<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.ubc.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=GarsonSam</id>
	<title>UBC Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.ubc.ca/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=GarsonSam"/>
	<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/Special:Contributions/GarsonSam"/>
	<updated>2026-10-04T15:22:34Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.43.10</generator>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=904262</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=904262"/>
		<updated>2026-09-15T06:35:05Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: Added information about generating keys within the KRP.&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) provides an SSH tunnel between UBC &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; and Internal &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.  Once the connection via the SSH Proxy Pool to the SSH Destination Host is established, then other protocols may be emitted from the SSH Destination Host at the discretion of the SSH Destination Host system administrator.  This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.&lt;br /&gt;
&lt;br /&gt;
It does not:&lt;br /&gt;
&lt;br /&gt;
* allow other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039;&lt;br /&gt;
* provide a full replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].&lt;br /&gt;
* provide any user control or management of accounts or authentication on SSH Destination Hosts&lt;br /&gt;
* provide an approved method for administration of systems over SSH using privileged accounts.  Remote SSH systems administration with privileged accounts should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
[[File:Sshproxyservicescope.png|frameless|931x931px]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Address&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool - UBC Vancouver&lt;br /&gt;
|p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
142.103.90.160/28&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
|443&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|}&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || If you are a server administrator who would like to provide access to a server through the SSH Proxy Service, please see the &#039;&#039;&#039;Information for System Administrators and Destination Host Administrators&#039;&#039;&#039; section at the bottom of this page.&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* CWL accounts with MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* CWL usernames with SSH keys.&lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* CWL with MFA is required to register SSH keys at https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || At this time, there is no key expiration on SSH keys, but this may change in the future.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Best practices:&lt;br /&gt;
&lt;br /&gt;
* Do not reuse an existing SSH key pair for the SSH Proxy Service unless there is a specific operational requirement to do so.&lt;br /&gt;
* SSH keys consist of two parts: a &#039;&#039;&#039;private key&#039;&#039;&#039; and a &#039;&#039;&#039;public key&#039;&#039;&#039;.&lt;br /&gt;
* The &#039;&#039;&#039;public key&#039;&#039;&#039; is intended to be shared with systems that need to authenticate you.  &lt;br /&gt;
* The &#039;&#039;&#039;private key&#039;&#039;&#039; must remain confidential and be protected at all times.&lt;br /&gt;
* Never copy your private key to another system unless it is one of your own trusted workstations or secure physical storage devices [such as encrypted disks or hardware security tokens].  If you must copy a private key, protect it with a strong passphrase.&lt;br /&gt;
* When SSH keys are used for automated, non-interactive authentication between systems, passphrase-less private keys may be appropriate.&lt;br /&gt;
* Automation keys should be unique to their intended purpose.  Each distinct use case [for example, a different service, application, or automation script] should have its own dedicated SSH key pair.  Do not reuse automation keys across multiple services or workflows.&lt;br /&gt;
&lt;br /&gt;
=== SSH Key Generation ===&lt;br /&gt;
Keys should be generated following the Mozilla [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Keys may be generated within the SSH Proxy Registration Portal (Add New SSH Key -&amp;gt; Generate Key)&lt;br /&gt;
&lt;br /&gt;
* The &amp;quot;Generate&amp;quot; button will generate a new key using your browser (you must then save the private key; the Key Registration Portal does not get a copy of your private key).&lt;br /&gt;
* After generating the key, the &amp;quot;Save&amp;quot; button will save it in your profile.&lt;br /&gt;
&lt;br /&gt;
Keys may also be generated outside of the SSH Proxy Registration Portal and then uploaded to the SSH Proxy Registration Portal&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsshp_$(date +%Y%m%d) -C &amp;quot;UBC key for SSHP&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
This creates one keypair consisting of a public and a private key.  Register the &#039;&#039;&#039;public&#039;&#039;&#039; key in the SSH Proxy Key Registration Portal - &#039;&#039;&#039;NOT the private key&#039;&#039;&#039;.  &lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SSHP ===&lt;br /&gt;
Connecting through SSHP Proxy Pool p01.sshp.cybersecurity.ubc.ca interactively with SSH to the Destination Host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.cybersecurity.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to &#039;&#039;&#039;foo.ubc.ca&#039;&#039;&#039; as user &#039;&#039;&#039;jbdoe-dest&#039;&#039;&#039; using CWL username &#039;&#039;&#039;jbdoe-cwl&#039;&#039;&#039; via SSHP:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.cybersecurity.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (SSH Key-based) Auth to SSHP ===&lt;br /&gt;
Connecting through SSHP using SSH key-based auth requires you first create an SSHP Proxy Pool-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsshp_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the [https://sshp.cybersecurity.ubc.ca/ SSH Proxy Key Registration Portal].&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is your CWL username. If you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.cybersecurity.ubc.ca).&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Key Registration Portal, the private key will be used during the authentication with the SSH Proxy Pool, and you will not be required to perform an interactive login with the SSH Proxy Pool -- however, you will still need to authenticate with the SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.cybersecurity.ubc.ca jdoe-dest@ssh-target.misc.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Repeated failed authentication attempts within a short period of time&lt;br /&gt;
 may result in a temporary network block affecting access to this&lt;br /&gt;
 proxy service from your source IP address.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 ---------------------------------------------------------------------&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsshp_20221206&#039;:&lt;br /&gt;
 SSH Proxy Session ID: ITSO-A4E59.2176796&lt;br /&gt;
 &lt;br /&gt;
 SSH Proxy Pool login successful.&lt;br /&gt;
 &lt;br /&gt;
 =====================================================================&lt;br /&gt;
 DESTINATION HOST SESSION BEGINS BELOW THIS LINE&lt;br /&gt;
 For further assistance, contact the destination host administrator.&lt;br /&gt;
 =====================================================================&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     6 Security notice(s)&lt;br /&gt;
         3 Important Security notice(s)&lt;br /&gt;
         2 Medium Security notice(s)&lt;br /&gt;
         1 Low Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last failed login: Fri May 15 23:26:30 UTC 2026 from 10.93.46.42 on ssh:notty&lt;br /&gt;
 There was 1 failed login attempt since the last successful login.&lt;br /&gt;
 Last login: Fri May 15 22:29:02 2026 from 10.93.46.42&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$&lt;br /&gt;
&lt;br /&gt;
=== SSH Port Forwarding through SSHP ===&lt;br /&gt;
SSH port forwarding [also known as SSH tunneling] may be used through the SSH Proxy Service provided that the tunnel terminates on an authorized SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
The SSH Proxy Service does not permit SSH Proxy Hosts to be used as port forwarding endpoints.  However, once a connection to an SSH Destination Host has been established through the SSH Proxy Service, standard SSH port forwarding features, if supported by the SSH Destination Host, remain available.&lt;br /&gt;
&lt;br /&gt;
For an introduction to SSH tunneling concepts and usage patterns, see:&lt;br /&gt;
&lt;br /&gt;
* [https://help.ubuntu.com/community/SSH/OpenSSH/PortForwarding Ubuntu Community Documentation: SSH/OpenSSH/PortForwarding]&lt;br /&gt;
* [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Tunnels Wikibooks OpenSSH/Cookbook/Tunnels]&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Create a local tunnel to www.ubc.ca:443 through an SSH Destination Host:&lt;br /&gt;
 ssh -N -J &amp;lt;cwlusername&amp;gt;@p01.sshp.cybersecurity.ubc.ca -L 8443:www.ubc.ca:443 \&lt;br /&gt;
   &amp;lt;destination_username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
The resulting traffic path is: &lt;br /&gt;
&lt;br /&gt;
User Workstation:8443 ==&amp;gt; SSH Proxy Host ==&amp;gt; SSH Destination Host ==&amp;gt; www.ubc.ca:443&lt;br /&gt;
&lt;br /&gt;
The SSH tunnel is established on the SSH Destination Host.  Any outbound connections generated by the tunnel originate from the SSH Destination Host and are subject to the policies, network controls, and authorization decisions of the SSH Destination Host administrator.&lt;br /&gt;
&lt;br /&gt;
==== Limitation ====&lt;br /&gt;
SSH Proxy Hosts cannot be used as general-purpose TCP forwarding endpoints.&lt;br /&gt;
&lt;br /&gt;
For example, the following connection attempt is not permitted and will fail because it does not use the destination as the tunnel endpoint - it uses the proxy host itself:&lt;br /&gt;
 ssh -N -L 8443:www.ubc.ca:443 &amp;lt;cwlusername&amp;gt;@p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
When traffic attempts to use the tunnel, the SSH client will receive an error similar to:&lt;br /&gt;
 channel 2: open failed: administratively prohibited: open failed&lt;br /&gt;
This behavior is intentional and prevents SSH Proxy Hosts from being used as generic network relays.&lt;br /&gt;
&lt;br /&gt;
=== Using SSHP via ssh config === &lt;br /&gt;
Connecting with SSH to a Destination Host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.cybersecurity.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SSHP Proxy Pool that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SSHP Proxy Pool p01.sshp.cybersecurity.ubc.ca with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections to the Destination Host through SSHP from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SSHP with an SSHP-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SSHP.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsshp_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your CWL password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SSHP for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SSHP):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SSHP for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SSHP Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.cybersecurity.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SSHP: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.cybersecurity.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SSHP: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SSHP: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SSHP: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsshp_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SSHP: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsshp_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match Host *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SSHP: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Silent mode: Suppressing proxy-side output for non-interactive workflows ===&lt;br /&gt;
The SSH Proxy banner and SSH Proxy Session ID are displayed on STDERR - you can see them, but they do not appear on STDOUT, so the majority of non-interactive workflows will not capture them or be affected by them [eg: &amp;gt; or &amp;gt;&amp;gt; redirects].&lt;br /&gt;
&lt;br /&gt;
However, should you encounter difficulty with the banner or the SSH Proxy Session ID being displayed, you can suppress them following the instructions below.&lt;br /&gt;
&lt;br /&gt;
==== Banner Suppression ====&lt;br /&gt;
To suppress the banner that is displayed when you connect to the service, you can disable the &#039;&#039;&#039;Display SSH Banner&#039;&#039;&#039; option in the Key Registration Portal.  &lt;br /&gt;
&lt;br /&gt;
==== SSH Proxy Session ID Suppression ====&lt;br /&gt;
To suppress the SSH Proxy Session ID that is displayed when you connect to the service, you can disable the &#039;&#039;&#039;Display SSH Proxy Session ID&#039;&#039;&#039; option in the Key Registration Portal.  If you need support, you may be asked to re-enable this feature to allow us to assist you with troubleshooting.&lt;br /&gt;
&lt;br /&gt;
==== Full Suppression Workaround [Unsupported] ====&lt;br /&gt;
Some non-interactive workflows require clean STDOUT/STDERR from the SSH Destination Host, such as database dumps, scripts, rsync-like tools, or SSH used as a transport.  You can use this workaround but please note that it is not supported - we cannot provide assistance to users with this workaround.&lt;br /&gt;
&lt;br /&gt;
Avoid suppressing STDERR on the outer SSH command, for example:&lt;br /&gt;
&lt;br /&gt;
  ssh destination-host &#039;mysqldump ...&#039; 2&amp;gt;/dev/null&lt;br /&gt;
&lt;br /&gt;
This suppresses all STDERR from the SSH command, including useful errors from the destination host or remote command.&lt;br /&gt;
&lt;br /&gt;
Instead, use ProxyCommand to suppress STDERR &#039;&#039;&#039;only&#039;&#039;&#039; from the SSH Proxy Pool connection:&lt;br /&gt;
&lt;br /&gt;
  Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
      User &amp;lt;cwlusername&amp;gt;&lt;br /&gt;
      IdentityFile ~/.ssh/id_ed25519_ubcsshp_20221206&lt;br /&gt;
&lt;br /&gt;
  Host destination-host&lt;br /&gt;
      User &amp;lt;destination_username&amp;gt;&lt;br /&gt;
      ProxyCommand ssh p01.sshp.cybersecurity.ubc.ca -W %h:%p 2&amp;gt;/dev/null&lt;br /&gt;
&lt;br /&gt;
With this pattern, proxy-side banner/session output is suppressed, while STDERR from the SSH Destination Host and remote command is still displayed.&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&#039;&#039;&#039;Error Message&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Was SSH Proxy Session ID† Displayed&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Was Destination Host Notice‡ Displayed&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Probable Causes&#039;&#039;&#039;&lt;br /&gt;
!&#039;&#039;&#039;Correction&#039;&#039;&#039;&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 Error 500: SSH Proxy Service error. Submit a ticket at &amp;lt;nowiki&amp;gt;https://it.ubc.ca/selfservice&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by &amp;lt;ip address&amp;gt; port 22&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|SSH Proxy Service server-side error.&lt;br /&gt;
|This is a service error that has to be corrected by the SSH Proxy Service administrators.  Submit a ticket to notify us of the error.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 Error 503: SSH Proxy Service is currently offline.  Please try again later.&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by &amp;lt;ip address&amp;gt; port 22&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|SSH Proxy Service has been intentionally taken offline.&lt;br /&gt;
|Try again later, watch status.it.ubc.ca for updates.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 &amp;lt;after three password attempts&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 jdoe@p01.sshp.devl.infosec.it.ubc.ca: Permission denied (publickey,keyboard-interactive).&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Invalid CWL username or password.&lt;br /&gt;
|Check to ensure that your username and password are valid.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jdoe&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Account is enrolled in Duo MFA, but does not have a license for Duo.&lt;br /&gt;
|Submit a ticket to request a Duo MFA license.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 &amp;lt;SSH key provided as authentication parameter&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|&#039;&#039;&#039;Cause 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Public SSH key is not registered in portal.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cause 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Public SSH key is registered in portal, but hasn&#039;t been pushed to the proxy pool yet.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cause 3&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Private SSH key cannot be read.&lt;br /&gt;
|&#039;&#039;&#039;Correction 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Register public SSH key in portal.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Correction 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Wait 2-5 minutes, try again.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Correction 3&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Ensure that permissions on your private SSH key are correct.  See this video for more information.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 no such identity: &amp;lt;filename&amp;gt;: No such file or directory&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Private SSH key does not exist.&lt;br /&gt;
|Check name for typo, check to ensure file exists as displayed.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 no such identity: &amp;lt;filename&amp;gt;: Permission denied&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Permissions on directory holding private key is too restrictive.&lt;br /&gt;
|Set permissions on key directory to be readable by current user.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
 &lt;br /&gt;
 @         WARNING: UNPROTECTED PRIVATE KEY FILE!          @&lt;br /&gt;
 &lt;br /&gt;
 @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@&lt;br /&gt;
 &lt;br /&gt;
 Permissions &amp;lt;permissions&amp;gt; for &#039;&amp;lt;filename&amp;gt;&#039; are too open.&lt;br /&gt;
 &lt;br /&gt;
 It is required that your private key files are NOT accessible by others.&lt;br /&gt;
 &lt;br /&gt;
 This private key will be ignored.&lt;br /&gt;
 &lt;br /&gt;
 Load key &amp;quot;&amp;lt;filename&amp;gt;&amp;quot;: bad permissions&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Private key file has permissions that are too open.&lt;br /&gt;
|Set permissions on file to 0400 (user: read, group: none, other:none).  See this video for more information.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 Load key &amp;quot;&amp;lt;filename&amp;gt;&amp;quot;: Permission denied&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
|No&lt;br /&gt;
|No&lt;br /&gt;
|Private key file has permissions that are too restrictive.&lt;br /&gt;
|Set permissions on file to 0400 (user: read, group: none, other:none).  See this video for more information.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 SSH Proxy Session ID: &amp;lt;session id&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 Error 403: Authorization denied by SSH Proxy Service policy.&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by &amp;lt;ip address&amp;gt; port 22&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|Yes&lt;br /&gt;
|No&lt;br /&gt;
|&#039;&#039;&#039;Cause 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
User account is disabled.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cause 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
User does not have the required permissions to use the SSH Proxy Service.&lt;br /&gt;
|&#039;&#039;&#039;Correction 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Check to ensure your CWL account is working by logging in at &amp;lt;nowiki&amp;gt;https://myaccount.ubc.ca&amp;lt;/nowiki&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Correction 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Submit a ticket for the SSH Proxy Service.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 channel 0: open failed: administratively prohibited: open failed&lt;br /&gt;
 &lt;br /&gt;
 stdio forwarding failed&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|Yes&lt;br /&gt;
|Yes&lt;br /&gt;
|&#039;&#039;&#039;Cause 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Typo in the Destination Host name or port (a default port of 22 is assumed but some Destination Hosts may be using a non-standard port).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cause 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Attempting to reach a Destination Host that is not authorized.&lt;br /&gt;
|&#039;&#039;&#039;Correction 1&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Check to ensure that the Destination Host name (and port, if provided) are correct.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Correction 2&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Request that the Destination Host be registered with the SSH Proxy Service.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 channel 0: open failed: connect failed: open failed&lt;br /&gt;
 &lt;br /&gt;
 Connection to p01.sshp.cybersecurity.ubc.ca closed.&lt;br /&gt;
|Yes&lt;br /&gt;
|Yes&lt;br /&gt;
|Attempting to login to the proxy host directly via SSH.&lt;br /&gt;
|Use the proxy pool via the -J parameter or ProxyJump option.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 &amp;lt;very long delay before message&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 channel 0: open failed: connect failed: Connection timed out&lt;br /&gt;
 &lt;br /&gt;
 stdio forwarding failed&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|Yes&lt;br /&gt;
|Yes&lt;br /&gt;
|Destination host is authorized but is not responding.&lt;br /&gt;
|Contact the Destination Host administrator for assistance.  The host may be offline, or a firewall on the destination side is blocking the connection attempt.&lt;br /&gt;
|- valign=&amp;quot;top&amp;quot;&lt;br /&gt;
|&lt;br /&gt;
 &amp;lt;displayed by itself AFTER the Destination Host Notice&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
 Connection closed by UNKNOWN port 65535&lt;br /&gt;
|Yes&lt;br /&gt;
|Yes&lt;br /&gt;
|Destination Host is authorized and destination port is open, but it is not communicating using SSH.&lt;br /&gt;
|Contact the Destination Host administrator for assistance.&lt;br /&gt;
|}&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|† The &#039;&#039;&#039;SSH Proxy Session ID&#039;&#039;&#039; will only be shown when authentication to the proxy pool is successful.  If you see the SSH Proxy Session ID, the username, password, MFA challenges have passed, or a valid SSH key was provided.&lt;br /&gt;
&#039;&#039;&#039;NOTE:&#039;&#039;&#039; If you turned off the Display SSH Proxy Session ID option in the SSH Proxy Key Registration Portal, the SSH Proxy Session ID will never be displayed. &lt;br /&gt;
&lt;br /&gt;
An example of a successful authentication displaying an SSH Proxy Session ID is:&lt;br /&gt;
 SSH Proxy Session ID: ITSO-A4E59.0353334&lt;br /&gt;
 &lt;br /&gt;
 SSH Proxy Pool login successful.&lt;br /&gt;
‡ The &#039;&#039;&#039;Destination Host Notice&#039;&#039;&#039; refers to the following text which appears after the SSH Proxy Service has authenticated and authorized the user, and determined that the destination is authorized.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;NOTE:&#039;&#039;&#039; If you turned off the Display Banner option in the SSH Proxy Key Registration Portal, the Destination Host Notice will never be displayed.&lt;br /&gt;
 =====================================================================&lt;br /&gt;
 &lt;br /&gt;
 DESTINATION HOST SESSION BEGINS BELOW THIS LINE&lt;br /&gt;
 &lt;br /&gt;
 For further assistance, contact the destination host administrator.&lt;br /&gt;
 &lt;br /&gt;
 =====================================================================&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Information for System Administrators and Destination Host Administrators ==&lt;br /&gt;
&lt;br /&gt;
=== Modifying Firewall Rules ===&lt;br /&gt;
To allow inbound communication from a specific SSH Proxy Pool, open your inbound firewalls to the address listed in the &#039;&#039;&#039;Connectivity Information&#039;&#039;&#039; section of this page for your specific Destination Host and Port.&lt;br /&gt;
&lt;br /&gt;
=== Adding Destination Hosts ===&lt;br /&gt;
To request a host be added as a Destination Host, please submit a [https://ubc.service-now.com/selfservice?id=sc_cat_item_v2&amp;amp;sys_id=9440ab761b136c500dbaec21b24bcbbb Cybersecurity Services Support Request] through the UBC Self-Service Portal.  Provide the following information:&lt;br /&gt;
&lt;br /&gt;
# Your department and role&lt;br /&gt;
# Destination Hostname (FQDN)&lt;br /&gt;
## Only Destination Hosts with FQDNs are eligible for this service&lt;br /&gt;
# Destination IP Address&lt;br /&gt;
# Destination Port&lt;br /&gt;
# Technical Owner Name&lt;br /&gt;
# Technical Owner Email&lt;br /&gt;
# Business Owner Name&lt;br /&gt;
# Business Owner Email&lt;br /&gt;
# Reason&lt;br /&gt;
&lt;br /&gt;
A request has been submitted to have a custom form for this type of request.&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding the SSH Proxy Service, please submit a [https://ubc.service-now.com/selfservice?id=sc_cat_item_v2&amp;amp;sys_id=9440ab761b136c500dbaec21b24bcbbb Cybersecurity Services Support Request] through the UBC Self-Service Portal.&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896548</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896548"/>
		<updated>2026-05-15T23:58:41Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* Using SPS via ssh config */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test cases below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH Proxy Pool) and CWL staging account (for logging into the SSH Key Registration Portal and the test SSH Destination Host).&lt;br /&gt;
&lt;br /&gt;
- Have an SSH Destination Host to connect to (a test host has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) provides an SSH tunnel between the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; and the &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.  Once the SSH tunnel to the SSH Destination Host is established, then other protocols may be emitted from the SSH Destination Host at the discretion of the SSH Destination Host system administrator.  This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.&lt;br /&gt;
&lt;br /&gt;
It does not:&lt;br /&gt;
&lt;br /&gt;
* allow other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039;&lt;br /&gt;
* provide a full replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].&lt;br /&gt;
* provide any user control or management of accounts or authentication on SSH Destination Hosts&lt;br /&gt;
** provide an approved method for administration of systems over SSH using privileged accounts.  Remote SSH systxems administration with privileged accounts should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
[[File:Sshproxyservicescope.png|frameless|931x931px]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool&lt;br /&gt;
|p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
|443&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy TEST Destination Host&lt;br /&gt;
|ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
(Cybersecurity user group only)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Service unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Pools, Key Registration Portal&lt;br /&gt;
&lt;br /&gt;
CWL Production Account (for Cybersecurity users) to access the test destination host&lt;br /&gt;
&lt;br /&gt;
(Non-Cybersecurity users are asked to submit an SSHP onboarding request to have their desired destination host onboarded if it is not already accessible via SSHP).&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe@p01.sshp.cybersecurity.ubc.ca jbdoe@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 &lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Repeated failed authentication attempts within a short period of time&lt;br /&gt;
 may result in a temporary network block affecting access to this&lt;br /&gt;
 proxy service from your source IP address.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 ---------------------------------------------------------------------&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jdoe@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jdoe&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3):&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 SSH Proxy Session ID: ITSO-A4E59.2114461&lt;br /&gt;
 &lt;br /&gt;
 SSH Proxy Pool login successful.&lt;br /&gt;
 &lt;br /&gt;
 =====================================================================&lt;br /&gt;
 DESTINATION HOST SESSION BEGINS BELOW THIS LINE&lt;br /&gt;
 For further assistance, contact the destination host administrator.&lt;br /&gt;
 =====================================================================&lt;br /&gt;
 &lt;br /&gt;
 (jdoe@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     6 Security notice(s)&lt;br /&gt;
         3 Important Security notice(s)&lt;br /&gt;
         2 Medium Security notice(s)&lt;br /&gt;
         1 Low Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Thu Apr 30 04:11:02 2026 from 10.93.46.42&lt;br /&gt;
 [jdoe@ssh-target ~]$ ~&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.cybersecurity.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.cybersecurity.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Pool (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Pool, your private key will be used during the authentication with the SSH Proxy Pool, and you will not be required to perform an interactive login with the SSH Proxy Pool -- however, you will still need to authenticate with the SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.cybersecurity.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Repeated failed authentication attempts within a short period of time&lt;br /&gt;
 may result in a temporary network block affecting access to this&lt;br /&gt;
 proxy service from your source IP address.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 ---------------------------------------------------------------------&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH Proxy Session ID: ITSO-A4E59.2176796&lt;br /&gt;
 &lt;br /&gt;
 SSH Proxy Pool login successful.&lt;br /&gt;
 &lt;br /&gt;
 =====================================================================&lt;br /&gt;
 DESTINATION HOST SESSION BEGINS BELOW THIS LINE&lt;br /&gt;
 For further assistance, contact the destination host administrator.&lt;br /&gt;
 =====================================================================&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     6 Security notice(s)&lt;br /&gt;
         3 Important Security notice(s)&lt;br /&gt;
         2 Medium Security notice(s)&lt;br /&gt;
         1 Low Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last failed login: Fri May 15 23:26:30 UTC 2026 from 10.93.46.42 on ssh:notty&lt;br /&gt;
 There was 1 failed login attempt since the last successful login.&lt;br /&gt;
 Last login: Fri May 15 22:29:02 2026 from 10.93.46.42&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.cybersecurity.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.cybersecurity.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; ||&lt;br /&gt;
 Host p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy Pool DNS name&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896544</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896544"/>
		<updated>2026-05-15T22:38:18Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test cases below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH Proxy Pool) and CWL staging account (for logging into the SSH Key Registration Portal and the test SSH Destination Host).&lt;br /&gt;
&lt;br /&gt;
- Have an SSH Destination Host to connect to (a test host has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) provides an SSH tunnel between the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; and the &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.  Once the SSH tunnel to the SSH Destination Host is established, then other protocols may be emitted from the SSH Destination Host at the discretion of the SSH Destination Host system administrator.  This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.&lt;br /&gt;
&lt;br /&gt;
It does not:&lt;br /&gt;
&lt;br /&gt;
* allow other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039;&lt;br /&gt;
* provide a full replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].&lt;br /&gt;
* provide any user control or management of accounts or authentication on SSH Destination Hosts&lt;br /&gt;
** provide an approved method for administration of systems over SSH using privileged accounts.  Remote SSH systxems administration with privileged accounts should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
[[File:Sshproxyservicescope.png|frameless|931x931px]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool&lt;br /&gt;
|p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
|443&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy TEST Destination Host&lt;br /&gt;
|ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
(Cybersecurity user group only)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://sshp.cybersecurity.ubc.ca/&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Service unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Pools, Key Registration Portal&lt;br /&gt;
&lt;br /&gt;
CWL Production Account (for Cybersecurity users) to access the test destination host&lt;br /&gt;
&lt;br /&gt;
(Non-Cybersecurity users are asked to submit an SSHP onboarding request to have their desired destination host onboarded if it is not already accessible via SSHP).&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe@p01.sshp.cybersecurity.ubc.ca jbdoe@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 &lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Pool (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Pool, your private key will be used during the authentication with the SSH Proxy Pool, and you will not be required to perform an interactive login with the SSH Proxy Pool -- however, you will still need to authenticate with the SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy Pool DNS name&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896530</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=896530"/>
		<updated>2026-05-15T20:46:12Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test cases below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH Proxy Pool) and CWL staging account (for logging into the SSH Key Registration Portal and the test SSH Destination Host).&lt;br /&gt;
&lt;br /&gt;
- Have an SSH Destination Host to connect to (a test host has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) provides an SSH tunnel between the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; and the &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.  Once the SSH tunnel to the SSH Destination Host is established, then other protocols may be emitted from the SSH Destination Host at the discretion of the SSH Destination Host system administrator.  This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.&lt;br /&gt;
&lt;br /&gt;
It does not:&lt;br /&gt;
&lt;br /&gt;
* allow other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039;&lt;br /&gt;
* provide a full replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].&lt;br /&gt;
* provide any user control or management of accounts or authentication on SSH Destination Hosts&lt;br /&gt;
** provide an approved method for administration of systems over SSH using privileged accounts.  Remote SSH systxems administration with privileged accounts should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
[[File:Sshproxyservicescope.png|frameless|931x931px]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool&lt;br /&gt;
|p01.sshp.cybersecurity.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy TEST Destination Host&lt;br /&gt;
|ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Service unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Pools, Key Registration Portal&lt;br /&gt;
&lt;br /&gt;
CWL Production Account (for Cybersecurity users) to access the test destination host&lt;br /&gt;
&lt;br /&gt;
(Non-Cybersecurity users are asked to submit an SSHP onboarding request to have their desired destination host onboarded if it is not already accessible via SSHP).&lt;br /&gt;
&lt;br /&gt;
CWL Staging Account: Access to Key Registration Portal, and the test destination host&lt;br /&gt;
&lt;br /&gt;
Note: If your staging account password cannot be reset via [https://www.myaccount.stg.id.ubc.ca/myAccount/ MyAccount-STG], then a ticket may be submitted to UBCIT - IAM to request a password reset.&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Pool (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Pool, your private key will be used during the authentication with the SSH Proxy Pool, and you will not be required to perform an interactive login with the SSH Proxy Pool -- however, you will still need to authenticate with the SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy Pool DNS name&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895671</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895671"/>
		<updated>2026-04-29T20:07:36Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: password reset for stg instructions under FAQ&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test cases below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH Proxy Pool) and CWL staging account (for logging into the SSH Key Registration Portal and the test SSH Destination Host).&lt;br /&gt;
&lt;br /&gt;
- Have an SSH Destination Host to connect to (a test host has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca).&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) provides an SSH tunnel between the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; and the &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.  Once the SSH tunnel to the SSH Destination Host is established, then other protocols may be emitted from the SSH Destination Host at the discretion of the SSH Destination Host system administrator.  This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.&lt;br /&gt;
&lt;br /&gt;
It does not:&lt;br /&gt;
&lt;br /&gt;
* allow other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039;&lt;br /&gt;
* provide a full replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].&lt;br /&gt;
* provide any user control or management of accounts or authentication on SSH Destination Hosts&lt;br /&gt;
** provide an approved method for administration of systems over SSH using privileged accounts.  Remote SSH systxems administration with privileged accounts should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
[[File:Sshproxyservicescope.png|frameless|931x931px]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|CWL STG Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy TEST Destination Host&lt;br /&gt;
|ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL STG Account&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Service unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Pools&lt;br /&gt;
&lt;br /&gt;
CWL Staging Account: Access to Key Registration Portal, and the test destination host&lt;br /&gt;
&lt;br /&gt;
Note: If your staging account password cannot be reset via [https://www.myaccount.stg.id.ubc.ca/myAccount/ MyAccount-STG], then a ticket may be submitted to UBCIT - IAM to request a password reset.&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Pool (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Pool, your private key will be used during the authentication with the SSH Proxy Pool, and you will not be required to perform an interactive login with the SSH Proxy Pool -- however, you will still need to authenticate with the SSH Destination Host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy Pool DNS name&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895376</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895376"/>
		<updated>2026-04-24T17:07:25Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH proxy host) and CWL staging account (for logging into the SSH key registration portal and the test destination host).&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Pools&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
!Credentials&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Pool&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL Production Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|CWL STG Account&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy TEST Destination Host&lt;br /&gt;
|ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|CWL STG Account&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Pools&lt;br /&gt;
&lt;br /&gt;
CWL Staging Account: Access to Key Registration Portal, and the test destination host&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895343</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895343"/>
		<updated>2026-04-23T20:45:04Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL production (for logging into the SSH proxy host) and CWL staging account (for logging into the SSH key registration portal and the test destination host).&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Which credentials are supported in the test deployment?&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
CWL Production Account: Access to SSH Proxy Hosts&lt;br /&gt;
&lt;br /&gt;
CWL Staging Account: Access to Key Registration Portal, and the test destination host&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895342</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895342"/>
		<updated>2026-04-23T20:30:47Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL prod and CWL staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC PAM (Privileged Access Management)] service.  PAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to PAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - not all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentityFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895341</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895341"/>
		<updated>2026-04-23T20:25:02Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid CWL prod and CWL staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentifyFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895340</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895340"/>
		<updated>2026-04-23T20:23:30Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* How does this align with the UBC Enhanced System Access Management (eSAM) service? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://it.ubc.ca/services/accounts-passwords/privileged-access-management-pam UBC Privileged Access Management Service?] ====&lt;br /&gt;
This service is intended for user activities using unprivileged accounts.  It is not a replacement or competitor for the UBC PAM service, which is the correct solution for system administration activities using privileged accounts.  If you are an administrator, you are encouraged to enroll your server into PAM. The below table outlines the differences between using PAM vs SSHP for access to servers. &lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
!&lt;br /&gt;
!PAM&lt;br /&gt;
!SSHP&lt;br /&gt;
|-&lt;br /&gt;
|System administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Automatic credential rollover&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Logging&lt;br /&gt;
|Logging and session monitoring/recording.&lt;br /&gt;
|Only logs connection attempts.&lt;br /&gt;
|-&lt;br /&gt;
|Redundancy&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Delegated administration&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|-&lt;br /&gt;
|Requires server to be registered&lt;br /&gt;
|Y&lt;br /&gt;
|Y&lt;br /&gt;
|-&lt;br /&gt;
|Credential Storage&lt;br /&gt;
|Y&lt;br /&gt;
|N&lt;br /&gt;
|}&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentifyFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895271</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895271"/>
		<updated>2026-04-22T20:38:57Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
&amp;lt;replace with callout block&amp;gt; &lt;br /&gt;
&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentifyFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Common Issues and Troubleshooting ==&lt;br /&gt;
&#039;&#039;&#039;Permission Denied Error&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Incorrect username&lt;br /&gt;
* Missing SSH key&lt;br /&gt;
* Access not granted to the target server&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify credentials&lt;br /&gt;
* Confirm your SSH key is registered&lt;br /&gt;
* Contact IT support if access is missing&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Connection Timed Out&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Firewall blocking SSH&lt;br /&gt;
* Incorrect hostname&lt;br /&gt;
* Network connectivity issue&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Verify the SSH Proxy hostname&lt;br /&gt;
* Check internet connectivity&lt;br /&gt;
* Ensure port 22 is not blocked&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;MFA Authentication Failure&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
Possible causes:&lt;br /&gt;
&lt;br /&gt;
* Device not enrolled in MFA&lt;br /&gt;
* Authentication request denied&lt;br /&gt;
&lt;br /&gt;
Solution:&lt;br /&gt;
&lt;br /&gt;
* Ensure MFA device is properly configured&lt;br /&gt;
* Retry login and approve the request&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Best Practices&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
To ensure secure usage:&lt;br /&gt;
&lt;br /&gt;
* Use &#039;&#039;&#039;SSH keys instead of passwords&#039;&#039;&#039;&lt;br /&gt;
* Protect your private keys with a passphrase&lt;br /&gt;
* Keep your SSH client updated&lt;br /&gt;
* Disconnect sessions when finished&lt;br /&gt;
* Do not store credentials in scripts&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895207</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895207"/>
		<updated>2026-04-21T22:24:11Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* How does this align with the UBC Enhanced System Access Management (eSAM) service? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
&amp;lt;replace with callout block&amp;gt; &lt;br /&gt;
&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentifyFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895195</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895195"/>
		<updated>2026-04-21T17:39:23Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* FAQ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.10.93&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@p01.sshp.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;IdentifyFile&#039;&#039; is the private key corresponding to the private which you registered with the Key Registration Proxy.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;User&#039;&#039; is the user which you use to access the SSH Proxy Host (if you do not specify a username in the &#039;&#039;config&#039;&#039; file, you will need to specify it in the connection string (i.e. jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca)&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
Because the public key has been registered with the SSH Proxy Host, your private key will be used during the authentication with the SSH Proxy Host, and you will not be required to perform an interactive login with the SSH Proxy Host -- however, you will still need to authenticate with the destination host.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J p01.sshp.devl.infosec.it.ubc.ca jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 UBC SSH Proxy Service                               &amp;lt;nowiki&amp;gt;https://it.ubc.ca&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
 ------------------------------ NOTICE -------------------------------&lt;br /&gt;
 You are connecting to the UBC SSH Proxy Service.&lt;br /&gt;
 &lt;br /&gt;
 After authentication succeeds here, your SSH client will connect&lt;br /&gt;
 through this proxy to your destination host.&lt;br /&gt;
 &lt;br /&gt;
 Any subsequent username, password, MFA, or host key prompts may be&lt;br /&gt;
 originating from your destination host, not from this proxy service.&lt;br /&gt;
 &lt;br /&gt;
 If authentication or access fails after the proxy connection has&lt;br /&gt;
 been established, contact the administrator of your destination host.&lt;br /&gt;
 &lt;br /&gt;
 The use of this proxy service may be monitored and recorded for&lt;br /&gt;
 administrative and security purposes. Monitoring is limited to&lt;br /&gt;
 activity on the proxy service itself and does not include activity&lt;br /&gt;
 on your destination host, which may be monitored separately. Anyone&lt;br /&gt;
 accessing this service expressly consents to such monitoring and is&lt;br /&gt;
 advised that if such monitoring reveals possible evidence of criminal&lt;br /&gt;
 activity, UBC may provide that evidence to law enforcement officials.&lt;br /&gt;
 #####################################################################&lt;br /&gt;
 &lt;br /&gt;
 Enter passphrase for key &#039;id_ed25519_ubcsps_20221206&#039;:&lt;br /&gt;
 SSH proxy login successful. Further authentication is handled by the destination host.&lt;br /&gt;
 Contact the destination host administrator if access fails beyond this point.&lt;br /&gt;
 &lt;br /&gt;
 (jdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Tue Apr 21 16:56:23 2026 from 10.93.10.93&lt;br /&gt;
 [jdoe-dest@ssh-target ~]$ ls&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the p01.sshp.devl.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J p01.sshp.devl.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@p01.sshp.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump p01.sshp.devl.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895172</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895172"/>
		<updated>2026-04-21T04:46:20Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* Non-Interactive (Key-based) Auth to SPS */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
 &lt;br /&gt;
 Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.    IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.46.42&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh-proxy.misc.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh-proxy.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895115</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895115"/>
		<updated>2026-04-20T20:16:49Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* Interactive Auth to SPS */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
 &lt;br /&gt;
 Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.    IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.46.42&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh-proxy.misc.devl.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895114</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=895114"/>
