add keys and certificate to forwarded agent on remote host

Peter Stuge peter at stuge.se
Tue Sep 18 04:29:48 AEST 2018


Rory Campbell-Lange wrote:
> Can ssh-add work on the remote socket file?

I expect that it will just work<tm>. The local socket is just a
socket, and the protocol[1] message SSH_AGENT_ADD_KEY is the same.


> Is such an operation advisable?

That's up to you. ssh-add decrypts the private key locally where invoked
and transfers the key in a form immediately usable to the agent.

Once the agent has the key, it's not really possible to force the agent
to remove it.


//Peter

[1] https://tools.ietf.org/html/draft-miller-ssh-agent-02


More information about the openssh-unix-dev mailing list