29 files under ProjectCode/ConfigFiles lacked a trailing newline. They deploy via `cat file > target`, and several targets are subsequently appended to (notably /etc/ssh/sshd_config, which configure_ssh_2fa appends `AuthenticationMethods publickey,keyboard-interactive` to). Without a trailing newline the append fused onto the last line, producing `LoginGraceTime 60AuthenticationMethods ...`, which sshd -t rejected as an invalid time value and aborted provisioning under errexit. This is the same defect class that already broke the managed authorized_keys files. Add the trailing newline to every config file that was missing one so the cat-then-append pattern is always safe. 🤖 Generated with [Crush](https://github.com/charmassociates/crush) Assisted-by: GLM-5 via Crush <crush@charm.land>
21 lines
530 B
Plaintext
21 lines
530 B
Plaintext
Include /etc/ssh/sshd_config.d/*.conf
|
|
HostKey /etc/ssh/ssh_host_rsa_key
|
|
HostKey /etc/ssh/ssh_host_ed25519_key
|
|
KbdInteractiveAuthentication no
|
|
PrintMotd no
|
|
PasswordAuthentication no
|
|
AllowTcpForwarding no
|
|
X11Forwarding no
|
|
ChallengeResponseAuthentication no
|
|
AcceptEnv LANG LC_*
|
|
Subsystem sftp /usr/lib/openssh/sftp-server
|
|
UsePAM yes
|
|
Banner /etc/issue.net
|
|
MaxAuthTries 2
|
|
MaxStartups 10:30:100
|
|
PermitRootLogin prohibit-password
|
|
ClientAliveInterval 300
|
|
ClientAliveCountMax 3
|
|
AllowUsers root localuser subodev
|
|
LoginGraceTime 60
|