Skip to content
49 changes: 49 additions & 0 deletions release/models/system/openconfig-aaa.yang
Original file line number Diff line number Diff line change
Expand Up @@ -420,6 +420,23 @@ module openconfig-aaa {
description
"Operational state data for local users";
}

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

nit: check your whitespace + spaces vs. tabs - github UI doesn't help for this

grouping authorized-ssh-key-config {
description
"Configuration data for user SSH keys";

leaf key-name {
Comment thread
syaghi-c marked this conversation as resolved.
Outdated
type string;
description
"The name with which to reference the authorized SSH public key";
}

leaf authorized-ssh-key {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nomenclature-wise, would suggest key/public-key vs. "authorized-ssh-key" throughout - This also replicated the list name as a child

type string;

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

description
"Authorized SSH public key for the user (RSA or ECDSA)";
Comment thread
syaghi-c marked this conversation as resolved.
Outdated
}
}

grouping aaa-authentication-user-top {
description
Expand Down Expand Up @@ -458,6 +475,38 @@ module openconfig-aaa {
uses aaa-authentication-user-config;
uses aaa-authentication-user-state;
}

container authorized-ssh-keys {

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggest putting this into a grouping rather and outside of this grouping

description
"Top-level container for authorized SSH keys";

list authorized-ssh-key {
key "key-name";
description
"Authorized SSH public keys for the user (RSA or ECDSA)";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Remove the key type refs


leaf key-name {
type leafref {
path "../config/key-name";

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggested change
path "../config/key-name";
path "../config/name";

}
description
"References the key name in the configuration block";
}

container config {
description
"Configuration data for the authorized SSH key";
uses authorized-ssh-key-config;
}

container state {
config false;
description
"Operational state data for the authorized SSH key";
uses authorized-ssh-key-config;
}
}
}
}

}
Expand Down