Back to the feed

~/article/locking-your-ssh-agent-exposed-local-only-keys-until-openssh-10-5-1dvemf
infoSource: Help Net Security

Locking your ssh-agent exposed local-only keys until OpenSSH 10.5

Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fix shipped today in OpenSSH 10.5. The agent holds your decrypted private keys so you are not retyping a passphrase…

Read at the source

Summary written for cymesh.dev. The full article lives at Help Net Security.

Topics

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/locking-your-ssh-agent-exposed-local-only-keys-until-openssh-10-5-1dvemf