Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Match Group administrators is silently skipped for Entra ID administrators (keys read from per-user authorized_keys)

Aperta
#2,466 1 commento 1 reazione 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
4/5
Tempo stimato
3-5 giorni
Idoneità per principianti
48/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Attiva

Direzione di ricerca

Reproduce the issue with the supplied Windows, sshd_config, SYSTEM-task, and debug-log steps, then trace ga_init(), generate_s4u_user_token(), and get_user_token() during Match Group evaluation. Compare the administrator’s expected group membership with the reported empty group set; done means membership rules are evaluated correctly or the failure is clearly surfaced without silently using per-user keys.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Area-Authentication Area-Logging/Diagnostics Area-sshd Investigate Issue-Bug
Prerequisites
  • Write a descriptive title.
  • Make sure you are able to repro it on the latest version
  • Search the existing issues.

Related: #1787 (SSH with AAD/Entra ID credentials). The behaviour below comes from PowerShell/openssh-portable#744, which made ga_init() non-fatal when no user token can be generated.

Steps to reproduce
  1. Entra ID–joined Windows 11 device; an Entra ID user (SID S-1-12-1-…) who is a member of the local Administrators group.
  2. Default %ProgramData%\ssh\sshd_config, which contains:
    Match Group administrators
           AuthorizedKeysFile __PROGRAMDATA__/ssh/administrators_authorized_keys
    
  3. Run sshd.exe 10.0.0.0p2 as SYSTEM (as the service does). For the logs below: sshd.exe -ddd -p 2223 -E log.txt from a SYSTEM scheduled task.
  4. Put the user's public key in C:\Users\<user>\.ssh\authorized_keys.
  5. ssh -p 2223 -l 'azuread\<user>' <host>
Expected behavior

The Match Group administrators block applies to an administrator, so their keys are looked up only in administrators_authorized_keys, as documented in OpenSSH key management. If group membership can't be determined, sshd should say so clearly rather than silently treating the user as a non-administrator.

Actual behavior

sshd can't create an S4U token for the Entra ID user (see #1787), so since #744 ga_init() reports the user as being in no groups. The Match Group administrators block is skipped for an Entra ID administrator, and the key is read from the per-user authorized_keys:

checking match for 'Group administrators' user azuread\\<user> host <client> ... lport 2223 on line 87
lookup_principal_name: User principal name lookup failed for user 'azuread\\<user>' (explicit: 1355, implicit: 1355)
debug1: generate_s4u_user_token: LsaLogonUser() failed. User 'azuread\\<user>' Status: 0xC0000062 SubStatus 0.
get_user_token - unable to generate token on 2nd attempt for user azuread\\<user>
ga_init, unable to resolve user azuread\\<user>
debug1: Can't Match group because user azuread\\<user> not in any group at line 87
debug3: match not found on line 87
Accepted key ED25519 SHA256:... found at C:/Users/<user>/.ssh/authorized_keys:1
Accepted publickey for azuread\\<user> from <client> port ... ssh2: ED25519 SHA256:...

(The session then fails with fork of unprivileged child failed, the S4U limitation tracked in #1787.)

Any other Match Group block an admin relies on (e.g. ForceCommand, ChrootDirectory, AllowTcpForwarding) is silently skipped for Entra ID users in the same way, because their membership always reads as "no groups".

Suggestion: when the token can't be generated, resolve membership another way (e.g. the account SID against the local group, including Entra role SIDs nested in Administrators), or at least log a warning that Match Group rules could not be evaluated for that user.

Environment data
Windows 11 Pro 25H2, build 10.0.26200, Entra ID–joined (AzureAdJoined: YES, DomainJoined: NO)
Windows PowerShell 5.1.26100
Version
OpenSSH_for_Windows_10.0p2 Win32-OpenSSH-GitHub, LibreSSL 4.2.0   (GitHub release 10.0.0.0p2-Preview, zip, run as SYSTEM)
Inbox OpenSSH_for_Windows_9.5 (sshd.exe 9.5.6.2) on the same machine fails earlier: ga_init() still calls fatal() there (pre-#744).
Lingua principale
Nessun dato sulla lingua
Stelle
8.3k
Fork
822
Merge medio
12m
PR unite (30g)
1

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di PowerShell/Win32-OpenSSH

Tutte le issue di PowerShell/Win32-OpenSSH

Issue simili

Altre issue su Security

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.