Configuring Redhat / CentOS 5 SSH to authenticate to IPA server with public keysUpdating Samba From RPMsHelp setting up a secondary authoritative DNS serverHOw to make rsa key pairs work in CentOS 6Why has CD/DVD host passthrough been disabled in CentOS 7 RHEL 7?SSHD on Cygwin: can't connect as “root” from a Linux boxMove home directory on Azure Linux VMipa users cannot sudo on some machines only, including the ipa serverIPA server NFS services adding issue centos 7.2Yum update - /bin/python not foundsss_ssh_authorizedkeys returns error code 13 when called from sshd

Eliminate empty elements from a list with a specific pattern

Can I legally use front facing blue light in the UK?

Was there ever an axiom rendered a theorem?

How to answer pointed "are you quitting" questioning when I don't want them to suspect

Are cabin dividers used to "hide" the flex of the airplane?

Where else does the Shulchan Aruch quote an authority by name?

How to move the player while also allowing forces to affect it

Is Fable (1996) connected in any way to the Fable franchise from Lionhead Studios?

I’m planning on buying a laser printer but concerned about the life cycle of toner in the machine

Why do UK politicians seemingly ignore opinion polls on Brexit?

Ideas for 3rd eye abilities

What are the advantages and disadvantages of running one shots compared to campaigns?

Does bootstrapped regression allow for inference?

Why airport relocation isn't done gradually?

Are objects structures and/or vice versa?

How can I fix this gap between bookcases I made?

How did the USSR manage to innovate in an environment characterized by government censorship and high bureaucracy?

How to manage monthly salary

Piano - What is the notation for a double stop where both notes in the double stop are different lengths?

What to wear for invited talk in Canada

Hosting Wordpress in a EC2 Load Balanced Instance

Why is my log file so massive? 22gb. I am running log backups

COUNT(*) or MAX(id) - which is faster?

How to create a consistent feel for character names in a fantasy setting?



Configuring Redhat / CentOS 5 SSH to authenticate to IPA server with public keys


Updating Samba From RPMsHelp setting up a secondary authoritative DNS serverHOw to make rsa key pairs work in CentOS 6Why has CD/DVD host passthrough been disabled in CentOS 7 RHEL 7?SSHD on Cygwin: can't connect as “root” from a Linux boxMove home directory on Azure Linux VMipa users cannot sudo on some machines only, including the ipa serverIPA server NFS services adding issue centos 7.2Yum update - /bin/python not foundsss_ssh_authorizedkeys returns error code 13 when called from sshd






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty height:90px;width:728px;box-sizing:border-box;








0















I'm trying to configure some Red Hat/CentOS servers to use an ipa-server on CentOS 6 for SSH authentication with public keys. I'm storing the public keys on the IPA server, which works great on Centos6 using "AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys" in /etc/ssh/sshd_config. However, on RH 5.10, neither the "AuthorizedKeysCommand" directive or the "/usr/bin/sss_ssh_authorizedkeys" command exist to pull the public key from the directory. Is there a different way to make this work? Googling this mostly returns instructions for setting it up on 6.










share|improve this question




























    0















    I'm trying to configure some Red Hat/CentOS servers to use an ipa-server on CentOS 6 for SSH authentication with public keys. I'm storing the public keys on the IPA server, which works great on Centos6 using "AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys" in /etc/ssh/sshd_config. However, on RH 5.10, neither the "AuthorizedKeysCommand" directive or the "/usr/bin/sss_ssh_authorizedkeys" command exist to pull the public key from the directory. Is there a different way to make this work? Googling this mostly returns instructions for setting it up on 6.










    share|improve this question
























      0












      0








      0








      I'm trying to configure some Red Hat/CentOS servers to use an ipa-server on CentOS 6 for SSH authentication with public keys. I'm storing the public keys on the IPA server, which works great on Centos6 using "AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys" in /etc/ssh/sshd_config. However, on RH 5.10, neither the "AuthorizedKeysCommand" directive or the "/usr/bin/sss_ssh_authorizedkeys" command exist to pull the public key from the directory. Is there a different way to make this work? Googling this mostly returns instructions for setting it up on 6.










      share|improve this question














      I'm trying to configure some Red Hat/CentOS servers to use an ipa-server on CentOS 6 for SSH authentication with public keys. I'm storing the public keys on the IPA server, which works great on Centos6 using "AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys" in /etc/ssh/sshd_config. However, on RH 5.10, neither the "AuthorizedKeysCommand" directive or the "/usr/bin/sss_ssh_authorizedkeys" command exist to pull the public key from the directory. Is there a different way to make this work? Googling this mostly returns instructions for setting it up on 6.







      centos redhat keys freeipa






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Aug 22 '14 at 15:51









      blindsnowmobileblindsnowmobile

      205313




      205313




















          1 Answer
          1






          active

          oldest

          votes


















          1














          Did you try to install 'sssd' package on RHEL 5.10?



          yum install sssd


          That package will install 'sss_ssh_authorizedkeys' binary.



