HTML5 (plugin free) web-based terminal emulator and SSH client
github.com
github.com
I could see a number of use cases for this. However, I would like to know that it has been vetted for possible security issues.
-- Dan McDougall - Author of Gate One
In fact its just a front end. So yeah it's plugin free, but it's still not interesting. Means also that your password travels to the host machine then and that you get double latency.
"Bleh" comes to mind :-(
Please someone tell me I missed a sshprotocol.py and that the ssh.py was not full of system() calls :'(
I don't think that's possible. You would have to implement encryption in JavaScript and that is a horror in it's own right, especially when it comes to performance. There would be other problems too.
Means also that your password travels to the host machine then and that you get double latency.
Yes, but if you install this on your machine or another machine on your local network, it shouldn't be too bad.
"Bleh" comes to mind :-(
This is actually very cool! I develop on Windows (personal preference), but my development + production is all Linux. There's also instances on Rackspace and EC2, all Linux. This allows me to connect to them through the browser, without running SecureCRT or Putty!
edit: found websockify[1], which should be enough as the server-side component. Now only client-side remains :)
You probably mean WebSockets to TCP. That kinda kills the client-side concept. That is a neat little library though.
Otherwise there shouldn't be really many obstructions.
The entire point of SSH as opposed to Telnet is that it uses encryption. That means you need to do encryption in JavaScript. Now, I have a number of encryption algorithms that I use on a regular basis in JavaScript for short strings. In theory, you can do it for longer strings. In practice, I suspect you'll grind your browser to a halt.
Would be interesting if somebody else tried it though ...
Exactly. And that's why I'd prefer complete end-to-end encryption instead of giving plaintext to a middleman (or in worst-case scenario to an unknown middleman).
edit: Re: Performance. Best source I could find[1] about encryption with JS claims unoptimized AES implementation doing 30 kB/s in Firefox 3 on 2 GHz Core 2. Certainly enough for interactive use.
What is the improvement for your workflow? I'm genuinely interested, because I cannot even imagine why I'd drop putty (or something similar) and go for a web client here (at least not unless it would be something completely without a backend that I need to install first).
So: Why would you like to drop ~native~ clients?
I use SecureCRT (not free). Really good software, has tabs, a ton of features. However ...
1. I have to install it on every computer I use. It's not free or cheap. If I re-install OS, I have to re-install it. It is supported on Windows, Mac, and Linux, but if I need access while using my tablet or phone ... I'd need to install something else.
2. I use many servers and it doesn't synchronize settings between computers. I want to have access to all my servers whether I'm in the office or using my laptop at home. Not an issue with a web based system.
3. I make web based software, so ... it only makes sense that I support the ecosystem =)
* Gate One makes temporary network disruptions a trivial inconvenience: If your connection drops (which is sadly very common with business VPNs and home Internet connections) you can instantly resume all your open terminals the moment it comes back online. This also works for when you need to reboot your computer (not that Windows ever makes you do that ;).
* Gate One's bookmark manager is vastly superior to PuTTY's built-in session manager. With PuTTY, if you have more than a few "Saved Sessions" you'll have to scroll and scroll to find the one you want and the connection window isn't resizable. Also, you can't attach notes or classify them in any way. Gate One's bookmark manager is so much nicer (and faster to navigate).
* Gate One terminals don't clutter up your task manager. I've seen Systems Administrators struggle to find the right window when they have dozens of PuTTY windows open. Some other SSH clients support tabs but those can get out of control just as quickly. Gate One's grid view lets you manage (and find) a large number of terminals very efficiently.
* Gate One's session logging/recording, playback, and sharing features. PuTTY supports raw, text-based logging but it is unreliable (if you don't shut down PuTTY properly the log will be lost).
Of course, there's other features you might like but I won't enumerate them all here. PuTTY does some things Gate One can't do (e.g. port forwarding) but for most day-to-day stuff Gate One will probably be better.
-- Dan McDougall - Author of Gate One
"HTML5 SSH Client" is a misleading title because is not accurate. The heavy lifting resources to python and system calls.
-- Dan McDougall - Author of Gate One
Edit: Apparently FireSSH uses a javascript port of the paramiko ssh library. The port can be found here: http://www.mozdev.org/source/browse/fireftp/src/content/js/c...
Edit: From the paramikojs library: Q: Can I use FireSSH on a webpage? A: It's not possible at this time. The web at large currently doesn't allow javascript the same amount of permissions like addons have. The main issue is basically making socket connections. No, websockets don't cut it :-/
anyone know how he plans to do that? license it under different terms to network hardware device vendors for integration or something?
1) Gate One is licensed under the AGPLv3 which requires that you publicly distribute the source of anything that uses Gate One. Even if it is hosted via a SaaS or ASP solution. So if you want to include Gate One into another product you'll either have to make that product open source or buy a license (which will be available when Gate One reaches 1.0).
2) Support contracts. There's no requirement that business buy a support contract just to use Gate One inside their organization (please do!). Having said that, in my experience most businesses would be happy to pay for support if the price is right. Especially if there's worries about licensing (and many organizations are terrified of the AGPLv3).
