5 ms·
If SSH is already being used, can't one just create an SSH tunnel to forward the login?
by jadedtuna 4y ago
If SSH is already being used, can't one just create an SSH tunnel to forward the login?
- minitoar 4y agossh -D ftw
- chupasaurus 4y agoAllowTcpForwarding no ftl
- minitoar 4y agoeh if you have shell access anyway this is easy to circumvent.
- chupasaurus 4y ago"If" is a good word. The setting above is usually being used in environments where network security is a bit paranoid, so shell access won't help against lack of a hole through the firewall somewhere in-between, unless there's a way to use avian carriers.
- minitoar 4y agoThe thread we are in is talking specifically about using cli tools on a remote machine, so that’s why I mentioned it. If you have that you don’t need a hole in the firewall.
- est 4y agoSome login requires Identity and access management (IAM) with a web interface only, if such gateway exists, a CLI tool would have to give user a link to open oneself I guess?
- theamk 4y agoMy SSH usage has multiple servers (staging, dev, etc..) and multiple clients (laptop, desktop). Some of those connections are going through jumphosts. Setting up SSH tunnel would be possible, but a major pain, as every source/dest combination will need to have its own port, and every signin should specify the port number. Compared to the current system, which prints a URL in terminal which I just need to click, it would be a major usability regression.
- GreyStache 4y agoSomething akin to ssh agent-forwarding ("oauth-forwarding"?) is really needed. And it needs to be integrated similarly well like support for jumphosts. Haven't seen anything like this, I'll try to bring this up with the openssh folks.
- dgoldstein0 4y agoPossibly redirect to localhost:<port> where the port is one forwarded over ssh could do the trick?
- _flux 4y agoCurl can connect over unix domain sockets and ssh can forward them, I feel this would be a decent way to forward authentication as access control rules would apply to the sockets.