20 ms·
SSH hacks – a little sanity for remote workers
- xioxox 6y agoEveryone probably already knows this, but enabling compression (-C) makes running remote X programs more usable over slower connections.
- asdff 6y agoChanging the cipher supposedly helps, too. Probably placebo though.
- Piskvorrr 6y agoAnd while we're at it, if you need remote X, consider Xpra instead of ssh -X - it's way faster, can survive connection drops, and is far more flexible.
- MaxBarraclough 6y agoI've not heard of that, is it like VNC?
- Piskvorrr 6y agoThe best metaphor is "tmux for X programs": the X server runs on the same host as the X programs, xpra then "forwards" the windows over a configurable transport (e.g. via SSH) to the client. X was IIRC intended for local networks, so forwarding it over the Internet is sloooow (both by verbose protocol and naive latency handling) - this takes care of both issues. IIRC it's written in Python, so it runs in most places: https://xpra.org/ https://xpra.org/
- MaxBarraclough 6y agoNot a bad tip, but using gzip compression over the wire seems pretty stone-age. The proper solution is surely to use a modern lossy video-compression algorithm. Is that possible with X? It's not something I know a lot about. Is this where VNC steps in?
- lucb1e 6y agoI don't know much about it, but I'm fairly sure that compressing the Xorg data stream with lossy compression is going to mess it up completely and would require a complete overhaul of the protocol to make that work. VNC is indeed the more standard unix thing (insofar as remote GUIs can be considered standard on unix-likes) that applies lossy compression to the pictures being sent over.
- xioxox 6y agox2go and xpra allow some lossy compression algorithms.
- jlgaddis 6y ago> ... using gzip compression over the wire seems pretty stone-age. Really? Probably half of all web servers on the Internet (using HTTP/1.1) use it. > The proper solution is surely to use a modern lossy video-compression algorithm. The X11 protocol doesn't send bitmaps so I'm not certain that a "lossy video-compression algorithm" is gonna have the effect you think it will.
- tomc1985 6y agoI miss having a job that required SSH'ing into a server to get work done. Nowadays everything is abstracted, push your code to the magic cloud and pull in 1000x other stupid little APIs. It's so boring...
- rubatuga 6y agoYou need to press Enter before using the SSH ~ escape key.
- downerending 6y agoYup. I have no idea why they call it an escape character. It's an escape sequence, always of length two.
- tashian 6y agoAnd on an international keyboard it’s ~~, because ~ defaults to being a character modifier. If you nest SSH sessions, then you add more ~s. So in your fifth nested SSH session on an international keyboard the escape sequence would be \n~~~~~~~~~~.
- downerending 6y agoHmm. Is that right? I thought you could type ~~ to send a ~ through to the destination. So, ignoring the international aspect, I was thinking you'd type ~ to escape your first target, ~~ for the second, ~~~~ for the third, and ~~~~~~~~ for the fourth. (Too lazy to test it.) Perhaps better is to set a different escape char for layers you care about.
- rubatuga 6y agoI think the parent is still right, just a problem with international keyboards.
- jonah-archive 6y agoDoes anyone know of a modification that will e.g. dump hostname on a ~? -- so many times I'm in a few layers deep and likely to miscount.
- downerending 6y agoSounds like maybe ~C could do it? Too lazy to try it out.
- segfaultbuserr 6y ago> What are your favorite SSH tips & tricks? $ ssh -J user1@host1 user_final@host_final or $ ssh -J user1@host1,user2@host2 user_final@host_final Not many people know it, you don't need to launch a SSH within a SSH session - SSH has built-in support of using one SSH server as a proxy to another SSH server. Useful for <del>hacking servers</del> accessing servers behind a firewall, or using your own server as a proxy to bypass a bottleneck in the network.
- nprescott 6y agoThis is a good one. I've used this in the past in order to get onto IPv6-only networks as well. In my case I don't have IPv6 enabled on my home internet (thanks Verizon!) and I had a tiny virtual machine with Vultr, which at their lowest price point aren't offering IPv4 address space any more. Using a jump through another machine with both 4 and 6 address space saved me from having to cough up more money solely for a IPv4 address.
- _wldu 6y agoUse teredo at home. apt install miredo (on most debian based systems) https://en.wikipedia.org/wiki/Teredo_tunneling https://en.wikipedia.org/wiki/Teredo_tunneling
- segfaultbuserr 6y agoYou can also use Tor as IPv6 proxy in a pure IPv4 network (or as IPv4 proxy in a pure IPv6 network), recent versions of Tor can work under pure IPv6, gaining privacy and connectivity simultaneously. The speed is not actually too bad for web browsing, although not ideal for SSH. But still comes handy sometimes, I'm used it before to clone packages from GitHub on IPv6-only servers.
- Polylactic_acid 6y agoHow does github not have an AAAA record in 2020?? The faster people move to gitlab the better. ipv6 servers are not at all rare. Useful for individual use since you can save $1/month by dropping a useless for personal use feature.
