Proposal for hardening agent forwarding

Damien Miller djm at mindrot.org
Sun Mar 14 10:27:03 AEDT 2021


On Fri, 12 Mar 2021, Mitchell Blank Jr wrote:

> Hello.
> 
> This week I've been experimenting with some hardening of the agent-forwarding
> process.  I know there have been other proposals in the past, but I thought
> I'd share what I have in case they are of any upstream interest.
> 
> For easier review (and to spare your inboxes) I just opened it as a PR
> on the openssh-portable github mirror here: https://github.com/openssh/openssh-portable/pull/233

I mentioned this on the PR, but I also have a proposal for restricting
agent forwarding in progress: https://github.com/djmdjm/openssh-wip/pull/5

-d


More information about the openssh-unix-dev mailing list