3 ms·
autossh + tmux still. How are people getting around the lack of SSH agent forwarding?
by drewr 10y ago
autossh + tmux still. How are people getting around the lack of SSH agent forwarding?
- geofft 10y agoI think "Not wanting to use SSH agent forwarding" is the answer. I don't want every single machine I use to be able to authenticate as me to anyone else. If I actually want to be able to connect to a third machine, I'll have an SSH key on the second machine. For instance, my phone has an SSH key to SSH/mosh to my VPS, and my VPS has a different SSH key that can authenticate to GitHub. If I suspect my VPS got compromised, I can kill its key on GitHub without having to worry about whether my single, master, local key got compromised. Given that ssh-keygen is so easy and basically every server I want to talk to supports multiple authorized_keys, I haven't seen much use for agent forwarding. Also, mosh was developed at MIT, where there's a good Kerberos setup for most SSH-able machines. So if you really want forwarding, you can forward your Kerberos ticket with the initial SSH connection. The mosh-server command on Athena is actually a wrapper script that copies your Kerberos ticket (so it's not destroyed when the SSH session exits) and sets up a Kerberos + AFS session for the actual mosh-server to run inside: http://web.mit.edu/mosh_project/arch/amd64_deb60/bin/mosh-server http://web.mit.edu/mosh_project/arch/amd64_deb60/bin/mosh-se... There's little use for key-based authentication on Athena, let alone agent forwarding, because if you don't forward Kerberos tickets, you don't have access to your network home directory.
- TimWolla 10y ago> I don't want every single machine I use to be able to authenticate as me to anyone else. There is the `-c` option to `ssh-add` for that reason: -c Indicates that added identities should be subject to confirmation before being used for authentication. Confirmation is performed by ssh-askpass(1). Successful confirmation is signaled by a zero exit status from ssh-askpass(1), rather than text entered into the requester.
- cyphar 10y agoSecurity by policy is worse than security by design. Mosh doesn't have code that implements agent forwarding, so there's no bugs in the policy code I have to be worried about.