浏览代码

Ensure privilege separation exists

Bob Mottram 8 年前
父节点
当前提交
28381df8f5
共有 1 个文件被更改,包括 3 次插入0 次删除
  1. 3
    0
      src/freedombone-utils-ssh

+ 3
- 0
src/freedombone-utils-ssh 查看文件

115
         echo "KexAlgorithms $SSH_KEX" >> /etc/ssh/sshd_config
115
         echo "KexAlgorithms $SSH_KEX" >> /etc/ssh/sshd_config
116
     fi
116
     fi
117
     sed -i "s|#KexAlgorithms $SSH_KEX|KexAlgorithms $SSH_KEX|g" /etc/ssh/sshd_config
117
     sed -i "s|#KexAlgorithms $SSH_KEX|KexAlgorithms $SSH_KEX|g" /etc/ssh/sshd_config
118
+    if ! grep -q 'UsePrivilegeSeparation' /etc/ssh/sshd_config; then
119
+        echo 'UsePrivilegeSeparation sandbox' >> /etc/ssh/sshd_config
120
+    fi
118
     sed -i 's|#UsePrivilegeSeparation .*|UsePrivilegeSeparation sandbox|g' /etc/ssh/sshd_config
121
     sed -i 's|#UsePrivilegeSeparation .*|UsePrivilegeSeparation sandbox|g' /etc/ssh/sshd_config
119
     sed -i 's|UsePrivilegeSeparation .*|UsePrivilegeSeparation sandbox|g' /etc/ssh/sshd_config
122
     sed -i 's|UsePrivilegeSeparation .*|UsePrivilegeSeparation sandbox|g' /etc/ssh/sshd_config
120
 
123