Tunnel-only SSH keys

markzero mark at darklogik.org
Thu Sep 22 08:27:22 PDT 2005


Hello.

I once read somewhere that it's possible to limit SSH pubkeys to
'tunnel-only'. I can't seem to find any information about this
in any of the usual places.

I'm going to be deploying a few servers in a couple of days and
I'd like them to log to a central server over an SSH tunnel (using
syslog-ng) however I'd like to prevent actual logins (hence
'tunnel-only').

Can this be done with OpenSSH? I'd like to try and stay away from
the complexities of a chrooted-stunnel for now...

cheers,
M

-- 
pgp: http://www.darklogik.org/pub/pgp/pgp.txt
0160 A46A 9A48 D3B0 C92F B690 17FB 4B72 0207 ED43
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 825 bytes
Desc: not available
Url : http://lists.freebsd.org/pipermail/freebsd-security/attachments/20050922/6912e42c/attachment.bin


More information about the freebsd-security mailing list