From mboxrd@z Thu Jan 1 00:00:00 1970 From: =?UTF-8?q?Cl=C3=A9ment=20Lassieur?= Subject: [PATCH 1/2] services: openssh: Enable PAM. Date: Sat, 18 Feb 2017 12:46:16 +0100 Message-ID: <20170218114617.6714-1-clement@lassieur.org> References: <20170217184529.3a610d81@lepiller.eu> Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:43378) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cf3TO-0007kW-BH for guix-devel@gnu.org; Sat, 18 Feb 2017 06:46:43 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cf3TL-00026J-A3 for guix-devel@gnu.org; Sat, 18 Feb 2017 06:46:42 -0500 Received: from mail.lassieur.org ([83.152.10.219]:60666) by eggs.gnu.org with esmtps (TLS1.0:DHE_RSA_AES_256_CBC_SHA1:32) (Exim 4.71) (envelope-from ) id 1cf3TL-000265-0Y for guix-devel@gnu.org; Sat, 18 Feb 2017 06:46:39 -0500 Received: from localhost.localdomain (lib59-3-82-233-190-39.fbx.proxad.net [82.233.190.39]) by mail.lassieur.org (Postfix) with ESMTPSA id 3CDF1640103 for ; Sat, 18 Feb 2017 12:46:35 +0100 (CET) In-Reply-To: <20170217184529.3a610d81@lepiller.eu> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: guix-devel@gnu.org * gnu/services/ssh.scm: (%openssh-pam-services): New variable. (openssh-service-type): Use it to extend PAM-ROOT-SERVICE-TYPE. ()[challenge-response-authentication?]: New field. ()[use-pam?]: New field. (openssh-config-file): Add them. * doc/guix.texi (Networking Services): Document them. --- doc/guix.texi | 16 ++++++++++++++++ gnu/services/ssh.scm | 19 ++++++++++++++++++- 2 files changed, 34 insertions(+), 1 deletion(-) diff --git a/doc/guix.texi b/doc/guix.texi index 6cdb5e592..22eef3a64 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -9163,6 +9163,22 @@ enabled---in other words, @command{ssh} options @option{-X} and @item @code{protocol-number} (default: @code{2}) The SSH protocol number to use. + +@item @code{challenge-response-authentication?} (default: @code{#f}) +Specifies whether challenge response authentication is allowed (e.g. via +PAM). + +@item @code{use-pam?} (default: @code{#t}) +Enables the Pluggable Authentication Module interface. If set to +@code{#t}, this will enable PAM authentication using +@code{challenge-response-authentication?} and +@code{password-authentication?}, in addition to PAM account and session +module processing for all authentication types. + +Because PAM challenge response authentication usually serves an +equivalent role to password authentication, you should disable either +@code{challenge-response-authentication?} or +@code{password-authentication?}. @end table @end deftp diff --git a/gnu/services/ssh.scm b/gnu/services/ssh.scm index 58c35c9f5..7d6abcd33 100644 --- a/gnu/services/ssh.scm +++ b/gnu/services/ssh.scm @@ -278,7 +278,12 @@ The other options should be self-descriptive." (x11-forwarding? openssh-configuration-x11-forwarding? ;Boolean (default #f)) (protocol-number openssh-configuration-protocol-number ;integer - (default 2))) + (default 2)) + (challenge-response-authentication? + openssh-configuration-challenge-response-authentication? ;Boolean + (default #f)) + (use-pam? openssh-configuration-use-pam? ;Boolean + (default #t))) (define %openssh-accounts (list (user-group (name "sshd") (system? #t)) @@ -334,6 +339,13 @@ The other options should be self-descriptive." "yes" "no")) (format port "PidFile ~a\n" #$(openssh-configuration-pid-file config)) + (format port "ChallengeResponseAuthentication ~a\n" + #$(if (openssh-configuration-challenge-response-authentication? + config) + "yes" "no")) + (format port "UsePAM ~a\n" + #$(if (openssh-configuration-use-pam? config) + "yes" "no")) #t)))) (define (openssh-shepherd-service config) @@ -354,11 +366,16 @@ The other options should be self-descriptive." #:pid-file #$pid-file)) (stop #~(make-kill-destructor))))) +(define %openssh-pam-services + (list (unix-pam-service "sshd"))) + (define openssh-service-type (service-type (name 'openssh) (extensions (list (service-extension shepherd-root-service-type openssh-shepherd-service) + (service-extension pam-root-service-type + (const %openssh-pam-services)) (service-extension activation-service-type openssh-activation) (service-extension account-service-type -- 2.11.1