Keep sshd_config.d drop-ins working and resolve sftp-server per distro
The wholesale sshd_config replacement is intentional, but two side effects were not: - The template had no Include line, so reinstalling dropped the `Include /etc/ssh/sshd_config.d/*.conf` that update_ssh_banners_config appends, leaving the per-user banner drop-in on disk but inert. Add it as the last line: OpenSSH uses the first value it obtains for a keyword, so the template's own settings still take precedence over any drop-in and only the Match blocks become effective. - The template hardcoded the Debian path for sftp-server. sshd -t does not verify that the binary exists, so SFTP broke silently on distributions that ship it elsewhere. install.sh now probes the common locations and rewrites the Subsystem line. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
b0a0aa9e3c
commit
a0476a7e9c
+21
@@ -99,6 +99,27 @@ cp "$SSHD_CONFIG" "$BACKUP"
|
||||
cp "$SCRIPT_DIR/ssh" "$SSHD_CONFIG"
|
||||
chmod 600 "$SSHD_CONFIG"
|
||||
|
||||
# The template carries the Debian path for sftp-server. sshd -t does not check
|
||||
# that the binary exists, so on other distributions SFTP would silently break.
|
||||
SFTP_SERVER=""
|
||||
for candidate in \
|
||||
/usr/lib/openssh/sftp-server \
|
||||
/usr/libexec/openssh/sftp-server \
|
||||
/usr/lib/ssh/sftp-server \
|
||||
/usr/libexec/sftp-server
|
||||
do
|
||||
if [[ -x "$candidate" ]]; then
|
||||
SFTP_SERVER="$candidate"
|
||||
break
|
||||
fi
|
||||
done
|
||||
if [[ -n "$SFTP_SERVER" ]]; then
|
||||
sed -i "s|^Subsystem sftp .*|Subsystem sftp $SFTP_SERVER|" "$SSHD_CONFIG"
|
||||
echo "Using sftp-server: $SFTP_SERVER"
|
||||
else
|
||||
echo "WARNING: no sftp-server binary found; leaving the Subsystem line unchanged."
|
||||
fi
|
||||
|
||||
# Validate SSH config (silent)
|
||||
if ! sshd -t 2>/dev/null; then
|
||||
echo "ERROR: SSH configuration is invalid!"
|
||||
|
||||
@@ -28,3 +28,8 @@ AcceptEnv LANG LC_*
|
||||
Subsystem sftp /usr/lib/openssh/sftp-server
|
||||
UsePAM yes
|
||||
Banner /etc/bannerssh
|
||||
|
||||
# Kept last on purpose. OpenSSH uses the first value it obtains for a keyword,
|
||||
# so everything above still wins over any drop-in; this only lets the Match
|
||||
# blocks that menu.sh writes to sshd_config.d (per-user banners) take effect.
|
||||
Include /etc/ssh/sshd_config.d/*.conf
|
||||
|
||||
Reference in New Issue
Block a user