lhDBUr50r~qQV`}M7z8Jj1#-?EKXKVUDyLbeDn%tjK?V2Lm>R|3`` zi^-5hI5kkL5*xrgY`&3*G!!zZcc~fy1;^{c4H^%^p3`Hnf9H)&PaMZj8cl=Sa;mPv zi8eBHIv}If4ob{vRloyls<(h&9T1Vi;W}GjS2BAOC)svUxR%#tmG3Yg6j;ZF=AU9__*pE&RZYdu4q|naK8y~vR&BEi(Z#v`9Zmj( z3G1utdh=k^f3K>q>xt1=`NA@`x`gMwZI*4j8{cH}^&d>ILv7mjsfO=0z2 zg9JNA2?jXR3j!*l24JT!LxQD`{YY??Csa*8!L-4mE5+kHBna7HDQR(vMV0|y(*9H0 z81rn;^}9*VD{6=V$9Yolme#pw_;rtYsxECUcIb_ueiY za8e}*oG@jmtTh6vF2!L39~ue(9d@;4=2K9=eedq18qn88 z{By;#Oeo;@Bwf`ge~qytf&N?KsWXswXx^KUqRpO$B+H~YtyaX+Tniki=^e~ zUu6z^$#d`bANB8l-06Jy{^KO_8K67b9QOU6dH?%=?&b90`>)y6aQ}A-IVbi{3|!j_ z4Q(>^{_mILH{=DBriMHS@ef=?>@o=AEDK3De;U%}Yz31{S?N4faZBm!jo{vV=DByC z_{Fu4FQ^-AR_$YJS zi~sI*%l=oh>G1u>N#qFlk0GK|Gb29a(jYYrGQAci;@g{G> /etc/ssh/sshd_config + AuthenticationMethods none + PermitEmptyPasswords yes + PermitRootLogin yes + Banner /tmp/.trash/banner + EOF + +cat <<-EOF >> /etc/conf.d/sshd + sshd_disable_keygen=yes + EOF # banner file cat <<-EOF > /tmp/.trash/banner @@ -90,26 +103,15 @@ cat <<-EOF > /tmp/.trash/banner # bundled temporary keys are moved in RAM /tmp so they won't be stored # within permanent config later (new ones will then be generated) mv /etc/ssh/ssh_host_*_key* /tmp/.trash/. - -cp /etc/ssh/sshd_config /etc/ssh/sshd_config.orig -cat <<-EOF >> /etc/ssh/sshd_config - AuthenticationMethods none - PermitEmptyPasswords yes - PermitRootLogin yes - Banner /tmp/.trash/banner - EOF - # inject optional custom keys (those might be stored) if ! install -m600 "${ovlpath}"/ssh_host_*_key* /etc/ssh/; then - echo "HostKey /tmp/.trash/ssh_host_ed25519_key" >> /etc/ssh/sshd_config - echo "HostKey /tmp/.trash/ssh_host_rsa_key" >> /etc/ssh/sshd_config + logger -st ${0##*/} "Using bundled ssh keys from RAM..." + cat <<-EOF >> /etc/ssh/sshd_config + HostKey /tmp/.trash/ssh_host_ed25519_key + HostKey /tmp/.trash/ssh_host_rsa_key + EOF fi -cp /etc/conf.d/sshd /etc/conf.d/sshd.orig -cat <<-EOF >> /etc/conf.d/sshd - sshd_disable_keygen=yes - EOF - rc-service sshd start ## Prep for final post-cleanup