4 ms·
Exactly. Actually, I haven't yet seen a scenario where ssh agent forwarding is useful. It always increases the risks: the machine you're forwarding to may be co
by jsn 16y ago
Exactly. Actually, I haven't yet seen a scenario where ssh agent forwarding is useful. It always increases the risks: the machine you're forwarding to may be compromised, and in case it is, your private key is not private anymore. And the attacker who gets your key gets instant access to all other machines you access with that key. How is it worth it? Why would anyone bet the [server] farm on that when you can easily use "ssh -L" or something to forward your ssh connections without exposing your key? Beats me.
- qjz 16y agoThe documentation suggests that the private key is not at risk, just the agent session. I typically work from a variety of laptops that contain no sensitive data. I log into a remote workstation in a secure environment that houses my main repositories, where I'll check out a project, develop it, and publish the code to a remote server. Since most of my transfers use rsync over ssh, or mercurial via ssh, agent forwarding comes in really handy. It's convenient, fast, and my private keys are protected adequately with passphrases, so I don't need to worry if my laptop gets stolen, since it doesn't have anything valuable on it.
- Groxx 16y agoWhy would your private keys be lost? They're not transferred at any time. That's kind of the point of private keys in an asymmetrical encryption scheme. All the agent forwarding exposes you to is someone in the middle routing requests they generate to authenticate against your computer, which is automatically responded to by your using an agent. If you don't use an agent, it'll ask for your password to use your private key. edit: using a second agent on the middle computer without agent forwarding exposes your private key, because the agent on that computer needs to be able to respond to its outbound connections. Agent forwarding prevents this from being necessary. It's specifically built to prevent what you described as the danger.
- jsn 16y agoDuh. Where exactly did you get the idea that your private key would be lost? It's no longer private because the attacker can use your forwarded connection "to authenticate using the identities loaded into the agent". It's right there in ssh man page. Neither did I ever suggest using the second agent on the middle computer -- sure, it's obviously stupid. > It's specifically built to prevent what you described as the danger. You're wrong. See "man ssh", it's documented right there in "-A" option description.
- Groxx 16y agoBecause you mentioned: >your private key is not private anymore and: >the attacker who gets your key gets instant access to all other machines you access with that key. Which is wrong. They don't get your key. They get the ability to authenticate as you while you are connected, and nothing else.