4 ms·
Hi everyone! Author here This has been my stress-reliever for the past ~2 years. I'm sticking around, so feel free to ask any questions. Github Repo: https://
by m_sahaf 5y ago
Hi everyone! Author here
This has been my stress-reliever for the past ~2 years. I'm sticking around, so feel free to ask any questions.
Github Repo: https://github.com/mohammed90/caddy-ssh https://github.com/mohammed90/caddy-ssh
- explorigin 5y agoCool! (not a security professional) One of the reasons in my understanding that projects don't deviate from older languages was because they give you some control around compilation that would be necessary to thwart timing-based attacks. Does this consider timing-based attacks or is that at a lower-level library?
- gunapologist99 5y agoExcellent point; it does appear that the author did consider timing attacks in at least one location: https://github.com/mohammed90/caddy-ssh/blob/master/internal/ssh/ssh.go#L126 https://github.com/mohammed90/caddy-ssh/blob/master/internal...
- m_sahaf 5y agoTo be fair, this bit is borrowed/forked from github.com/gliderlabs/ssh.
- thefreeman 5y agoCurious why you would just copy the entire gilderlabs/ssh package into your repo instead of referencing it as a module? How do you plan to keep up to date with bug / security fixes?
- francislavoie 5y agoSome of the changes necessary were too invasive/breaking to gliderlabs/ssh, such as https://github.com/gliderlabs/ssh/pull/161 https://github.com/gliderlabs/ssh/pull/161 so making a copy ended up making more sense, I think. That's my understanding from what Mohammed's told me, anyways.
- m_sahaf 5y agoThat's right. Moreover, the activity no the repo has been a bit stagnant (no disrespect to the maintainers, they are likely busy with other projects or life). Other projects have opted to fork the repo, rewrite the module repo path, and maintain their fork (e.g. https://github.com/tailscale/ssh/ https://github.com/tailscale/ssh/, but I've seen many others too). I didn't want to maintain a fork, so a copy under internal/ in my own repo means it's firm-fork (between soft and hard) where I can confidently break its APIs I'm the only one depending on without worry. It will slowly morph to fit the needs of the project only. The maintainers gliderlabs/ssh have plans for a new version with more ergonomic APIs but the work hasn't started yet. I didn't want to wait either.
- m_sahaf 5y agoNot very too level. I had to take that into consideration at some parts. For example, the static username_password provider calls a hasher defined in Caddy which uses `subtle.ConstantTimeCompare` function used. At other places, I don't return early (when possible) on auth failures to avoid timing attacks. That said, I'd love to know if there are places where I fell short.
- enneff 5y agoI have reviewed some of the crypto code in the Go standard library that this is built with, and there is use of constant time primitives in there so it is at least possible and some attention has been spent on it.
- XzAeRosho 5y agoCongratulations! Looks like a really cool project. So, if I get this right, this should be a drop-in replacement for current SSH servers? I get that an adapter has to be built to support sshd config files, but is that the ultimate goal here? Is security the main selling point of this project?
- m_sahaf 5y agoThank you! Indeed, you're right. The ultimate goal is to be drop-in replacement. There is a PR hanging waiting to be taken up. I might look at it once I finish furnishing the foundation, but others are welcome to take it up!
- DHowett 5y agoHey! This is awesome. I’m the engineering manager for the Windows console subsystem team. I’d be happy to help out with your ConPTY issues! Feel free to file a discussion issue over on GitHub at microsoft/terminal, or email me at duhowett@(corporate domain name). I suspect what you need is CreatePseudoConsoleAsUser… which we should have offered as a public API.
- password4321 5y agoCan you point the right person to this internally for the real OpenSSH shipped with Windows? I'm actually curious how licensing works out for 3rd party servers like Caddy-SSH. Licensing / Multi-user access / CAL | https://github.com/PowerShell/Win32-OpenSSH/issues/926 https://github.com/PowerShell/Win32-OpenSSH/issues/926 (Oct 2017)
- nodesocket 5y agoAm I understanding that the public keys used for authorization (authorized_keys) can come from a centralized source? Being able to add and remove authorized keys from say Redis or Consul centrally would be extremely useful from a management perspective. Obviously, security of that Redis or Consul would have to be tight and prevent public access.
- frutiger 5y agoSlightly off-topic, but OpenSSH already supports this via `AuthorizedKeysCommand`: https://man.openbsd.org/sshd_config#AuthorizedKeysCommand https://man.openbsd.org/sshd_config#AuthorizedKeysCommand
- nodesocket 5y agoOh really interesting. Any good guides you know of how to implement AuthorizedKeysCommand with Redis for example?
- macno 5y agoHi @nodesocket, you can take a look how we solved it with Theo https://theoapp.readthedocs.io/en/latest/index.html https://theoapp.readthedocs.io/en/latest/index.html It supports fine hosts/users grants - i.e. I can connect as "dev" user on servers "node1" and "node2" but not on "node3" - and it leverages asymmetric key signing to validate the public SSH keys. Theo supports mysql/mariadb/sqlite/postgresql(experimental) for storing data and redis/memecached for caching. Happy to answer any further questions!
- frutiger 5y agoI'm not really an expert on redis. Perhaps one can fashion something with `redis-cli`? Or write a program that links the redis client library.
- m_sahaf 5y agoThat's right! Currently such (static) keys are loaded at provision-time, when the server is first booting up, but there's nothing preventing it from being lazy-loaded at authentication-time. Of course loading them at authentication-time incurs latency as tax. Nothing prevents two separate modules from existing: one eager-loads the keys, and another lazy-loads them.
- jamal-kumar 5y agoHmm interesting. Considering memory corruption vulnerabilities have been pretty much the vast rarity in the OpenSSH codebase, and other classes of vulnerabilties have been more common, I'm curious to know what you're doing to address those classes of vulnerabilities as well as support for other best practices like SSH certificates? [2] I think I see the appeal of an entirely memory-safe OS running an entirely memory-safe SSH implementation because if we're talking about eliminating that class of vulnerability, you might as well go the whole hog - I just don't see that close to the point of being battle tested yet nor taking care of stuff like side channel attacks or tricking people into thinking their TOFU isn't smelly. I like your project because I think that this stuff is important, I think it's just like "how do you improve on the original" may actually be more than just eliminating one class of vuln. [1] https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=openssh https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=openssh [2] https://smallstep.com/blog/use-ssh-certificates/ https://smallstep.com/blog/use-ssh-certificates/