From owner-freebsd-security@FreeBSD.ORG Thu Sep 22 17:33:53 2005 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5FA3416A41F for ; Thu, 22 Sep 2005 17:33:53 +0000 (GMT) (envelope-from reichert@numachi.com) Received: from meisai.numachi.com (meisai.numachi.com [198.175.254.6]) by mx1.FreeBSD.org (Postfix) with SMTP id 41D4A43D48 for ; Thu, 22 Sep 2005 17:33:51 +0000 (GMT) (envelope-from reichert@numachi.com) Received: (qmail 78797 invoked from network); 22 Sep 2005 17:33:45 -0000 Received: from natto.numachi.com (198.175.254.216) by meisai.numachi.com with SMTP; 22 Sep 2005 17:33:45 -0000 Received: (qmail 42885 invoked by uid 1001); 22 Sep 2005 17:33:47 -0000 Date: Thu, 22 Sep 2005 13:33:47 -0400 From: Brian Reichert To: David Wolfskill , freebsd-security@freebsd.org Message-ID: <20050922173347.GI74605@numachi.com> References: <20050922152718.GB91509@logik.internal.network> <20050922162238.GZ54033@bunrab.catwhisker.org> Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <20050922162238.GZ54033@bunrab.catwhisker.org> User-Agent: Mutt/1.5.9i Cc: Subject: Re: Tunnel-only SSH keys X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 22 Sep 2005 17:33:53 -0000 On Thu, Sep 22, 2005 at 09:22:38AM -0700, David Wolfskill wrote: > On Thu, Sep 22, 2005 at 04:27:18PM +0100, markzero wrote: > > Hello. > > > > I once read somewhere that it's possible to limit SSH pubkeys to > > 'tunnel-only'. I can't seem to find any information about this > > in any of the usual places. > > ... > > Can this be done with OpenSSH? I'd like to try and stay away from > > the complexities of a chrooted-stunnel for now... > > See the section "AUTHORIZED_KEYS FILE FORMAT" in the sshd man page. > > There is also a discussion of this in the O'Reilly _SSH_ book. Sorry for the arm-wave (in that I don't have the details of this rumor), but I recall it's possible, via a client, to screw with the remote environment, as to supply a different shell; that would affect these tactics, perhaps. > Peace, > david > -- > David H. Wolfskill david@catwhisker.org > Prediction is difficult, especially if it involves the future. -- Niels Bohr -- Brian Reichert 55 Crystal Ave. #286 Daytime number: (603) 434-6842 Derry NH 03038-1725 USA BSD admin/developer at large