Diff
1diff --git a/server/ssh/ssh.go b/server/ssh/ssh.go
2index a962721d67d19636d31477aa7fb009097c001b45..6e727fbd2431fa2d81631f44f025266e4808215f 100644
3--- a/server/ssh/ssh.go
4+++ b/server/ssh/ssh.go
5@@ -163,7 +163,7 @@ func (s *SSHServer) Shutdown(ctx context.Context) error {
6 // PublicKeyAuthHandler handles public key authentication.
7 func (s *SSHServer) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) (allowed bool) {
8 if pk == nil {
9- return s.cfg.Backend.AllowKeyless()
10+ return false
11 }
12
13 ak := backend.MarshalAuthorizedKey(pk)
14@@ -173,11 +173,12 @@ func (s *SSHServer) PublicKeyHandler(ctx ssh.Context, pk ssh.PublicKey) (allowed
15
16 ac := s.cfg.Backend.AccessLevelByPublicKey("", pk)
17 s.logger.Debugf("access level for %q: %s", ak, ac)
18- allowed = ac >= backend.ReadOnlyAccess
19+ allowed = ac >= backend.ReadWriteAccess
20 return
21 }
22
23 // KeyboardInteractiveHandler handles keyboard interactive authentication.
24+// This is used after all public key authentication has failed.
25 func (s *SSHServer) KeyboardInteractiveHandler(ctx ssh.Context, _ gossh.KeyboardInteractiveChallenge) bool {
26 ac := s.cfg.Backend.AllowKeyless()
27 keyboardInteractiveCounter.WithLabelValues(ctx.User(), strconv.FormatBool(ac)).Inc()