PubkeyAuthentication yes UsePAM yes Match Group {{ allowed_groups | join(',') }} AuthorizedKeysCommand /usr/sbin/kanidm_ssh_authorizedkeys %u AuthorizedKeysCommandUser nobody