Deny password-based SSH login for all users through a Python script

Viewed 151

I am writing a Python script to deny password-based SSH login for a remote server (Ubuntu 18.04). I will be running the Python script inside my host system (Windows). Therefore I have already established an SSH connection with the remote host using the paramiko module and initialising the SSH client.

In order to deny password-based SSH login, I should edit the /etc/ssh/sshd_config file and change the line 'PasswordAuthentication yes' to 'PasswordAuthentication no' Note that my remote system allows passwordless sudo. I need to just do this one replace in the sshd_config file.

Given below is the command that I tried:

ssh_client.exec_command("sed -i 's/PasswordAuthentication yes/PasswordAuthentication no/g' /etc/ssh/sshd_config")

I'm hitting the error: couldn't open temporary file .sedVg2nV6: Permission Denied

Has anyone encountered this before? Is there another way to replace a part of config file other than sed? Is sed only for .txt files?

1 Answers

I think you should change
ssh_client.exec_command("sed -i 's/PasswordAuthentication yes/PasswordAuthentication no/g' /etc/ssh/sshd_config")
to
ssh_client.exec_command("sudo sed -i 's/PasswordAuthentication yes/PasswordAuthentication no/g' /etc/ssh/sshd_config") (the sed command will be executed with root permissions).

Related