Fix ssh-config short-lived-cert for subpath-ed hostnames
Fixes https://github.com/cloudflare/cloudflared/issues/923
This commit is contained in:
parent
39ed5dc182
commit
653bf87197
|
@ -40,8 +40,8 @@ Add to your {{.Home}}/.ssh/config:
|
||||||
{{- if .ShortLivedCerts}}
|
{{- if .ShortLivedCerts}}
|
||||||
Match host {{.Hostname}} exec "{{.Cloudflared}} access ssh-gen --hostname %h"
|
Match host {{.Hostname}} exec "{{.Cloudflared}} access ssh-gen --hostname %h"
|
||||||
ProxyCommand {{.Cloudflared}} access ssh --hostname %h
|
ProxyCommand {{.Cloudflared}} access ssh --hostname %h
|
||||||
IdentityFile ~/.cloudflared/%h-cf_key
|
IdentityFile ~/.cloudflared/{{.SSHCertFilePath}}-cf_key
|
||||||
CertificateFile ~/.cloudflared/%h-cf_key-cert.pub
|
CertificateFile ~/.cloudflared/{{.SSHCertFilePath}}-cf_key-cert.pub
|
||||||
{{- else}}
|
{{- else}}
|
||||||
Host {{.Hostname}}
|
Host {{.Hostname}}
|
||||||
ProxyCommand {{.Cloudflared}} access ssh --hostname %h
|
ProxyCommand {{.Cloudflared}} access ssh --hostname %h
|
||||||
|
@ -365,10 +365,11 @@ func sshConfig(c *cli.Context) error {
|
||||||
ShortLivedCerts bool
|
ShortLivedCerts bool
|
||||||
Hostname string
|
Hostname string
|
||||||
Cloudflared string
|
Cloudflared string
|
||||||
|
SSHCertFilePath string
|
||||||
}
|
}
|
||||||
|
|
||||||
t := template.Must(template.New("sshConfig").Parse(sshConfigTemplate))
|
t := template.Must(template.New("sshConfig").Parse(sshConfigTemplate))
|
||||||
return t.Execute(os.Stdout, config{Home: os.Getenv("HOME"), ShortLivedCerts: genCertBool, Hostname: hostname, Cloudflared: cloudflaredPath()})
|
return t.Execute(os.Stdout, config{Home: os.Getenv("HOME"), ShortLivedCerts: genCertBool, Hostname: hostname, Cloudflared: cloudflaredPath(), SSHCertFilePath: token.GenerateSSHCertFilePathFromURL(url.Parse(ensureURLScheme(hostname)), sshgen.keyName)})
|
||||||
}
|
}
|
||||||
|
|
||||||
// sshGen generates a short lived certificate for provided hostname
|
// sshGen generates a short lived certificate for provided hostname
|
||||||
|
|
Loading…
Reference in New Issue