Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

>Do not SSH cross-server

This doesn't make sense. You can safely setup SSH agent forwarding to ssh from server to server without storing your ssh private key anywhere but your local host.



If the server you're forwarding your agent to is compromised it can now talk to your agent. This point could also be 'assume gateway servers are compromised'.


If your gateway servers are compromised to this degree you have a much larger problem than your ssh agent being compromised.


But the article suggests to use ssh-agent.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: