Match Group administrators is silently skipped for Entra ID administrators (keys read from per-user authorized_keys)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 48/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Attiva
- Ambito
- authentication, operating-systems, security
Direzione di ricerca
Reproduce the issue with the supplied Windows, sshd_config, SYSTEM-task, and debug-log steps, then trace ga_init(), generate_s4u_user_token(), and get_user_token() during Match Group evaluation. Compare the administrator’s expected group membership with the reported empty group set; done means membership rules are evaluated correctly or the failure is clearly surfaced without silently using per-user keys.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Prerequisites
- Write a descriptive title.
- Make sure you are able to repro it on the latest version
- Search the existing issues.
Related: #1787 (SSH with AAD/Entra ID credentials). The behaviour below comes from PowerShell/openssh-portable#744, which made ga_init() non-fatal when no user token can be generated.
Steps to reproduce
- Entra ID–joined Windows 11 device; an Entra ID user (SID
S-1-12-1-…) who is a member of the local Administrators group. - Default
%ProgramData%\ssh\sshd_config, which contains:Match Group administrators AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys - Run
sshd.exe10.0.0.0p2 as SYSTEM (as the service does). For the logs below:sshd.exe -ddd -p 2223 -E log.txtfrom a SYSTEM scheduled task. - Put the user's public key in
C:\Users\<user>\.ssh\authorized_keys. ssh -p 2223 -l 'azuread\<user>' <host>
Expected behavior
The Match Group administrators block applies to an administrator, so their keys are looked up only in administrators_authorized_keys, as documented in OpenSSH key management. If group membership can't be determined, sshd should say so clearly rather than silently treating the user as a non-administrator.
Actual behavior
sshd can't create an S4U token for the Entra ID user (see #1787), so since #744 ga_init() reports the user as being in no groups. The Match Group administrators block is skipped for an Entra ID administrator, and the key is read from the per-user authorized_keys:
checking match for 'Group administrators' user azuread\\<user> host <client> ... lport 2223 on line 87
lookup_principal_name: User principal name lookup failed for user 'azuread\\<user>' (explicit: 1355, implicit: 1355)
debug1: generate_s4u_user_token: LsaLogonUser() failed. User 'azuread\\<user>' Status: 0xC0000062 SubStatus 0.
get_user_token - unable to generate token on 2nd attempt for user azuread\\<user>
ga_init, unable to resolve user azuread\\<user>
debug1: Can't Match group because user azuread\\<user> not in any group at line 87
debug3: match not found on line 87
Accepted key ED25519 SHA256:... found at C:/Users/<user>/.ssh/authorized_keys:1
Accepted publickey for azuread\\<user> from <client> port ... ssh2: ED25519 SHA256:...
(The session then fails with fork of unprivileged child failed, the S4U limitation tracked in #1787.)
Any other Match Group block an admin relies on (e.g. ForceCommand, ChrootDirectory, AllowTcpForwarding) is silently skipped for Entra ID users in the same way, because their membership always reads as "no groups".
Suggestion: when the token can't be generated, resolve membership another way (e.g. the account SID against the local group, including Entra role SIDs nested in Administrators), or at least log a warning that Match Group rules could not be evaluated for that user.
Environment data
Windows 11 Pro 25H2, build 10.0.26200, Entra ID–joined (AzureAdJoined: YES, DomainJoined: NO)
Windows PowerShell 5.1.26100
Version
OpenSSH_for_Windows_10.0p2 Win32-OpenSSH-GitHub, LibreSSL 4.2.0 (GitHub release 10.0.0.0p2-Preview, zip, run as SYSTEM)
Inbox OpenSSH_for_Windows_9.5 (sshd.exe 9.5.6.2) on the same machine fails earlier: ga_init() still calls fatal() there (pre-#744).
- Lingua principale
- Nessun dato sulla lingua
- Stelle
- 8.3k
- Fork
- 822
- Merge medio
- 12m
- PR unite (30g)
- 1
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di PowerShell/Win32-OpenSSH
-
Area-ssh-agent Issue-Upstream Parity
Difficoltà 2/5 1-3 ore Idoneità per principianti 74/100
PowerShell/Win32-OpenSSH#2458 · 1 reazione ·
-
Area-sshd Area-Terminal Investigate Issue-Regression
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
PowerShell/Win32-OpenSSH#2465 · 1 commento · 1 reazione ·
-
Area-ssh-agent Issue-Enhancement
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
PowerShell/Win32-OpenSSH#2462 · 1 commento · 1 reazione ·
-
Area-ssh-agent Investigate
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
PowerShell/Win32-OpenSSH#2460 · 1 reazione ·
-
User-defined environment variables referenced in the user PATH are not expanded in SSH sessionsApertaArea-sshd Investigate
Difficoltà 4/5 3-5 giorni Idoneità per principianti 68/100
PowerShell/Win32-OpenSSH#2456 · 1 reazione ·
Tutte le issue di PowerShell/Win32-OpenSSH
Issue simili
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
WordPress/two-factor#1022 · 1 commento ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno
-
beginner friendly community contributions-welcome enhancement good first issue hacktoberfest help wanted security up-for-grabs
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Team/Identity Server Core Type/Improvement U2
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
wso2/product-is#28553 ·
I maintainer di solito rispondono entro 1 giorno