Skip to content

NAS-143402 / 27.0.0-BETA.1 / Stricter user SSH public key validation to match OpenSSH behavior (by themylogin) - #19726

Merged
themylogin merged 1 commit into
masterfrom
NAS-143402-27.0.0-BETA.1
Sep 15, 2026
Merged

themylogin merged 1 commit into
masterfrom
NAS-143402-27.0.0-BETA.1

Conversation

@bugclerk

Copy link
Copy Markdown
Contributor

sshd opens the authorized_keys file as the user itself, so every directory leading to the home directory has to
be traversable by the account.

On top of that StrictModes makes sshd refuse to use the file when the home directory is world-writable or is
owned neither by the user nor by root.

A public key that is stored under any of those conditions silently never authenticates anyone, so it should be rejected up front.

Original PR: #19652

@bugclerk

Copy link
Copy Markdown
Contributor Author

@yocalebo
yocalebo requested a review from themylogin September 15, 2026 14:15
@themylogin
themylogin merged commit a04501c into master Sep 15, 2026
4 checks passed
@themylogin
themylogin deleted the NAS-143402-27.0.0-BETA.1 branch September 15, 2026 19:06
@bugclerk

Copy link
Copy Markdown
Contributor Author

This PR has been merged and conversations have been locked.
If you would like to discuss more about this issue please use our forums or raise a Jira ticket.

@truenas truenas locked as resolved and limited conversation to collaborators Sep 15, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants