OpenSSH: allow -R only

From: Thomas Themel (themel-comp.security.ssh-030828_at_isogsglei.iwoars.net)
Date: 08/28/03


Date: 28 Aug 2003 10:35:28 GMT

Hi,

I'm trying to set up an account on an OpenSSH server to only allow -R
forwarding, but not -L forwarding. I've gone through a lot of OpenSSH
documentation and Google results, but it seems there is no way to configure
this.

Things I've tried that failed:

- no-port-forwarding also blocks -R forwarding
- permitopen can be used to allow specific -L connection

The target scenario should allow authorized clients to connect and let
the (host-key authenticated) server access their forwards, but not allow
the clients any extra access to the network of the server.

Is there a way to do this in OpenSSH (preferrably 3.4, but upgrade is
possible)?

ciao,

-- 
[*Thomas  Themel*]      one with nintendo
[extended contact]      halcyon symbiosis
[info provided in]      hand thinks for itself
[*message header*]  -- D. A. Koronakos and B. Roberts; "High-tech Haikus"


Relevant Pages

  • OpenSSH: allow -R only
    ... forwarding, but not -L forwarding. ... I've gone through a lot of OpenSSH ... the server access their forwards, ... the clients any extra access to the network of the server. ...
    (comp.security.ssh)
  • Re: Openssh, kerberos and Solaris 10
    ... I am getting credentials through PAM. ... I don't want to use Sun SSH; I would rather use OpenSSH. ... I cannot hope to enable OpenSSH krb5 cred forwarding. ... The client and server should negotiate the use of network authentication ...
    (comp.protocols.kerberos)
  • RE: Email Rules Forwarding and Fax Forwarding Not Working
    ... In Exchange 2003, "Allow automatic forward" is disabled by default. ... On the SBS server, ... Microsoft CSS Online Newsgroup Support ... Email Rules Forwarding and Fax Forwarding Not Working ...
    (microsoft.public.windows.server.sbs)
  • Re: Multiple copies of email in "Forward to"contact
    ... There is no forwarding set on his private mail (that would be via MS ... I have selected to keep a copy of on the server so that when he comes ... The only exception to this case being when I, or anyone whose mailbox is ... His home server then also sends a copy of this message to his ...
    (microsoft.public.exchange.admin)
  • duplication of forwarded email
    ... There is no forwarding set on his private mail (that would be via MS ... I have selected to keep a copy of on the server so that when he comes ... The only exception to this case being when I, or anyone whose mailbox is ... His home server then also sends a copy of this message to his ...
    (microsoft.public.exchange.admin)