bastion.md 3.8 KB

% Bastion

Installation

Installation en cours: Devuan

ssh bastion

Provisoire

lauhub@ecaz:~$ sudo -u mat nano /home/mat/.bashrc
lauhub@ecaz:~$ sudo -u mat tail -1 /home/mat/.bashrc
PATH=/opt/restricted/bin

lauhub@ecaz:~$ sudo mkdir /opt/restricted/bin
mkdir: cannot create directory ‘/opt/restricted/bin’: No such file or directory
lauhub@ecaz:~$ sudo mkdir -p /opt/restricted/bin
lauhub@ecaz:~$ cd /opt/restricted/bin
lauhub@ecaz:/opt/restricted/bin$ ln -s $(which ssh)
ln: failed to create symbolic link './ssh': Permission denied
lauhub@ecaz:/opt/restricted/bin$ sudo ln -s $(which ssh)
lauhub@ecaz:/opt/restricted/bin$ ll
total 0
lrwxrwxrwx 1 root root 12 Sep 21 02:23 ssh -> /usr/bin/ssh
lauhub@ecaz:/opt/restricted/bin$ cd -
/home/lauhub

sshd_config

Match User mat
   AllowAgentForwarding no
   AllowTcpForwarding yes
   X11Forwarding no
   PermitTunnel no
   GatewayPorts no
   ForceCommand echo 'This account can only be used for ProxyJump (ssh -J)'

TODO

Sécurisation (ajouts possibles)

Webographie

Certificats

Autres solutions

Comment configurer un serveur Bastion avec Warpgate sur Debian