Warpgate: Smart SSH bastion that works with any SSH client
github.com
github.com
I had it so that a user needed to login to the service with their GSuite account every 24H, and each login required 2fa as well. SSH sessions were recorded in asciicast format (which seems to be used here as well) and there was an audit log to track connections. They could be joined in real time and disconnected from a simple admin interface. The ACL system was a pretty basic method of using regex for defining auth rules.
Worked pretty well and helped with compliance audits we were completing at the time. I think the benefits here of being in Rust is definitely performance and memory safety. Granted, The Go implementation was pretty fast and safe as well. Go made it pretty easy to implement due to the SSH implementation in the standard library.
[0] https://github.com/notion/bastion
[1] https://www.vaultproject.io/docs/secrets/ssh/signed-ssh-cert...
OpenSSH has been battle-tested to death and comes from a good stable (OpenBSD, LibreSSL).
I'm very weary indeed of re-implementations of SSH servers.
Also, I'm less concerned about the memory safety than the _complete reimplementation of SSH_ from scratch. So give me OpenSSH any day for things that are actually important.
The feature turns off extra compile time checks. That’s it. It doesn’t mean the program is correct.
This program still allows potentially damaging things like `rm -rf /`. So, it’s not data safe. It’s unknown whether it’s secure safe either, since it’s not been audited and it’s still “alpha”.
Which offers a little more than a simple SSH bastion would, unless there are features like this in OpenSSH I'm not aware of.
The security properties of this are a little scary, too: the recommended configuration here has all hosts trusting the bastion, which kind of undoes the point. Pwn the bastion host, and pwn everything.
It's trickier, but a decent ssh jumphost requires the user to authenticate to the bastion and the host behind.
So have wet paper bags ;]
But SSO support does feel like an enterprise feature that people typically pay for.
I can’t think of any other feature gate that would work as well for software such as this. Though it typically is the largest hinderance to SSO adoption.
Obviously big companies will pay for SSO because they must have SSO. At my scale I skip products that are overpricing SSO or I put them behind a oauth2-proxy when I can.
Is Rust unable to provide a suitable back end - the need for node seems offputting
Not used or needed at runtime