3 ms·
I guess you need a valid SSL certificate to do this? So it may not work well if you SSH into an IP instead of a domain -- it is not always possible to get an SS
by d3w4s9 3y ago
I guess you need a valid SSL certificate to do this? So it may not work well if you SSH into an IP instead of a domain -- it is not always possible to get an SSL certificate for an IP address ( https://stackoverflow.com/questions/2043617/is-it-possible-to-have-ssl-certificate-for-ip-address-not-domain-name https://stackoverflow.com/questions/2043617/is-it-possible-t... ).
It is probably trivial for people here to get a domain and then point it to the IP, but still, this seems a minor limitation.
- jamespwilliams 3y agoYou could probably use a self-signed cert, then configure socat either to trust that certificate (with the cafile option) or to disable verification (with the verify option)
- georgyo 3y agoThere is no need for a valid SSL cert, self signed will do. The ProxyCommand just needs to not validate the cert.