forked from heavy-duty/rig
The StrictModes-shaped gate reads files, and files can all look right while the door stays shut: a sudoers drop-in that never landed, an AllowUsers or Match block elsewhere in sshd's config. #17 names the two checks that interrogate behavior instead, and they now run per candidate, additively, before the drop-in installs: 'runuser -u <admin> -- sudo -n true' (NOPASSWD sudo answers or it does not — -n never prompts; a missing runuser skips the proof with a loud warning rather than blocking the door on a missing prover), and 'sshd -T -C user=<admin>,host=...,addr=...' (the per-user EFFECTIVE config — pubkeyauthentication yes, no literal DenyUsers hit, AllowUsers if set must name them; Allow/Deny patterns match literally, fail closed). The one thing no local check can prove remains possession of the private key — the separate-session advisory stays load-bearing. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| cli.sh | ||
| db-integration.sh | ||