home | list info | list archive | date index | thread index

Re: [OCLUG-Tech] ssh, X11 forwarding not working (CentOS 6.3)

We now use ssh -Y.


>From the ssh man page:

     -X      Enables X11 forwarding.  This can also be specified on a
per-host basis in a configuration file.

             X11 forwarding should be enabled with caution.  Users with the
ability to bypass file permissions on the remote host (for the user's X
authorization database) can access the local X11 display through the
forwarded con‐
             nection.  An attacker may then be able to perform activities
such as keystroke monitoring.

             For this reason, X11 forwarding is subjected to X11 SECURITY
extension restrictions by default.  Please refer to the ssh -Y option and
the ForwardX11Trusted directive in ssh_config(5) for more information.

     -x      Disables X11 forwarding.

     -Y      Enables trusted X11 forwarding.  Trusted X11 forwardings are
not subjected to the X11 SECURITY extension controls.

-- 
"*A child is a person who can't understand why someone would give away a
perfectly good kitten.*"
-- Doug Larson