Short: SSH2 server and client suite with SFTP Author: Stefan Franke (BebboSSH), Michele Dipace (AROS port) Uploader: michele dipace kaffeine net (Michele Dipace) Type: comm/net Version: 1.0.3 Requires: AROS One x86_64 (ABIv11) with a TCP/IP stack (AROSTCP) Architecture: i386-aros WHAT IS THIS? BebboSSH is an SSH2 implementation for Amiga systems by Stefan "Bebbo" Franke. This archive is its port to AROS x86_64 (AROS One 64-bit, ABIv11). With it you can log in to an AROS machine from any SSH client, run commands, and copy files with scp and sftp; the native clients connect from AROS to other SSH servers. The original 68k version is comm/net/bebbossh.lha; the AROS i386 build is comm/net/bebbossh.i386-aros.lha. PROGRAMS bebbosshd SSH2 server: remote commands, SFTP, SCP, TCP port forwarding (direct-tcpip), password and public-key login bebbossh SSH2 client, with -L local port forwarding bebboscp SCP client bebbosshkeygen Ed25519 key generator Algorithms: curve25519-sha256 key exchange, ssh-ed25519 host and user keys, aes128-gcm@openssh.com and chacha20-poly1305@openssh.com ciphers. AES-GCM uses AES-NI and PCLMULQDQ when the CPU provides them. REQUIREMENTS - AROS One x86_64 (ABIv11). - A configured TCP/IP stack (AROSTCP, bsdsocket.library). - No extra libraries: the crypto code is linked into each program. - In a virtual machine, use an rtl8139 or pcnet network card, not e1000 (see KNOWN LIMITS). CONTENTS BebboSSH/bebbosshd, bebbossh, bebboscp, bebbosshkeygen BebboSSH/sshd_config.example, passwd.example BebboSSH/README.AROS.txt install and configuration guide BebboSSH/README.md, AROS_PORTING.md, docs/, scripts/ BebboSSH/COPYING, LICENSE license texts (GNU GPL v3) BebboSSH/SHA256SUMS checksums of the files above INSTALLATION 1. Extract the archive to a persistent volume, for example DH0:. 2. In an AROS Shell, create the configuration and a host key: cd DH0:BebboSSH copy sshd_config.example sshd_config copy passwd.example passwd bebbosshkeygen -f ssh_host_ed25519_key 3. Edit passwd: one "username password" pair per line. The test/test entry of the example is for a first test only; replace it. 4. Start the server: stack 262144 bebbosshd 5. From another machine: ssh username@
To start the server at boot, add these lines to S:User-Startup: Stack 262144 If EXISTS DH0:BebboSSH/bebbosshd Run DH0:BebboSSH/bebbosshd EndIf To call the clients from anywhere, copy bebbossh, bebboscp and bebbosshkeygen to C:. Keep bebbosshd in its own directory: the example configuration finds its files through PROGDIR:. CONFIGURATION bebbosshd reads ENVARC:ssh/sshd_config if it exists, otherwise PROGDIR:sshd_config. The main directives of the example: Port 22 TCP port ListenAddress 0.0.0.0 address to listen on (0.0.0.0 = all) HostKey PROGDIR:ssh_host_ed25519_key Passwords PROGDIR:passwd HomeDir DH0: start directory of commands and SFTP (on x86_64 only with BEBBOSSH_AROS_X64_CD set) Stack 262144 stack of command tasks (default 1 MiB) DebugLevel 1 log level: 0 none to 8 ultra, or a name such as error or debug SendNoop some keepalive messages to idle sessions Ciphers aes128-gcm@openssh.com,chacha20-poly1305@openssh.com ciphers offered (both by default) Command-line options override the file: -p port, -A password file, -K host key, -H home directory, -v log level (for example -v5). Public-key login reads ENVARC:.ssh/authorized_keys (OpenSSH format, one key per line). README.AROS.txt describes every file in detail. USAGE From a PC with OpenSSH: ssh user@aros-host version scp file.txt user@aros-host:DH0: sftp user@aros-host From AROS: bebbossh user@host bebbossh -i DH0:keys/id_ed25519 user@host command bebbossh -L 8080:localhost:80 user@host bebboscp localfile user@host:remotefile bebbosshkeygen -f DH0:keys/id_ed25519 KNOWN LIMITS - No full interactive PTY programs: the interactive shell runs simple commands, and programs that read their input are rejected with exit status 2. - No redirection or pipes (>, <, |) in remote commands. - Remote commands run one at a time and block the server until they end: keep them short. - An SFTP path on a volume that is not mounted opens an "insert volume" requester and blocks the server until it is closed. - With an Intel e1000 network card and heavy network load, AROS One x86_64 can halt or reboot. The cause is the AROS e1000.device; it is fixed upstream (deadwood2/AROS issue 274). Until AROS One ships the fix, use an rtl8139 or pcnet card. - Some features are off unless set before starting bebbosshd (setenv NAME 1): BEBBOSSH_AROS_X64_CD (cd and pwd in the interactive shell), BEBBOSSH_AROS_X64_SFTP_MTIME (keep upload times), BEBBOSSH_AROS_X64_SFTP_LINKS (SFTP readlink and symlink). - The native client has not been tested on an AROS console yet. - OpenSSH "put -p" sets the file time before it closes the file, and AROS updates the date on close, so that time is not kept. - passwd.example contains a test password: change it. WHAT IS NEW IN 1.0.3 - Ctrl-C (Break) stops the server, and it can be started again at once. - The server reads sshd_config. Without it, the defaults of earlier releases apply. - SendNoop now sends keepalives. - ListenAddress with a specific address works. - DebugLevel accepts the numbers used by -v. - SFTP reads return at most 32736 bytes, the advertised limit. TESTED On AROS One x86_64 under QEMU with an rtl8139 card, with the programs of this archive: OpenSSH ssh, scp and sftp; 100 logins in a row; 80 file transfers without pauses; four servers at once; Ctrl-C and restart; a server configured only by sshd_config; the native clients; with and without AES-NI. SOURCE AND LICENSE GNU GPL v3 or later (see COPYING). Source of this release: https://github.com/kaffeine1/bebbossh-aros/tree/v1.0.3-aros-x86_64 Original BebboSSH: https://franke.ms/git/bebbo/bebbossh Bug reports: https://github.com/kaffeine1/bebbossh-aros/issues Port by Michele Dipace .