SSH gateway to an OpenSSH server
Connect with a regular SSH client to Bifröst and open a shell on a private OpenSSH server. Bifröst authenticates the incoming connection, then makes a separate SSH connection to the target. It is not a transparent proxy.
This Linux example requires a running Bifröst host service, an existing target-user account on target.example.org, and two distinct SSH keys: the client's key for Bifröst and Bifröst's key for the target.
Prepare the two connections
- Put the client's public key in
/etc/engity/bifroest/gateway-clients.pubon the gateway. Keep the corresponding private key on the client. -
On the gateway, create a separate key for the target connection:
1 2 3
sudo bifroest key generate \ --identityFile /etc/engity/bifroest/id_target \ --publicFile /etc/engity/bifroest/id_target.pubAdd
id_target.pubtotarget-user's~/.ssh/authorized_keyson the target. The private key stays on the gateway. 3. Verify the target host-key fingerprint through a trusted channel, then import that host key on the gateway:1 2 3 4
sudo bifroest key import host \ --knownHostsFile /etc/engity/bifroest/target_known_hosts \ --address target.example.org \ --expectedFingerprint SHA256:REPLACE_WITH_VERIFIED_FINGERPRINTDo not use
--expectedFingerprint unknownfor a production target. The fingerprint must match the host key negotiated by this command.
Configure Bifröst
Replace the host service's /etc/engity/bifroest/configuration.yaml with the following configuration, using your actual target address and account. Keep access to the gateway through another channel while changing its SSH service.
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | |
Restart Bifröst (sudo systemctl restart bifroest.service), then connect from the client:
1 2 | |
The expected output is target-user. Check Bifröst's own host key with the gateway administrator on first connection; it is not the target's host key. No Bifröst account named gateway is needed: simple matches the incoming SSH name and its public key. If the target connection fails, first check the target account's authorized_keys and the verified knownHostsFile.
The example disables port forwarding. SFTP is allowed by default only if the target accepts it; the gateway does not forward arbitrary SSH session requests. For user certificates or Bifröst-to-Bifröst delegation, see the SSH environment reference.