* Drop net6.0 target
* Update src/Renci.SshNet/Common/TaskToAsyncResult.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* remove redundant #if
for some reason this made the compiler suddenly
realize that the plain text variables are unused.
* use TargetFrameworkIdentifier
this doesn't work in Directory.Build.props, moved it to Directory.Build.targets.
* fix null reference warnings in Benchmarks
seems like the warnings were (somehow) disabled here
before and were fixed by the previous TargetFrameworkIdentifier
change.
* fix unused plainTextOffset in AesGcmCipher.BclImpl
* CI retry
* more cosmetics
* more
* update README
* Revert "use TargetFrameworkIdentifier"
This reverts commit 076ede161d.
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
Co-authored-by: Robert Hague <rh@johnstreetcapital.com>
* Use System.Security.Cryptography in DesCipher and TripleDesCipher; Fall back to use BouncyCastle if BCL doesn't support
* Drop DesCipher; Replace PKCS7Padding with BouncyCastle's implementation.
* Restore `CbcCipherMode`
* Restore AesCipherMode; Use BlockImpl instead of BouncyCastleImpl for 3DES-CFB on lower targets.
* Restore the xml doc comment
* Replace DiagnosticAbstrations with Microsoft.Extensions.Logging.Abstractions
* add documentation
* reduce allocations by SessionId hex conversion
generate the hex string once instead of every log
call and optimize ToHex().
* Update docfx/logging.md
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* reduce log levels
* hook up testcontainers logging
* drop packet logs further down to trace
* add kex traces
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Migrate from AppVeyor to GitHub Actions
* also run on pull_request
* small formatting improvements
* add on: workflow_dispatch
this is needed to re-run jobs manually from the web UI
* Publish NuGet package to GitHub Registry
only on develop branch.
* re-add empty appveyor.yml
so it doesn't fail CI until AppVeyor integration is disabled
* fix appveyor
* typo
* Add support for OpenSSL PKCS#8 private key format
* Update comments
* Convert public key to ssh format
* Convert existing keys instead of generate new keys; Use DataRow for testing
* Minimize the change
* Minimize the change
* Fix build
* [AesGcmCipher] Use BouncyCastle as a fallback if BCL does not support.
* Switch back to collection initializer
* Remove conditional compilation
* Throw SshConnectionException with Reason MacError when authentication tag mismatch
* Separate BCL and BouncyCastle implementation
* Update AesGcmCipher.BclImpl.cs
* Naming enhancement
* Remove empty line
* Disable S1199. See https://github.com/sshnet/SSH.NET/pull/1371#discussion_r1704293356
* Set InnerException when MAC error. Remove Message check.
* Store KeyParameter as private field
* Use GcmCipher.ProcessAadBytes to avoid the copy of associated data
* Move nonce to constructor to avoid creating AeadParameters each packet
* Use const int for tag size
---------
Co-authored-by: Wojciech Nagórski <wojtpl2@gmail.com>
* Implements ChaCha20 cipher algorithm.
* Implements chacha20-poly1305@openssh.com
* Update Cipher.cs
* Update ChaCha20Poly1305Cipher.cs
* Note that the length of the concatenation of 'packet_length',
'padding_length', 'payload', and 'random padding' MUST be a multiple
of the cipher block size or 8, whichever is larger.
See https://www.rfc-editor.org/rfc/rfc4253#section-6
* Use Chaos.Nacl Poly1305Donna
* Fix build. Fix typo. Update README
* Update README.md
* Fix build
* Remove trailing whitespace
* Fix build
* Change to BouncyCastle
* Inherit from SymmetricCipher instead of StreamCipher since StreamCipher is deleted
* Resolve conflicts
* Move field to local variable
* Compute poly key stream once
* Update test/Renci.SshNet.IntegrationTests/CipherTests.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Fix build; Add net48 integration test in CI
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
Co-authored-by: Wojciech Nagórski <wojtpl2@gmail.com>
This drops some of the algorithms long-considered legacy/insecure.
The idea is both to improve the theoretical security of the library by not offering
these algorithms, and to improve the practical security of the library by not having
hand-written, barely tested crypto code.
The overarching goal is for the library to have minimal exposure to crypto
implementation, relying firstly on the .NET base libraries, and secondly on
third-party providers, such as BouncyCastle.
This change covers deleting the cipher algorithms arcfour, blowfish, twofish, cast.
It covers deleting the MD5-based and truncated HMAC algorithms.
These were all disabled in OpenSSH server (sshd) in 2014[^1]:
> sshd(8): The default set of ciphers and MACs has been altered to
> remove unsafe algorithms. In particular, CBC ciphers and arcfour*
> are disabled by default.
>
> The full set of algorithms remains available if configured
> explicitly via the Ciphers and MACs sshd_config options.
and in the client in 2016[^2]:
> This release disables a number of legacy cryptographic algorithms
> by default in ssh:
>
> * Several ciphers blowfish-cbc, cast128-cbc, all arcfour variants
> and the rijndael-cbc aliases for AES.
