Skip to content

Commit 2489177

Browse files
committed
Merge pull request #102 from linaksa/master
Configurable PasswordAuthentication
2 parents dd908ed + 3f3cacb commit 2489177

File tree

2 files changed

+2
-1
lines changed

2 files changed

+2
-1
lines changed

attributes/default.rb

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -66,6 +66,7 @@
6666
default['ssh']['allow_groups'] = [] # sshd
6767
default['ssh']['print_motd'] = false # sshd
6868
default['ssh']['print_last_log'] = false # sshd
69+
default['ssh']['password_authentication'] = false # sshd
6970
# set this to nil to let us use the default OpenSSH in case it's not set by the user
7071
default['ssh']['use_dns'] = nil # sshd
7172
# set this to nil to let us detect the attribute based on the node platform

templates/default/opensshd.conf.erb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -104,7 +104,7 @@ HostbasedAuthentication no
104104
# Enable PAM to enforce system wide rules
105105
UsePAM <%= ((@node['ssh']['use_pam']) ? "yes" : "no" ) %>
106106
# Disable password-based authentication, it can allow for potentially easier brute-force attacks.
107-
PasswordAuthentication no
107+
PasswordAuthentication <%= ((@node['ssh']['password_authentication']) ? "yes" : "no" ) %>
108108
PermitEmptyPasswords no
109109
ChallengeResponseAuthentication no
110110

0 commit comments

Comments
 (0)