#1103773 openssh-server: systemd unit to After=network-online.target

Package:
openssh-server
Source:
openssh-server
Description:
secure shell (SSH) server, for secure access from remote machines
Submitter:
Martin-Éric Racine
Date:
2025-12-02 10:43:05 UTC
Severity:
normal
#1103773#5
Date:
2025-04-21 12:38:39 UTC
From:
To:
The systemd unit current launches:

After=network.target remote-fs.target nss-lookup.target

This doesn't guarantee that we have acquired an IP address (see: https://www.freedesktop.org/wiki/Software/systemd/NetworkTarget/).

Because of this, binding to an address using e.g. 'ListenAddress 192.168.1.12' will make sshd fail to launch if the interface hasn't acquired an IP yet.

network-online.target should probably be added to the above to positively ensure that we've acquired an IP before sshd launches.

Best Regards,
Martin-Éric

#1103773#10
Date:
2025-04-21 12:49:14 UTC
From:
To:
* Martin-Éric Racine <martin-eric.racine@iki.fi> [250421 14:42]:

network-online.target makes no guarantees on addresses, or even the
specific address configured in sshd.conf.

If it helps in your local setup, I'd encourage you to use a local
override file.

Chris

#1103773#15
Date:
2025-04-21 17:09:33 UTC
From:
To:
Control: severity -1 wishlist

Yeah, I think the requested change would be counterproductive for other
users: a lot of people want sshd enabled as soon as possible, and most
people don't explicitly set ListenAddress.

I'd be happy to add additional advice about this to README.Debian if
somebody else writes it.  But ideally it'd be more fine-grained than
just whacking in a dependency on network-online.target; perhaps we can
advise people how to configure their system so that ssh.service waits
for a particular interface to come up.

Thanks,

#1103773#22
Date:
2025-04-21 17:16:46 UTC
From:
To:
* Colin Watson <cjwatson@debian.org> [250421 19:09]:

+1

Another way might be to set IP_FREEBIND, possibly with an sshd
config option.

Personally I just enable the ip_nonlocal_bind sysctl on machines
where I intend to bind services (not just sshd) to specific IP
addresses.

Chris

#1103773#27
Date:
2025-04-21 17:22:58 UTC
From:
To:
FWIW upstream WONTFIXed a request for that (at least until it has more
widespread OS support), and suggested the affected people just locally
add a dependency on network-online.target:
https://bugzilla.mindrot.org/show_bug.cgi?id=2512

#1103773#32
Date:
2025-04-21 18:15:55 UTC
From:
To:
Hallo Martin-Éric Racine,

21.04.25 14:38 Martin-Éric Racine:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=965132

If your problem is not something else needing to bind the same port,
firewalling might be another solution.


Grüße
Timo