-
Notifications
You must be signed in to change notification settings - Fork 174
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Wrong permissions for ssh host private keys on CentOS 7 #2617
Comments
@immarvin Hi, Yang song, will you pls take a look at this issue? Thx! |
fixed in #2724 |
immarvin
added a commit
to immarvin/xcat-core
that referenced
this issue
Mar 22, 2017
immarvin
added a commit
to immarvin/xcat-core
that referenced
this issue
Mar 22, 2017
immarvin
added a commit
to immarvin/xcat-core
that referenced
this issue
Mar 22, 2017
neo954
pushed a commit
that referenced
this issue
Mar 22, 2017
fix issue Wrong permissions for ssh host private keys on CentOS 7 #2617
fixed in #2724 |
@junxiawang , Could you help to verify this issue? thanks |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
The remoteshell postscript sets wrong permissions and wrong group ownership on
/etc/ssh/ssh_host_*key
files (0600), that is not compatible with hostbased authentication (for users) on CentOS 7.At least on RHEL 7/CentOS 7, the openssh package creates ssh host key files with the group
ssh_keys
and permissions 0640 for user host-based ssh authentification to work (the setuid helper program/usr/libexec/openssh/ssh-keysign
is used to read the keys and requires these permissions).Expected permissions:
xCAT permissions:
Related link: https://bugzilla.redhat.com/show_bug.cgi?id=819896
The text was updated successfully, but these errors were encountered: