4 ms·
The following two things are highlights for me: * ssh(1): Add a ssh_config(5) "Match" keyword that allows conditional configuration to be applied by match
by jaryd 13y ago
The following two things are highlights for me:
* ssh(1): Add a ssh_config(5) "Match" keyword that allows
conditional configuration to be applied by matching on hostname,
user and result of arbitrary commands.
* ssh(1): Add support for client-side hostname canonicalisation
using a set of DNS suffixes and rules in ssh_config(5). This
allows unqualified names to be canonicalised to fully-qualified
domain names to eliminate ambiguity when looking up keys in
known_hosts or checking host certificate names.
- stormbrew 13y agoBoth great things. I'm pretty excited about elliptic curve keys and the ability to have ProxyCommand-like ProxyUseFDPass return an fd instead of act as an long-lived intermediary, personally. A lot to like in this.
- djmdjm 13y agoMore details on the hostname canonicalisation here: http://blog.djm.net.au/2014/01/hostname-canonicalisation-in-openssh.html http://blog.djm.net.au/2014/01/hostname-canonicalisation-in-...
- nodata 13y agoThe Match keyword is great, but the syntax of "and continue reading until the end of the file" is a pain. They should add an EndMatch keyboard to close the block, or force indentation or something.
- newman314 13y agoI would still like to see an easy way to switch between a gateway ssh host and going direct depending on location/IP. If I'm home, I want to be able to ssh to the gateway machine automatically and when I'm at work, go direct. Obviously, this can be fixed with a shell script but it's hacky.
- stormbrew 13y agoThe Match keyword does allow you to configure based on your local address, so on first glance it would seem like it would allow you to do this, but for some reason ProxyCommand is not on the list of whitelisted keywords acceptable in a Match block. :/ That's really a shame.