2026-10-01 08:57:29 why alpinelinux's sudo and doas are configured --wihout-pam 2026-10-01 09:06:00 qaqland 2026-10-01 09:06:52 dongdigua: idk :) 2026-10-01 10:26:43 Hi 2026-10-01 10:26:58 I upgraded a few days ago my Alpine VM, and now at boot it says: 2026-10-01 10:27:10 * eth0 ...udhcpc: started, v1.38.0 2026-10-01 10:27:10 [ !! ] 2026-10-01 10:27:10 ifup: failed to change interface eth0 state to 'up' 2026-10-01 10:27:10 udhcpc: socket(AF_PACKET,2,8): Address family not supported by protocol 2026-10-01 10:27:20 Any idea what could be happening? 2026-10-01 10:27:56 Interface is there 2026-10-01 10:27:56 2: eth0: mtu 1500 qdisc pfifo_fast state UP mode DEFAULT group default qlen 1000 2026-10-01 10:28:13 link/ether xx:xx:xx:xx:xx:xx brd ff:ff:ff:ff:ff:ff 2026-10-01 10:30:03 Sorry nevermind, just saw that extlinux.conf is borked for some reason, it's booting an older kernel that obviously is missing the drivers 2026-10-01 10:30:10 Not sure how that happened, I never edit that file 2026-10-01 10:42:07 Hey, I'm setting up a new non-root user on Alpine but I'm struggling with getting sshd to read ~/.ssh/authorized_keys and thus it keeps denying my keys. I'm confused as I didn't do anything different than in Debian and Arch containers just minutes prior. 2026-10-01 10:42:44 what does sshd say in its logs? 2026-10-01 10:42:46 lol idk 2026-10-01 10:43:16 Where does sshd keep logs on Alpine? 2026-10-01 10:43:27 There's no /var/log/sshd.log 2026-10-01 10:45:24 in syslog; from there - wherever syslogd is configured to put 'auth' and 'authpriv' logs 2026-10-01 10:45:25 rip api 2026-10-01 10:47:09 I *think* /var/log/messages is the default location for everything 2026-10-01 10:47:42 you'll want "LogLevel VERBOSE" or maybe even "LogLevel DEBUG2" in your sshd_config 2026-10-01 10:47:47 Ah, /var/log/messages, "auth.info sshd-session[3451]: User usernamehere not allowed because account is locked", that system user has a login shell and they're forced to SSH ForceCommand right after login 2026-10-01 10:48:21 yeah those things do not override the account being locked 2026-10-01 10:48:46 usermod -U 2026-10-01 10:49:47 Someone online says sshd_config should have "UsePAM yes", Debian defaults that to yes while Alpine defaults to no 2026-10-01 10:50:45 usermod as an executable isn't present on my Alpine system 2026-10-01 10:50:49 it'll follow more or less the same logic either way 2026-10-01 10:51:12 with PAM enabled, it's pam_unix that'll check whether the account is locked, without PAM it's sshd itself doing that check 2026-10-01 10:51:33 (or at least I'd hope they do the same check, would be "fun" if they diverged) 2026-10-01 10:51:59 how are you creating the new non-root user? 2026-10-01 10:52:02 :) right, so how can I unlock that account for SSH key logins 2026-10-01 10:53:03 adduser -S -s /bin/sh name 2026-10-01 10:53:33 flags are system user and login shell 2026-10-01 10:53:48 besides enabling pam in sshd_config, also need to install opessh-server-pam 2026-10-01 10:54:20 Podman config structure changed recently right? 2026-10-01 10:54:21 rip api 2026-10-01 10:55:48 looks like busybox's passwd has -u/--unlock 2026-10-01 10:56:06 does it have to be a 'system user' though? 2026-10-01 10:56:10 After enabling UsePAM, 'apk add openssh-server-pam', and 'rc-service sshd restart' later SSH key login works now 2026-10-01 10:56:23 because if it accepts remote logins, it's not really a system user 2026-10-01 10:57:02 It isn't meant for a human but a remote system's daemon 2026-10-01 11:10:49 Yeah everything works fine now, cheers, TIL that Alpine has an additional PAM package for openssh-server while Debian and Arch seem to include it by default 2026-10-01 15:11:44 help