- kbenson 6y agoI was tired enough of losing connections to work systems I was working on when network topology changes, or my laptop was moved, or it went to sleep, or I moved to a new computer (e.g. I'm at home) that I wrote a simple script to jump all my ssh connections through a VM at work, but with the extra step that the connection from the jump VM happens in a tmux that's named based on the desired host, and with options to reconnect to an existing session if it exists. With the script named "go", Here's what that allows in practice: go foo.bar - Connects to host foo.bar go foo.bar - Second connection to host foo.bar that uses same session, so keystrokes show in both, even if they originate from separate locations, like home and work. go foo.bar 2 - Additional param is added to session name, so you get a new connection to foo.bar. go -list - Lists all connection sessions, and only connection sessions, because there's a special prefix to distinguish them from normal tmux sessions that might exist on the VM. go -restore - Spawn a new terminal for all open connections. Useful for getting all terminals back after the network drops, or you reboot, or you're on your home computer instead of work, etc. Currently this is implemented in a batch script on windows with some ugly hacks to make it work well with what PuTTY's command line options support (commands for the remote host need to be in a file you specify...), and it's pretty ugly, but I'll share if if anyone is interested. It would be much easier in bash with openssh (it's even possible OpenSSH supports enough features to do this in the ssh config).
- geocrasher 6y agoWhy not just use Mosh? It's stateless connections that are persistent even when internet connectivity isn't.
- sh-run 6y agoOr better yet, eternal terminal. That way you can keep your scrollback https://eternalterminal.dev/ https://eternalterminal.dev/
- kbenson 6y agoI do have my scrollback buffer. The tmux session is on the VM, and within that session is another ssh connection to the target system. If the target system and the VM are disconnected (very unlikely without either the target or VM restarting) then sure, I might lose my scrollback (since tmux is execed with the SSH command, when it exits the session will end), but in the much more common scenario that my side loses connectivity to the VM (or I change locations), the VM still has an active connection going on in a tmux session that I'm joining. ET looks great for a lot of things, but not necessarily this environment, which is a few hundred systems administered by multiple people, with extremely high stability and security requirements. Honestly, all the extra stuff ET and MOSH does is to give you that extra 1-2% of features to make it seamless, but at the expense of separate protocols and new software, so you don't have to expend new hardware (or in this case, virtualized hardware. Connectivity problems almost always come from the last mile, whether that's you moving to make the last mile somewhere else or your wifi or home connection having a problem. A VM at Digital Ocean, or in my case the highly redundant and available VMware cluster at work, is much less likely to have any sort of problems, as are the servers that are generally being connected to (and it those ARE having problems, you can't rely on sessions to them being kept anyway). For 99% of the cases, you can get by easily by just SSHing to a highly available VM, starting a tmux session for the desired connection, and within that session SSHing to the desired system. Jumping through other systems with SSH is so common that OpenSSH has features built in to support it, even transparently (where your config can just make it automatic for a class of systems). In fact, I bet there's a way to get the OpenSSH Proxying SSH server to keep the session open to reconnect to from the client if it's only the client side that had a problem, so it doesn't even require the little script I have. It's actually on my todo list to figure out the windows included OpenSSH agent stuff and see how well the new Windows Terminal works as an SSH terminal, but I haven't gotten around to it (or just use the WSL stuff, but I haven't seen much need for it yet, I'm happy to do most my dev work in vim on a dev server).
- outluch 6y agomosh + tmux for sessions of uptime length ssh-copy-id to never enter passwords again ~/.ssh/config add servers to never write hostnames etc again and repo on gitlab with bash script that installs all of this and sets up own config of zsh and tmux for me on any new ubuntu server machine. what else to dream about? curious
- montroser 6y agoOne that has come in handy a few times: When a machine is so starved for resources that it can't even allocate a pts for you, but you want to run some forensics, use `-T`: $ ssh -T user@host <command> Even if you're plumb out of file descriptors for example, you can run... $ ssh -T user@host lsof ...or whatever, and get your command output dumped to the screen, even if you don't get the niceties of a terminal.
- heavyset_go 6y agoPort tunneling, X forwarding, keys + agents, sshuttle and byobu all make SSH a good solution for getting stuff done.
- lucb1e 6y agoIt would be nice if you could include at least one sentence about these product names to give an idea of what they do. For other readers: sshuttle: > Transparent proxy server that works as a poor man's VPN. Forwards over ssh. Doesn't require admin. Works with Linux and MacOS. Supports DNS tunneling. > Forward all traffic: > sshuttle -r username@sshserver 0.0.0.0/0 byobu: > Byobu is an enhancement for the GNU Screen terminal multiplexer or tmux [...] that can be used to provide on-screen notification or status, and tabbed multi-window management. It is intended to improve terminal sessions when users connect to remote servers.
- chaps 6y agoIf you let ssh connection dies, these keys, in order, will kill the ssh process before the timeout kicks in: esc ~ .
- kazinator 6y agoMy favorite SSH trick is to have a machine at work SSH back to my home domain, and provide a tunnel back for Remote Desktop or what have you. Wee, no VPN to deal with. No lack of a VPN for remote access to deal with. https://cygwin.com/pipermail/cygwin/2020-April/244384.html https://cygwin.com/pipermail/cygwin/2020-April/244384.html
- dallbee 6y agoDo be careful doing this, if your company cares, a competent network admin can tell what's going on.
- shawnz 6y agoYou can defeat deep packet inspection by tunneling it over an HTTPS proxy, using the SSH ProxyCommand option and the proxytunnel utility
- varenc 6y agoA corporate IT admin would probably detect this by pulling information directly from the company managed machines. i.e. osquery https://www.metalliccode.com/detecting-ssh-tunnels https://www.metalliccode.com/detecting-ssh-tunnels
- yownie 6y agoor just sshuttle
- shawnz 6y agoSshuttle solves a different problem. It uses SSH as a transport so it could not bypass a firewall that blocks outgoing SSH.
