thanks heaps William.
Appreciated


On Sun, Jul 29, 2018 at 3:07 PM William Muriithi via FreeIPA-users <freeipa-users@lists.fedorahosted.org> wrote:
Hi Alfredo,
>
> Anyone on this question?
> cheers
>
> /Alfredo
>
> On Thu, 26 Jul 2018, 18:35 Alfredo De Luca, <alfredo.deluca@gmail.com>
> wrote:
>
>> Hi all.
>> I wonder how to force ssh keys only all the users with freeIPA. We have
>> 4.5.4 version.
>> Is it the only way changing the sshd_config from PasswordAuthentication
>> from yes to *NO*?
>>
Its the same stuff you need to do for none IPA system.

You will also need to:
-  Have them generate a public private ssh key pair
-  (Have them add it to their IPA user profile) or add their public
key on authorization file.

If you do this, the IPA server don't do any authentication at all.  So
if you are using something like a kerberos based NFS, they will have
issues mounting their home directories.

Regards,
William
_______________________________________________
FreeIPA-users mailing list -- freeipa-users@lists.fedorahosted.org
To unsubscribe send an email to freeipa-users-leave@lists.fedorahosted.org
Fedora Code of Conduct: https://getfedora.org/code-of-conduct.html
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: https://lists.fedoraproject.org/archives/list/freeipa-users@lists.fedorahosted.org/message/QGRKVFKDUZBVZYWZVREDMP4OE2D6XHZA/


--
Alfredo