3 ms·
> 3. Only forward your agent connection to machines you trust. You can get the convenience of agent forwarding without the negatives by using openssh's ProxyJu
by sillystuff 5y ago
> 3. Only forward your agent connection to machines you trust.
You can get the convenience of agent forwarding without the negatives by using openssh's ProxyJump (or, in old versions ProxyCommand). Either allows you to transparently forward your ssh connection via another host (or chain of hosts).
- jffry 5y agoProxyJump can also be pretty magic. If you have machines all on a subnet (in my example below, 10.1.0.0/24) that you need to use the same SSH jumpbox to reach, you can easily set up a wildcard to transparently proxy jump to any of them: Host jumpbox-10.1.0.x HostName jumpbox.example.com Port ... User ... Host 10.1.0.* ProxyJump jumpbox-10.1.0.x Then you can just run any random command like ssh 10.1.0.4 and it will just transparently jump through the jumpbox without you needing to specify it! (Of course, if you have a local subnet that collides and you are also trying to SSH to local hosts then this won't be the right approach for you).
- sillystuff 5y agoYou can add exclusions for the hosts in your local colliding subnet with something like: Host 10.1.0.* ProxyJump jumpbox-10.1.0.x !host hosta,hostb.example.org,hostc,10.1.0.23
- jffry 5y agoInteresting, would there be any reason to prefer that style over exempting them from the Host pattern? Host 10.1.0.* !hosta !hostb.example.org !hostc !10.1.0.23 ProxyJump jumpbox-10.1.0.x Doing it at the Host level would also make it easier if there were other config you wanted to apply for the group of machines (like IdentifyFile or Port)
- sillystuff 5y agoSorry, I made two mistakes when I wrote my response. The !host bit should be in the line above I've only used it in a Match block. I think your syntax is correct for a Host block exclusion. e.g., Match !exec "test1 -h %h -p %p >/dev/null 2>&1 || test2 >/dev/null 2>&1" host 10.1.0.*,*@example.org !host 10.1.0.4,10.1.0.11,hostb@example.org ProxyJump jumpbox-10.1.0.x The tests can be, e.g., see if the destination host can be reached directly, and if yes, bypass the jumphost. Using %h and %p ssh will pass the destination hostname and port to the test command.
- remram 5y agoWhat use-case is there for agent forwarding? My work does have machines only accessible through bastion hosts, but I never find myself using agent forwarding. It's too easy to ProxyJump (e.g. like you mention, it works automatically thanks to .ssh/config) or if a direct connection between remote hosts is required, generate a new key (e.g. to use rsync).