mirror of
git://git.proxmox.com/git/pve-docs.git
synced 2025-01-21 18:03:45 +03:00
ssh: document PVE-specific setup
such as adapted configs and managed files. Signed-off-by: Fabian Grünbichler <f.gruenbichler@proxmox.com>
This commit is contained in:
parent
95d15550a0
commit
c58d2f179c
18
pvecm.adoc
18
pvecm.adoc
@ -922,6 +922,24 @@ transfer memory and disk contents.
|
||||
|
||||
* Storage replication
|
||||
|
||||
SSH setup
|
||||
~~~~~~~~~
|
||||
|
||||
On {pve} systems, the following changes are made to the SSH configuration/setup:
|
||||
|
||||
* the `root` user's SSH client config gets setup to prefer `AES` over `ChaCha20`
|
||||
|
||||
* the `root` user's `authorized_keys` file gets linked to
|
||||
`/etc/pve/priv/authorized_keys`, merging all authorized keys within a cluster
|
||||
|
||||
* `sshd` is configured to allow logging in as root with a password
|
||||
|
||||
NOTE: Older systems might also have `/etc/ssh/ssh_known_hosts` set up as symlink
|
||||
pointing to `/etc/pve/priv/known_hosts`, containing a merged version of all
|
||||
node host keys. This system was replaced with explicit host key pinning in
|
||||
`pve-cluster <<INSERT VERSION>>`, the symlink can be deconfigured if still in
|
||||
place by running `pvecm updatecerts --unmerge-known-hosts`.
|
||||
|
||||
Pitfalls due to automatic execution of `.bashrc` and siblings
|
||||
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user