StrictModes constraints on authorized_keys file permissions
29K reputation · 16 Aug 2023, 16:45 UTC
OpenSSH utilizes the StrictModes configuration to ensure that authentication keys are stored in a secure environment. When enabled, the SSH daemon validates that the authorized_keys file and its parent directory are not writable by group or others.
A design uncertainty arises when balancing security requirements with automated deployment tools that may inadvertently modify file ownership or permissions during configuration updates. If permissions are set too loosely, the server ignores the key file, resulting in a silent authentication failure on the client side.
- What are the specific permission masks that trigger a
StrictModesviolation for the.sshdirectory versus theauthorized_keysfile? - Does the daemon evaluate the ownership of the entire directory path leading to the home directory, or only the immediate parent of the key file?
1 answer
0 question comments
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.