Simple authorization
Authorizes a user request via stored credentials.
Properties
type
Authorization Type = "simple"
Has to be set to simple to enable simple authorization.
trustedUserCAs
OpenSSH public keys of certificate authorities that may sign user certificates for every entry in this authorization. The requested SSH username must be included in the certificate's principals.
trustedUserCAsFile
Same as trustedUserCAs, but loaded from one file when the authorization is initialized. Both properties can be used together. A configured file must exist, contain at least one valid public key, and be no larger than 4 MiB because its keys are materialized during startup.
entries
[]Entry
Each entry will be inspected to check if a remote user should be authorized.
Entry
One of the following properties normally has to match in combination with name:
An entry containing only name can additionally be authenticated by a user certificate signed by trustedUserCAs or trustedUserCAsFile.
Properties
name
string
Name the remote user has to have.
Like: ssh <name>@my-great-domain.tld to match this entry.
authorizedKeys
Contains SSH Public Keys in the format of classic authorized keys.
An entry with the cert-authority option treats its key as a user certificate authority for this simple entry. The optional principals="..." option restricts it further.
authorizedKeysFile
Similar to authorizedKeys, but in a dedicated file.
password
Password (if user uses interactive or password authentication method) to be evaluated against.
passwordFile
Same as password, but is receiving the value from this file.
If both properties are defined and have values, password will be used.
createPasswordFileIfAbsentOfType
If this property is provided and passwordFile is defined, but does not exist, the file will be generated with a random password of this type.
The result will be printed into the startup logs of Bifröst.
This feature usually only makes sense for cases where you want to create dummy configurations of Bifröst to demonstrate some functionality, like we're utilizing it in our demonstration configurations: contrib/configurations/simple-inside-docker.yaml.
Context
This authorization will produce a context of type Authorization Simple.
Examples
- Using plain password:
1 2 3 4
type: simple entries: - name: foo password: plain:bar - Using authorized keys:
```yaml
type: simple
entries:
- name: foo authorizedKeys: | ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC80lm5FQbbyRUut6RwZJRbxTLO3W4f08ITDi9fA3+jx foo@foo.tld ```
- Using an OpenSSH user certificate authority:
1 2 3 4 5
type: simple trustedUserCAs: | ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIExampleOrganizationCA entries: - name: foo
User certificates must be current, signed by the selected CA, have the requested SSH username as a principal, and contain no critical options. Missing permit-pty, permit-port-forwarding, or permit-agent-forwarding certificate extensions disable the corresponding capability. Authorized-key options can only restrict these capabilities further.
Compatibility
linux |
darwin |
windows |
|---|---|---|
| / | / | / |