guix-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[PATCH 1/2] services: openssh: Use PAM in sshd by default.


From: Clément Lassieur
Subject: [PATCH 1/2] services: openssh: Use PAM in sshd by default.
Date: Fri, 17 Feb 2017 17:37:07 +0100

* gnu/services/ssh.scm: (%openssh-pam-services): New variable.
  (openssh-service-type): Use it to extend PAM-ROOT-SERVICE-TYPE.
  (<openssh-configuration>)[challenge-response-authentication?]: New field.
  (<openssh-configuration>)[use-pam?]: New field.
  (openssh-config-file): Add them.
---
 gnu/services/ssh.scm | 19 ++++++++++++++++++-
 1 file changed, 18 insertions(+), 1 deletion(-)

diff --git a/gnu/services/ssh.scm b/gnu/services/ssh.scm
index 58c35c9f5..7d6abcd33 100644
--- a/gnu/services/ssh.scm
+++ b/gnu/services/ssh.scm
@@ -278,7 +278,12 @@ The other options should be self-descriptive."
   (x11-forwarding?       openssh-configuration-x11-forwarding? ;Boolean
                          (default #f))
   (protocol-number       openssh-configuration-protocol-number ;integer
-                         (default 2)))
+                         (default 2))
+  (challenge-response-authentication?
+   openssh-configuration-challenge-response-authentication?  ;Boolean
+   (default #f))
+  (use-pam?              openssh-configuration-use-pam?  ;Boolean
+                         (default #t)))
 
 (define %openssh-accounts
   (list (user-group (name "sshd") (system? #t))
@@ -334,6 +339,13 @@ The other options should be self-descriptive."
                        "yes" "no"))
          (format port "PidFile ~a\n"
                  #$(openssh-configuration-pid-file config))
+         (format port "ChallengeResponseAuthentication ~a\n"
+                 #$(if 
(openssh-configuration-challenge-response-authentication?
+                        config)
+                       "yes" "no"))
+         (format port "UsePAM ~a\n"
+                 #$(if (openssh-configuration-use-pam? config)
+                       "yes" "no"))
          #t))))
 
 (define (openssh-shepherd-service config)
@@ -354,11 +366,16 @@ The other options should be self-descriptive."
                                              #:pid-file #$pid-file))
          (stop #~(make-kill-destructor)))))
 
+(define %openssh-pam-services
+  (list (unix-pam-service "sshd")))
+
 (define openssh-service-type
   (service-type (name 'openssh)
                 (extensions
                  (list (service-extension shepherd-root-service-type
                                           openssh-shepherd-service)
+                       (service-extension pam-root-service-type
+                                          (const %openssh-pam-services))
                        (service-extension activation-service-type
                                           openssh-activation)
                        (service-extension account-service-type
-- 
2.11.1




reply via email to

[Prev in Thread] Current Thread [Next in Thread]