Who can still log in as deploy? SEC-93

OpenSecurity · Easy · Fix · about 25 min ·Linux

Lab machine

A private Linux machine with the problem already set up. Sessions last up to 60 minutes.
Priya Raman opened SEC-93 at 10:00task

The access review for the deploy account is overdue. Its authorized_keys file has been edited by hand since 2025, and nobody is sure whose keys are in it.

The deploy account ships Waybill, so whoever can log in as deploy can ship anything. Its authorized_keys has been edited by hand since 2025.

"Comments are not evidence. Anyone can write backup-key on any key. Match fingerprints against the records." (Priya)

One more thing the file has wrong: sshd silently ignores an authorized_keys that other users can write. If you fix the keys and not the permissions, nobody gets in.

Your task

Remove the keys of people who left and revoked keys, keep current staff and CI, restrict the CI key to the deploy command, and fix the permissions so sshd will accept the file.

On the machine

  • hosts/deploy/.ssh/authorized_keys
  • docs/keys.md (fingerprints), docs/offboarding.md, docs/revoked.txt
  • docs/ssh-policy.md
  • ssh-keygen -lf <file>

Timeline

Aug 30Last access review.
Sep 2A staff laptop is stolen from a car (SEC-77). Its key is revoked in the records.
Sep 19Jonas's contract ends.
10:00SEC-93: review deploy@depot-west-01.

Done when

  1. Keys of people who left and revoked keys are removed.
  2. Current staff and CI keep access, and sshd would accept the file's permissions.
  3. The CI key is restricted to the deploy command.

Hints

Hint 1

ssh-keygen -lf hosts/deploy/.ssh/authorized_keys prints one fingerprint per key.

Hint 2

Match fingerprints against docs/keys.md and docs/revoked.txt, not comments.

Hint 3

Prefix the CI key with restrict,command="/usr/local/bin/deploy-only" and a space.

Hint 4

chmod 700 hosts/deploy/.ssh and chmod 600 on the file.

Show the solution

Run `ssh-keygen -lf hosts/deploy/.ssh/authorized_keys` and match each fingerprint against docs/keys.md and docs/revoked.txt. Delete the line whose fingerprint is Jonas's (whatever its comment says, and whatever options precede it) and the line whose fingerprint is revoked (the stolen laptop's old key), add restrict,command="/usr/local/bin/deploy-only" in front of the CI key, and set the directory to 700 and the file to 600.