Initial Awawawa
This commit is contained in:
36
sshd/patchbay-sshd
Executable file
36
sshd/patchbay-sshd
Executable file
@@ -0,0 +1,36 @@
|
||||
#!/bin/sh
|
||||
# Starts the dedicated PatchBay sshd in the foreground. Used by all init systems.
|
||||
# Usage: patchbay-sshd [config] (default /etc/patchbay/patchbay.conf)
|
||||
set -eu
|
||||
|
||||
CONF=${1:-/etc/patchbay/patchbay.conf}
|
||||
LIBDIR=$(dirname "$(readlink -f "$0")")
|
||||
PATCHBAYD=${PATCHBAYD:-patchbayd}
|
||||
SSHD=${SSHD:-$(command -v sshd || echo /usr/sbin/sshd)}
|
||||
|
||||
get() {
|
||||
"$PATCHBAYD" -c "$CONF" --print-config | sed -n "s/^$1=//p"
|
||||
}
|
||||
|
||||
RUNDIR=$(get RunDir)
|
||||
HOSTKEY=$(get SSHHostKey)
|
||||
mkdir -p "$RUNDIR" /run/sshd
|
||||
chmod 755 "$RUNDIR"
|
||||
|
||||
if [ ! -f "$HOSTKEY" ]; then
|
||||
ssh-keygen -q -t ed25519 -N '' -C patchbay-target -f "$HOSTKEY"
|
||||
fi
|
||||
|
||||
# authorized_keys must exist before sshd accepts connections.
|
||||
"$PATCHBAYD" -c "$CONF" --write-keys
|
||||
|
||||
sed -e "s|@PORT@|$(get TargetPort)|" \
|
||||
-e "s|@HUBPORT@|$(get HubPort)|" \
|
||||
-e "s|@HOSTKEY@|$HOSTKEY|" \
|
||||
-e "s|@AUTHKEYS@|$(get AuthorizedKeys)|" \
|
||||
-e "s|@USER@|$(get SSHUser)|" \
|
||||
-e "s|@RUNDIR@|$RUNDIR|" \
|
||||
"$LIBDIR/sshd_config.in" > "$RUNDIR/sshd_config"
|
||||
|
||||
"$SSHD" -t -f "$RUNDIR/sshd_config"
|
||||
exec "$SSHD" -D -e -f "$RUNDIR/sshd_config"
|
||||
38
sshd/sshd_config.in
Normal file
38
sshd/sshd_config.in
Normal file
@@ -0,0 +1,38 @@
|
||||
# PatchBay dedicated sshd. Generated by patchbay-sshd from this template;
|
||||
# values come from patchbay.conf via "patchbayd --print-config".
|
||||
|
||||
Port @PORT@
|
||||
HostKey @HOSTKEY@
|
||||
PidFile @RUNDIR@/sshd.pid
|
||||
AuthorizedKeysFile @AUTHKEYS@
|
||||
AllowUsers @USER@
|
||||
|
||||
PubkeyAuthentication yes
|
||||
PasswordAuthentication no
|
||||
KbdInteractiveAuthentication no
|
||||
PermitRootLogin no
|
||||
UsePAM no
|
||||
StrictModes yes
|
||||
|
||||
# Clients may only open data channels to the hub port; per-key options in
|
||||
# authorized_keys repeat this and force the control relay command.
|
||||
AllowTcpForwarding local
|
||||
PermitOpen 127.0.0.1:@HUBPORT@
|
||||
AllowStreamLocalForwarding no
|
||||
AllowAgentForwarding no
|
||||
X11Forwarding no
|
||||
PermitTunnel no
|
||||
GatewayPorts no
|
||||
PermitTTY no
|
||||
PermitUserRC no
|
||||
PermitUserEnvironment no
|
||||
PrintMotd no
|
||||
Banner none
|
||||
|
||||
# Throughput: AEAD ciphers first, no compression.
|
||||
Ciphers aes128-gcm@openssh.com,aes256-gcm@openssh.com,chacha20-poly1305@openssh.com,aes128-ctr,aes256-ctr
|
||||
Compression no
|
||||
ClientAliveInterval 30
|
||||
ClientAliveCountMax 3
|
||||
MaxStartups 50:30:200
|
||||
LogLevel INFO
|
||||
Reference in New Issue
Block a user