Skip to content

SSH Access (Login Node)

This is the one host users log into interactively, so instead of denying SSH outright, pubkey auth is disabled for slurmUsers (with one named exception) — copied from SSH Access Control, kept in sync there.

Why

Pubkey authentication bypasses LDAP shadowExpire enforcement (see Enforce Expiration Dates) — a user with an expired LDAP account can still log in via key even though password auth would reject them. Blocking pubkey for slurmUsers closes that bypass, with slurm_majedalshaibani excepted.

Rule of Thumb

sshd uses first match wins per directive across Match blocks, not last. Put specific user exceptions before broad group/default rules.

Correct Configuration

Match User slurm_majedalshaibani
    PubkeyAuthentication yes

Match Group slurmUsers
    PubkeyAuthentication no

Verify

sudo sshd -t
sudo sshd -T -C user=slurm_majedalshaibani,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
sudo sshd -T -C user=<other_slurm_user>,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth

slurm_majedalshaibani → yes, other slurmUsers members → no.

Reload after confirming:

sudo systemctl reload sshd