我正在运行Mac OS X Leopard服务器并且我创建了一个新用户,但没有为该用户指定主目录。是否可以让该用户使用公钥进行身份验证?
我知道当用户 拥有主目录时,它会进入~/.ssh/authorized_keys
我不想为这个用户创建一个主目录,因为我的理解是它允许他们在给定物理访问时登录。
更新:我需要允许此用户仅进行安全FTP连接。将登录Shell设置为/bin/false/
也会阻止它们远程连接。
答案 0 :(得分:9)
您必须修改/etc/ssh/sshd_config
或其在计算机上的位置并更改AuthorizedKeysFile
设置。
文档说:
AuthorizedKeysFile
Specifies the file that contains the public keys that can be used
for user authentication. AuthorizedKeysFile may contain tokens of
the form %T which are substituted during connection setup. The fol-
lowing tokens are defined: %% is replaced by a literal '%', %h is
replaced by the home directory of the user being authenticated, and
%u is replaced by the username of that user. After expansion,
AuthorizedKeysFile is taken to be an absolute path or one relative
to the user's home directory. The default is
``.ssh/authorized_keys''.
但是为什么没有家的用户(可以登录)?