Skip to content

Enable SSH agent forwarding for scp #6600

Description

@BrHal

Hello,

As a specific security requirement, on my lab,
SSH authentication is performed thru a tool named "BalaBit - Shell Control Box (SCB)", which supports SSH agent forwarding.
However, this security tool has a flaw in its current release : it is unable to fallback to ssh interactive password when authentication is set to ssh key exchange.

Therefore, I must use SSH key authentication and agent forwarding.
In addition, hosts I connect to have no internet connection, thus : localServerDownload
Last but not least, I must use cygwin ssh because activating windows openssh forward agent requires admin rights on laptop, I don't have them.

All this works OK for remote ssh editing but the upload of vscode-server fails because scp ignores ForwardAgent ssh directive in config file unless "-A" flag is present on the cmd line.

I am using following explicit remote SSH Setup :
{
"remote.SSH.configFile": "path_to_my_ssh_config",
"remote.SSH.localServerDownload": "always",
"remote.SSH.showLoginTerminal": true,
"remote.SSH.logLevel": "trace",
}
all other options are on default values, including remote.SSH.enableAgentForwarding : true

To overcome this issue, some extra remote.SSH setting for scp command should be useful in this case...
say:
Remote.SSH.scpExtraOptions: "-A" default ""

Activity

  1. changed the title [-]Issue with forwardAgent[/-] [+]Remote-SSH: Add setting for SCP options to pass in additional flags like -A[/+] on Apr 12, 2022
  2. vscode-triage-bot commented on Apr 12, 2022

    @vscode-triage-bot
    Collaborator

    This feature request is now a candidate for our backlog. The community has 60 days to upvote the issue. If it receives 10 upvotes we will move it to our backlog. If not, we will close it. To learn more about how we handle feature requests, please see our documentation.

    Happy Coding!

  3. tanhakabir commented on Apr 12, 2022

    @tanhakabir

    scp ignores ForwardAgent ssh directive in config file unless "-A" flag is present on the cmd line.

    How do you know this is the case?

  4. BrHal commented on Apr 13, 2022

    @BrHal
    Author

    How do you know this is the case?

    Ran tests on my lab, - sorry not showing because of sensitive details - plus found a rel note there :

    https://www.openssh.com/txt/release-8.4

    • scp(1), sftp(1): allow the -A flag to explicitly enable agent
      forwarding in scp and sftp. The default remains to not forward an
      agent, even when ssh_config enables it.
  5. modified the milestones: Backlog Candidates, , Backlog on Apr 13, 2022
  6. tanhakabir commented on Apr 13, 2022

    @tanhakabir

    Ah I see, seems reasonable to add a setting to add the -A flag on scp.

  7. changed the title [-]Remote-SSH: Add setting for SCP options to pass in additional flags like -A[/-] [+]Enable SSH agent forwarding for scp[/+] on Dec 17, 2022
  8. etozhecyber commented on Oct 23, 2023

    @etozhecyber

    I have found a workaround for this problem
    echo "alias scp='scp -A'" > .bash_profile

  9. joshspicer commented on Dec 13, 2024

    @joshspicer
    Contributor

    enableAgentForwarding is enabled by default, and for security reasons I don't think we'd want to always forward the agent through scp. If adding this we may want to detect if the host's configuration has ForwardAgent yes, and from there add the -A to scp

  10. removed their assignment
    on Sep 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    feature-requestRequest for new features or functionalitysshIssue in vscode-remote SSH

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions