Re: restricting TCP forwarding



Richard E. Silverman wrote:
"SM" == Steven Mocking <ufo@xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx> writes:

SM> Any user with an existing file as a shell entry in /etc/passwd can
SM> use ssh forwarding. This rather defeats the purpose of scponly.

SM> Is it possible to restrict this on a per-group or per-user basis?
SM> Or is running a second ssh server the only solution?

Not with OpenSSH, though other SSH servers such as Tectia and vshd do have
this capability.

With openssh if you set ownership and permissions on .ssh & ..ssh/authorized_keys such that the user can't modify it (e.g. owned by root) you can use the no-port-forwarding option on the key.
--
Flash Gordon, living in interesting times.
Web site - http://home.flash-gordon.me.uk/
comp.lang.c posting guidelines and intro:
http://clc-wiki.net/wiki/Intro_to_clc
.



Relevant Pages

  • Re: Safest way of accessing a home computer from outside?
    ... what if I my router doesent have a public IP ... use for ssh is forwarded to your ssh server. ... You can find Hamachi at ...
    (Fedora)
  • Re: Safest way of accessing a home computer from outside?
    ... what if I my router doesent have a public IP ... I agree - ssh with no password and then use certificates to ... use for ssh is forwarded to your ssh server. ... You can find Hamachi at ...
    (Fedora)
  • Re: AIX 5.2L "who" question
    ... SSH is corrupting the utmp file! ... where did you get the SSH server you are running? ... We have a 44P-270 running AIX 5.2L, when users connected via ssh they can't ... Monitoring ...
    (AIX-L)
  • Re: Blocking attacks from spoofed IP addresses
    ... Some of the ssh attacks are distributed. ... So IMHO public key authentication does not necessarily reduce risks. ... if one is scared about login unwanted attempts on a ssh server ...
    (comp.os.linux.networking)
  • Re: Remote Desktop from Linux console
    ... if your running a SSH server on L you can connect to V using RDC through the SSH tunnel. ... I do, or did, that all the time when I ran a SSH server on either a PC inside my router or on the router itself, ie. DD-WRT running on the router. ...
    (microsoft.public.windows.vista.networking_sharing)