From c58d2f179c04bb084459c70987742bacce24295a Mon Sep 17 00:00:00 2001 From: =?utf8?q?Fabian=20Gr=C3=BCnbichler?= Date: Thu, 11 Jan 2024 11:51:20 +0100 Subject: [PATCH] ssh: document PVE-specific setup MIME-Version: 1.0 Content-Type: text/plain; charset=utf8 Content-Transfer-Encoding: 8bit such as adapted configs and managed files. Signed-off-by: Fabian Grünbichler --- pvecm.adoc | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/pvecm.adoc b/pvecm.adoc index 2c0e8a4..5117eaa 100644 --- a/pvecm.adoc +++ b/pvecm.adoc @@ -922,6 +922,24 @@ transfer memory and disk contents. * Storage replication +SSH setup +~~~~~~~~~ + +On {pve} systems, the following changes are made to the SSH configuration/setup: + +* the `root` user's SSH client config gets setup to prefer `AES` over `ChaCha20` + +* the `root` user's `authorized_keys` file gets linked to + `/etc/pve/priv/authorized_keys`, merging all authorized keys within a cluster + +* `sshd` is configured to allow logging in as root with a password + +NOTE: Older systems might also have `/etc/ssh/ssh_known_hosts` set up as symlink +pointing to `/etc/pve/priv/known_hosts`, containing a merged version of all +node host keys. This system was replaced with explicit host key pinning in +`pve-cluster <>`, the symlink can be deconfigured if still in +place by running `pvecm updatecerts --unmerge-known-hosts`. + Pitfalls due to automatic execution of `.bashrc` and siblings ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -- 2.39.2