[SSHD-1302] AbstractClientChannel: don't close inverted output streams

Closing them when the channel closes leads to the strange situation
that the application reads from an already closed InputStream. That's
not a good idea.

It's the caller's responsibility to close the input stream obtained
from Channel.getInvertedOut() or getInvertedErr(). And of course it
should do so only after it has read all the data it wanted, and the
channel is closed.

It's not a real problem if the stream is not closed (for instance, if
the application never even called getInvertedOut() and never read
anything). Closing doesn't do much anyway except awaking a potentially
waiting read() call. Moreover, if the channel is short-lived and didn't
transmit a lot of data, the application may well start reading from the
stream only after the underlying SSH channel is already closed.

One problem with this ChannelPipedInputStream is that it may buffer up
to a full SSH channel window. If the window size is large, that may
consume a lot of memory if the application only reads infrequently (or
doesn't read at all). However, not reading from such a stream is bad
practice anyway if there is any chance that there might be a substantial
amount of data; as with processes, it may lead to a blocked execution
when buffers fill up or the channel window is exhausted.
6 files changed
tree: d48e5c9af59acfb33743a0610bac7301021869b2
  1. .github/
  2. assembly/
  3. docs/
  4. sshd-cli/
  5. sshd-common/
  6. sshd-contrib/
  7. sshd-core/
  8. sshd-git/
  9. sshd-ldap/
  10. sshd-mina/
  11. sshd-netty/
  12. sshd-openpgp/
  13. sshd-osgi/
  14. sshd-putty/
  15. sshd-scp/
  16. sshd-sftp/
  17. sshd-sources/
  18. sshd-spring-sftp/
  19. .gitattributes
  20. .gitignore
  21. CHANGES.md
  22. java-checkstyle-license-header.txt
  23. LICENSE.txt
  24. NOTICE-bin.txt
  25. NOTICE.txt
  26. pom.xml
  27. README.md
  28. SECURITY.md
  29. security.txt
  30. sshd-checkstyle-suppressions.xml
  31. sshd-checkstyle.xml
  32. sshd-eclipse-formatter-config.xml
  33. sshd-findbugs.xml
  34. sshd-owasp-suppressions.xml
  35. sshd-pmd-ruleset.xml
README.md

Apache MINA SSHD

Apache MINA SSHD

Apache SSHD is a 100% pure java library to support the SSH protocols on both the client and server side. This library can leverage Apache MINA, a scalable and high performance asynchronous IO library. SSHD does not really aim at being a replacement for the SSH client or SSH server from Unix operating systems, but rather provides support for Java based applications requiring SSH support.

Supported standards

Reference implementation documentation

Implemented/available support

Authentication methods

Ciphers

Digests

  • md5, sha1, sha224, sha256, sha384, sha512

Macs

Key exchange

  • diffie-hellman-group1-sha1, diffie-hellman-group-exchange-sha256, diffie-hellman-group14-sha1, diffie-hellman-group14-sha256 , diffie-hellman-group15-sha512, diffie-hellman-group16-sha512, diffie-hellman-group17-sha512, diffie-hellman-group18-sha512 , ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521, curve25519-sha256, curve25519-sha256@libssh.org, curve448-sha512

Compressions

Signatures/Keys

Note: The above list contains all the supported security settings in the code. However, in accordance with the latest recommendations the default client/server setup includes only the security settings that are currently considered safe to use. Users who wish to include the unsafe settings must do so explicitly. The following settings have been deprecated and are no longer included in the default setup:

Caveat:: According to RFC 8332 - section 3.31

Implementation experience has shown that there are servers that apply authentication penalties to clients attempting public key algorithms that the SSH server does not support.

When authenticating with an RSA key against a server that does not implement the “server-sig-algs” extension, clients MAY default to an “ssh-rsa” signature to avoid authentication penalties. When the new rsa-sha2-* algorithms have been sufficiently widely adopted to warrant disabling “ssh-rsa”, clients MAY default to one of the new algorithms.

This means that users that encounter this (and related) problems must modify the supported security settings explicitly in order to avoid the issue.

Special notice: ssh-rsa was left in as part of the default setup since there are still a lot of systems / users using it. However, in future version it will be removed from the default. We therefore strongly encourage users to migrate to other keys (e.g. ECDSA, ED25519) as soon as possible.

Release notes

Core requirements

  • Java 8+ (as of version 1.3)

  • Slf4j

The code only requires the core abstract slf4j-api module. The actual implementation of the logging API can be selected from the many existing adaptors.

Basic artifacts structure

  • sshd-common - contains basic classes used throughout the project as well as code that does not require client or server network support.

  • sshd-core - contains the basic SSH client/server code implementing the connection, transport, channels, forwarding, etc..

    • sshd-mina, sshd-netty - replacements for the default NIO2 connector used to establish and manage network connections using MINA and/or Netty libraries respectively.
  • sshd-sftp - contains the server side SFTP subsystem and the SFTP client code.

  • sshd-scp - contains the server side SCP command handler and the SCP client code.

  • sshd-ldap - contains server-side password and public key authenticators that use an LDAP server.

  • sshd-git - contains replacements for JGit SSH session factory.

  • sshd-osgi - contains an artifact that combines sshd-common and sshd-core so it can be deployed in OSGi environments.

  • sshd-putty - contains code that can parse PUTTY key files.

  • sshd-openpgp - contains code that can parse OpenPGP key files (with some limitations - see relevant section)

  • sshd-cli - contains simple templates for command-line client/server - used to provide look-and-feel similar to the Linux ssh/sshd commands.

  • sshd-contrib - experimental code that is currently under review and may find its way into one of the other artifacts (or become an entirely new artifact - e.g., sshd-putty evolved this way).

Optional dependencies

Quick reference

Building the code

Including tests

mvn clean install

Without tests

mvn -Pquick clean install

Set up an SSH client in 5 minutes

Embedding an SSHD server instance in 5 minutes

SSH functionality breakdown

Security providers setup

Commands infrastructure

SCP

SFTP

Port forwarding

Internal support classes

Event listeners and handlers

Command line clients

GIT support

Configuration/data files parsing support

Extension modules

HOWTO(s)

Technical Documentation

SSH Key Exchange

TCP/IP Port Forwarding

Global Requests