Repository navigation
Enable SSH agent forwarding for scp #6600
Description
Activity
- addedfeature-requestRequest for new features or functionalityRequest for new features or functionality
on Apr 12, 2022 - changed the title
[-]Issue with forwardAgent[/-][+]Remote-SSH: Add setting for SCP options to pass in additional flags like -A[/+]on Apr 12, 2022 - added this to the Backlog Candidates milestone
on Apr 12, 2022 vscode-triage-bot commented
on Apr 12, 2022 CollaboratorMore actionsThis feature request is now a candidate for our backlog. The community has 60 days to upvote the issue. If it receives 10 upvotes we will move it to our backlog. If not, we will close it. To learn more about how we handle feature requests, please see our documentation.
Happy Coding!
scp ignores ForwardAgent ssh directive in config file unless "-A" flag is present on the cmd line.
How do you know this is the case?
How do you know this is the case?
Ran tests on my lab, - sorry not showing because of sensitive details - plus found a rel note there :
https://www.openssh.com/txt/release-8.4
- scp(1), sftp(1): allow the -A flag to explicitly enable agent
forwarding in scp and sftp. The default remains to not forward an
agent, even when ssh_config enables it.
- scp(1), sftp(1): allow the -A flag to explicitly enable agent
- modified the milestones: Backlog Candidates, This milestone has been deleted, Backlog
on Apr 13, 2022 Ah I see, seems reasonable to add a setting to add the -A flag on scp.
- changed the title
[-]Remote-SSH: Add setting for SCP options to pass in additional flags like -A[/-][+]Enable SSH agent forwarding for scp[/+]on Dec 17, 2022 I have found a workaround for this problem
echo "alias scp='scp -A'" > .bash_profileReacted by joshspicerenableAgentForwardingis enabled by default, and for security reasons I don't think we'd want to always forward the agent through scp. If adding this we may want to detect if the host's configuration hasForwardAgent yes, and from there add the-Ato scp
Hello,
As a specific security requirement, on my lab,
SSH authentication is performed thru a tool named "BalaBit - Shell Control Box (SCB)", which supports SSH agent forwarding.
However, this security tool has a flaw in its current release : it is unable to fallback to ssh interactive password when authentication is set to ssh key exchange.
Therefore, I must use SSH key authentication and agent forwarding.
In addition, hosts I connect to have no internet connection, thus : localServerDownload
Last but not least, I must use cygwin ssh because activating windows openssh forward agent requires admin rights on laptop, I don't have them.
All this works OK for remote ssh editing but the upload of vscode-server fails because scp ignores ForwardAgent ssh directive in config file unless "-A" flag is present on the cmd line.
I am using following explicit remote SSH Setup :
{
"remote.SSH.configFile": "path_to_my_ssh_config",
"remote.SSH.localServerDownload": "always",
"remote.SSH.showLoginTerminal": true,
"remote.SSH.logLevel": "trace",
}
all other options are on default values, including remote.SSH.enableAgentForwarding : true
To overcome this issue, some extra remote.SSH setting for scp command should be useful in this case...
say:
Remote.SSH.scpExtraOptions: "-A" default ""