- Package:
- openssh-server
- Source:
- openssh-server
- Description:
- secure shell (SSH) server, for secure access from remote machines
- Submitter:
- Martin-Éric Racine
- Date:
- 2025-12-02 10:43:05 UTC
- Severity:
- normal
The systemd unit current launches: After=network.target remote-fs.target nss-lookup.target This doesn't guarantee that we have acquired an IP address (see: https://www.freedesktop.org/wiki/Software/systemd/NetworkTarget/). Because of this, binding to an address using e.g. 'ListenAddress 192.168.1.12' will make sshd fail to launch if the interface hasn't acquired an IP yet. network-online.target should probably be added to the above to positively ensure that we've acquired an IP before sshd launches. Best Regards, Martin-Éric
* Martin-Éric Racine <martin-eric.racine@iki.fi> [250421 14:42]: network-online.target makes no guarantees on addresses, or even the specific address configured in sshd.conf. If it helps in your local setup, I'd encourage you to use a local override file. Chris
Control: severity -1 wishlist Yeah, I think the requested change would be counterproductive for other users: a lot of people want sshd enabled as soon as possible, and most people don't explicitly set ListenAddress. I'd be happy to add additional advice about this to README.Debian if somebody else writes it. But ideally it'd be more fine-grained than just whacking in a dependency on network-online.target; perhaps we can advise people how to configure their system so that ssh.service waits for a particular interface to come up. Thanks,
* Colin Watson <cjwatson@debian.org> [250421 19:09]: +1 Another way might be to set IP_FREEBIND, possibly with an sshd config option. Personally I just enable the ip_nonlocal_bind sysctl on machines where I intend to bind services (not just sshd) to specific IP addresses. Chris
FWIW upstream WONTFIXed a request for that (at least until it has more widespread OS support), and suggested the affected people just locally add a dependency on network-online.target: https://bugzilla.mindrot.org/show_bug.cgi?id=2512
Hallo Martin-Éric Racine, 21.04.25 14:38 Martin-Éric Racine: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965132 If your problem is not something else needing to bind the same port, firewalling might be another solution. Grüße Timo