		<updated>2026-04-20T20:10:28Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
 &lt;br /&gt;
 Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.    IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options:&lt;br /&gt;
 &lt;br /&gt;
 1. Duo Push to XXX-XXX-1234&lt;br /&gt;
 2. Phone call to XXX-XXX-1234&lt;br /&gt;
 3. SMS passcodes to XXX-XXX-1234&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-3): 1&lt;br /&gt;
 &lt;br /&gt;
 Pushed a login request to your device...&lt;br /&gt;
 Success. Logging you in...&lt;br /&gt;
 (jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 Updates Information Summary: available&lt;br /&gt;
     8 Security notice(s)&lt;br /&gt;
         5 Important Security notice(s)&lt;br /&gt;
         3 Medium Security notice(s)&lt;br /&gt;
 &lt;br /&gt;
    ,     #_&lt;br /&gt;
    ~\_  ####_        Amazon Linux 2023&lt;br /&gt;
   ~~  \_#####\&lt;br /&gt;
   ~~     \###|&lt;br /&gt;
   ~~       \#/ ___   &amp;lt;nowiki&amp;gt;https://aws.amazon.com/linux/amazon-linux-2023&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
    ~~       V~&#039; &#039;-&amp;gt;&lt;br /&gt;
 &amp;lt;nowiki&amp;gt;    ~~~         /&amp;lt;/nowiki&amp;gt;&lt;br /&gt;
       ~~._.   _/&lt;br /&gt;
          _/ _/&lt;br /&gt;
        _/m/&#039;&lt;br /&gt;
 Last login: Mon Apr 20 19:44:56 2026 from 10.93.46.42&lt;br /&gt;
 [jbdoe-dest@ssh-target ~]$&lt;br /&gt;
 &lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894116</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894116"/>
		<updated>2026-04-13T20:23:05Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca jbdoe-dest@ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh-proxy.misc.devl.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894115</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894115"/>
		<updated>2026-04-13T19:18:11Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
&lt;br /&gt;
- Have a proxy destination host to connect to (a sample has been provisioned at: ssh-target.misc.devl.infosec.it.ubc.ca&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
 &lt;br /&gt;
Register the key in the key registration portal.&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894114</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=894114"/>
		<updated>2026-04-13T18:52:01Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: Updated testing requirements&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|In order to successfully complete the test case below, you must:&lt;br /&gt;
- Be connected to the UBC VPN via the ubcit.tech VPN pool&lt;br /&gt;
- Have a valid cwl staging account.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=890533</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=890533"/>
		<updated>2026-03-30T20:14:27Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: /* Connectivity Information */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Garson to add some notes in here around the requirements that you have to be connected to the ubcit.tech pool, and have a cwl staging account, in order to test this service&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|https://ssh-proxy.misc.devl.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
	<entry>
		<id>https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=889258</id>
		<title>Sandbox:SSH Proxy Service Interim Technical Documentation</title>
		<link rel="alternate" type="text/html" href="https://wiki.ubc.ca/index.php?title=Sandbox:SSH_Proxy_Service_Interim_Technical_Documentation&amp;diff=889258"/>
		<updated>2026-03-16T22:03:03Z</updated>

		<summary type="html">&lt;p&gt;GarsonSam: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| TESTING REQUIREMENTS&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Garson to add some notes in here around the requirements that you have to be connected to the ubcit.tech pool, and have a cwl staging account, in order to test this service&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Scope of Service ==&lt;br /&gt;
The &#039;&#039;&#039;SSH Proxy Service&#039;&#039;&#039; (&#039;&#039;&#039;SSHP&#039;&#039;&#039;) does not provide SSH tunneling for other protocols to be emitted from the &#039;&#039;&#039;SSH Proxy Hosts&#039;&#039;&#039; - it is not a replacement for the [https://it.ubc.ca/services/email-voice-internet/myvpn UBC myVPN service].  It does support SSH tunneling for other protocols to be emitted from &#039;&#039;&#039;SSH Destination Hosts&#039;&#039;&#039;.&lt;br /&gt;
This service is intended for &#039;&#039;&#039;end-user use&#039;&#039;&#039; of SSH services.  It is not intended for administration of systems over SSH.  Remote SSH systems administration should be facilitated through the use of the high-security [https://privacymatters.ubc.ca/esam UBC eSAM (Enhanced System Access Management)] service.  eSAM offers session recording, privileged account management, and a host of other security features which make it the right choice for systems administration work.&lt;br /&gt;
&lt;br /&gt;
[[File:SSH Proxy Service Use Cases.png||In-scope and out-of-scope use cases for the SSH Proxy Service.]]&lt;br /&gt;
&lt;br /&gt;
== Connectivity Information ==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|+&lt;br /&gt;
!Purpose&lt;br /&gt;
!Host&lt;br /&gt;
!Port&lt;br /&gt;
|-&lt;br /&gt;
|SSH Proxy Host&lt;br /&gt;
|http://p01.sshp.test.infosec.it.ubc.ca/&lt;br /&gt;
|22&lt;br /&gt;
|-&lt;br /&gt;
|SSH Key Registration Web Portal&lt;br /&gt;
|https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
|443&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
SSH connections can be made to ssh.infosec.it.ubc.ca port 22. For the PoC, there are no &#039;&#039;&#039;intentional&#039;&#039;&#039; session timeouts implemented.  Should SPS enter production, a formal decision on intentional session timeouts will be made.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;  width=100% align=&amp;quot;center&amp;quot;valign=&amp;quot;top&amp;quot;&lt;br /&gt;
!style=&amp;quot;background: #faecc8;&amp;quot;| Warning&lt;br /&gt;
|- &lt;br /&gt;
|style=&amp;quot;background: #faf6ed; align=left; padding:3px 7px 3px 7px;&amp;quot;|Avoid the use of SSH Agent forwarding! SSH Agent forwarding exposes your authentication to the server you’re connecting to. By default, an attacker with control of the server (i.e. root access) can communicate with your agent and use your key to authenticate to other servers without any notification (i.e. impersonate you). For this reason, one must be careful when using SSH agent forwarding. Defaulting to always forwarding the agent is &#039;&#039;&#039;strongly&#039;&#039;&#039; discouraged. Note also that while the attacker can use your key as long as the agent is running and forwarded, they cannot steal/download the key for offline/later use.  &amp;lt;ref name=&amp;quot;Mozilla OpenSSH Guidelines&amp;quot;&amp;gt;{{cite web |url=https://infosec.mozilla.org/guidelines/openssh#ssh-agent-forwarding |title=Mozilla OpenSSH Guidelines |publisher=Mozilla}}&amp;lt;/ref&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=== Authentication Options ===&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || This service requires the use of a [https://privacymatters.ubc.ca/learn-about-enhancedcwl UBC Enhanced CWL with Duo MFA].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Interactive&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with Duo MFA.&lt;br /&gt;
* MFA required on every authentication.&lt;br /&gt;
* Convenient and easy to use - best suited for ad-hoc work.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Non-Interactive (Key-based)&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
* Enhanced CWL accounts with SSH keys.  &lt;br /&gt;
* MFA not required on authentication.&lt;br /&gt;
* MFA is required to pre-register your SSH key at https://ssh-proxy.cad.devl.infosec.it.ubc.ca/keys&lt;br /&gt;
* Best-suited for heavy users or non-interactive connections.&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border: 1px #98B2C3 solid; padding: 0; border-radius: 0.25rem; padding-right: .3em;&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;span style=&amp;quot;font-size: 36px; background: #C3D0DB; border-radius: 0.25rem; padding: .1em .3em .1em .3em; color: #002145; margin-right: .2em; margin-left: .1em;&amp;quot;&amp;gt;&amp;amp;#8505;&amp;lt;/span&amp;gt; || For the purposes of the PoC, SSH keys will &#039;&#039;&#039;not expire&#039;&#039;&#039;.  However, should SPS enter production, there will be a set key expiration and renewal process.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== SSH Key Handling ==&lt;br /&gt;
