Re: Tunnel-only SSH keys

2005-09-22 Thread Brian Reichert
On Thu, Sep 22, 2005 at 06:09:59PM +0200, Jeremie Le Hen wrote: > Hi, > > > I once read somewhere that it's possible to limit SSH pubkeys to > > 'tunnel-only'. I can't seem to find any information about this > > in any of the usual places. > > > > I'm going to be deploying a few servers in a coup

Re: Tunnel-only SSH keys

2005-09-22 Thread Brian Reichert
On Thu, Sep 22, 2005 at 09:22:38AM -0700, David Wolfskill wrote: > On Thu, Sep 22, 2005 at 04:27:18PM +0100, markzero wrote: > > Hello. > > > > I once read somewhere that it's possible to limit SSH pubkeys to > > 'tunnel-only'. I can't seem to find any information about this > > in any of the usua

Re: Tunnel-only SSH keys

2005-09-22 Thread markzero
> > Hello. > > > > I once read somewhere that it's possible to limit SSH pubkeys to > > 'tunnel-only'. I can't seem to find any information about this > > in any of the usual places. > > ... > > Can this be done with OpenSSH? I'd like to try and stay away from > > the complexities of a chrooted-st

Re: Tunnel-only SSH keys

2005-09-22 Thread David Wolfskill
On Thu, Sep 22, 2005 at 04:27:18PM +0100, markzero wrote: > Hello. > > I once read somewhere that it's possible to limit SSH pubkeys to > 'tunnel-only'. I can't seem to find any information about this > in any of the usual places. > ... > Can this be done with OpenSSH? I'd like to try and stay awa

Re: Tunnel-only SSH keys

2005-09-22 Thread Jeremie Le Hen
Hi, > I once read somewhere that it's possible to limit SSH pubkeys to > 'tunnel-only'. I can't seem to find any information about this > in any of the usual places. > > I'm going to be deploying a few servers in a couple of days and > I'd like them to log to a central server over an SSH tunnel (

Tunnel-only SSH keys

2005-09-22 Thread markzero
Hello. I once read somewhere that it's possible to limit SSH pubkeys to 'tunnel-only'. I can't seem to find any information about this in any of the usual places. I'm going to be deploying a few servers in a couple of days and I'd like them to log to a central server over an SSH tunnel (using sys