mirror of
https://git.yoctoproject.org/poky
synced 2026-04-18 03:32:13 +02:00
ssh-pregen-hostkeys: Limit to qemu machines by default
There are potential security issues from using pre-generated host keys. We made the recipe available for autobuilder testing purposes but concerns remain about how easily this could end up in production. I thought we'd already done this, but limit the recipe to qemu* machines, which means any real hardware trying to use it will need to be a bit more explicit about it and specifically enable it. (From OE-Core rev: b0405972d4fd6fa12f90afea5ecb9a50c01c21c6) Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
@@ -8,6 +8,8 @@ LIC_FILES_CHKSUM = "file://${COMMON_LICENSE_DIR}/MIT;md5=0835ade698e0bcf8506ecda
|
||||
|
||||
INHIBIT_DEFAULT_DEPS = "1"
|
||||
|
||||
COMPATIBLE_MACHINE = "^qemu.*$"
|
||||
|
||||
do_install () {
|
||||
install -d ${D}${sysconfdir}/dropbear
|
||||
install ${UNPACKDIR}/dropbear_rsa_host_key -m 0600 ${D}${sysconfdir}/dropbear/
|
||||
@@ -16,4 +18,4 @@ do_install () {
|
||||
install ${UNPACKDIR}/openssh/* ${D}${sysconfdir}/ssh/
|
||||
chmod 0600 ${D}${sysconfdir}/ssh/*
|
||||
chmod 0644 ${D}${sysconfdir}/ssh/*.pub
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user