[aurweb,2/2] Add FIDO/U2F ssh keytypes to default config

Message ID 20210610183512.516429-2-void@fluix.one
State New
Headers show
Series [aurweb,1/2] Source valid ssh prefixes from config | expand

Commit Message

Steven Guikal June 10, 2021, 6:35 p.m. UTC
---
 conf/config.defaults | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

Comments

Eli Schwartz June 10, 2021, 7:35 p.m. UTC | #1
On 6/10/21 2:35 PM, Steven Guikal via aur-dev wrote:
> ---
>  conf/config.defaults | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/conf/config.defaults b/conf/config.defaults
> index 98e033b7..e6961520 100644
> --- a/conf/config.defaults
> +++ b/conf/config.defaults
> @@ -62,7 +62,7 @@ ECDSA = SHA256:L71Q91yHwmHPYYkJMDgj0xmUuw16qFOhJbBr1mzsiOI
>  RSA = SHA256:Ju+yWiMb/2O+gKQ9RJCDqvRg7l+Q95KFAeqM5sr6l2s
>  
>  [auth]
> -valid-keytypes = ssh-rsa ssh-dss ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 ssh-ed25519
> +valid-keytypes = ssh-rsa ssh-dss ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 ssh-ed25519 sk-ssh-ecdsa@openssh.com sk-ssh-ed25519@openssh.com


Thanks, this seems like a very reasonable change. :)

To gitlab.archlinux.org:archlinux/aurweb.git
   a625df07..b32022a1  b32022a176ede116068a405c928cf25e23ffb691 -> master


>  username-regex = [a-zA-Z0-9]+[.\-_]?[a-zA-Z0-9]+$
>  git-serve-cmd = /usr/local/bin/aurweb-git-serve
>  ssh-options = restrict
>

Patch

diff --git a/conf/config.defaults b/conf/config.defaults
index 98e033b7..e6961520 100644
--- a/conf/config.defaults
+++ b/conf/config.defaults
@@ -62,7 +62,7 @@  ECDSA = SHA256:L71Q91yHwmHPYYkJMDgj0xmUuw16qFOhJbBr1mzsiOI
 RSA = SHA256:Ju+yWiMb/2O+gKQ9RJCDqvRg7l+Q95KFAeqM5sr6l2s
 
 [auth]
-valid-keytypes = ssh-rsa ssh-dss ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 ssh-ed25519
+valid-keytypes = ssh-rsa ssh-dss ecdsa-sha2-nistp256 ecdsa-sha2-nistp384 ecdsa-sha2-nistp521 ssh-ed25519 sk-ssh-ecdsa@openssh.com sk-ssh-ed25519@openssh.com
 username-regex = [a-zA-Z0-9]+[.\-_]?[a-zA-Z0-9]+$
 git-serve-cmd = /usr/local/bin/aurweb-git-serve
 ssh-options = restrict