>
> * MD5-based and truncated HMAC algorithms.
>
> These algorithms are already disabled by default in sshd.
This change also drops PKCS5Padding, which is a line-for-line copy of PKCS7Padding,
and StreamCipher, which is now unused (and useless anyway).
[^1]: https://www.openssh.com/txt/release-6.7
[^2]: https://www.openssh.com/txt/release-7.2
Co-authored-by: Wojciech Nagórski <wojtpl2@gmail.com>
- Update README to point to https://sshnet.github.io/SSH.NET rather than the CHM file
- Add a CONTRIBUTING.md with some how-tos
For https://sshnet.github.io/SSH.NET:
- Use the repo README as the landing page to keep them in sync
- Combine the API-per-TFM pages to just one "API" page
- Add a couple more examples
- Add a GitHub link in the header.
* Init AeadCipher
* Move AeadCipher to parent folder. Move EncryptBlock/DecryptBlock from SymmetricCipher to BlockCipher
* simplify parameter name
* Implement AesGcmCipher
* Update README
* Remove protected IV from AeadCipher; Set offset to outbound sequence just like other ciphers
* Rename associatedData to packetLengthField
* Use Span<byte> to avoid unnecessary allocations
* Use `Span` to improve performance when `IncrementCounter()`
* Add `IsAead` property to `CipherInfo`. Include packet length field and tag field in offset and length when call AesGcm's `Decrypt(...)` method. Do not determine HMAC if cipher is AesGcm during kex.
* Fix build
* Fix UT
* Check `AesGcm.IsSupported` before add to the `Encryptions` collection.
Guard AES-GCM with `NET6_0_OR_GREATER`.
Insert AES-GCM ciphers right after AES-CTR ciphers but before AES-CBC ciphers, which is similar with OpenSSH:
```
debug2: ciphers ctos: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
debug2: ciphers stoc: chacha20-poly1305@openssh.com,aes128-ctr,aes192-ctr,aes256-ctr,aes128-gcm@openssh.com,aes256-gcm@openssh.com
```
Although Dictionary's order is not defined, from observation, it is in the same order with add. Anyway that would be another topic.
* Suppress CA1859 "Use concrete types when possible for improved performance" for `ConnectionInfo.Encryptions`.
Test `Aes128Gcm` and `Aes256Gcm` only when `NET6_0_OR_GREATER`
* Update xml doc comments. Do not treat AesGcmCipher separately in Session.cs
* Fix build
* Fix build
* Update the comment as ChaCha20Poly1305 uses a separated key to encypt the packet length and the size it 4.
* Update src/Renci.SshNet/Security/Cryptography/Cipher.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Make `AesGcmCipher` internal.
Assert offset when decrypt.
* Fix nullable error in build
* typos
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Integrate `ZLibStream` from .NET 6.0+ with SSH.NET.
* OpenSSH server does not support zlib (pre-auth); OpenSSH client still supports zlib (pre-auth)
* Correct compression algorithm name; Update README.md
* Integrate `ZLibStream` from .NET 6.0+ with SSH.NET.
* OpenSSH server does not support zlib (pre-auth); OpenSSH client still supports zlib (pre-auth)
* Correct compression algorithm name; Update README.md
* Test the compression by upload/download file
* Refactor compression.
* Move delayed compression logic to base class.
* seal Zlib
* update unit test
* update unit test to see if it can trigger integration test
* Flush zlibStream
* Fix integration test
* update test
* Update ConnectionInfo.cs
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Update README.md
---------
Co-authored-by: Rob Hague <rob.hague00@gmail.com>
* Support ETM (Encrypt-then-MAC) variants for HMAC
* Support ETM (Encrypt-then-MAC) variants for HMAC
* Remove `ETM` property from `HashInfo`
* Add support for HmacMd5Etm, HmacMd5_96_Etm, HmacSha1Etm and HmacSha1_96_Etm
Explicitly specify etm even if false
* Add Encrypt-then-MAC variants to README.md
* Add back empty span to prevent auto link
* Store ETM in `HashInfo`;
Change `HMAC Create[...]Hash()` to `HashAlgorithm Create[...]Hash(out bool isEncryptThenMAC)`
Remove support for legacy / deprecated target frameworks while adding support for .NET 6.0 (and higher).
The supported target frameworks are now:
* .NETFramework 4.6.2 (and higher)
* .NET Standard 2.0
* .NET 6.0 (and higher)
* OPENSSH KeyReader for more keys
Add support to parse OpenSSH Keys with ECDSA 256/384/521 and RSA.
https://github.com/openssh/openssh-portable/blob/master/PROTOCOL.key
Change-Id: Iaa9cce0f2522e5fee377a82cb252f81f0b7cc563
* Fix ED25519Key KeyLength
* Fix ED25519 PubKey-auth
LeadingZeros of BigInteger-Conversion have to be removed
before sending the Key.