- LilBytes 6y agoWe had a sys. admin who did exactly this to access his home computer to play World of Tanks. :) He still works there in a Government Agency riddled with staff who are perfectly adapt at doing enough to stay hired and doing little enough to describe their job as a paid hobby.
- gumby 6y agoJust run a remote command, via ssh foo the_command I commonly do ssh remote ‘(cd foo; git pull; make && run)’ Of course with tramp I don’t have to do this as much as I used to.
- madars 6y ago> When debugging a complex issue on your servers, you might like to share an SSH session with someone who is not in the same room. tmux is perfect for this for terminal sharing! Here are the steps: > [..] > Both of you will need to SSH to the machine using the same account. If you want, it is very easy to do view-only tmux sessions with no third-party tools required. That is, you start your tmux specifying a socket (tmux -S ...), and then have a dedicated ssh user which references it (tmux -S ... attach -r, where -r is for read-only) as sshd's ForceCommand (a 10-liner https://gist.github.com/madars/e6b957ea508be1dcd9044fd2c70969ac https://gist.github.com/madars/e6b957ea508be1dcd9044fd2c7096...)
- mnw21cam 6y agoOr you can execute a shell inside ytalk.
- Camillo 6y agoIf you have a Mac, the correct way to use SSH is: 1. Install iTerm. 2. ssh -t remote.workstation 'tmux -CC new-session -A -D -s main'
- rootusrootus 6y agoI recommend iTerm2, not iTerm.
- gbrayut 6y agoOne of my most used commands is Ctrl+d for closing the input stream and causing a remote or local shell session to exit https://unix.stackexchange.com/q/110240/8692 https://unix.stackexchange.com/q/110240/8692
- flyinprogrammer 6y agohttps://gravitational.com/teleport/docs/ https://gravitational.com/teleport/docs/ Is another great tool for getting off SSH. Similarly if you're in AWS and not using Session Manager, you're missing out on a huge value add: https://docs.aws.amazon.com/systems-manager/latest/userguide/session-manager.html https://docs.aws.amazon.com/systems-manager/latest/userguide...
- mmalone 6y agoDisclosure: not OP, but work at smallstep Smallstep has a product[1] that's a lot like gravitational teleport. That's how we got deep enough into SSH to write this post. Teleport isn't bad. The two biggest differentiators are probably: - Smallstep SSH is hosted (with HSM-backed private keys) - Smallstep SSH does user & group syncing from your identity provider (i.e., you don't need to adduser / deluser folks anymore) so you don't need to do any user or key management on servers at all We're also doing everything using standard OpenSSH, whereas teleport replaces your SSH client & server (or at least it used to, skimming their docs it looks like that might be changing). Authentication is via OAuth OIDC (single sign-on), user & group sync is via SCIM, plus PAM & NSS on the host side. So it's all pretty standard stuff. Finally, Smallstep SSH is built on our open source toolchain, step[2] and step-ca[3]. Actually, if you want something completely free that does all of this you can just use those tools and do something like gravitational yourself. We have a blog post[4] explaining how. This product is only a couple weeks old, so feedback is very welcome! [1] https://smallstep.com/sso-ssh/ https://smallstep.com/sso-ssh/ [2] https://github.com/smallstep/cli https://github.com/smallstep/cli [3] https://github.com/smallstep/certificates https://github.com/smallstep/certificates [4] https://smallstep.com/blog/diy-single-sign-on-for-ssh/ https://smallstep.com/blog/diy-single-sign-on-for-ssh/
- jefftk 6y agoThis skips my favorite reason to use mosh: it has predictive local echo and so makes high latency connections much more useable
- rcpt 6y agoMosh would be so great if it worked with the mouse.
- lucb1e 6y agoIsn't that called remote desktop?
- rcxdude 6y agoTerminals can have mouse support. It works with some TUI apps like vim.
- lucb1e 6y agoAll the terminal software with mouse support I've found so far just messes with things, I wasn't aware that people actually use this (e.g. in vim enabling mouse support messes with the yank buffer and doesn't let me select things for clipboard copying anymore, I immediately turn that off in setups where some overzealous maintainer default-enabled it). The amount of software with support is very low anyway, so if one really wants to use a mouse, remote desktop might serve one better.
- sesuximo 6y ago?? Sounds like mosh is the only program in the stack that doesn't support this
- pahool 6y agomosh is a lifesaver on flights, where latency typically exceeds 500ms
- 6y ago
- axegon_ 6y agoA few I can't live without off the top of my head: * "-D" for ssh tunneling. * "-L" for forwarding all traffic on a specific port. * sshfs - mount small directories over ssh on your local machine (works with big ones but way too slow, for big ones I go rsync).
- sullyj3 6y agosshfs is the biggest one for me. Allows you to use all your local tools.
- Piskvorrr 6y agoIf you work with a large tree where a few files at a time change, you may want to look at lsyncd - backed by inotify and rsync, syncs the local changes to remote. Not really suited for interactive edits, but if you find yourself running rsync in a loop, this is a better replacement.
