Merge pull request #307464 from tomfitzhenry/ssh-minimal

openssh: fix linkOpenSSL=false by linking libxcrypt

Changed files
+52 -2
nixos
pkgs
tools
networking
openssh
+37 -1
nixos/tests/openssh.nix
···
import ./make-test-python.nix ({ pkgs, ... }:
let inherit (import ./ssh-keys.nix pkgs)
-
snakeOilPrivateKey snakeOilPublicKey;
+
snakeOilPrivateKey snakeOilPublicKey snakeOilEd25519PrivateKey snakeOilEd25519PublicKey;
in {
name = "openssh";
meta = with pkgs.lib.maintainers; {
···
};
};
+
server-no-openssl =
+
{ ... }:
+
{
+
programs.ssh.package = pkgs.opensshPackages.openssh.override {
+
linkOpenssl = false;
+
};
+
services.openssh = {
+
enable = true;
+
hostKeys = [
+
{ type = "ed25519"; path = "/etc/ssh/ssh_host_ed25519_key"; }
+
];
+
settings = {
+
# Must not specify the OpenSSL provided algorithms.
+
Ciphers = [ "chacha20-poly1305@openssh.com" ];
+
KexAlgorithms = [
+
"curve25519-sha256"
+
"curve25519-sha256@libssh.org"
+
];
+
};
+
};
+
users.users.root.openssh.authorizedKeys.keys = [
+
snakeOilEd25519PublicKey
+
];
+
};
+
server-no-pam =
{ pkgs, ... }:
{
···
server_allowed_users.wait_for_unit("sshd", timeout=30)
server_localhost_only.wait_for_unit("sshd", timeout=30)
server_match_rule.wait_for_unit("sshd", timeout=30)
+
server_no_openssl.wait_for_unit("sshd", timeout=30)
server_no_pam.wait_for_unit("sshd", timeout=30)
server_lazy.wait_for_unit("sshd.socket", timeout=30)
···
)
client.fail(
"ssh -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -i privkey.snakeoil carol@server-allowed-users true",
+
timeout=30
+
)
+
+
with subtest("no-openssl"):
+
client.succeed(
+
"cat ${snakeOilEd25519PrivateKey} > privkey.snakeoil"
+
)
+
client.succeed("chmod 600 privkey.snakeoil")
+
client.succeed(
+
"ssh -o UserKnownHostsFile=/dev/null -o StrictHostKeyChecking=no -i privkey.snakeoil server-no-openssl true",
timeout=30
)
+12
nixos/tests/ssh-keys.nix
···
"yNTYAAABBBChdA2BmwcG49OrQN33f/sj+OHL5sJhwVl2Qim0vkUJQCry1zFpKTa"
"9ZcDMiWaEhoAR6FGoaGI04ff7CS+1yybQ= snakeoil"
];
+
+
snakeOilEd25519PrivateKey = pkgs.writeText "privkey.snakeoil" ''
+
-----BEGIN OPENSSH PRIVATE KEY-----
+
b3BlbnNzaC1rZXktdjEAAAAABG5vbmUAAAAEbm9uZQAAAAAAAAABAAAAMwAAAAtzc2gtZW
+
QyNTUxOQAAACAYBTIWo1J4PkY4/7AhVyPT8xvAUI67tp+yYFFRdSm7+QAAAJC89yCivPcg
+
ogAAAAtzc2gtZWQyNTUxOQAAACAYBTIWo1J4PkY4/7AhVyPT8xvAUI67tp+yYFFRdSm7+Q
+
AAAEDJmKp3lX6Pz0unTc0QZwrHb8Eyr9fJUopE9d2/+q+eCxgFMhajUng+Rjj/sCFXI9Pz
+
G8BQjru2n7JgUVF1Kbv5AAAACnRvbUBvemRlc2sBAgM=
+
-----END OPENSSH PRIVATE KEY-----
+
'';
+
+
snakeOilEd25519PublicKey = "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIBgFMhajUng+Rjj/sCFXI9PzG8BQjru2n7JgUVF1Kbv5 snakeoil";
}
+3 -1
pkgs/tools/networking/openssh/common.nix
···
, withLdns ? true
, libkrb5
, libfido2
+
, libxcrypt
, hostname
, nixosTests
, withFIDO ? stdenv.hostPlatform.isUnix && !stdenv.hostPlatform.isMusl
···
# https://github.com/NixOS/nixpkgs/pull/107606
++ lib.optional withKerberos pkgs.libkrb5
++ extraNativeBuildInputs;
-
buildInputs = [ zlib openssl libedit ]
+
buildInputs = [ zlib libedit ]
+
++ [ (if linkOpenssl then openssl else libxcrypt) ]
++ lib.optional withFIDO libfido2
++ lib.optional withKerberos libkrb5
++ lib.optional withLdns ldns