The wholesale sshd_config replacement is intentional, but two side effects
were not:
- The template had no Include line, so reinstalling dropped the
`Include /etc/ssh/sshd_config.d/*.conf` that update_ssh_banners_config
appends, leaving the per-user banner drop-in on disk but inert. Add it as
the last line: OpenSSH uses the first value it obtains for a keyword, so
the template's own settings still take precedence over any drop-in and
only the Match blocks become effective.
- The template hardcoded the Debian path for sftp-server. sshd -t does not
verify that the binary exists, so SFTP broke silently on distributions
that ship it elsewhere. install.sh now probes the common locations and
rewrites the Subsystem line.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>