-- Dan McDougall - Author of Gate One
* http://pypi.python.org/pypi/pyte * http://github.com/samfoo/vt102 * http://antony.lesuisse.org/software/ajaxterm/
(to name a few)
The biggest reason of all was the speed. Gate One needed to support multiple users running multiple terminals. Every terminal--when the screen is updated--needs to be converted into HTML and sent to the client. I wrote terminal.py to be as fast as possible with this purpose in mind.
For reference, I hadn't heard of pyte until I saw your link just now. I'll definitely be checking it out.
Having said all that, now that I've already written my own terminal emulator for Gate One, it includes some additional features that only Gate One is suited to take advantage of (special escape handlers that only terminal.py would know how to handle--for plugin authors to use). I don't think it would be practical to use something else at this point.
-- Dan McDougall - Author of Gate One
- they are either poorly or completely unsupported
- the code is a nightmare, badly written, undocumented
Both make extending a VTE an almost impossible task. Actually, that's why we (at Selectel) wrote `pyte` [http://github.com/selectel/pyte], which soon became open-source.As for speed issues, have you considered implementing incremental updates (like in AnyTerm, for example)? This approach works perfectly in our setup (multiple clients, multiple terminals).
P. S. Looking through the code, I can tell that you had some tough nights throughout those 9 months :) Good job!
There's another advantage to having all your terminals under one tab: They don't clutter up your tabs! LOL! If you've ever had a dozen or so PuTTY windows open you'll know that they can really clutter the heck out of your task manager. Having a zillion tabs open would have a similar effect.
-- Dan McDougall - Author of Gate One
Both (gateone and eftw) render terminal output on the server side using a python terminal emulator, while shellinabox mentioned in another comment uses a Javascript terminal emulator on the client side.
Edit: The docs say, the terminal class was written from scratch.
Also, the two work on completely different principals. EFTW uses long-held HTTP streams (which differs from Ajaxterm's long-polling method) while Gate One uses asynchronous WebSockets. WebSockets are vastly superior to the old AJAX methods in that they're much less bandwidth/CPU intensive and provide an order of magnitude less latency.
-- Dan McDougall - Author of Gate One
That said, if we get value of it, I'm not opposed to paying for it either. I'm just more interested in understanding whether the AGPL really forces this.
The GPL does not require you to release your modified version, or any part of it. You are free to make modifications and use them privately, without ever releasing them. This applies to organizations (including companies), too; an organization can make a modified version and use it internally without ever releasing it outside the organization.
http://www.gnu.org/licenses/gpl-faq.html
As long as all the users are internal to your organization, you don't have to provide the source to anyone.
The bigger concern with such an integration is if it ever gets exposed to the Internet at large. Then you'll need to distribute the source or be in violation. Why risk it? Licenses will be pretty cheap for such one-off situations. Everything is negotiable regardless.
-- Dan McDougall - Author of Gate One
- unicode characters (for instance you can't type in russian) -- try there http://demos.anyterm.org/shellinabox_nano
- speed could've been better, there's a noticeable delay when running something like `mc`
I haven't tried Gate One yet, but I did look very closely at your project at some point. Great work, btw :)I guess an "Under Construction" animated GIF would be better than a 403
sudo apt-get purge tornado
sudo pip install tornado pyopenssl kerberos
sudo ./setup.py install
cd /opt/gateone
./gateone.pyWhat advantage does this have over running ssh normally on my terminal, or putty?
Not being sarcastic, just genuinely curious about the rational of this application.
Most recently, I was able to rebook an upcoming flight in Sabre (a travel agent's reservation terminal) from an internet kiosk in the Hong Kong subway. It ran a very weird kiosk-mode browser based at least in part on IE 6.0, but I was still able to securely [2] open a terminal session on my server.
[1] http://code.google.com/p/shellinabox/
[2] I have an SSL certificate for my shellinabox vhost, which protects both the Javascript client code and the terminal communications; while I do have to trust that the web browser is properly validating the SSL certificate, it's pretty much the most secure solution possible that doesn't involve carrying around my own hardware.
- Easier to run on your 'mom's computer'
- Easier to get it to work on ipod/ipad without downloading the app.
- May avoid the ssh-key annoying stuff on different servers. (For instance, you've got a vps somewhere.. you can just login there to access your stuff; it makes it easier to associate which ssh is which).
- For device with only browsers (google laptop for instance)
- To have *everything* in the browsers; emails, todolist, consoles, etc.
- To make it easier to add some goodies; I.e. you've got the tab open, but you can bind some javascript stuff to ease your workflow. Way easier to write a chrome extension than modify Putty.
- Run it from school or jobs that need administrative access to do trivial things. (I.e. One could use emacs from his browser if he couldn't install it on his computer).
This is just some examples on the top of my head.Also, there's compliance (Gate One can be configured to log everything every user does--even to a central log server), the awesome bookmark manager, and then there's the fact that it is pretty much your only option if using a Chromebook :).
Side note: Gate One also has an interesting feature in that you can kill the Gate One daemon, start it back up, and everyone's sessions will be restored. It does this by way of the dtach program. This feature is actually the groundwork for some big things coming in the future for Gate One. Features that will likely make the front page again =)
-- Dan McDougall - Author of Gate One
Sounds scary.
-- Dan McDougall - Author of Gate One
Edit: To put it other way, this feels like using telnet to connect to a server where you can then ssh where you were going to. And the telnet server recording all traffic that goes through it.