Re: RFC: non-root ssh tun access

This is a discussion on Re: RFC: non-root ssh tun access within the OpenSSH Development forums, part of the Networking and Network Related category; Damien Miller wrote: > On Fri, 25 Aug 2006, Chris Rapier wrote: > >> A while ago we developed ...


Go Back   Usenet Forums > Networking and Network Related > OpenSSH Development

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 08-28-2006
Chris Rapier
 
Posts: n/a
Default Re: RFC: non-root ssh tun access



Damien Miller wrote:
> On Fri, 25 Aug 2006, Chris Rapier wrote:
>
>> A while ago we developed a series of patches we call PMVPN for Poor
>> Man's VPN. Basically what we did was intercept open() calls and compare
>> the tuple to a set of rules we had (using LD_PRELOAD (windows and OS X
>> required more annoying proceedures that we didn't explore in any
>> depth)). If the rule matched then we'd automatically open an SSH tunnel
>> to the target and forward the appropriate port over it.

>
> You can do something similar with an unmodified ssh, "socksify" and
> DynamicForward


Well, the idea was to integrate things in order to bring greater
security to a larger number of people. The majority of people won't go
to the hassle of paying for and installing socksify and then do all of
the DynamicForward routines from the command line. Its not that
difficult of course, but people generally just won't do it. Our feeling
was that the easier we made it the more people would use it. The more
people that used it the safer we'd all be (the idea of herd immunity).
The end result was going to be a nice GUI so that users wouldn't have to
drop down to the CLI - which turns a lot of people off. I spend a lot of
time supporting users so the easier I make it for them the easier my job
ends up being :)

We might be re-exploring this question in the upcoming year but it
depends on what the grant situation looks like.

Chris
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
http://lists.mindrot.org/mailman/lis...enssh-unix-dev
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 09:33 PM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0