|
Size: 1728
Comment: Change config to avoid the -p 443
|
Size: 1945
Comment:
|
| Deletions are marked like this. | Additions are marked like this. |
| Line 4: | Line 4: |
== How can I protect my @debian.org address from spam ? == Please read http://lists.debian.org/debian-devel-announce/2006/12/msg00010.html and http://lists.debian.org/debian-devel-announce/2006/12/msg00011.html |
?TableOfContents
Resources for Debian developers
How can I protect my @debian.org address from spam ?
Please read http://lists.debian.org/debian-devel-announce/2006/12/msg00010.html and http://lists.debian.org/debian-devel-announce/2006/12/msg00011.html
Is there a way to connect to Debian servers if the SSH port is firewalled?
The machine people.debian.org (currently gluck.debian.org) runs a SSH server on port 443 (usually the "https" port). If your firewall gives you access to this port (or if a proxy does it for you), then you can connect to your account. If you plan to use this access to connect to other Debian hosts, please don't run an ssh-agent on gluck and don't put your private SSH keys over there. Instead you're strongly advised to customize your ~/.ssh/config file and create special entries to connect to other Debian machines.
Direct access to external machines via port 443 allowed
With the sample config below, you can do "ssh master.overgluck" to connect to master.debian.org via gluck's SSH server running on port 443.
Host gluck.debian.org people.debian.org gluck
Port 443
ForwardAgent no
ForwardX11 no
Host *.overgluck
ProxyCommand ssh -q -a -x gluck.debian.org 'nc -w1 $(basename %h .overgluck) 22'
ForwardAgent no
ForwardX11 no
Direct access forbidden, going through a proxy
If you have to go through an https proxy, you can install the connect-proxy package and use something like this in your ~/.ssh/config:
Host gluck.debian.org people.debian.org gluck
ProxyCommand connect-proxy -H <proxy>:<port> gluck.debian.org 443
ForwardAgent no
ForwardX11 no
Host *.overgluck
ProxyCommand ssh -q -a -x gluck.debian.org 'nc -w1 $(basename %h .overgluck) 22'
ForwardAgent no
ForwardX11 no(Reference: RT ticket [https://rt.debian.org/Ticket/Display.html?id=69 #69])
