OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Tunnel-only SSH keys

From: David Wolfskill (davidcatwhisker.org)
Date: Thu Sep 22 2005 - 11:22:38 CDT


On Thu, Sep 22, 2005 at 04:27:18PM +0100, markzero wrote:
> Hello.
>
> I once read somewhere that it's possible to limit SSH pubkeys to
> 'tunnel-only'. I can't seem to find any information about this
> in any of the usual places.
> ...
> Can this be done with OpenSSH? I'd like to try and stay away from
> the complexities of a chrooted-stunnel for now...

See the section "AUTHORIZED_KEYS FILE FORMAT" in the sshd man page.

There is also a discussion of this in the O'Reilly _SSH_ book.

Peace,
david
--
David H. Wolfskill davidcatwhisker.org
Prediction is difficult, especially if it involves the future. -- Niels Bohr

See http://www.catwhisker.org/~david/publickey.gpg for public key.
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-security
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"