- mercora 6y agoalso: * "-R" for reverse forwarding on a specific address. That is, you can connect from the remote host to your local network. I used to do this to make my system at home accessible on my workstation in the office :) if you don't specify the address to forward to you will get a SOCKS proxy on the port specified that tunnels connections to your local network. It is also possible to forward non local ports but ports on machines accessible to the side that is forwarding too.
- asdff 6y agoMy advice is to make heavy use of your .ssh/config Here is an example of some of mine (double spaced to read clearly on HN): Host * Ciphers aes128-ctr Compression yes ServerAliveInterval 120 ForwardX11 yes Host example HostName example.url.com User my_name ForwardX11Trusted yes I keep global settings behind the glob, and more specific settings for all the hosts I use. No need to use aliases in your .bashrc or wherever. With this setup, typing 'ssh example' is equivalent to 'ssh -XCY -c aes128-ctr my_name@example.url.com' which definitely saves some keystrokes.
- m463 6y agoI always create and heavily use ~/.ssh/config Host x Hostname full.host.name.com (or 1.2.3.4) User <myuser> IdentitiesOnly yes IdentityFile ~/.ssh/id_x_ed25519 I give hosts short names so you can `ssh x` to do automatic login, I generate identities for some machines ssh-keygen -t ed25519 -f ~/.ssh/id_x_ed25519 use ssh-copy-id to copy the identity to the target machine so it lets you in: ssh-copy-id -i ~/.ssh/id_x_ed25519.pub x or if your machine doesn't have ssh-copy-id (older macs); cat ~/.ssh/id_x_ed25519.pub | ssh x "cat >> .ssh/authorized_keys" IdentitiesOnly means it will only send that one identity for that one machine (otherwise it will try all of them, like a janitor trying to open a locker with a big keychain of identical keys) If you always want to use a password to log into a machine, but want to be able to log in in other windows to the same machine without a password: Host x ... ControlMaster auto ControlPath ~/.ssh/master-%r@%h:%p this will multiplex all activity to that host through one tcp connection you can also use Host * at the beginning of your config to do this for all hosts to tunnel vnc over ssh to a remote mac(I do this with mac) Host foo ... LocalFoward 5900 localhost:5900 ssh foo then locally vnc to localhost:127.0.0.1
- 3r8riacz 6y agoDoesn't ed25519 keys are fixed to 256 in terms of the -b flag, so no need to specify there anything?
- jstanley 6y agoYes. From the ssh-keygen man page: > Specifies the number of bits in the key to create. For RSA keys, the minimum size is 1024 bits and the default is 2048 bits. Generally, 2048 bits is considered sufficient. DSA keys must be exactly 1024 bits as specified by FIPS 186-2. For ECDSA keys, the -b flag determines the key length by selecting from one of three elliptic curve sizes: 256, 384 or 521 bits. Attempting to use bit lengths other than these three values for ECDSA keys will fail. Ed25519 keys have a fixed length and the -b flag will be ignored.
- m463 6y agohey you're right! I have removed '-b 521' from the ssh-keygen command.
- 14k12j41j211 6y agoThe most gain I've had in the recent years was having vscode remote. Instead of fiddling with terminal editors forever, just have a decent ssh config with all your host, and connect instantly. Still looking for a way to make sftp/scp work fast.
- Cthulhu_ 6y agoI've tried that for a while but our servers / VMs are so slow (I/O is a bottleneck I suspect) that that was unworkable. At the moment I use intellij which has a "sync with remote" function; I can run the things local and push them to the remote testing environment whenever I feel like it. (my predecessor would use git a lot, ugh)
- lucb1e 6y ago> Still looking for a way to make sftp/scp work fast. Making it fast while still using it, not sure. But I can share an alternative, since a friend had the same issue and this was a literally ten times faster for a lot of small files (in the order of 30 minutes instead of 5 hours): cd path/to/target/location ssh user@target 'tar c /tmp/example' | tar x Quick guide to tar, since it's super simple: c for compress x for extract f for file (since we send it to stdout / read from stdin, I don't use the f option) v for verbosity (not sure if that works on the remote side) z for zlib compression (ssh can do compression already, so also unused here) t for testing (reading) an archive without extracting it ("tar tv <your.tar" will show you the contents, it's almost like real TV!) That's all I've ever needed. So what this will do is run "tar create <directory>" on the remote system and, tar being a classic tool, it'll just output that binary archive data to stdout since you didn't specify a file ("tar cf your.tar <directory>"). On the receiving side, you pipe it to another tar command that reads from stdin (since, again, no file was specified) and extracts the files from the incoming data stream.
- m463 6y agoif rsync is available it's easy: rsync -av lcldir/ x:remotedir/ rsync -av x:remotedir/ lcldir/ I've gotten pretty strict about trailing slashes otherwise I end up creating directories within directories depending on whether things exist or not
- jldugger 6y agoIMO among the most useful ssh config settings is the Include directive, which supports wildcards. Hence, the following is the entirey of my ~/.ssh/config: Include config.d/* Include hosts.d/* config.d is basically one 'Host *' file, but hosts.d lets me keep the random host/device settings for work and personal use separated.
- pawurb 6y ago2FA for SSH sounds great but I can only imagine how cumbersome it must be for using on a daily basis. I've recently started permanently locking my SSH ports and only briefly whitelisting them for only my IP with a bash scripts whenever the access is needed https://pawelurbanek.com/ec2-ssh-dynamic-access https://pawelurbanek.com/ec2-ssh-dynamic-access
- mmalone 6y agoCheck out our single sign-on for SSH stuff at smallstep (where I work). Either in open source[1] or our product[2]. The hassle of 2FAing all the time is one of the big reasons I love single sign-on for SSH. Basically, you do 2FA when you're pushed through single sign-on. But then you're issued a short-lived certificate that gets put in your ssh-agent. You only need to 2FA to get a certificate. So you can tune 2FA challenge frequency based on certificate lifetime. It's sort of like a browser session where you "login" and then you can browse until your cookie expires. Here you "login" and you can SSH until your certificate expires. So you have strong authentication, but you're only asked to do it periodically. [1] https://smallstep.com/blog/diy-single-sign-on-for-ssh/ https://smallstep.com/blog/diy-single-sign-on-for-ssh/ [2] https://smallstep.com/sso-ssh/ https://smallstep.com/sso-ssh/
- kqr 6y agoAre the numbers for the ServerAliveCountMax and ServerAliveInterval accidentally swapped? Wouldn't it make much more sense to check every second, and fail if five consecutive checks failed, rather than check only every five seconds, and then fail immediately if one check is dropped due to very transient network issues?
- zepearl 6y agoYeah, I would set as well a higher value for "ServerAliveCountMax".
- hawski 6y agoAt your home install nss-mdns on Linux. It uses avahi for mDNS name resolution on your LAN. You can then forgo /etc/hosts and DHCP reservations between your machines at home. It is compatible with Mac's. I don't know what you can use on Windows for the purpose. Then to extend this a notch or two install Zerotier on all your hosts. Now you have virtual LAN between all your machines even outside of your home. It is P2P and does hole punching and whatever you need to work. You can connect to your computer via tethering from a puny little laptop while sitting on a bench outside your house. If you are a home admin for your family you can add those computers to your virtual LAN. Or your friends can also join. Then you can easily share photos or whatever straight with Samba or even an intranet of sorts.
- AnthonBerg 6y agoStrongly seconded! (Tossing some further dots to connect into the mix: Mosh and tmux and iTerm2's tmux integration fit very well in too. I think Visual Studio's Live Share should also work faster over ZeroTier - it should serve as a direct connection. I'm also really keen to try Emacs multiuser editing on a remote terminal over mosh and tmux.) And: I don't know if it's the placebo effect, but it seems to me that connections over ZeroTier are noticeably more responsive. Like slightly but noticeably.
- hawski 6y agoConnections on Zerotier itself often survive roaming. I was amazed when I went from tethering outside to home Wi-Fi and ssh session was still responsive. Although it can freeze and definitely can timeout. I'm yet to try mosh. I did not hear about Live Share, but was planning on using Visual Studio Code Remote Development. For my current work ssh -CX is often enough for me. I also intend to use Xpra, as I found X2Go a bit more rough around the edges. It could be interesting to measure the effect. Probably they did some testing already, but probably as you said - placebo ;)
- skocznymroczny 6y agossh not having support for --password argument is a big drawback. Usually requires to use some weird workarounds, especially when copying ssh keys to the machine are not an option.
- Cthulhu_ 6y agoIt would put your password into your `~/.bash_history` and show up on the screen though; using a commandline argument to pass passwords is inherently unsafe. Sure you could have a secure system that only you use, but the people behind ssh cannot make that assumption. Removing the risk entirely is better than trusting the users. I'm sure there's a shell trick you could use to pass a password on the prompt anyway. For all other use cases, copy SSH keys securely.
- lucb1e 6y ago> It would put your password into your `~/.bash_history` I'm fine typing (or pasting) my password in an interactive prompt when I'm interactively using it; that's not the problem. What I would like a --password option for is when I'm not interactively using it, like from a script. It'll still show up in the process list (ssh could overwrite it but there are some µs where it's there) but my laptop is single-user so that's no big deal. > I'm sure there's a shell trick you could use to pass a password on the prompt anyway. There is software that does it, but it's a real pain to find a short command that does it. Simply echo password | ssh user@host does not work, the openssh authors disabled that on purpose. Ssh keys are, of course, the solution whenever possible, but that's not always possible. I'll be the first to admit that the legitimate uses for --password are rare, but they're definitely there and having to install extra software to make that crap work is just a real pain. I'd rather be able to shoot myself in the foot with unix tools.
- dredmorbius 6y agoIt's quite likely that what you want in this case is to use SSH forced commands with sshkey auth and a remote account exclusively dedicated to serving this one request. https://binblog.info/2008/10/20/openssh-going-flexible-with-forced-commands/ https://binblog.info/2008/10/20/openssh-going-flexible-with-...
- fredley 6y agoIs your SSH session hung, and you can't even ctrl-C out? Typing ~. Enter (hit tilde, then period, then enter), will immediately kill the session and drop you back to your local shell.
- pinopinopino 6y agoI am missing certificates on this list, you never have to distribute individual public keys. And you can sign certificates with an API. It is also nice to give someone temporary access, because they are valid in a time interval.
