4 ms·
SSH agent extensions are really powerful. I'm maintaining a crate for writing own agents (and clients) and just recently added an example of providing decrypti
by wiktor-k 2y ago
SSH agent extensions are really powerful.
I'm maintaining a crate for writing own agents (and clients) and just recently added an example of providing decryption over extensions [0] which, coupled with the other examples, allows using SSH agent as a proxy between OpenPGP Card devices (eg Yubikeys) and OpenPGP encrypted data.
[0]: https://github.com/wiktor-k/ssh-agent-lib/pull/70 https://github.com/wiktor-k/ssh-agent-lib/pull/70
Got some really positive feedback about this one: https://chaos.social/@Foxboron/112416348981479022 https://chaos.social/@Foxboron/112416348981479022 ;)
> Windows didn't really do Unix sockets until recently so everything there is awful
Sadly the support for Unix sockets on Windows in Rust's standard lib is stuck in a limbo: https://github.com/rust-lang/libs-team/issues/271 https://github.com/rust-lang/libs-team/issues/271
Fortunately the built-in Windows' SSH client and agent work over Named Pipes and it's quite easy to communicate with them that way: https://github.com/wiktor-k/ssh-agent-lib#agent https://github.com/wiktor-k/ssh-agent-lib#agent
- mjg59 2y agoUnfortunately the version included in git for Windows doesn't and you have to emulate sockets using magic files instead...
- Joker_vD 2y agoWhat is so great about Unix sockets that e.g. a normal TCP socket bound to localhost or even a named pipe can not do properly?
- wiktor-k 2y agoThe server can get the calling process info [0], which may be useful for local access control. TCP sockets cannot distinguish clients like that. [0]: https://docs.rs/tokio/latest/tokio/net/struct.UnixStream.html#method.peer_cred https://docs.rs/tokio/latest/tokio/net/struct.UnixStream.htm...
- dijit 2y agoUNIX Sockets are more flexible than named pipes; * You can use them for more than two processes communicating (eg. a server process with potentially multiple client processes connecting); * They are bidirectional; * They support passing kernel-verified UID / GID credentials between processes; * They support passing file descriptors between processes; * They support packet and sequenced packet modes. TCP only grants you 2 of these extra features (sequenced packet mode/bidirection), leaving a giant hole in security in the process.
- Joker_vD 2y agoThe named pipes, at least on Windows, also support all of that except for passing UID/GID and file handles.
- wiktor-k 2y agoAFAIR you can choose to use Windows OpenSSH or the other one during Git for Windows installation. [0] [0]: https://duckduckgo.com/?q=git+for+Windows+openssh&t=fpas&iax=images&ia=images&iai=https%3A%2F%2Fwww.softwaretestingo.com%2Fwp-content%2Fuploads%2F2022%2F06%2FInstall-GIT-on-Windows-11-OpenSSH.png https://duckduckgo.com/?q=git+for+Windows+openssh&t=fpas&iax...
- ThePowerOfFuet 2y agoHow hard would that be to extend that to include PKCS#11?
- wiktor-k 2y agoThe SSH agent shipped with OpenSSH already includes PKCS#11 support (check out the `-s` flag). I'm using that daily to work with TPM-backed keys.