This is a Debian package that includes OpenSSH into initramfs for the purpose of remote unlocking of an encrypted system.
A lot of tutorials on the topic 'remote unlocking of encrypted systems' describe how to set up a Dropbear SSH server instead of the more widely used OpenSSH server. In comparison with OpenSSH, Dropbear lacks in features and is not generally compatible with OpenSSH. This openssh-initramfs Debian package tries to solve this issue, by providing a simple way to install and configure OpenSSH in initramfs.
Table of Contents:
There are no dependencies required to build this Debian package. You simply have to clone/download this repository and run the build command on a Debian based distribution:
# clone the repository
git clone https://github.com/Aisbergg/debian-package-openssh-initramfs.git
# build
cd openssh-initramfs
dpkg-deb --build openssh-initramfs/ "openssh-initramfs_$(sed -nE 's/^Version: (.*)/\1/p' openssh-initramfs/DEBIAN/control)_all.deb"Alternatively you can build the package using Docker, which doesn't require you to run a Debian system:
docker run -t --rm -v "$(pwd):/shared" -u $(id -u) debian:10 bash -c "cd /shared && dpkg-deb --build openssh-initramfs/ \"openssh-initramfs_$(sed -nE 's/^Version: (.*)/\1/p' openssh-initramfs/DEBIAN/control)_all.deb\""You can download a pre-built package from the releases page or build your own. Install the package using dpkg:
dpkg -i openssh-initramfs_*_all.deb| File | Required | Description |
|---|---|---|
/etc/initramfs-tools/initramfs.conf |
yes | General configuration for mkinitramfs(8). See initramfs.conf(5). |
/etc/openssh-initramfs/config |
no | Configuration for openssh-initramfs module. |
/etc/openssh-initramfs/authorized_keys |
no | Extra authorized_keys file to be copied into the initramfs. |
/etc/openssh-initramfs/sshd_config |
no | The SSH daemon configuration. If this file doesn't exist, the systems configuration will be used (/etc/ssh/sshd_config). |
/etc/openssh-initramfs/ssh_host*key* |
yes | SSH host keys used by the SSH daemon. |
Whenever a file has changed, the initramfs needs to be rebuilt. Use the following command to update your initramfs:
update-initramfs -uThis is the general configuration for mkinitramfs. The only relevant options here are DEVICE and IP. These are used to enable and configure a network interface, so that you are able to remotely login via SSH. Read more about the options in initramfs.conf(5) and initramfs.conf(7). Example configuration:
DEVICE=enp4s0
IP=:::::enp4s0:dhcpThe main configuration of the openssh-initramfs module resides in /etc/openssh-initramfs/config. It contains mainly three important options:
SSH_PORT: The SSH port the daemon inside the initramfs should listen on. This option overwrites the configuration set in thesshd_config. The port should differ from the regular SSH port, so theknown_hostswon't clash.SSH_OPTIONS: Extra options to pass to the SSH daemon. This can be used to overwrite any option of thesshd_config.SSH_AUTHORIZED_KEYS_FROM: In addition to define authorized keys in/etc/openssh-initramfs/authorized_keys, the module also allows to copy the authorized keys from users. To do so, simply add the users names toSSH_AUTHORIZED_KEYS_FROMspace separated list. Note, that only therootuser is available in initramfs, so any listed user has to use therootaccount instead of their regular account to log into the initramfs busybox.
You can add authorized SSH keys to the /etc/openssh-initramfs/authorized_keys file. Any of those keys will then be accepted when logging into the initramfs SSH server.
The SSH host keys are necessary for cryptographic operations and identification of the server. You should not simply copy your systems SSH host keys into the initramfs, because anything inside the initramfs will not be encrypted and might get stolen by an adversary. Therefore, it is safer to create new host keys and use those only inside the initramfs:
ssh-keygen -t ed25519 -f /etc/openssh-initramfs/ssh_host_ed25519_key -q -N ""
ssh-keygen -t ecdsa -f /etc/openssh-initramfs/ssh_host_ecdsa_key -q -N ""
ssh-keygen -t rsa -b 4096 -f /etc/openssh-initramfs/ssh_host_rsa_key -q -N ""- PAM integration does not work yet and is therefore disabled.
GPL v2 in order to facilitate potential inclusion inside Debian as official package.