- mmalone 6y agoYea we like certificates at smallstep. We’ve got a couple[1] other[2] posts[3] that cover them pretty well. Should have probably made a more prominent mention though :). [1] https://smallstep.com/blog/use-ssh-certificates/ https://smallstep.com/blog/use-ssh-certificates/ [2] https://smallstep.com/blog/diy-single-sign-on-for-ssh/ https://smallstep.com/blog/diy-single-sign-on-for-ssh/ [3] https://smallstep.com/blog/smallstep-ssh/ https://smallstep.com/blog/smallstep-ssh/
- tgb 6y agoI often ssh then open a vim on the server. But it would make more sense to me if vim had support for open remote files via its own ssh connection instead. Does this exist (for vim or some other editors)? Then I could always use my local config and it would be easier to type on a bad connection.
- mercora 6y agoi don't know about vim but in emacs tramp mode allows this. However, you could just mount the remote filesystem via sshfs which makes it work everywhere (its slow though).
- switch007 6y agoEmacs supports e.g. /ssh:my.server.net:/path (with host name completion too e.g. /ssh:my.<tab>)
- Tistel 6y agoemacs is nice too in that if you are using tramp mode (/ssh:blah) to open a remote file you can create a remote eshell too. you can do diffs and merges between remote machines also. in the pre container/k8s days i worked at a place that did horizontal load balancing between 20ish remote VMs. the ability to have many eshell tiled on screen was so helpful. i also had some elisp that took advantage of tramp mode to very crudely do VM orchestration across the 20. i will shut up now because i don’t want to be that emacs guy.
- jenscow 6y agoTried sshfs? It mounts sftp.
- tgb 6y agoI haven't, I'll look into it.
- enriquto 6y ago> Does this exist (for vim or some other editors)? It does: vim scp://server//path Run :h netrw inside vim to learn all about editing remote files.
- dijit 6y agoThis reminds me of the ugliest hack I have ever written. For context: passwords rotate every 90 days, there are different passwords for client facing and "internal" servers, (and different passwords for linux machines vs Windows machines). All connections to client facing servers (which is my job) must go via: 1) a VPN 2) a "local" jumphost (both ssh/rdp), only accessible via VPN 3) a "remote" jumphost (also, both ssh/rdp), only accessible via the "local" jumphost". Additionally; The majority of my servers are Windows based. So, what do you do when everything goes wrong? well, you VPN with your "normal" password, and your 2FA RSA token. Then you rdp (or SSH) to the local jumphost with the same password as the vpn, then you rdp (or, ssh) to the remote jumphost with a different password, then you finally RDP into the machine that is interesting. So, being the lazy git that I am, I wrote a program that scrapes my passwords from 1password, and ssh's into those jumphosts creating a tunnel all the way through. Then I call freerdp on localhost. For this to work I had to do a bunch of ugly things like: 1) figure out the dimensions of my display and scale everything, because freerdp doesn't do this automatically. 2) call python from bash because getting a unique random socket requires binding to "port 0" which is not something I think is possible inside of bash. 3) do the same on each hop. 4) determine which password is needed based on the "domain" of the machine 5) detect if the machine is actually accessible or not (IE; are you on the VPN? is the machine actually "local"?) Anyway, I should share the code, we can all revel in its ugliness.
- 1cvmask 6y agoWhen will you share it?
- dustinkirkland 6y agoTry using ssh-import-id to fetch your (or a friend or colleague's) public key from Github!
- mmalone 6y agoIf you like ssh-import-id to pull keys from GitHub, you’ll love AuthorizedKeysCommand to pull keys from GitHub. Depending on use case, though, this can be a bit sketch. At smallstep we like SSH certificates, which make life similarly easy on everyone with a bunch of other benefits. You can find a couple relevant posts on our blog if you’re interested. Incidentally, GitHub now supports SSH certificates (for enterprise edition, at least).
- ransom1538 6y agoscreen. If you are out there and you DO NOT want to lose your session due to a network error screen is for you! Even better, you can have your coworkers join your screen or reattach to it and watch you use ssh.
- danielecook 6y agoIf you are working on an HPC cluster: [1] The ssh package for vscode is great https://code.visualstudio.com/docs/remote/ssh https://code.visualstudio.com/docs/remote/ssh [2] Also check out rsub which allows you to open a file in your terminal locally https://github.com/henrikpersson/rsub https://github.com/henrikpersson/rsub
- Tehnix 6y agoI'd recommend wemux[0] for anyone wanting to share tmux sessions with other people (or even just themselves). It supports several modes: - mirror: to attach to server in read-only mode. - pair: attach to server in pair mode, allowing the client to control the terminal as well. - rogue: attach to server in rogue mode, which allows both editing with the host and switching to windows independently from the host. I personally use rogue to share tmux sessions between my own devices without affecting whatever I'm doing on the other devices. [0]: https://github.com/zolrath/wemux https://github.com/zolrath/wemux
- neilv 6y agoI've also long used SSH in various simple tunnels for my personal laptop's Web browser and/or mail client, such as through EC2 instances (and at one point also through a filtering HTTP proxy). Here's one version of it. while true ; do # TODO: make this do desktop notifications instead of osd_cat echo "TUNNEL CONNECTING" | osd_cat --pos=middle --align=center --lines=1 \ --font="-unregistered-latin modern sans-bold-r-*-*-140-*-*-*-*-*-*-*" \ --color=green1 --outline=2 --outlinecolour=white --delay=1 ssh -2 -4 -a -k -n -x -y -N -T -D 127.0.0.1:1234 user@example.com sleep 3 done Separate from these little personal tunnels, there's some additional SSH timeout options (sorry I don't have handy at the moment) that I've found frequently helpful in my uses of SSH at work, plus an external timeout wrapper that can kill the ssh process, for long-running scripts dealing with a non-OpenSSH server, but they've almost never been necessary in practice for these personal tunnels.
