`AuthorizedPrincipalsFile` behavior does not match `AuthorizedKeysFile`
Nobody has claimed this yet.
Assessment
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Newbie friendliness
- 45/100
- Issue type
- Bug
- Clarity
- Mostly clear
- Activity status
- Stale
- Tech stack
- c
- Domain
- authentication, operating-systems, security
Research direction
Start by reproducing the listed AuthorizedPrincipalsFile cases on Windows and compare them with AuthorizedKeysFile using the corresponding sshd_config entries. Trace how each directive resolves relative paths, separators, and %h/%u substitutions. Done means the failing formats behave consistently with AuthorizedKeysFile and the authentication scenario succeeds.
Written by the indexing model from the issue text.
Description
Prerequisites
- Write a descriptive title.
- Make sure you are able to repro it on the latest version
- Search the existing issues.
Steps to reproduce
The sshd_config directive AuthorizedPrincipalsFile fails to read many formats.
- sign a user key with a principal that is not a valid username on the server
- create
$env:USERPROFILE\.ssh\authorized_principalson the server and add the principal - make sure all other forms of authentication are disabled for that user
- add
AuthorizedPrincipalsFile .ssh/authorized_principalstosshd_config(same format asAuthorizedKeysFile .ssh/authorized_keys) - observe that logging in fails with
error: Certificate does not contain an authorized principalin the sshd log
Expected behavior
`AuthorizedPrincipalsFile` has the same behavior as `AuthorizedKeysFile`
Actual behavior
The following fail:
AuthorizedPrincipalsFile .ssh/authorized_principals
AuthorizedPrincipalsFile .ssh\authorized_principals
AuthorizedPrincipalsFile %h/.ssh/authorized_principals
AuthorizedPrincipalsFile %h\.ssh\authorized_principals
AuthorizedPrincipalsFile C:\Users\%u\.ssh\authorized_principals
This one works:
AuthorizedPrincipalsFile C:/Users/%u/.ssh/authorized_principals
Error details
Environment data
PSVersion 5.1.26100.7462
PSEdition Desktop
PSCompatibleVersions {1.0, 2.0, 3.0, 4.0...}
BuildVersion 10.0.26100.7462
CLRVersion 4.0.30319.42000
WSManStackVersion 3.0
PSRemotingProtocolVersion 2.3
SerializationVersion 1.1.0.1
Version
OpenSSH_for_Windows_10.0p2 Win32-OpenSSH-GitHub, LibreSSL 4.2.0
Visuals
No response
- Dominant language
- No language data
- Stars
- 8.3k
- Forks
- 820
- Avg merge
- 12m
- Merged PRs (30d)
- 1
Getting set up
- No Dockerfile or Docker Compose file
- No pull request template
- Read the contributing guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from PowerShell/Win32-OpenSSH
-
Area-ssh-agent Issue-Upstream Parity
Difficulty 2/5 1-3 hours Newbie friendliness 74/100
PowerShell/Win32-OpenSSH#2458 · 1 reaction ·
-
Area-Authentication Area-Logging/Diagnostics Area-sshd Investigate Issue-Bug
Difficulty 4/5 3-5 days Newbie friendliness 48/100
PowerShell/Win32-OpenSSH#2466 · 1 comment · 1 reaction ·
-
Area-sshd Area-Terminal Investigate Issue-Regression
Difficulty 4/5 3-5 days Newbie friendliness 48/100
PowerShell/Win32-OpenSSH#2465 · 1 comment · 1 reaction ·
-
Area-ssh-agent Issue-Enhancement
Difficulty 5/5 Over a week Newbie friendliness 25/100
PowerShell/Win32-OpenSSH#2462 · 1 comment · 1 reaction ·
-
Area-ssh-agent Investigate
Difficulty 5/5 Over a week Newbie friendliness 25/100
PowerShell/Win32-OpenSSH#2460 · 1 reaction ·
All issues in PowerShell/Win32-OpenSSH
Similar issues
-
github_actions security
Difficulty 2/5 1-3 hours Newbie friendliness 75/100
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
langchain-ai/langgraphjs#2958 ·
Maintainers usually reply within 1 day
-
allow igdb.comOpen
Difficulty 2/5 1-3 hours Newbie friendliness 61/100
AdguardTeam/HostlistsRegistry#939 ·
Maintainers usually reply within 1 day
-
backlog
Difficulty 2/5 1-3 hours Newbie friendliness 65/100
Maintainers usually reply within 1 day
-
RPMDistro._update_packages() always passes --nogpgcheck, bypassing package signature verificationOpen
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Maintainers usually reply within 1 day