Local authorization
Authorizes a user request via the local user database of the host on which Bifröst is running.
Note
On Linux, this authorization requires Bifröst to run with root permissions.
On Windows, the default authorizedKeys path uses .user.homeDir, which requires LocalSystem to resolve the user's profile via S4U. For a custom path without .user.homeDir, Bifröst only needs permission to read the file. The Windows local environment also requires LocalSystem to start processes as the local account.
Properties
type
Authorization Type = "local"
Has to be set to local to enable the local authorization.
trustedUserCAs
OpenSSH public keys of certificate authorities that may sign user certificates for existing local users. The requested SSH username must be included in the certificate's principals.
trustedUserCAsFile
Same as trustedUserCAs, but loaded from one file when the authorization is initialized. Both properties can be used together. A configured file must exist, contain at least one valid public key, and be no larger than 4 MiB because its keys are materialized during startup.
authorizedKeys
[]File Path<Authorized Keys> Core =
["{{.user.homeDir}}/.ssh/authorized_keys"]
Contains files with the format of classic authorized keys, in which Bifröst will look for SSH Public Keys.
An entry with the cert-authority option treats its key as a user certificate authority for that local user. The optional principals="..." option restricts it further. An empty authorizedKeys list does not disable certificate authentication through trustedUserCAs or trustedUserCAsFile.
password
See below.
pamService
string = "<os and edition specific>"
If set to a non-empty value, this PAM service will be directly used during the authorization process instead of /etc/passwd and /etc/shadow.
On macOS, PAM password and keyboard-interactive authentication runs both authentication and account-management checks. The generic edition fails closed when pamService is empty and loads the system PAM library dynamically without CGO. The default sshd service uses /etc/pam.d/sshd; review that service's policy before exposing Bifröst.
PAM is unavailable on Windows; a non-empty pamService is rejected there.
Default settings
linux/extended |
darwin |
anything else |
|---|---|---|
sshd |
sshd |
empty |
Password
- On Linux, passwords are validated via
/etc/passwdand/etc/shadowwhenpamServiceis empty, or via PAM when it is set. - On macOS, a non-empty PAM service is required; there is no local password-repository fallback.
- On Windows, password and keyboard-interactive authentication validate the password of an existing local SAM account. Windows account restrictions (such as disabled accounts or denied network logon) still apply. Domain and Microsoft Entra accounts are not supported by
localauthorization.
Properties
allowed
bool Context Password Authorization Request = true
If true, the user is allowed to use passwords via classic password authentication
interactiveAllowed
bool Context Interactive Authorization Request = true
If true, the user is allowed to use passwords via interactive authentication.
emptyAllowed
bool Context * Authorization Request = false
If true, the user is allowed to use empty passwords.
Danger
This is explicitly not recommend.
Context
This authorization will produce a context of type Authorization Local.
Examples
Using OpenSSH Certificates
1 2 3 4 | |
Using Local accounts
1 2 3 4 5 6 7 8 | |
User certificates must be current, signed by the selected CA, have the requested SSH username as a principal, and contain no critical options. Missing permit-pty, permit-port-forwarding, or permit-agent-forwarding certificate extensions disable the corresponding capability. Authorized-key options can only restrict these capabilities further.
Compatibility
| Feature | linux |
darwin |
windows |
|---|---|---|---|
| PAM | / | / | / |
| anything else | / | / | / |