- bogomipz 6y agoI would like to mention sshuttle if your access only is via a jumphost and you don't want to have to create a port forward for every single host/port you want to connect to on the internal network. It basically acs like a cheap VPN: https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle https://sshuttle.readthedocs.io/en/latest/overview.html https://sshuttle.readthedocs.io/en/latest/overview.html
- beagle3 6y agoMore votes for sshuttle! It's a poor man's one way VPN: It inherits encryption/integrity/authentication (and some authorization) from ssh; It works incredibly well; For most practical network purposes it puts you on the computer you are sshuttlling to; And all it needs on that computer is the ability to ssh into it and some version of python - no special privileges or prior installations. The bad: It only does TCP (and does some UDP magic to make DNS work, but not UDP in general). It's only one way (no one on the destination network can "call you back", as you don't have an IP on that network). The only config is which network addresses get routed across the sshuttle (no policy / rules / firewall / anything else). You appear to come from the computer you shuttled to (so, unlike a real VPN, for better or worse - no policy along the way can tell you are coming from outside)
- donaldihunter 6y agoYep, sshuttle is awesome. It's also used under the covers by telepresence for connecting into a k8s cluster. https://www.telepresence.io/ https://www.telepresence.io/
- carapace 6y agoThe coolest thing I ever saw in the wild, a guy I once worked with wanted to transfer a directory of files from my machine to his (and maybe show off a little.) This was long enough ago that I didn't know quite how to proceed (time before rsync, scp...? Nah...) so he asked if he could do it and I let him have the keyboard. He tar'd (with z) the dir, piped the output of tar to ssh, with a remote command to cat it out there through tar again, all in one CLI line. Blew my mind at the time. UNIX philo FTW.
- e12e 6y agoNote that upstream suggests rsync rather than scp in the general case. Of course pipes work too. I sometimes forget, and the remember half way through a big recursive scp operation. Just use rsync.
- rsync 6y agoFrom a very old notes file I have ... tar cf - /mnt/data2 | ssh user@10.0.0.10 "cat > /mnt/data1/file1/file_data2.tar" ... and if the directory is large, you can 'split' it into multiple files: tar cfp - /mnt/data1 | ssh user@10.0.0.10 "split - -b 1024m /mnt/data1/file1/file_data2.tar" This is really no longer relevant because, of course, we all just use rsync ... but in the modern world, my favorite example of the unix philosophy is: mysqldump -u mysql db | ssh user@rsync.net "dd of=db_dump"
- jandrese 6y agoNone of those are quite right IMHO: tar -czvf - <sourcedir> | ssh <user>@<remotehost> tar -xzf - -C <remotedir> This is _much_ faster if you're sending over a directory with a lot of small files, especially if the link has even a modest amount of latency. The 'z' parameter can be omitted if the source files are not compressible (media files or already compressed). If the files are highly compressible but very large you might consider this instead: tar -cvf - <sourcedir> | pbzip2 -c | ssh <user>@<remotehost> tar -xf - -C <remotedir>
- m463 6y agoI think rsync has obsoleted a lot of that: rsync -av --progress indir/ x:outdir/
- joshlk 6y agoIt’s a bit annoying that the word hack is used to mean tips and tricks here. As hacking ssh is big area
- m463 6y agohacker as in "hacker news" is closest to "tricks" of tips and tricks https://stallman.org/articles/on-hacking.html https://stallman.org/articles/on-hacking.html However if someone said "hacking ssh" without the context of hacker news, I can see why the general computer person would probably think of the newer definition, which implies cracking or seeking security vulnerabilities.
