From ac7e8b2232d49866fd484d154dfe8c36d7cd805a Mon Sep 17 00:00:00 2001 From: Dongsu Park Date: Mon, 13 Dec 2021 14:52:01 +0100 Subject: [PATCH] sys-auth/google-oslogin: accept ssh-rsa in sshd_config for openssh 8.8 Temporarily accept ssh-rsa algorithm in sshd_config for openssh >= 8.8, until most ssh clients could deprecate ssh-rsa. It is the same fix as https://github.com/flatcar-linux/init/pull/54. However, we should do that again for GCE, because the google-oslogin ebuild overwrites the existing sshd_config. --- .../coreos-overlay/sys-auth/google-oslogin/files/sshd_config | 4 ++++ ...0200910.00.ebuild => google-oslogin-20200910.00-r1.ebuild} | 0 2 files changed, 4 insertions(+) rename sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/{google-oslogin-20200910.00.ebuild => google-oslogin-20200910.00-r1.ebuild} (100%) diff --git a/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/files/sshd_config b/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/files/sshd_config index 26630084d3..5b174fcad4 100644 --- a/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/files/sshd_config +++ b/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/files/sshd_config @@ -9,3 +9,7 @@ PrintMotd no # handled by PAM # Needed for google oslogin AuthorizedKeysCommand /usr/libexec/google_authorized_keys AuthorizedKeysCommandUser root +# Temporarily accept ssh-rsa algorithm for openssh >= 8.8, +# until most ssh clients could deprecate ssh-rsa. +HostkeyAlgorithms +ssh-rsa +PubkeyAcceptedAlgorithms +ssh-rsa diff --git a/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/google-oslogin-20200910.00.ebuild b/sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/google-oslogin-20200910.00-r1.ebuild similarity index 100% rename from sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/google-oslogin-20200910.00.ebuild rename to sdk_container/src/third_party/coreos-overlay/sys-auth/google-oslogin/google-oslogin-20200910.00-r1.ebuild