Rob Hague fe65570ebc Use System.Security.Cryptography for DSA (#1458)
* Use System.Security.Cryptography for DSA

This is the analogue of the RSA change #1373 for DSA. This has a couple of caveats:

- The BCL supports only FIPS 186-compliant keys, that is, public (P, Q) lengths
  of (512 <= P <= 1024, 160) for FIPS 186-1/186-2; and (2048, 256), (3072, 256)
  for FIPS 186-3/186-4. The latter also specifies (2048, 224) but due to a quirk
  in the Windows API, the BCL does not support Q values of length 224[^1].
- OpenSSH, based on the SSH spec, only supports (supported) Q values of length 160,
  but appears to also work in non-FIPS-compliant cases such as in our integration
  tests with a (2048, 160) host key. That test now fails and I changed that host key
  to (1024, 160).

This basically means that (1024, 160) is the largest DSA key size supported by both
SSH.NET and OpenSSH. However, given that OpenSSH deprecated DSA in 2015[^2], and the
alternative that I have been considering is just to delete support for DSA in the
library, this change seems reasonable to me. I don't think we can justify keeping the
current handwritten code around.

I think we may still consider dropping DSA from the library, I just had this branch
laying around and figured I'd finish it off.

[^1]: https://github.com/dotnet/runtime/blob/fadd8313653f71abd0068c8bf914be88edb2c8d3/src/libraries/Common/src/System/Security/Cryptography/DSACng.ImportExport.cs#L259-L265
[^2]: https://www.openssh.com/txt/release-7.0

* Appease mono

* test experiment

* Revert "Appease mono"

This reverts commit 881eefe5e8.
2024-08-11 07:48:58 +02:00
2024-07-04 10:31:07 +02:00
2021-02-21 10:39:55 +01:00
2024-05-10 11:38:47 +02:00
2024-04-17 13:43:36 +02:00
2024-05-10 11:38:47 +02:00
2023-12-01 22:56:48 +01:00
2022-12-20 16:24:20 +01:00
2024-05-22 20:36:15 +02:00
2023-10-14 22:16:11 +02:00

Logo SSH.NET

SSH.NET is a Secure Shell (SSH-2) library for .NET, optimized for parallelism.

Version NuGet download count Build status

Key Features

  • Execution of SSH command using both synchronous and asynchronous methods
  • SFTP functionality for both synchronous and asynchronous operations
  • SCP functionality
  • Remote, dynamic and local port forwarding
  • Interactive shell/terminal implementation
  • Authentication via publickey, password and keyboard-interactive methods, including multi-factor
  • Connection via SOCKS4, SOCKS5 or HTTP proxy

How to Use

Run a command

using (var client = new SshClient("sftp.foo.com", "guest", new PrivateKeyFile("path/to/my/key")))
{
    client.Connect();
    using SshCommand cmd = client.RunCommand("echo 'Hello World!'");
    Console.WriteLine(cmd.Result); // "Hello World!\n"
}

Upload and list files using SFTP

using (var client = new SftpClient("sftp.foo.com", "guest", "pwd"))
{
    client.Connect();

    using (FileStream fs = File.OpenRead(@"C:\tmp\test-file.txt"))
    {
        client.UploadFile(fs, "/home/guest/test-file.txt");
    }

    foreach (ISftpFile file in client.ListDirectory("/home/guest/"))
    {
        Console.WriteLine($"{file.FullName} {file.LastWriteTime}");
    }
}

Main Types

The main types provided by this library are:

  • Renci.SshNet.SshClient
  • Renci.SshNet.SftpClient
  • Renci.SshNet.ScpClient
  • Renci.SshNet.PrivateKeyFile
  • Renci.SshNet.SshCommand
  • Renci.SshNet.ShellStream

Additional Documentation

Encryption Methods

SSH.NET supports the following encryption methods:

  • aes128-ctr
  • aes192-ctr
  • aes256-ctr
  • aes128-gcm@openssh.com (.NET 6 and higher)
  • aes256-gcm@openssh.com (.NET 6 and higher)
  • chacha20-poly1305@openssh.com
  • aes128-cbc
  • aes192-cbc
  • aes256-cbc
  • 3des-cbc

Key Exchange Methods

SSH.NET supports the following key exchange methods:

  • curve25519-sha256
  • curve25519-sha256@libssh.org
  • ecdh-sha2-nistp256
  • ecdh-sha2-nistp384
  • ecdh-sha2-nistp521
  • diffie-hellman-group-exchange-sha256
  • diffie-hellman-group-exchange-sha1
  • diffie-hellman-group16-sha512
  • diffie-hellman-group14-sha256
  • diffie-hellman-group14-sha1
  • diffie-hellman-group1-sha1

Public Key Authentication

SSH.NET supports the following private key formats:

  • RSA in OpenSSL PEM ("BEGIN RSA PRIVATE KEY") and ssh.com ("BEGIN SSH2 ENCRYPTED PRIVATE KEY") format
  • DSA in OpenSSL PEM ("BEGIN DSA PRIVATE KEY") and ssh.com ("BEGIN SSH2 ENCRYPTED PRIVATE KEY") format
  • ECDSA 256/384/521 in OpenSSL PEM format ("BEGIN EC PRIVATE KEY")
  • ECDSA 256/384/521, ED25519 and RSA in OpenSSH key format ("BEGIN OPENSSH PRIVATE KEY")

Private keys can be encrypted using one of the following cipher methods:

  • DES-EDE3-CBC
  • DES-EDE3-CFB
  • DES-CBC
  • AES-128-CBC
  • AES-192-CBC
  • AES-256-CBC

Host Key Algorithms

SSH.NET supports the following host key algorithms:

  • ssh-ed25519
  • ecdsa-sha2-nistp256
  • ecdsa-sha2-nistp384
  • ecdsa-sha2-nistp521
  • rsa-sha2-512
  • rsa-sha2-256
  • ssh-rsa
  • ssh-dss

Message Authentication Code

SSH.NET supports the following MAC algorithms:

  • hmac-sha2-256
  • hmac-sha2-512
  • hmac-sha1
  • hmac-sha2-256-etm@openssh.com
  • hmac-sha2-512-etm@openssh.com
  • hmac-sha1-etm@openssh.com

Compression

SSH.NET supports the following compression algorithms:

  • none (default)
  • zlib@openssh.com

Framework Support

SSH.NET supports the following target frameworks:

  • .NETFramework 4.6.2 (and higher)
  • .NET Standard 2.0 and 2.1
  • .NET 6 (and higher)

Building the library

The library has no special requirements to build, other than an up-to-date .NET SDK. See also CONTRIBUTING.md.

Supporting SSH.NET

Do you or your company rely on SSH.NET in your projects? If you want to encourage us to keep on going and show us that you appreciate our work, please consider becoming a sponsor through GitHub Sponsors.

S
Description
SSH.NET is a Secure Shell (SSH) library for .NET, optimized for parallelism.
Readme MIT 32 MiB
Languages
C# 99.9%