sss_ssh_authorizedkeys.1.xml revision 558998ce664055a75595371118f818084d8f2b23
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive<?xml version="1.0" encoding="UTF-8"?>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end<!DOCTYPE reference PUBLIC "-//OASIS//DTD DocBook V4.4//EN"
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end"http://www.oasis-open.org/docbook/xml/4.4/docbookx.dtd">
6fbd2e53c97ea6976d93e0ac521adabc55e0fb73nd<reference>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end<title>SSSD Manual pages</title>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end<refentry>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="include/upstream.xml" />
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <refmeta>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <refentrytitle>sss_ssh_authorizedkeys</refentrytitle>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <manvolnum>1</manvolnum>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end </refmeta>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <refnamediv id='name'>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <refname>sss_ssh_authorizedkeys</refname>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end <refpurpose>get OpenSSH authorized keys</refpurpose>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end </refnamediv>
a7835c7a8cf86045fdaee65dc2839bfe6314fb1end
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <refsynopsisdiv id='synopsis'>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <cmdsynopsis>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <command>sss_ssh_authorizedkeys</command>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <arg choice='opt'>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <replaceable>options</replaceable>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </arg>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <arg choice='plain'><replaceable>USER</replaceable></arg>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </cmdsynopsis>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </refsynopsisdiv>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <refsect1 id='description'>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <title>DESCRIPTION</title>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <command>sss_ssh_authorizedkeys</command> acquires SSH
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive public keys for user <replaceable>USER</replaceable> and
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive outputs them in OpenSSH authorized_keys format (see the
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <quote>AUTHORIZED_KEYS FILE FORMAT</quote> section of
87ea898bcffe2ef490e833dc246a1cc0465d783fslive <citerefentry><refentrytitle>sshd</refentrytitle>
5e9423b4ca454c6416a2dc465dea1b1d34cec7a9slive <manvolnum>8</manvolnum></citerefentry> for more
1cb160a981947e75a8353da3fe40a653aa87100eslive information).
1cb160a981947e75a8353da3fe40a653aa87100eslive </para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <citerefentry><refentrytitle>sshd</refentrytitle>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <manvolnum>8</manvolnum></citerefentry> can be configured
f5d245e2129454d0fcaa77e21de055a30ea8a9c7slive to use <command>sss_ssh_authorizedkeys</command> for public
46d1ef8cb385aa2f519ce7d355afc51f144bd938slive key user authentication if it is compiled with support for
1cb160a981947e75a8353da3fe40a653aa87100eslive either <quote>AuthorizedKeysCommand</quote> or
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <quote>PubkeyAgent</quote> <citerefentry>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive <refentrytitle>sshd_config</refentrytitle>
f5d245e2129454d0fcaa77e21de055a30ea8a9c7slive <manvolnum>5</manvolnum></citerefentry> options.
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive If <quote>AuthorizedKeysCommand</quote> is supported,
5e9423b4ca454c6416a2dc465dea1b1d34cec7a9slive <citerefentry><refentrytitle>sshd</refentrytitle>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <manvolnum>8</manvolnum></citerefentry> can be configured to
1c6a10274e908898347be82bc82bc7ae18c66410slive use it by putting the following directive in <citerefentry>
1c6a10274e908898347be82bc82bc7ae18c66410slive <refentrytitle>sshd_config</refentrytitle>
1c6a10274e908898347be82bc82bc7ae18c66410slive <manvolnum>5</manvolnum></citerefentry>:
1c6a10274e908898347be82bc82bc7ae18c66410slive<programlisting>
1c6a10274e908898347be82bc82bc7ae18c66410sliveAuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys
1c6a10274e908898347be82bc82bc7ae18c66410slive</programlisting>
1c6a10274e908898347be82bc82bc7ae18c66410slive </para>
1c6a10274e908898347be82bc82bc7ae18c66410slive <para>
1c6a10274e908898347be82bc82bc7ae18c66410slive If <quote>PubkeyAgent</quote> is supported,
1c6a10274e908898347be82bc82bc7ae18c66410slive <citerefentry><refentrytitle>sshd</refentrytitle>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <manvolnum>8</manvolnum></citerefentry> can be configured to
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive use it by using the following directive for <citerefentry>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <refentrytitle>sshd</refentrytitle>
46d1ef8cb385aa2f519ce7d355afc51f144bd938slive <manvolnum>8</manvolnum></citerefentry> configuration:
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive<programlisting>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslivePubKeyAgent /usr/bin/sss_ssh_authorizedkeys %u
f5d245e2129454d0fcaa77e21de055a30ea8a9c7slive</programlisting>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="include/experimental.xml" />
1c6a10274e908898347be82bc82bc7ae18c66410slive </para>
1c6a10274e908898347be82bc82bc7ae18c66410slive </refsect1>
1c6a10274e908898347be82bc82bc7ae18c66410slive
1c6a10274e908898347be82bc82bc7ae18c66410slive <refsect1 id='options'>
1c6a10274e908898347be82bc82bc7ae18c66410slive <title>OPTIONS</title>
1c6a10274e908898347be82bc82bc7ae18c66410slive <variablelist remap='IP'>
1c6a10274e908898347be82bc82bc7ae18c66410slive <varlistentry>
1c6a10274e908898347be82bc82bc7ae18c66410slive <term>
1c6a10274e908898347be82bc82bc7ae18c66410slive <option>-d</option>,<option>--domain</option>
1c6a10274e908898347be82bc82bc7ae18c66410slive <replaceable>DOMAIN</replaceable>
1c6a10274e908898347be82bc82bc7ae18c66410slive </term>
1c6a10274e908898347be82bc82bc7ae18c66410slive <listitem>
1c6a10274e908898347be82bc82bc7ae18c66410slive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive Search for user public keys in SSSD domain <replaceable>DOMAIN</replaceable>.
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </listitem>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </varlistentry>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <xi:include xmlns:xi="http://www.w3.org/2001/XInclude" href="include/param_help.xml" />
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </variablelist>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </refsect1>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive <refsect1 id='see_also'>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive <title>SEE ALSO</title>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <para>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <citerefentry>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <refentrytitle>sshd</refentrytitle><manvolnum>8</manvolnum>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive </citerefentry>,
5e9423b4ca454c6416a2dc465dea1b1d34cec7a9slive <citerefentry>
3fa58e00171aebf3b2cfa90035ed530f5b1f651dslive <refentrytitle>sshd_config</refentrytitle><manvolnum>5</manvolnum>
368bcafaedaee463f769c1b5f3547b9970df90d0slive </citerefentry>,
368bcafaedaee463f769c1b5f3547b9970df90d0slive <citerefentry>
368bcafaedaee463f769c1b5f3547b9970df90d0slive <refentrytitle>sss_ssh_knownhostsproxy</refentrytitle><manvolnum>1</manvolnum>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive </citerefentry>.
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive </para>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive </refsect1>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive</refentry>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive</reference>
0097a4f3e468c0192a2ce52ffee7bc8cea0a620bslive