SSH Access (Login Node)¶
This is the one host users log into interactively, so instead of denying SSH outright, pubkey auth is disabled for slurmUsers (with one named exception) — copied from SSH Access Control, kept in sync there.
Why¶
Pubkey authentication bypasses LDAP shadowExpire enforcement (see Enforce Expiration Dates) — a user with an expired LDAP account can still log in via key even though password auth would reject them. Blocking pubkey for slurmUsers closes that bypass, with slurm_majedalshaibani excepted.
Rule of Thumb¶
sshd uses first match wins per directive across Match blocks, not last. Put specific user exceptions before broad group/default rules.
Correct Configuration¶
Match User slurm_majedalshaibani
PubkeyAuthentication yes
Match Group slurmUsers
PubkeyAuthentication no
Verify¶
sudo sshd -t
sudo sshd -T -C user=slurm_majedalshaibani,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
sudo sshd -T -C user=<other_slurm_user>,host=localhost,addr=127.0.0.1 | grep -i pubkeyauth
slurm_majedalshaibani → yes, other slurmUsers members → no.
Reload after confirming: