+# and defaults to "prohibit-password" since openssh-server v1:7.1p1-1
+if grep -q '^PermitRootLogin ' "${target}/etc/ssh/sshd_config" ; then
+ # make sure we don't modify our own disabled snippet once again
+ if ! grep -q 'PermitRootLogin .*disabled via grml-live' "${target}/etc/ssh/sshd_config" ; then
+ sed -i "s/^\(PermitRootLogin .*\)/# \1 # disabled via grml-live\nPermitRootLogin yes/" "${target}/etc/ssh/sshd_config"
+ fi
+else
+ echo "# Added via grml-live script:" >> "${target}/etc/ssh/sshd_config"
+ echo "PermitRootLogin yes" >> "${target}/etc/ssh/sshd_config"
+fi