[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#959726: openssh-server: HostKey config in /etc/ssh/sshd_config.d/ not found by postinst script



Package: openssh-server
Version: 1:8.2p1-4
Severity: minor

The postinst script generates host keys for keys defined in 
/etc/ssh/sshd_config, but NOT for definitions in /etc/ssh/sshd_config/*.

That's a bit inconsistent, perhaps these should be looked at too.

Sadly that means parsing "Include" statements from the config file,
which opens a new can of worms...
Perhaps sshd should be asked which host keys are configured, or it should 
(optionally) create keys as needed by itself... (?)


-- System Information:
Debian Release: bullseye/sid
  APT prefers testing
  APT policy: (990, 'testing'), (500, 'unstable-debug'), (500, 'testing-debug'), (500, 'unstable'), (500, 'stable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 5.5.0-1-amd64 (SMP w/8 CPU cores)
Kernel taint flags: TAINT_WARN
Locale: LANG=de_AT.UTF-8, LC_CTYPE=de_AT.UTF-8 (charmap=UTF-8), LANGUAGE=de_AT:de (charmap=UTF-8)
Shell: /bin/sh linked to /usr/bin/dash
Init: systemd (via /run/systemd/system)
LSM: AppArmor: enabled

Versions of packages openssh-server depends on:
ii  adduser                3.118
ii  debconf [debconf-2.0]  1.5.74
ii  dpkg                   1.19.7
ii  libaudit1              1:2.8.5-3+b1
ii  libc6                  2.30-4
ii  libcom-err2            1.45.6-1
ii  libcrypt1              1:4.4.16-1
ii  libgssapi-krb5-2       1.17-7
ii  libkrb5-3              1.17-7
ii  libpam-modules         1.3.1-5
ii  libpam-runtime         1.3.1-5
ii  libpam0g               1.3.1-5
ii  libselinux1            3.0-1+b3
ii  libssl1.1              1.1.1g-1
ii  libsystemd0            245.5-2
ii  libwrap0               7.6.q-30
ii  lsb-base               11.1.0
ii  openssh-client         1:8.2p1-4
ii  openssh-sftp-server    1:8.2p1-4
ii  procps                 2:3.3.16-4
ii  runit-helper           2.8.15
ii  ucf                    3.0038+nmu1
ii  zlib1g                 1:1.2.11.dfsg-2

Versions of packages openssh-server recommends:
ii  libpam-systemd [logind]  245.5-2
ii  ncurses-term             6.2-1
ii  xauth                    1:1.0.10-1

Versions of packages openssh-server suggests:
ii  lxqt-openssh-askpass [ssh-askpass]  0.14.1-1
pn  molly-guard                         <none>
pn  monkeysphere                        <none>
pn  ufw                                 <none>

-- debconf information excluded

-- 


Reply to: