<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to check SSH-agent forwarding in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-SSH-agent-forwarding/m-p/222015#M42553</link>
    <description>&lt;P&gt;That's only relevant when using the system as an SSH client. Check the &lt;A href="https://man.openbsd.org/ssh_config" target="_self"&gt;client config files&lt;/A&gt;. Agent forwarding is disabled by default, so if it isn't explicitly enabled in a client config file, it's not enabled. By default, the relevant files are:&lt;/P&gt;
&lt;P&gt;/etc/ssh/ssh_config&lt;/P&gt;
&lt;P&gt;~/.ssh/config&lt;/P&gt;</description>
    <pubDate>Fri, 26 Jul 2024 14:12:28 GMT</pubDate>
    <dc:creator>Bob_Zimmerman</dc:creator>
    <dc:date>2024-07-26T14:12:28Z</dc:date>
    <item>
      <title>How to check SSH-agent forwarding</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-SSH-agent-forwarding/m-p/222006#M42551</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;TABLE border="1" width="925px" cellspacing="4" cellpadding="5"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD width="79.9531px"&gt;&lt;A href="https://access.redhat.com/security/cve/CVE-2023-38408" target="_blank" rel="noopener"&gt;CVE-2023-38408&lt;/A&gt;&lt;/TD&gt;&lt;TD width="844.047px"&gt;Not vulnerable - This CVE relates to forwarding the SSH-agent to an attacker's controlled system. We do not use SSH-agent forwarding in Gaia OS.&lt;BR /&gt;Note: You may configure SSH-agent forwarding manually, though this may be vulnerable. We will release a fix once it is available from Redhat. In the meantime, customers that manually configured SSH-agent forwarding should review their configuration and make sure it is only forwarded to safe locations.&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How to check whether SSH-agent forwarding is configured or not?&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 12:47:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-SSH-agent-forwarding/m-p/222006#M42551</guid>
      <dc:creator>tavi0906</dc:creator>
      <dc:date>2024-07-26T12:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: How to check SSH-agent forwarding</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-SSH-agent-forwarding/m-p/222015#M42553</link>
      <description>&lt;P&gt;That's only relevant when using the system as an SSH client. Check the &lt;A href="https://man.openbsd.org/ssh_config" target="_self"&gt;client config files&lt;/A&gt;. Agent forwarding is disabled by default, so if it isn't explicitly enabled in a client config file, it's not enabled. By default, the relevant files are:&lt;/P&gt;
&lt;P&gt;/etc/ssh/ssh_config&lt;/P&gt;
&lt;P&gt;~/.ssh/config&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jul 2024 14:12:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-check-SSH-agent-forwarding/m-p/222015#M42553</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-07-26T14:12:28Z</dc:date>
    </item>
  </channel>
</rss>

