mirror of
https://github.com/openwrt/openwrt.git
synced 2025-01-22 04:18:10 +00:00
dropbear: add config options for agent-forwarding support
* SSH agent forwarding might cause security issues, locally and on the jump machine (https://defn.io/2019/04/12/ssh-forwarding/). So allow to completely disabling it. * separate options for client and server * keep it enabled by default Signed-off-by: Sven Roederer <devel-sven@geroedel.de>
This commit is contained in:
parent
88a2ea41da
commit
5287defa1f
@ -95,6 +95,11 @@ config DROPBEAR_DBCLIENT
|
|||||||
bool "Build dropbear with dbclient"
|
bool "Build dropbear with dbclient"
|
||||||
default y
|
default y
|
||||||
|
|
||||||
|
config DROPBEAR_DBCLIENT_AGENTFORWARD
|
||||||
|
bool "Enable agent forwarding in dbclient"
|
||||||
|
default y
|
||||||
|
depends on DROPBEAR_DBCLIENT
|
||||||
|
|
||||||
config DROPBEAR_SCP
|
config DROPBEAR_SCP
|
||||||
bool "Build dropbear with scp"
|
bool "Build dropbear with scp"
|
||||||
default y
|
default y
|
||||||
@ -109,4 +114,8 @@ config DROPBEAR_ASKPASS
|
|||||||
|
|
||||||
Increases binary size by about 0.1 kB (MIPS).
|
Increases binary size by about 0.1 kB (MIPS).
|
||||||
|
|
||||||
|
config DROPBEAR_AGENTFORWARD
|
||||||
|
bool "Enable agent forwarding"
|
||||||
|
default y
|
||||||
|
|
||||||
endmenu
|
endmenu
|
||||||
|
@ -32,7 +32,8 @@ PKG_CONFIG_DEPENDS:= \
|
|||||||
CONFIG_DROPBEAR_CURVE25519 CONFIG_DROPBEAR_ZLIB \
|
CONFIG_DROPBEAR_CURVE25519 CONFIG_DROPBEAR_ZLIB \
|
||||||
CONFIG_DROPBEAR_ED25519 CONFIG_DROPBEAR_CHACHA20POLY1305 \
|
CONFIG_DROPBEAR_ED25519 CONFIG_DROPBEAR_CHACHA20POLY1305 \
|
||||||
CONFIG_DROPBEAR_UTMP CONFIG_DROPBEAR_PUTUTLINE \
|
CONFIG_DROPBEAR_UTMP CONFIG_DROPBEAR_PUTUTLINE \
|
||||||
CONFIG_DROPBEAR_DBCLIENT CONFIG_DROPBEAR_SCP CONFIG_DROPBEAR_ASKPASS
|
CONFIG_DROPBEAR_DBCLIENT CONFIG_DROPBEAR_SCP CONFIG_DROPBEAR_ASKPASS \
|
||||||
|
CONFIG_DROPBEAR_DBCLIENT_AGENTFORWARD CONFIG_DROPBEAR_AGENTFORWARD
|
||||||
|
|
||||||
include $(INCLUDE_DIR)/package.mk
|
include $(INCLUDE_DIR)/package.mk
|
||||||
|
|
||||||
@ -135,6 +136,8 @@ DB_OPT_CONFIG = \
|
|||||||
!!DROPBEAR_ECC_384|CONFIG_DROPBEAR_ECC_FULL|1|0 \
|
!!DROPBEAR_ECC_384|CONFIG_DROPBEAR_ECC_FULL|1|0 \
|
||||||
!!DROPBEAR_ECC_521|CONFIG_DROPBEAR_ECC_FULL|1|0 \
|
!!DROPBEAR_ECC_521|CONFIG_DROPBEAR_ECC_FULL|1|0 \
|
||||||
DROPBEAR_CLI_ASKPASS_HELPER|CONFIG_DROPBEAR_ASKPASS|1|0 \
|
DROPBEAR_CLI_ASKPASS_HELPER|CONFIG_DROPBEAR_ASKPASS|1|0 \
|
||||||
|
DROPBEAR_CLI_AGENTFWD|CONFIG_DROPBEAR_DBCLIENT_AGENTFORWARD|1|0 \
|
||||||
|
DROPBEAR_SVR_AGENTFWD|CONFIG_DROPBEAR_AGENTFORWARD|1|0 \
|
||||||
|
|
||||||
|
|
||||||
TARGET_CFLAGS += -DARGTYPE=3 -ffunction-sections -fdata-sections -flto
|
TARGET_CFLAGS += -DARGTYPE=3 -ffunction-sections -fdata-sections -flto
|
||||||
|
Loading…
Reference in New Issue
Block a user