<!
DOCTYPE reference PUBLIC "-//OASIS//DTD DocBook V4.4//EN"<
title>SSSD Manual pages</
title>
<
refentrytitle>sss_ssh_authorizedkeys</
refentrytitle>
<
refname>sss_ssh_authorizedkeys</
refname>
<
refpurpose>get OpenSSH authorized keys</
refpurpose>
<
refsynopsisdiv id='synopsis'>
<
command>sss_ssh_authorizedkeys</
command>
<
replaceable>options</
replaceable>
<
arg choice='plain'><
replaceable>USER</
replaceable></
arg>
<
refsect1 id='description'>
<
title>DESCRIPTION</
title>
<
command>sss_ssh_authorizedkeys</
command> acquires SSH
public keys for user <
replaceable>USER</
replaceable> and
outputs them in OpenSSH authorized_keys format (see the
<
quote>AUTHORIZED_KEYS FILE FORMAT</
quote> section of
<
citerefentry><
refentrytitle>sshd</
refentrytitle>
<
manvolnum>8</
manvolnum></
citerefentry> for more
<
citerefentry><
refentrytitle>sshd</
refentrytitle>
<
manvolnum>8</
manvolnum></
citerefentry> can be configured
to use <
command>sss_ssh_authorizedkeys</
command> for public
key user authentication if it is compiled with support for
either <
quote>AuthorizedKeysCommand</
quote> or
<
quote>PubkeyAgent</
quote> <
citerefentry>
<
refentrytitle>sshd_config</
refentrytitle>
<
manvolnum>5</
manvolnum></
citerefentry> options.
If <
quote>AuthorizedKeysCommand</
quote> is supported,
<
citerefentry><
refentrytitle>sshd</
refentrytitle>
<
manvolnum>8</
manvolnum></
citerefentry> can be configured to
use it by putting the following directives in <
citerefentry>
<
refentrytitle>sshd_config</
refentrytitle>
<
manvolnum>5</
manvolnum></
citerefentry>:
AuthorizedKeysCommandUser nobody
If <
quote>PubkeyAgent</
quote> is supported,
<
citerefentry><
refentrytitle>sshd</
refentrytitle>
<
manvolnum>8</
manvolnum></
citerefentry> can be configured to
use it by using the following directive for <
citerefentry>
<
refentrytitle>sshd</
refentrytitle>
<
manvolnum>8</
manvolnum></
citerefentry> configuration:
<
variablelist remap='IP'>
<
option>-d</
option>,<
option>--domain</
option>
<
replaceable>DOMAIN</
replaceable>
Search for user public keys in SSSD domain <
replaceable>DOMAIN</
replaceable>.
<
refsect1 id='exit_status'>
<
title>EXIT STATUS</
title>
In case of success, an exit value of 0 is returned. Otherwise,