Note: This bug is displayed in read-only format because
the product is no longer active in Red Hat Bugzilla.
RHEL Engineering is moving the tracking of its product development work on RHEL 6 through RHEL 9 to Red Hat Jira (issues.redhat.com). If you're a Red Hat customer, please continue to file support cases via the Red Hat customer portal. If you're not, please head to the "RHEL project" in Red Hat Jira and file new tickets here. Individual Bugzilla bugs in the statuses "NEW", "ASSIGNED", and "POST" are being migrated throughout September 2023. Bugs of Red Hat partners with an assigned Engineering Partner Manager (EPM) are migrated in late September as per pre-agreed dates. Bugs against components "kernel", "kernel-rt", and "kpatch" are only migrated if still in "NEW" or "ASSIGNED". If you cannot log in to RH Jira, please consult article #7032570. That failing, please send an e-mail to the RH Jira admins at rh-issues@redhat.com to troubleshoot your issue as a user management inquiry. The email creates a ServiceNow ticket with Red Hat. Individual Bugzilla bugs that are migrated will be moved to status "CLOSED", resolution "MIGRATED", and set with "MigratedToJIRA" in "Keywords". The link to the successor Jira issue will be found under "Links", have a little "two-footprint" icon next to it, and direct you to the "RHEL project" in Red Hat Jira (issue links are of type "https://issues.redhat.com/browse/RHEL-XXXX", where "X" is a digit). This same link will be available in a blue banner at the top of the page informing you that that bug has been migrated.
Document URL: https://access.redhat.com/site/documentation/en-US/Red_Hat_Enterprise_Linux/6/html/Deployment_Guide/openssh-sssd.html
Section Number and Name: 11.2.9.2. Configuring OpenSSH to Use SSSD for User Keys
Describe the issue:
The document incorrectly states that sss_ssh_authorizedkeys manages the file ~/.ssh/sss_authorized_keys and that it should be configured in ssh_config or ~/.ssh/config. There are also some missing configuration options.
Suggestions for improvement:
sss_ssh_authorizedkeys does not manage any file, it prints authorized keys on its standard output. See sshd_config man page, AuthorizedKeysCommand option for details.
This feature is configured in /etc/ssh/sshd_config. The sshd service must be restarted in order for any changes to take effect.
The AuthorizedKeysCommand option should be accompanied by AuthorizedKeysCommandRunAs option:
AuthorizedKeysCommand /usr/bin/sss_ssh_authorizedkeys
AuthorizedKeysCommandRunAs nobody
Remove the PubKeyAgent remark, this legacy option is not available in RHEL.
Additional information: