Re: workarounds for Host param not canonicalizing?

From: Alexander Klimov (alserkli_at_inbox.ru)
Date: 05/22/05

  • Next message: Ryan Barrett: "Re: workarounds for Host param not canonicalizing?"
    Date: Sun, 22 May 2005 11:25:48 +0300 (IDT)
    To: Ryan Barrett <secureshell@ryanb.org>
    
    

    On Fri, 20 May 2005, Ryan Barrett wrote:
    > hi all. the Host parameter in ssh_config matches against the hostname
    > typed on the command line, as opposed to the canonicalized host name. this
    > is to prevent DNS spoofing attacks, which is a Good Thing...
    >
    > ...but it does hurt usability if you routinely ssh to lots of machines.
    > instead of "Host *.foo.com", you have to use "Host abc def ghi ...".
    > needless to say, this is error-prone and hard to maintain.

    Could you elaborate on the problem. From man ssh_config:

         Host Restricts the following declarations (up to the next
               Host keyword) to be only for those hosts that match
               one of the patterns given after the keyword. Asterisk
               (*) and question mark (?) can be used as wildcards in
               the patterns. A single * as a pattern can be used to
               provide global defaults for all hosts. The host is the
               hostname argument given on the command line (that is,
               the name is not converted to a canonicalized host name
               before matching).

    so you CAN use `Host *.foo.com'

    -- 
    Regards,
    ASK
    

  • Next message: Ryan Barrett: "Re: workarounds for Host param not canonicalizing?"

    Relevant Pages

    • Re: SmallC
      ... to the host in the form of a 3-byte movement data packet (as described ... the counter is not incremented/decremented until it is reset. ... after the mouse receives any command from the host other than the ...
      (alt.lang.asm)
    • Re: ps/2 mouse w/o int33
      ... The standard PS/2 mouse sends movement/button information to the host ... (ie, after a packet is sent to the host, the movement counters are reset.) ... They are also reset after the mouse receives any command from the host ... Host: F3 Set Sample Rate: Attempt to Enter Microsoft ...
      (comp.lang.asm.x86)
    • RV: remote tape with ontape (dd command) fail after openssh install
      ... I solved the permission denied of root remote command adding remote host to ... The source of problem has to do with the post installation openssh. ...
      (comp.databases.informix)
    • Re: One computer cant see the other.
      ... When I net view from the client computer to the host computer I get my ... When I click on the shared folders in My Network Places(on ... command prompt on my host machine and my client machine when I ping the host. ... Open a command prompt window first, ...
      (microsoft.public.windowsxp.network_web)
    • Re: SYSCONF and FTPIT jobs
      ... belonging to the 192.168/16 netblock and is connected to the ftp host via ... I also have concerns about the generated ftpin file. ... 200 PORT command successful. ...
      (comp.sys.hp.mpe)