          If the package doesn't exist in RHEL repositories for 5.10 you can safely use the CentOS RPM because they are binary compatible distros.






          share|improve this answer


















          • 1





            Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

            – blindsnowmobile
            Aug 27 '14 at 15:20












          • Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

            – Jakov Sosic
            Aug 28 '14 at 12:39











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "2"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f623359%2fconfiguring-redhat-centos-5-ssh-to-authenticate-to-ipa-server-with-public-keys%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          1 Answer
          1






          active

          oldest

          votes








          1 Answer
          1






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes









          1














          Did you try to install 'sssd' package on RHEL 5.10?



          yum install sssd


          That package will install 'sss_ssh_authorizedkeys' binary.



          If the package doesn't exist in RHEL repositories for 5.10 you can safely use the CentOS RPM because they are binary compatible distros.






          share|improve this answer


















          • 1





            Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

            – blindsnowmobile
            Aug 27 '14 at 15:20












          • Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

            – Jakov Sosic
            Aug 28 '14 at 12:39















          1














          Did you try to install 'sssd' package on RHEL 5.10?



          yum install sssd


          That package will install 'sss_ssh_authorizedkeys' binary.



          If the package doesn't exist in RHEL repositories for 5.10 you can safely use the CentOS RPM because they are binary compatible distros.






          share|improve this answer


















          • 1





            Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

            – blindsnowmobile
            Aug 27 '14 at 15:20












          • Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

            – Jakov Sosic
            Aug 28 '14 at 12:39













          1












          1








          1







          Did you try to install 'sssd' package on RHEL 5.10?



          yum install sssd


          That package will install 'sss_ssh_authorizedkeys' binary.



          If the package doesn't exist in RHEL repositories for 5.10 you can safely use the CentOS RPM because they are binary compatible distros.






          share|improve this answer













          Did you try to install 'sssd' package on RHEL 5.10?



          yum install sssd


          That package will install 'sss_ssh_authorizedkeys' binary.



          If the package doesn't exist in RHEL repositories for 5.10 you can safely use the CentOS RPM because they are binary compatible distros.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Aug 24 '14 at 11:41









          Jakov SosicJakov Sosic

          4,25921627




          4,25921627







          • 1





            Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

            – blindsnowmobile
            Aug 27 '14 at 15:20












          • Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

            – Jakov Sosic
            Aug 28 '14 at 12:39












          • 1





            Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

            – blindsnowmobile
            Aug 27 '14 at 15:20












          • Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

            – Jakov Sosic
            Aug 28 '14 at 12:39







          1




          1





          Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

          – blindsnowmobile
          Aug 27 '14 at 15:20






          Yes, I installed sssd. It does not have the sss_ssh_authorizedkeys binary in 5.10. The bigger issue is that openssh-server package in 5.10 does not appear to support the AuthorizedKeysCommand directive. I rolled my own script to pull the public key from the directory, but I can't tell openssh-server to use it. I was hoping I could handle this in PAM, but it looks like openssh-server bypasses PAM entirely to do public key authentication.

          – blindsnowmobile
          Aug 27 '14 at 15:20














          Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

          – Jakov Sosic
          Aug 28 '14 at 12:39





          Maybe you should try backporting sssd and SSH from 6.x series, or from the first Fedora release between Fedora 6 & Fedora 12, to minimize number of needed packages / libraries? If you want, I can try to find version which supports AuthorizedKeysCommand, and try backporting it?

          – Jakov Sosic
          Aug 28 '14 at 12:39

















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Server Fault!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f623359%2fconfiguring-redhat-centos-5-ssh-to-authenticate-to-ipa-server-with-public-keys%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Club Baloncesto Breogán Índice Historia | Pavillón | Nome | O Breogán na cultura popular | Xogadores | Adestradores | Presidentes | Palmarés | Historial | Líderes | Notas | Véxase tamén | Menú de navegacióncbbreogan.galCadroGuía oficial da ACB 2009-10, páxina 201Guía oficial ACB 1992, páxina 183. Editorial DB.É de 6.500 espectadores sentados axeitándose á última normativa"Estudiantes Junior, entre as mellores canteiras"o orixinalHemeroteca El Mundo Deportivo, 16 setembro de 1970, páxina 12Historia do BreogánAlfredo Pérez, o último canoneiroHistoria C.B. BreogánHemeroteca de El Mundo DeportivoJimmy Wright, norteamericano do Breogán deixará Lugo por ameazas de morteResultados de Breogán en 1986-87Resultados de Breogán en 1990-91Ficha de Velimir Perasović en acb.comResultados de Breogán en 1994-95Breogán arrasa al Barça. "El Mundo Deportivo", 27 de setembro de 1999, páxina 58CB Breogán - FC BarcelonaA FEB invita a participar nunha nova Liga EuropeaCharlie Bell na prensa estatalMáximos anotadores 2005Tempada 2005-06 : Tódolos Xogadores da Xornada""Non quero pensar nunha man negra, mais pregúntome que está a pasar""o orixinalRaúl López, orgulloso dos xogadores, presume da boa saúde económica do BreogánJulio González confirma que cesa como presidente del BreogánHomenaxe a Lisardo GómezA tempada do rexurdimento celesteEntrevista a Lisardo GómezEl COB dinamita el Pazo para forzar el quinto (69-73)Cafés Candelas, patrocinador del CB Breogán"Suso Lázare, novo presidente do Breogán"o orixinalCafés Candelas Breogán firma el mayor triunfo de la historiaEl Breogán realizará 17 homenajes por su cincuenta aniversario"O Breogán honra ao seu fundador e primeiro presidente"o orixinalMiguel Giao recibiu a homenaxe do PazoHomenaxe aos primeiros gladiadores celestesO home que nos amosa como ver o Breo co corazónTita Franco será homenaxeada polos #50anosdeBreoJulio Vila recibirá unha homenaxe in memoriam polos #50anosdeBreo"O Breogán homenaxeará aos seus aboados máis veteráns"Pechada ovación a «Capi» Sanmartín e Ricardo «Corazón de González»Homenaxe por décadas de informaciónPaco García volve ao Pazo con motivo do 50 aniversario"Resultados y clasificaciones""O Cafés Candelas Breogán, campión da Copa Princesa""O Cafés Candelas Breogán, equipo ACB"C.B. Breogán"Proxecto social"o orixinal"Centros asociados"o orixinalFicha en imdb.comMario Camus trata la recuperación del amor en 'La vieja música', su última película"Páxina web oficial""Club Baloncesto Breogán""C. B. Breogán S.A.D."eehttp://www.fegaba.com

          Vilaño, A Laracha Índice Patrimonio | Lugares e parroquias | Véxase tamén | Menú de navegación43°14′52″N 8°36′03″O / 43.24775, -8.60070

          Cegueira Índice Epidemioloxía | Deficiencia visual | Tipos de cegueira | Principais causas de cegueira | Tratamento | Técnicas de adaptación e axudas | Vida dos cegos | Primeiros auxilios | Crenzas respecto das persoas cegas | Crenzas das persoas cegas | O neno deficiente visual | Aspectos psicolóxicos da cegueira | Notas | Véxase tamén | Menú de navegación54.054.154.436928256blindnessDicionario da Real Academia GalegaPortal das Palabras"International Standards: Visual Standards — Aspects and Ranges of Vision Loss with Emphasis on Population Surveys.""Visual impairment and blindness""Presentan un plan para previr a cegueira"o orixinalACCDV Associació Catalana de Cecs i Disminuïts Visuals - PMFTrachoma"Effect of gene therapy on visual function in Leber's congenital amaurosis"1844137110.1056/NEJMoa0802268Cans guía - os mellores amigos dos cegosArquivadoEscola de cans guía para cegos en Mortágua, PortugalArquivado"Tecnología para ciegos y deficientes visuales. Recopilación de recursos gratuitos en la Red""Colorino""‘COL.diesis’, escuchar los sonidos del color""COL.diesis: Transforming Colour into Melody and Implementing the Result in a Colour Sensor Device"o orixinal"Sistema de desarrollo de sinestesia color-sonido para invidentes utilizando un protocolo de audio""Enseñanza táctil - geometría y color. Juegos didácticos para niños ciegos y videntes""Sistema Constanz"L'ocupació laboral dels cecs a l'Estat espanyol està pràcticament equiparada a la de les persones amb visió, entrevista amb Pedro ZuritaONCE (Organización Nacional de Cegos de España)Prevención da cegueiraDescrición de deficiencias visuais (Disc@pnet)Braillín, un boneco atractivo para calquera neno, con ou sen discapacidade, que permite familiarizarse co sistema de escritura e lectura brailleAxudas Técnicas36838ID00897494007150-90057129528256DOID:1432HP:0000618D001766C10.597.751.941.162C97109C0155020