Easy SSH for admin ONLY ! Developped for @leboncoin
https://nicolasbeguier.shost.ca/cassh.html
Table of Contents generated with DocToc
A client / server app to ease management of PKI based SSH keys.
PythonPostgres as backendAdd new key to cassh-server :
$ cassh add
Sign pub key :
$ cassh sign [--display-only] [--uid=UID] [--force]
Get public key status :
$ cassh status
Get ca public key :
$ cassh ca
Get ca krl :
cassh krl
Active Client username key :
cassh admin <username> active
Revoke Client username key :
cassh admin <username> revoke
Delete Client username key :
cassh admin <username> delete
Status Client username key :
cassh admin <username> status
Set Client username key :
cassh admin <username> set --set='expiry=+7d'
cassh admin <username> set --set='principals=username,root'
# Python Pip
sudo apt-get install \
python-pip \
python-dev \
libsasl2-dev \
libldap2-dev \
libssl-dev \
libpq-dev
pip install -r server/requirements.txt
OR
# Debian packages
sudo apt-get install \
python-psycopg2 \
python-webpy \
python-ldap \
python-configparser \
python-requests \
python-openssl
OR
docker pull leboncoin/cassh-server
# Generate CA ssh key and revocation key file
mkdir test-keys
ssh-keygen -C CA -t rsa -b 4096 -o -a 100 -N "" -f test-keys/id_rsa_ca # without passphrase
ssh-keygen -k -f test-keys/revoked-keys
# cassh.conf
[main]
ca = /etc/cassh/ca/id_rsa_ca
krl = /etc/cassh/krl/revoked-keys
port = 8080
# Optionnal : admin_db_failover is used to bypass db when it fails.
# admin_db_failover = False
[postgres]
host = cassh.domain.fr
dbname = casshdb
user = cassh
password = xxxxxxxx
# Highly recommended
[ldap]
host = ldap.domain.fr
bind_dn = OU=User,DC=domain,DC=fr
admin_cn = CN=Admin,OU=Group,DC=domain,DC=fr
# Key in user result to get his LDAP realname
filterstr = userPrincipalName
# Optionnal
[ssl]
private_key = /etc/cassh/ssl/cert.key
public_key = /etc/cassh/ssl/cert.pem
You need to create a database: SQL Model
pip3 insall -r requirements.txt
python3 server/web/cassh_web.py
Python 3
sudo apt-get install python3-pip
pip3 install -r requirements.txt
Python 2
sudo apt-get install python-pip
pip install -r requirements.txt
Docker
./contrib/cassh_docker.sh
TODO
[ssl]
private_key = __CASSH_PATH__/ssl/server.key
public_key = __CASSH_PATH__/ssl/server.pem
[ldap]
host = ldap.domain.fr
bind_dn = OU=User,DC=domain,DC=fr
admin_cn = CN=Admin,OU=Group,DC=domain,DC=fr
# Key in user result to get his LDAP realname
filterstr = userPrincipalName
Requirements:
docker : https://docs.docker.com/engine/installation/docker-compose: https://docs.docker.com/compose/installation/bats: https://github.com/sstephenson/batscurl & jq with your distro packages managerRun the tests
tests/tests.sh
Content type
Image
Digest
Size
342.1 MB
Last updated
over 6 years ago
docker pull leboncoin/cassh-server