- acdha 6y agoI highly recommend using the canonicalization feature if you use multiple networks: CanonicalizeHostname yes CanonicalDomains example.org That ensures that you never have the same host listed twice under the bare hostname and the fully-qualified version, avoiding the need to change keys twice when you rotate them. This setting allows you to automatically accept keys for new hosts but still report conflicts for existing hosts: StrictHostKeyChecking accept-new I highly recommend using the control-master feature to keep a persistent connection open to servers you access a lot. This makes new connections and tools like Git, scp, sftp, rsync, etc. much faster: Host *.amazonaws.com github.com *.github.com gitlab.com *.gitlab.com *.googleusercontent.com ControlMaster auto ControlPath ~/.ssh/control/%C.socket ControlPersist 600 On MacOS, you can use an x509 certificate on a device like a Yubikey as the SSH key so you can authenticate everywhere with the private key never leaving the token and, should you set it up that way, requiring a tap to use. This will enable the provider: PKCS11Provider=/usr/lib/ssh-keychain.dylib This will get the public key: ssh-keygen -D /usr/lib/ssh-keychain.dylib (see https://piv.idmanagement.gov/engineering/ssh/ https://piv.idmanagement.gov/engineering/ssh/ for other platforms)
- eneveu 6y agoAt my previous customer, we had to SSH through a bounce gateway (SSH key auth), then a bastion host (LDAP password auth), then the target host (LDAP password auth). Since it was quite annoying, I used multiple ssh_config tricks to make it work without having a 1000 lines SSH config, and I wrote a doc to share best practices. I anonymized it and posted it below. ---------------------- ssh_config_best_practices.md CanonicalizeHostname yes ############## ### GitHub ### ############## Host github.com User jdoe IdentityFile ~/.ssh/id_rsa_github ################## ### My Company ### ################## Host myproject-dev-* ProxyJump bastion-dev Host myproject-prod-* ProxyJump bastion-prod Host bastion-dev HostName bastion.myproject-dev.mycompany.com ProxyJump bounce.myproject-dev.mycompany.com Host bastion-prod HostName bastion.myproject-prod.mycompany.com ProxyJump bounce.myproject-prod.mycompany.com Host *.mycompany.com myproject-dev-* myproject-prod-* User john_doe IdentityFile ~/.ssh/id_rsa_mycompany ############## ### Common ### ############## Host * ControlMaster auto ControlPath ~/.ssh/sockets/%r@%h ControlPersist 2h # On OS X, UseKeyChain specifies that we should store passphrases in the Keychain. IgnoreUnknown UseKeychain UseKeychain yes AddKeysToAgent yes - "CanonicalizeHostname" ensures the config is re-parsed after hostname canonicalization. This means that when you SSH into "bastion-dev", SSH re-parses the config using the full hostname "bastion.myproject-dev.mycompany.com", which then correctly matches the entry "Host * .mycompany.com". - "ProxyJump" was added in OpenSSH 7.2 (2016) and is simpler and more powerful than "ProxyCommand". - "bastion-xxx" hosts are the only ones whose hostname can be resolved from the bounce gateways. To connect to other hosts, the trick we use in this config is to do two ProxyJumps: your machine --> bounce --> bastion --> target host. - "ControlMaster" lets you do SSH multiplexing, which in our case is particularly useful when channeling multiple connections through a bastion host. It also persists SSH connections for a while after we disconnect, which speeds up future connections, and avoids typing the password all the time. - When you ssh into a host, you must enter your LDAP password twice: first for the bastion, then for the target host. If you then ssh into a second host, you must enter your LDAP password only once, since ControlMaster reuses the SSH connection previously established to the bastion. Also, if you close those SSH shells, the connections will persist for two hours (see ControlPersist), so you won't need to type your password for those two hosts if you try to SSH into them again in the next two hours. - Using this ssh_config, there is no need to add an Host entry for each host. It is not even needed to specify the IP addresses, since they will be resolved using the DNS on the bastion host. - With this configuration, you can easily copy a file using scp between your local machine and the target host, without needing to first copy it to the bastion, then ssh to the bastion, then copy it to the target host, then remove it from the bastion... PS: an ssh_config is parsed from top to bottom, so specific comes first, generic comes last. That's why "Host *" must be at the bottom.
- terrywang 6y agoSome tips: - Customise ~/.ssh/config to suite your needs (be careful with storm - manage ssh like a boss, it helps when scripting or searching hosts but has a outstanding bug converting keywords to lowercase [1]) - Use ed25519 key over RSA - OpenSSH 8.1 added support for FIDO/U2F (use your YubiKey or equivalent) - Put `IPQoS lowdelay throughput` in your ~/.ssh/config if you run a rolling release (e.g. Arch, Gentoo) or your openssh rolls via homebrew on macOS. latest openssh client with older version of sshd may produce weird disconnection issues (server reset connection, client side is able to connect but terminal hangs in 5~10s). Spend quite some time digging only to find that it was caused by default change for IPQoS (to IPQoS af21 cs1) introduced in OpenSSH 7.8p1 [3] - leverage ssh-copy-id - ssh -vvv | ssh -G (troubleshooting from client side) - /usr/sbin/sshd -p 2222 -f /path/to/sshd_config -D -ddd (troubleshooting sshd server side) - Be careful with `UsePAM no`, make sur - use AllowUsers / DenyUsers vs DenyGroups vs AllowGroups , mind the order - know how to use ssh-add / ssh-keygen / ssh-agent / ssh-keyscan - audit SSH config (ssh-audit / lynis), version control ssh_config / sshd_config properly if possible - openssh + tmux ;-) Personal favourite tips/tricks: - ssh -D (used to use this dynamic port forwarding, open a local Socks5 proxy to punch hole in firewall, encrypt traffic, it worked for a while against the infamous GFW, only a little while though) - ssh -L | -R TCP forwarding - ssh -X | -Y X11 forwarding (run X11 apps remotely and display it on X Server locally) - More personal SSH tricks put together over the years, surprise to find that my person OpenSSH notes are 150+ pages in Google Docs, sorry can't put all in a comment... [2] - RTFM works, OpenSSH is worth the time ;-) [1]: https://github.com/emre/storm/issues/157 https://github.com/emre/storm/issues/157 [2]: https://sites.google.com/site/imterry/computer/tools/ssh https://sites.google.com/site/imterry/computer/tools/ssh [3]: ssh(1)/sshd(8): the default IPQoS used by ssh/sshd has changed. https://www.openssh.com/releasenotes.html https://www.openssh.com/releasenotes.html
- d33 6y agoSurprise not to see tmate.io get more attention: https://tmate.io https://tmate.io It's packaged for most Linux distributions and offers a seam-less "share your terminal" experience over the web. Has an optional read-only mode. Users can access the terminal via https and ssh. Great for low-bandwidth videoconferencing.
- deleted 6y ago[deleted]