Ssh Keygen Flags

Set up public-key authentication using SSH on a Linux or OS X computer. Ssh-keygen -t rsa. On the SSH command line: Add the -i flag and the path to your.

Both options have something to do with X11 forwarding. This means if you enable this you can use a graphical client through your SSH session (i.e. Use Firefox or something else). If you use ssh -X remotemachine the remote machine is treated as an untrusted client. So your local client sends a command to the remote machine and receives the graphical output.

If your command violates some security settings you'll receive an error instead. But if you use ssh -Y remotemachine the remote machine is treated as trusted client. This last option can open security problems.

Because other graphical (X11) client could sniff data from the remote machine (make screenshots, do keylogging and other nasty stuff) and it is even possible to alter those data. If you want to know more about those things I suggest reading the or the. Furthermore you can check the options ForwardX11 and ForwardX11Trusted in your /etc/ssh/ssh_config. Use neither when you don't need to run X11 programs remotely; use -X when you do; and hypothetically use -Y if an X11 program you care about works better with -Y than with -X.