Stop your SSH agent from leaking keys across every host you visit
SSH & Remote Administration
Stop your SSH agent from leaking keys across every host you visit
🧩 The Challenge
Everyone uses agent forwarding because it’s convenient, but then you realize you just gave every server you logged into the ability to impersonate you. It’s a massive security hole that I’ve seen burned by people who didn’t realize they were leaving their keys exposed to every root user on the remote box.
💡 The Fix
You can use the ProxyJump feature in your config file instead of forwarding your actual socket. It lets you hop through a jump host without ever exposing your local authentication credentials to the destination.
Host destination-server
ProxyJump user@jump-server:22
IdentityFile ~/.ssh/id_rsa
⚙️ Why It Works
Setting this up tells your local SSH client to establish a tunnel through the jump box and then connect directly to the end target. By doing it this way, the remote server never sees your local agent socket, so your private keys stay locked down tight on your own laptop.
🚀 Pro-Tip: Alias your jump hosts in the config so you just have to type ssh destination-server and be done with it.
Linux Tips & Tricks | © ngelinux.com | 8/2/2026
