Files
poky/meta/recipes-connectivity/openssh/openssh/sshd_check_keys
Joshua Watt ebb625a140 openssh: Fix key generation with systemd
106b59d9 broke SSH host key generation when systemd and a read-only root file
system are in use because there isn't a way for systemd to get the optional
weak assigment of SYSCONFDIR from /etc/default/sshd and still provide a default
value if it is not specified. Instead, move the logic for determining if keys
need to be created to a helper script that both the SysV init script and the
systemd unit file can reference.

This does mean that the systemd unit file can't check for file existence to
know if it should start the service, but it wasn't able to do that correctly
anyway anymore. This should be a problem since the serivce is only run once per
power cycle by systemd, and should exit quickly if the keys already exist

(From OE-Core rev: 73f1397d86f33abace089cc9a28e859b47bb7b6c)

Signed-off-by: Joshua Watt <JPEWhacker@gmail.com>
Signed-off-by: Ross Burton <ross.burton@intel.com>

(cherry picked from commit 7e49c5879862253ae1b6a26535d07a2740a95798)
Signed-off-by: André Draszik <adraszik@tycoint.com>
Signed-off-by: Armin Kuster <akuster808@gmail.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
2017-11-05 22:39:48 +00:00

2.4 KiB

#! /bin/sh

/etc/default/ssh may set SYSCONFDIR and SSHD_OPTS

if test -f /etc/default/ssh; then . /etc/default/ssh fi

[ -z "$SYSCONFDIR" ] && SYSCONFDIR=/etc/ssh mkdir -p $SYSCONFDIR

parse sshd options

set -- ${SSHD_OPTS} -- sshd_config=/etc/ssh/sshd_config while true ; do case "$1" in -f*) if [ "$1" = "-f" ] ; then sshd_config="$2" shift else sshd_config="${1#-f}" fi shift ;; --) shift; break;; *) shift;; esac done

parse location of keys

HOST_KEY_RSA=$(grep ^HostKey "${sshd_config}" | grep rsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_RSA}" ] && HOST_KEY_RSA=$(grep HostKey "${sshd_config}" | grep rsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_RSA}" ] && HOST_KEY_RSA=$SYSCONFDIR/ssh_host_rsa_key HOST_KEY_DSA=$(grep ^HostKey "${sshd_config}" | grep dsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_DSA}" ] && HOST_KEY_DSA=$(grep HostKey "${sshd_config}" | grep dsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_DSA}" ] && HOST_KEY_DSA=$SYSCONFDIR/ssh_host_dsa_key HOST_KEY_ECDSA=$(grep ^HostKey "${sshd_config}" | grep ecdsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_ECDSA}" ] && HOST_KEY_ECDSA=$(grep HostKey "${sshd_config}" | grep ecdsa | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_ECDSA}" ] && HOST_KEY_ECDSA=$SYSCONFDIR/ssh_host_ecdsa_key HOST_KEY_ED25519=$(grep ^HostKey "${sshd_config}" | grep ed25519 | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_ED25519}" ] && HOST_KEY_ED25519=$(grep HostKey "${sshd_config}" | grep ed25519 | tail -1 | awk ' { print $2 } ') [ -z "${HOST_KEY_ED25519}" ] && HOST_KEY_ED25519=$SYSCONFDIR/ssh_host_ed25519_key

create keys if necessary

if [ ! -f $HOST_KEY_RSA ]; then echo " generating ssh RSA key..." mkdir -p $(dirname $HOST_KEY_RSA) ssh-keygen -q -f $HOST_KEY_RSA -N '' -t rsa fi if [ ! -f $HOST_KEY_ECDSA ]; then echo " generating ssh ECDSA key..." mkdir -p $(dirname $HOST_KEY_ECDSA) ssh-keygen -q -f $HOST_KEY_ECDSA -N '' -t ecdsa fi if [ ! -f $HOST_KEY_DSA ]; then echo " generating ssh DSA key..." mkdir -p $(dirname $HOST_KEY_DSA) ssh-keygen -q -f $HOST_KEY_DSA -N '' -t dsa fi if [ ! -f $HOST_KEY_ED25519 ]; then echo " generating ssh ED25519 key..." mkdir -p $(dirname $HOST_KEY_ED25519) ssh-keygen -q -f $HOST_KEY_ED25519 -N '' -t ed25519 fi