-#!/bin/sh
+#! /bin/sh
### BEGIN INIT INFO
# Provides: sshd
# Required-Start: $remote_fs $syslog
# Required-Stop: $remote_fs $syslog
# Default-Start: 2 3 4 5
-# Default-Stop: 1
+# Default-Stop:
# Short-Description: OpenBSD Secure Shell server
### END INIT INFO
test -x /usr/sbin/sshd || exit 0
( /usr/sbin/sshd -\? 2>&1 | grep -q OpenSSH ) 2>/dev/null || exit 0
-export SSHD_OOM_ADJUST=-17
+umask 022
+
if test -f /etc/default/ssh; then
. /etc/default/ssh
fi
-# Are we in a virtual environment that doesn't support modifying
-# /proc/self/oom_adj?
-if grep -q 'envID:.*[1-9]' /proc/self/status; then
- unset SSHD_OOM_ADJUST
-fi
-
. /lib/lsb/init-functions
if [ -n "$2" ]; then
RSA1_KEY=/etc/ssh/ssh_host_key
RSA_KEY=/etc/ssh/ssh_host_rsa_key
DSA_KEY=/etc/ssh/ssh_host_dsa_key
+ECDSA_KEY=/etc/ssh/ssh_host_ecdsa_key
# Are we running from init?
run_by_init() {
check_config() {
if [ ! -e /etc/ssh/sshd_not_to_be_run ]; then
- /usr/sbin/sshd -t || exit 1
+ /usr/sbin/sshd $SSHD_OPTS -t || exit 1
+ fi
+}
+
+
+generate_ssh_keys() {
+ if ! test -f $RSA1_KEY ; then
+ log_action_msg "Generating SSH1 RSA host key..."
+ $KEYGEN -t rsa1 -f $RSA1_KEY -C '' -N '' || exit 1
+ fi
+
+ if ! test -f $RSA_KEY ; then
+ log_action_msg "Generating SSH2 RSA host key..."
+ $KEYGEN -t rsa -f $RSA_KEY -C '' -N '' || exit 1
+ fi
+
+ if ! test -f $DSA_KEY ; then
+ log_action_msg "Generating SSH2 DSA host key..."
+ $KEYGEN -t dsa -f $DSA_KEY -C '' -N '' || exit 1
+ fi
+
+ if ! test -f "$ECDSA_KEY" && grep -q "$ECDSA_KEY" /etc/ssh/sshd_config ; then
+ log_action_msg "Generating SSH2 ECDSA host key..."
+ $KEYGEN -t ecdsa -f "$ECDSA_KEY" -C '' -N '' || exit 1
fi
}
check_privsep_dir
check_for_no_start
check_dev_null
-
- if ! test -f $RSA1_KEY ; then
- log_action_msg "Generating SSH1 RSA host key..."
- $KEYGEN -t rsa1 -f $RSA1_KEY -C '' -N '' || exit 1
- fi
-
- if ! test -f $RSA_KEY ; then
- log_action_msg "Generating SSH RSA host key..."
- $KEYGEN -t rsa -f $RSA_KEY -C '' -N '' || exit 1
- fi
-
- if ! test -f $DSA_KEY ; then
- log_action_msg "Generating SSH2 DSA host key..."
- $KEYGEN -t dsa -f $DSA_KEY -C '' -N '' || exit 1
- fi
-
+ generate_ssh_keys
log_daemon_msg "Starting OpenBSD Secure Shell server" "sshd"
if start-stop-daemon --start --quiet --oknodo --pidfile /var/run/sshd.pid --exec /usr/sbin/sshd -- $SSHD_OPTS; then
log_end_msg 0
reload|force-reload)
check_for_no_start
check_config
+ generate_ssh_keys
log_daemon_msg "Reloading OpenBSD Secure Shell server's configuration" "sshd"
if start-stop-daemon --stop --signal 1 --quiet --oknodo --pidfile /var/run/sshd.pid --exec /usr/sbin/sshd; then
log_end_msg 0
restart)
check_privsep_dir
check_config
+ generate_ssh_keys
log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd"
start-stop-daemon --stop --quiet --oknodo --retry 30 --pidfile /var/run/sshd.pid
check_for_no_start log_end_msg
try-restart)
check_privsep_dir
check_config
+ generate_ssh_keys
log_daemon_msg "Restarting OpenBSD Secure Shell server" "sshd"
set +e
start-stop-daemon --stop --quiet --retry 30 --pidfile /var/run/sshd.pid