OpenSSH
[Top] [All Lists]

Re: tunneling through stdin/stdout, source routing

To: David Woodhouse <dwmw2@infradead.org>
Subject: Re: tunneling through stdin/stdout, source routing
From: Simon Richter <Simon.Richter@hogyros.de>
Date: Sat, 18 Nov 2006 00:42:25 +0100
Cc: openssh-unix-dev@mindrot.org
Delivered-to: sp-com-lists@consult.net
Delivered-to: openssh-unix-dev-list1@securepoint.com
Delivered-to: openssh-unix-dev-tmda@mindrot.org
Delivered-to: openssh-unix-dev@mindrot.org
In-reply-to: <1163600871.3396.196.camel@shinybook.infradead.org>
List-archive: <http://lists.mindrot.org/pipermail/openssh-unix-dev>
List-help: <mailto:openssh-unix-dev-request@mindrot.org?subject=help>
List-id: Development of portable OpenSSH <openssh-unix-dev.mindrot.org>
List-post: <mailto:openssh-unix-dev@mindrot.org>
List-subscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=subscribe>
List-unsubscribe: <http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev>, <mailto:openssh-unix-dev-request@mindrot.org?subject=unsubscribe>
Openpgp: url=http://www.hogyros.de/simon.asc
References: <4555C24C.7000007@hogyros.de> <20061114071345.GA25414@dementia.proulx.com> <455A571E.6010105@hogyros.de> <1163600871.3396.196.camel@shinybook.infradead.org>
Sender: openssh-unix-dev-bounces+openssh-unix-dev-list1=securepoint.com@mindrot.org
User-agent: Icedove 1.5.0.7 (X11/20061014)
Hello,

David Woodhouse wrote:

>> That's why I'd think a client-only solution would be the best solution 
>> here. My client can always ask for a port forward, the server doesn't 
>> care where it comes from.

> If you also use multiple _clients_ then you still have the problem of
> needing it compiled and installed for all machines.

Sure, but in general I have more control over the client than I have
over the machines in the DMZ at my university. In another setup I'd like
to be able to give people access to machines inside the internal network
without giving them a working shell in the passwd. If I require them to
run a command in order to hop to the next host I need to do that.

My point is that there is an use case for the feature I'm suggesting;
availability of only slightly less annoying ways to implement that does
not invalidate my use case.

I'd even be interested in contributing code, however I'm not sure on how
to do that in this case.

   Simon
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/listinfo/openssh-unix-dev

<Prev in Thread] Current Thread [Next in Thread>