summaryrefslogtreecommitdiffstats
path: root/debian/openssh-client.postinst
diff options
context:
space:
mode:
authorDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 05:19:51 +0000
committerDaniel Baumann <daniel.baumann@progress-linux.org>2024-04-28 05:19:51 +0000
commit0114a88b949fa5aab62150ab6c38e38c46984bee (patch)
tree0e471479410e8b25397e61d77207978319985c54 /debian/openssh-client.postinst
parentSetting MaxAuthTries in sshd_config to 3. (diff)
downloadopenssh-0114a88b949fa5aab62150ab6c38e38c46984bee.tar.xz
openssh-0114a88b949fa5aab62150ab6c38e38c46984bee.zip
Renaming ssh group to _ssh (Closes: #990456).
Signed-off-by: Daniel Baumann <daniel.baumann@progress-linux.org>
Diffstat (limited to '')
-rw-r--r--debian/openssh-client.postinst19
1 files changed, 16 insertions, 3 deletions
diff --git a/debian/openssh-client.postinst b/debian/openssh-client.postinst
index cf046ed..1c42009 100644
--- a/debian/openssh-client.postinst
+++ b/debian/openssh-client.postinst
@@ -23,12 +23,22 @@ create_alternatives() {
done
}
+update_ssh_group_name() {
+ # The _ssh group used to be called ssh, but that could clash with
+ # locally-created user accounts. Since this only exists as an
+ # otherwise-empty group to which ssh-agent is installed setgid, it's
+ # easy to rename.
+ if getent group ssh >/dev/null && ! getent group _ssh >/dev/null; then
+ groupmod -n _ssh ssh
+ fi
+}
+
set_ssh_agent_permissions() {
- if ! getent group ssh >/dev/null; then
- addgroup --system --quiet ssh
+ if ! getent group _ssh >/dev/null; then
+ addgroup --system --quiet --force-badname _ssh
fi
if ! dpkg-statoverride --list /usr/bin/ssh-agent >/dev/null; then
- chgrp ssh /usr/bin/ssh-agent
+ chgrp _ssh /usr/bin/ssh-agent
chmod 2755 /usr/bin/ssh-agent
fi
}
@@ -36,6 +46,9 @@ set_ssh_agent_permissions() {
if [ "$action" = configure ]; then
create_alternatives
+ if dpkg --compare-versions "$2" lt-nl 1:8.4p1-6~; then
+ update_ssh_group_name
+ fi
set_ssh_agent_permissions
fi