@georgalis commented on GitHub:
@robertgendler regarding (1) this would seem a stylistic variation of my PR #248 checks, is there a style guide? The PR style embraces the original syntax, with…
@bernstei commented on GitHub:
@bernstei that is not consistent with my experience with sshd and/or mac. I could speculate causes, but that would be something of a random walk. I'm certain some…
@georgalis commented on GitHub:
@robertgendler BTW the system I've used for many years to bring a vendor OS config to my standard is here: https://github.com/georgalis/pub/blob/master/boot/nbsd/h…
@georgalis commented on GitHub:
@robertgendler considering an alternate method for the sshd check/fix rules, a new approach is if sshd -T fails the check, use the include_dir and write a…
@paolafrancesca commented on GitHub:
@thanakijwanavit you provided a service acount json instead of a client api key one at https://console.developers.google.com/apis/credentials you can create…
@paolafrancesca commented on GitHub:
did you solve the issue @thanakijwanavit ? my client json file is like the following:
{"installed":{"client_id":"...","project_id":"...","auth_uri":"htt…
@georgalis commented on GitHub:
Hi @bernstei I do not see os_ssh_fips_140_macs or os_ssh_permit_root_login_configure in the repo, where are they from? Did not check the other names but I presume…
@robertgendler commented on GitHub:
Since opening this issue and pull request we had 2 thoughts on how to handle the check 1.
if sshd -T 2> /dev/null; then
....check...
else
...could…
@georgalis commented on GitHub:
@bernstei that is not consistent with my experience with sshd and/or mac. I could speculate causes, but that would be something of a random walk. I'm certain some…
@bernstei commented on GitHub:
Good question - let me check.
[edited]
Those are typos, because it wasn't easy to cut and paste. I dropped off the "d" from sshd, i.e. they are actually…
@bernstei commented on GitHub:
Also, FWIW, I started "remote login" from the sharing control panel and then stopped it, and sshd -T still says "No hostkeys available", so it having been…
@georgalis commented on GitHub:
@bernstei thanks, patch #248 should cover os_sshd_* rules, @robertgendler I'll craft a separate PR for the os_ssh_* rules, this evening.
@robertgendler commented on GitHub:
@georgalis the check to do is not fail potentially if the hostkey isn't found. Because checking for sshd running then only checks if sshd is running.