SSH from local to intermediate host to final

The name of the pictureThe name of the pictureThe name of the pictureClash Royale CLAN TAG#URR8PPP











up vote
0
down vote

favorite












I am using a jump server to connect to a final host with this command:



ssh -t intermediate ssh final


but I want it to work with a normal ssh or scp command, so I have tried to setup the config in .ssh/config:



Host final
ProxyCommand ssh -o 'ForwardAgent yes' intermediate 'ssh-add && nc %h %p'


this works, but there is one big dilemma. Intermediate's security policy requires me to password protect .ssh/id_rsa. When I add a password to it I can no longer use the command, as it does not ask me for a password, but rather assume it is empty.



  • I have to authenticate to intermediate using a password (key not possible)

  • intermediate has to authenticate to final using the keyfile








share

























    up vote
    0
    down vote

    favorite












    I am using a jump server to connect to a final host with this command:



    ssh -t intermediate ssh final


    but I want it to work with a normal ssh or scp command, so I have tried to setup the config in .ssh/config:



    Host final
    ProxyCommand ssh -o 'ForwardAgent yes' intermediate 'ssh-add && nc %h %p'


    this works, but there is one big dilemma. Intermediate's security policy requires me to password protect .ssh/id_rsa. When I add a password to it I can no longer use the command, as it does not ask me for a password, but rather assume it is empty.



    • I have to authenticate to intermediate using a password (key not possible)

    • intermediate has to authenticate to final using the keyfile








    share























      up vote
      0
      down vote

      favorite









      up vote
      0
      down vote

      favorite











      I am using a jump server to connect to a final host with this command:



      ssh -t intermediate ssh final


      but I want it to work with a normal ssh or scp command, so I have tried to setup the config in .ssh/config:



      Host final
      ProxyCommand ssh -o 'ForwardAgent yes' intermediate 'ssh-add && nc %h %p'


      this works, but there is one big dilemma. Intermediate's security policy requires me to password protect .ssh/id_rsa. When I add a password to it I can no longer use the command, as it does not ask me for a password, but rather assume it is empty.



      • I have to authenticate to intermediate using a password (key not possible)

      • intermediate has to authenticate to final using the keyfile








      share













      I am using a jump server to connect to a final host with this command:



      ssh -t intermediate ssh final


      but I want it to work with a normal ssh or scp command, so I have tried to setup the config in .ssh/config:



      Host final
      ProxyCommand ssh -o 'ForwardAgent yes' intermediate 'ssh-add && nc %h %p'


      this works, but there is one big dilemma. Intermediate's security policy requires me to password protect .ssh/id_rsa. When I add a password to it I can no longer use the command, as it does not ask me for a password, but rather assume it is empty.



      • I have to authenticate to intermediate using a password (key not possible)

      • intermediate has to authenticate to final using the keyfile






      ssh ssh-tunneling





      share












      share










      share



      share










      asked 1 min ago









      Vegard

      1112




      1112

























          active

          oldest

          votes











          Your Answer








          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "106"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          convertImagesToLinks: false,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: null,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













           

          draft saved


          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f479061%2fssh-from-local-to-intermediate-host-to-final%23new-answer', 'question_page');

          );

          Post as a guest



































          active

          oldest

          votes













          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes















           

          draft saved


          draft discarded















































           


          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2funix.stackexchange.com%2fquestions%2f479061%2fssh-from-local-to-intermediate-host-to-final%23new-answer', 'question_page');

          );

          Post as a guest













































































          Popular posts from this blog

          How to check contact read email or not when send email to Individual?

          Bahrain

          Postfix configuration issue with fips on centos 7; mailgun relay