Allow SSH forwarding safely
Review the included setup script before running it on your server.
A message such as administratively prohibited usually means SSH permits login but refuses the requested local forward. Ask the server administrator to inspect the effective SSH policy for this user and destination.
The native setup guide includes a Copy forwarding script button. Copying only places script text on your device clipboard; the app does not execute it on a server. Review the script and its SSH username and Keycloak port arguments before running it in your own trusted administrator session.
The supplied script restricts forwarding to the selected user and 127.0.0.1:KeycloakPort, disables unnecessary forwarding options, validates the SSH configuration and checks effective settings before reloading. Keep the existing administrator session open and test a second connection afterward.
Existing Match blocks, authorized_keys restrictions, container networking or a different SSH service can override the expected result. Keep a recovery route and review changes with your administrator. A successful script run does not prove your Keycloak HTTP listener is reachable.