3 ms·
If you're going to use weird ssh-hiding tricks like alternate ports, gateways, or port-knocking, be sure to read all about what you can do with ~/.ssh/config
by LordLandon 16y ago
If you're going to use weird ssh-hiding tricks like alternate ports, gateways, or port-knocking, be sure to read all about what you can do with ~/.ssh/config
Host securebox
#if not proxying
HostName securebox.tld
Port 1023
User fji00random
#if going through a gateway
ProxyCommand ssh gatewaybox.tld nc securebox.tld 22
#if knocking
ProxyCommand proxyknock %h %p 1337 1337 900
With that, you can have
ssh securebox
rather than
knock securebox.tld 1337 1337 900; ssh -p 1023 fji00random@securebox.tld
(and for systems without a knocker installed, you can use something like http://sprunge.us/HJHB http://sprunge.us/HJHB for proxyknock, which can be cloned along with the rest of your dotfiles/scripts)
And if you're doing public key auth, read about ssh-agent, it can store your private keys in memory so that you don't have to retype your passphrase all the time, while the "physical" key is still protected if stolen.
In my bash_profile, I have
SSHAFILE=/tmp/.$(whoami)-ssha
if [ -n "$SSH_AUTH_SOCK" ]; then
echo "We has auth!"
elif [ -f $SSHAFILE ]; then
. $SSHAFILE
else
eval `ssh-agent | tee $SSHAFILE`
chmod 600 $SSHAFILE
ssh-add
fi
This runs ssh-agent if it's not running, and sets proper env variables if it is.
(also, the ssh-agent can be forwarded, so you can use your private key to auth into box C, from box B, while the key is only on your local box, A - this can also be added to your .ssh/config)
- iuguy 16y agoThis is also good advice. I didn't want to put it in as I just wanted it to be an explanation of my own position on port munging and to keep it fairly simple, but ssh-agent is a great way of making multiple ssh accesses easier.