|
|
905b4d |
From 48db24e8e576c2bde0acdf41c4228fc2a29b4db4 Mon Sep 17 00:00:00 2001
|
|
|
905b4d |
From: Jakub Hrozek <jhrozek@redhat.com>
|
|
|
905b4d |
Date: Fri, 17 Oct 2014 18:14:53 +0200
|
|
|
905b4d |
Subject: [PATCH 41/46] SSH: Run the ssh responder as the SSSD user
|
|
|
905b4d |
|
|
|
905b4d |
Reviewed-by: Pavel Reichl <preichl@redhat.com>
|
|
|
905b4d |
Reviewed-by: Simo Sorce <simo@redhat.com>
|
|
|
905b4d |
(cherry picked from commit 76c8dafad2a18cf1514635aa766062085c23a5c8)
|
|
|
905b4d |
---
|
|
|
905b4d |
src/monitor/monitor.c | 3 ++-
|
|
|
905b4d |
src/responder/ssh/sshsrv.c | 3 ++-
|
|
|
905b4d |
2 files changed, 4 insertions(+), 2 deletions(-)
|
|
|
905b4d |
|
|
|
905b4d |
diff --git a/src/monitor/monitor.c b/src/monitor/monitor.c
|
|
|
905b4d |
index d09aeba9033ff1460f9d4a6c51f35edbf2e67fa6..0dea327213a1ad04b6f69c0ffb0fb87254420796 100644
|
|
|
905b4d |
--- a/src/monitor/monitor.c
|
|
|
905b4d |
+++ b/src/monitor/monitor.c
|
|
|
905b4d |
@@ -1066,7 +1066,8 @@ static bool svc_supported_as_nonroot(const char *svc_name)
|
|
|
905b4d |
|| (strcmp(svc_name, "pam") == 0)
|
|
|
905b4d |
|| (strcmp(svc_name, "autofs") == 0)
|
|
|
905b4d |
|| (strcmp(svc_name, "pac") == 0)
|
|
|
905b4d |
- || (strcmp(svc_name, "sudo") == 0)) {
|
|
|
905b4d |
+ || (strcmp(svc_name, "sudo") == 0)
|
|
|
905b4d |
+ || (strcmp(svc_name, "ssh") == 0)) {
|
|
|
905b4d |
return true;
|
|
|
905b4d |
}
|
|
|
905b4d |
return false;
|
|
|
905b4d |
diff --git a/src/responder/ssh/sshsrv.c b/src/responder/ssh/sshsrv.c
|
|
|
905b4d |
index b154ee1baa16de68f642d2e967b8e7c873c8d4e7..b1969b49de8579f0136c3afa78eb16d68c81ee4e 100644
|
|
|
905b4d |
--- a/src/responder/ssh/sshsrv.c
|
|
|
905b4d |
+++ b/src/responder/ssh/sshsrv.c
|
|
|
905b4d |
@@ -215,7 +215,8 @@ int main(int argc, const char *argv[])
|
|
|
905b4d |
/* set up things like debug, signals, daemonization, etc... */
|
|
|
905b4d |
debug_log_file = "sssd_ssh";
|
|
|
905b4d |
|
|
|
905b4d |
- ret = server_setup("sssd[ssh]", 0, 0, 0, CONFDB_SSH_CONF_ENTRY, &main_ctx);
|
|
|
905b4d |
+ ret = server_setup("sssd[ssh]", 0, uid, gid,
|
|
|
905b4d |
+ CONFDB_SSH_CONF_ENTRY, &main_ctx);
|
|
|
905b4d |
if (ret != EOK) {
|
|
|
905b4d |
return 2;
|
|
|
905b4d |
}
|
|
|
905b4d |
--
|
|
|
905b4d |
1.9.3
|
|
|
905b4d |
|