SSH can do much more than open terminals
Summary
Al Williams shows SSH configuration, file transfer, port forwarding, a SOCKS proxy and remote file systems as versatile tools for secure networks. SSH encrypts login and data traffic. scp and sftp transfer files over SSH.
Ideas
- The SSH configuration stores host names, users and keys per destination.
- Local port forwarding makes remote services reachable locally.
- Dynamic forwarding provides a SOCKS proxy.
- SSHFS mounts remote directories as a file system.
Insights
- A single proven protocol can replace many insecure special-purpose connections.
- Tunnel security ends at the two tunnel endpoints.
- Readable host profiles reduce error-prone command-line options.
Facts
- Forwarding has to be allowed on the server side.
Recommendations
- Disable password login once keys have been provided and tested.
- Restrict forwarding and keys to the destinations you need.
References
Links to the original source and the Web Archive open in a new tab.