Guilhem Moulin 2020-12-12 11:29:02 +0100
2020-12-12 11:45:24 +0100
commit22ef303cdc7b6d5f7de35d3189fbf157093c258e (patch)
parent4d2ad4a3c2b6bcdb97934264bc3d37a8c63239d4 (diff)
README: use 'restrict' option in authorized_keys(5) snippet.
This is shorter and more future-proof. Quoting the manual: restrict Enable all restrictions, i.e. disable port, agent and X11 forwarding, as well as disabling PTY allocation and execution of ~/.ssh/rc. If any future restriction capabilities are added to authorized_keys files they will be included in this set. Note that this won't work with Jessie's OpenSSH server.
configuration file (the default as of, hence running TLS
tests now require Dovecot 2.3 or later.
- documentation: simplify SSL options in the sample configuration files.
+ - README: suggest 'restrict,command="/usr/bin/doveadm exec imap"' as
+ authorized_keys(5) options.
-- Guilhem Moulin <guilhem@fripost.org> Fri, 11 Dec 2020 14:55:53 +0100
Compression yes
remote: ~user/.ssh/authorized_keys:
- command="/usr/lib/dovecot/imap",no-agent-forwarding,no-port-forwarding,no-pty,no-user-rc,no-X11-forwarding ssh-... id-interimap
+ restrict,command="/usr/bin/doveadm exec imap" ssh-[…] id-interimap
However for long-lived connections (using the --watch command-line
option), the TLS overhead becomes negligible hence the advantage offered