IQA*_*eas 14 users ssh configuration sshd
我正在尝试将相同的sshd设置应用于多个用户。
根据手册,它似乎Match User像一个AND:
引入条件块。如果
Match满足该行中的所有条件,则以下行中的关键字将覆盖在配置文件的全局部分中设置的那些
我如何状态“为这些用户......”,所以在这个例子中bob,joe和phil被允许使用SSH作为代理,但不允许登录:
Match User bob, User joe, User phil
PasswordAuthentication yes
AllowTCPForwarding yes
ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)
Kus*_*nda 27
我自己没有这样做,我只能继续手册上所说的:
从sshd_config手册:
匹配模式可以由单个条目或逗号分隔的列表组成,并且可以使用 的 PATTERNS 部分中描述的通配符和否定运算符
ssh_config(5)。
这意味着你应该能够说
Match User bob,joe,phil
PasswordAuthentication yes
AllowTCPForwarding yes
ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)
另请参阅信息安全论坛上的此答案:https : //security.stackexchange.com/a/18038
小智 5
对组而不是用户使用 Match 指令。然后将用户添加到该组
Match Group users_with_no_ssh
PasswordAuthentication yes
AllowTCPForwarding yes
ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)