keygen
ssh-keygen -b 4096
ssh-keygen -R host # remove host from `known_hosts`
ssh-keygen -p # change password for existing key
ssh-agent
ssh-add # add identity to agent
ssh-add -l # list identities in agent, `-L` gives actual keys
ssh-add -D # remove all identities from agent
master connection
<login> is how connection was made, usually it is user@host.
ssh -O check <login>
ssh -O cancel <login>
ssh -O exit <login>
ssh -O stop <login> # stop accepting new connections without killing current ones
x forwarding
ssh -CY
- -C enables compression
- -Y disables X11 SECURITY extension restrictions
socks proxy
ssh -D 9999 hbschr@hbschr.de
configure firefox to use network SOCKS 5 proxy on localhost:9999
sshfs via fuse
mount point should belong to user.
will be mounted as fs fuse.sshfs, specific options like btrfs subvolumes are not accessible.
sshfs heiko@loki:/ /mnt/loki/
host based identity
# in config
Host host
IdentityFile ~/.ssh/id_host
misc
- cipher: symmetric key, f.e. aes
- mac: message authentication code
- kex: key exchange, f.e. dh
- key: asymmetric key
ssh -Q cipher
ssh -Q mac
ssh -Q kex
ssh -Q key