在 'sshd_config' 中匹配多个用户

IQA*_*eas 14 users ssh configuration sshd

我正在尝试将相同的sshd设置应用于多个用户。

根据手册,它似乎Match User像一个AND:

引入条件块。如果Match满足该行中的所有条件,则以下行中的关键字将覆盖在配置文件的全局部分中设置的那些

我如何状态“为这些用户......”,所以在这个例子中bob,joe和phil被允许使用SSH作为代理,但不允许登录:

Match User bob, User joe, User phil
    PasswordAuthentication yes
    AllowTCPForwarding yes
    ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)

Kus*_*nda 27

我自己没有这样做,我只能继续手册上所说的:

从sshd_config手册:

匹配模式可以由单个条目或逗号分隔的列表组成,并且可以使用 的 PATTERNS 部分中描述的通配符和否定运算符ssh_config(5)。

这意味着你应该能够说

Match User bob,joe,phil
  PasswordAuthentication yes
  AllowTCPForwarding yes
  ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)

另请参阅信息安全论坛上的此答案:https : //security.stackexchange.com/a/18038

  • 重要细节,用户之间不允许有空格(例如逗号后) (4认同)
  • @ManuelManhart 不,完全正确;如手册中所述,名称应该是*逗号分隔*。 (2认同)

小智 5

对组而不是用户使用 Match 指令。然后将用户添加到该组

Match Group users_with_no_ssh
    PasswordAuthentication yes
    AllowTCPForwarding yes
    ForceCommand /bin/echo 'We talked about this guys. No SSH for you!'
Run Code Online (Sandbox Code Playgroud)