Do not re-use an existing key for the SSH Proxy Host unless required.&lt;br /&gt;
&lt;br /&gt;
Keys should be generated following the [https://infosec.mozilla.org/guidelines/openssh#key-generation|Mozilla OpenSSH guidelines], as per UBC Information Security Standard M3, section 4.&lt;br /&gt;
&lt;br /&gt;
Example:&lt;br /&gt;
&lt;br /&gt;
 $ ssh-keygen -t ed25519 -f ~/.ssh/id_ubcsps_$(date +%Y%m%d) -C &amp;quot;UBC key for SPS&amp;quot;&lt;br /&gt;
&lt;br /&gt;
== FAQ ==&lt;br /&gt;
&lt;br /&gt;
==== How can I use a hardware token as MFA when using the SSH Proxy with interactive authentication (no key)? ====&lt;br /&gt;
When connecting using interactive authentication, after providing your password you&#039;ll be prompted for Duo authentication methods.  Instead of choosing a method, simply trigger your hardware key to send the MFA code.&lt;br /&gt;
 [jbdoe-local@localhost ~]$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
 UBC JumpHost&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Password:&lt;br /&gt;
 (jbdoe-cwl@ssh.infosec.it.ubc.ca) Duo two-factor login for jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Enter a passcode or select one of the following options: &lt;br /&gt;
 &lt;br /&gt;
  1. Duo Push to XXX-XXX-4099&lt;br /&gt;
  2. Duo Push to iPad Pro (iOS)&lt;br /&gt;
  3. Phone call to XXX-XXX-4099&lt;br /&gt;
  4. SMS passcodes to XXX-XXX-4099&lt;br /&gt;
 &lt;br /&gt;
 Passcode or option (1-4): cccdfabcrrbbnctkqidcrkiirkvgfvtgfdgvvfqnhntfib&lt;br /&gt;
 Last login: Wed Jan 11 10:08:06 2023 from 206.87.62.99&lt;br /&gt;
 [jbdoe-dest@foo ~]$&lt;br /&gt;
&lt;br /&gt;
==== How does this align with the [https://privacymatters.ubc.ca/esam UBC Enhanced System Access Management (eSAM) service?] ====&lt;br /&gt;
eSAM is used for system-administration tasks and requires VPN with a CWL admin account.  eSAM offers session recording, privileged account management, and many other security features which make it the right choice for system administration work.  If you&#039;re doing sysadmin-type things, eSAM is the way (not just for SSH, either - it can do RDP, web, and more).  eSAM offers the highest level of security, stores credentials, and has a relatively high level of friction which end users would not find acceptable.&lt;br /&gt;
&lt;br /&gt;
SPS is intended to be used for user-level tasks - software or services that are used by end-users. Running command line applications, mounting home directories over SSH, doing development work, etc.  It offers a suitable level of security for this purpose, and has a significantly reduced level of friction compared to eSAM.  It does not store anything beyond SSH public keys, which are not high risk.&lt;br /&gt;
&lt;br /&gt;
== Use Case Patterns ==&lt;br /&gt;
(Note - note all of these have been validated with the service at this time. If you test any of these, please let us know what&#039;s working/not working).&lt;br /&gt;
&lt;br /&gt;
See the [https://en.wikibooks.org/wiki/OpenSSH/Cookbook/Proxies_and_Jump_Hosts#Jump_Hosts_--_Passing_Through_a_Gateway_or_Two Proxies and Jump Hosts section of the OpenSSH Cookbook] for many other scenarios.&lt;br /&gt;
&lt;br /&gt;
=== Interactive Auth to SPS ===&lt;br /&gt;
Connecting through SPS interactively with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;-J&#039;&#039;&#039; parameter.&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J &amp;lt;cwlusername&amp;gt;@ssh.infosec.it.ubc.ca &amp;lt;username&amp;gt;@&amp;lt;destination_host&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==== Example ====&lt;br /&gt;
Connect to foo.ubc.ca as user jbdoe-dest using CWL username jbdoe-cwl for SPS:&lt;br /&gt;
&lt;br /&gt;
 $ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
=== Non-Interactive (Key-based) Auth to SPS ===&lt;br /&gt;
Connecting through SPS using key-based auth requires you first create an SPS-specific &#039;&#039;&#039;Host&#039;&#039;&#039; directive in ~/.ssh/config.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
&lt;br /&gt;
After that, you can connect using the same &#039;&#039;&#039;-J&#039;&#039;&#039; parameter used in the Interactive section above.&lt;br /&gt;
&lt;br /&gt;
=== Using SPS via ssh config === &lt;br /&gt;
Connecting with SSH to the destination host can be accomplished transparently via use of the &#039;&#039;&#039;ProxyJump&#039;&#039;&#039; configuration setting for any given host defined in the ~/.ssh/config file.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Host &amp;lt;destination_host&amp;gt;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
However, doing this will result in the ssh.infosec.it.ubc.ca host being passed the local username of the source system, which may not be desired.  As such, you may want to also define a &#039;&#039;&#039;Host&#039;&#039;&#039; section for the SPS host that forces a specific username to be used.&lt;br /&gt;
&lt;br /&gt;
==== Example 1 ====&lt;br /&gt;
Connect to foo.ubc.ca through SPS with CWL username of jbdoe-cwl:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest:&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Note: &#039;&#039;&#039; This will route ALL ssh connections through SPS from the source host, including those that originate from on-campus.&lt;br /&gt;
&lt;br /&gt;
==== Example 2 ====&lt;br /&gt;
Use SPS with an SPS-specific SSH key for all hosts under UBC subdomain foo.ubc.ca, using a CWL username of jbdoe-cwl to login to SPS.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.ubc.ca as user jbdoe-dest, without being prompted for your SPS password.&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 3 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&lt;br /&gt;
&lt;br /&gt;
 Match Host *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
&lt;br /&gt;
With that in place, you can connect to foo.bar.ubc.ca as user jbdoe-dest (note that this will use whatever your local account username is to auth to SPS):&lt;br /&gt;
&lt;br /&gt;
 $ ssh jbdoe-dest@foo.bar.ubc.ca&lt;br /&gt;
&lt;br /&gt;
==== Example 4 ====&lt;br /&gt;
Use SPS for all hosts under UBC subdomain bar.ubc.ca except for foo.bar.ubc.ca and only off-campus:&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;~/.ssh/config&#039;&#039;&lt;br /&gt;
 Match Host *.bar.ubc.ca,!foo.bar.ubc.ca exec &amp;quot;[\[ `curl --no-progress-meter ifconfig.me` != 142\.103\.* ]]&amp;quot;&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
(Remove the \ - it&#039;s necessary here because [ is special.)&lt;br /&gt;
Tune the IP address expression to whatever is &amp;quot;on-campus&amp;quot; for you.&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
&lt;br /&gt;
|+ Identity Rubric&lt;br /&gt;
|-&lt;br /&gt;
! SSH Command Line !! ssh_config !! Local Username !! SPS Username !! Destination System Username !! Login UX&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J ssh.infosec.it.ubc.ca foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh -J jbdoe-cwl@ssh.infosec.it.ubc.ca jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || none || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh jbdoe-dest@foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt; || SPS: Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.bar.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
 &lt;br /&gt;
 Match *.bar.ubc.ca&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Interactive&lt;br /&gt;
foo.bar.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Host foo.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Interactive&lt;br /&gt;
|-&lt;br /&gt;
| &amp;lt;code&amp;gt;$ ssh foo.ubc.ca&amp;lt;/code&amp;gt; || &lt;br /&gt;
 Host ssh.infosec.it.ubc.ca&lt;br /&gt;
     User jbdoe-cwl&lt;br /&gt;
     IdentityFile ~/.ssh/id_ed25519_ubcsps_20221206&lt;br /&gt;
 &lt;br /&gt;
 Match *.ubc.ca&lt;br /&gt;
     User jbdoe-dest&lt;br /&gt;
     IdentityFile ~/.ssh/id_rsa_ubc_20201101&lt;br /&gt;
     ProxyJump ssh.infosec.it.ubc.ca&lt;br /&gt;
|| &amp;lt;code&amp;gt;jbdoe-local&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-cwl&amp;lt;/code&amp;gt; || &amp;lt;code&amp;gt;jbdoe-dest&amp;lt;/code&amp;gt;  || SPS: Non-Interactive&lt;br /&gt;
foo.ubc.ca: Non-Interactive&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Support / Feedback ==&lt;br /&gt;
For any questions, comments, suggestions or feedback regarding SPS PoC, please drop an email to [mailto:jagmeet.randhawa@ubc.ca?subject=&amp;amp;#x22;SSH&amp;amp;#x20;Proxy&amp;amp;#x20;Service&amp;amp;#x20;Feedback&amp;amp;#x22; jagmeet.randhawa@ubc.ca]&lt;br /&gt;
&lt;br /&gt;
== References ==&lt;br /&gt;
{{Reflist}}&lt;/div&gt;</summary>
		<author><name>GarsonSam</name></author>
	</entry>
</feed>