Skip to content
Snippets Groups Projects
Unverified Commit f895dce4 authored by Clément Lassieur's avatar Clément Lassieur Committed by Danny Milosavljevic
Browse files

services: openssh: Fix 'PrintLastLog' default behaviour.


* gnu/services/ssh.scm (openssh-config-file): Add 'print-last-log?' option.
(<openssh-configuration>)[print-last-log?]: Add it.
(openssh-activation): Touch /var/log/lastlog.
* doc/guix.texi (Networking Services): Document 'print-last-log?'.

Before that, the service did not work as expected because /var/log/lastlog did
not exist.

Signed-off-by: default avatarDanny Milosavljevic <dannym@scratchpost.org>
parent 1806a670
No related branches found
No related tags found
No related merge requests found
......@@ -9352,6 +9352,10 @@ Because PAM challenge response authentication usually serves an
equivalent role to password authentication, you should disable either
@code{challenge-response-authentication?} or
@code{password-authentication?}.
@item @code{print-last-log?} (default: @code{#t})
Specifies whether @command{sshd} should print the date and time of the
last user login when a user logs in interactively.
@end table
@end deftp
 
......
......@@ -279,6 +279,8 @@ (define-record-type* <openssh-configuration>
(challenge-response-authentication? openssh-challenge-response-authentication?
(default #f)) ;Boolean
(use-pam? openssh-configuration-use-pam?
(default #t)) ;Boolean
(print-last-log? openssh-configuration-print-last-log?
(default #t))) ;Boolean
(define %openssh-accounts
......@@ -298,6 +300,14 @@ (define (openssh-activation config)
(mkdir-p "/etc/ssh")
(mkdir-p (dirname #$(openssh-configuration-pid-file config)))
(define (touch file-name)
(call-with-output-file file-name (const #t)))
(let ((lastlog "/var/log/lastlog"))
(when #$(openssh-configuration-print-last-log? config)
(unless (file-exists? lastlog)
(touch lastlog))))
;; Generate missing host keys.
(system* (string-append #$(openssh-configuration-openssh config)
"/bin/ssh-keygen") "-A")))
......@@ -336,6 +346,9 @@ (define (openssh-config-file config)
(format port "UsePAM ~a\n"
#$(if (openssh-configuration-use-pam? config)
"yes" "no"))
(format port "PrintLastLog ~a\n"
#$(if (openssh-configuration-print-last-log? config)
"yes" "no"))
#t))))
(define (openssh-shepherd-service config)
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment