diff --git a/user/ssh_config.sh b/user/ssh_config.sh index 99a099e..1679535 100644 --- a/user/ssh_config.sh +++ b/user/ssh_config.sh @@ -23,17 +23,33 @@ function config_ssh() { echo "[ SSH ]: No public key provided, skipping..." fi - echo "[ SSH ]: Disabling root login" - sudo sed -i 's/^#\?PermitRootLogin.*/PermitRootLogin no/' /etc/ssh/sshd_config - echo "[ SSH ]: Root login disabled" + # Create SSH configuration file instead of modifying main sshd_config + config_file="/etc/ssh/sshd_config.d/server-initializer.conf" - echo "[ SSH ]: Adding $username to allowed users" - if grep -q "^AllowUsers" /etc/ssh/sshd_config; then - sudo sed -i "s/^AllowUsers.*/& $username/" /etc/ssh/sshd_config - else - echo "AllowUsers $username" | sudo tee -a /etc/ssh/sshd_config >/dev/null - fi - echo "[ SSH ]: User added to allowed users" + echo "[ SSH ]: Creating SSH configuration file" + sudo mkdir -p /etc/ssh/sshd_config.d + + # Create the configuration file with security settings + sudo tee "$config_file" >/dev/null <