Difference between revisions of "ForwardAgent"

From wikieduonline
Jump to navigation Jump to search
Line 1: Line 1:
  
 +
ForwardAgent
 +
Specifies whether the connection to the authentication agent (if any) will be forwarded to the remote machine. The
 +
argument must be ''yes'' or ''no''. The default is ''no''.
 +
 +
Agent forwarding should be enabled with caution. Users with the ability to bypass file permissions on the remote
 +
host (for the agent's Unix-domain socket) can access the local agent through the forwarded connection. An attacker
 +
cannot obtain key material from the agent, however they can perform operations on the keys that enable them to
 +
authenticate using the identities loaded into the agent.
  
 +
[[~/.ssh/config]]
 +
[[-J]]
  
[[~/.ssh/config]]
+
== See also ==
 +
* {{ssh}}
  
{{ssh}}
+
[[Category:ssh]]

Revision as of 12:43, 20 February 2023

ForwardAgent

Specifies whether the connection to the authentication agent (if any) will be forwarded to the remote machine. The 
argument must be yes or no. The default is no.

Agent forwarding should be enabled with caution. Users with the ability to bypass file permissions on the remote 
host (for the agent's Unix-domain socket) can access the local agent through the forwarded connection. An attacker 
cannot obtain key material from the agent, however they can perform operations on the keys that enable them to 
authenticate using the identities loaded into the agent.
~/.ssh/config
-J

See also

Advertising: