SFTP &

Peter Stuge peter at stuge.se
Wed Jun 25 10:35:22 EST 2014


Márk Csaba wrote:
> Match Group admin
>     AllowTCPForwarding yes
>     X11Forwarding yes
>     ForceCommand bash

> Is there a way to achieve the requirements above?

Remove the admin ForceCommand.


> Is there a way to create rules according to connection type?

In theory there's a way, but it's unreliable and unsecured. It
heuristics on plain text sent before any crypto is used. Such
rules could be tricked with a telnet client.


//Peter


More information about the openssh-unix-dev mailing list