Skip to content

Simple authorization

Authorizes a user request via stored credentials.

Properties

type

Authorization Type = "simple"

Has to be set to simple to enable simple authorization.

trustedUserCAs

OpenSSH public keys of certificate authorities that may sign user certificates for every entry in this authorization. The requested SSH username must be included in the certificate's principals.

trustedUserCAsFile

Same as trustedUserCAs, but loaded from one file when the authorization is initialized. Both properties can be used together. A configured file must exist, contain at least one valid public key, and be no larger than 4 MiB because its keys are materialized during startup.

entries

[]Entry

Each entry will be inspected to check if a remote user should be authorized.

Entry

One of the following properties normally has to match in combination with name:

An entry containing only name can additionally be authenticated by a user certificate signed by trustedUserCAs or trustedUserCAsFile.

Properties

name

string

Name the remote user has to have.

Like: ssh <name>@my-great-domain.tld to match this entry.

authorizedKeys

Contains SSH Public Keys in the format of classic authorized keys.

An entry with the cert-authority option treats its key as a user certificate authority for this simple entry. The optional principals="..." option restricts it further.

authorizedKeysFile

Similar to authorizedKeys, but in a dedicated file.

password

Password (if user uses interactive or password authentication method) to be evaluated against.

passwordFile

Same as password, but is receiving the value from this file.

If both properties are defined and have values, password will be used.

createPasswordFileIfAbsentOfType

If this property is provided and passwordFile is defined, but does not exist, the file will be generated with a random password of this type.

The result will be printed into the startup logs of Bifröst.

This feature usually only makes sense for cases where you want to create dummy configurations of Bifröst to demonstrate some functionality, like we're utilizing it in our demonstration configurations: contrib/configurations/simple-inside-docker.yaml.

Context

This authorization will produce a context of type Authorization Simple.

Examples

  1. Using plain password:
    1
    2
    3
    4
    type: simple
    entries:
      - name: foo
        password: plain:bar
    
  2. Using authorized keys: ```yaml type: simple entries:
    • name: foo authorizedKeys: | ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIC80lm5FQbbyRUut6RwZJRbxTLO3W4f08ITDi9fA3+jx foo@foo.tld ```
  3. Using an OpenSSH user certificate authority:
    1
    2
    3
    4
    5
    type: simple
    trustedUserCAs: |
      ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIExampleOrganizationCA
    entries:
      - name: foo
    

User certificates must be current, signed by the selected CA, have the requested SSH username as a principal, and contain no critical options. Missing permit-pty, permit-port-forwarding, or permit-agent-forwarding certificate extensions disable the corresponding capability. Authorized-key options can only restrict these capabilities further.

Compatibility

linux darwin windows
/ / /