Skip to content

SSH Access

dwiigoy edited this page Jul 19, 2026 · 2 revisions

SSH Access

NoBrain includes a managed OpenSSH server for the Linux guest.

Default policy

  • Login user: nobrain
  • Default port: 2223
  • Default mode: key only
  • Direct root login: rejected
  • Per-install Ed25519 bootstrap key

Open:

NoBrain menu -> SSH Access

Choose Key (secure, recommended) for the standard setup.

Export the bootstrap key

In the Key menu, choose Export key. The files are written to Android shared storage:

Internal storage/Download/NoBrain-SSH/nobrain_ed25519
Internal storage/Download/NoBrain-SSH/nobrain_ed25519.pub

The export path is based on Android shared storage, not a developer username or Linux home directory. If shared storage is unavailable, the operation fails instead of silently exporting a private key elsewhere.

If export fails:

  1. Grant NoBrain All files access in Android settings.
  2. Use NoBrain menu -> Shutdown.
  3. Reopen NoBrain and retry the export.

Connect from another device

Copy the private key to the client device, protect it, and connect to the Android device IP:

chmod 600 ~/.ssh/nobrain_ed25519
ssh -i ~/.ssh/nobrain_ed25519 -p 2223 nobrain@DEVICE_IP

Both devices must be able to reach each other. Android wireless-debugging ports are unrelated to the NoBrain SSH port.

Key management

The Key menu can:

  • display status and the bootstrap fingerprint;
  • export the bootstrap key;
  • import an authorized_keys file;
  • rotate the bootstrap key;
  • remove the exported private-key copy from shared storage.

For import, place this file first:

Internal storage/Download/NoBrain-SSH/authorized_keys

After confirming that SSH works from your normal client, remove the exported private key from shared storage. Keep a protected backup if required.

Password and Custom modes

Password mode exposes password authentication to the network. Change the default password before enabling it:

passwd nobrain

Custom mode is intended for experienced users. NoBrain validates the working sshd_config, checks requested ports, keeps a backup, and attempts to restore the previous configuration when applying a new listener fails.

Never attach a private SSH key or a real sshd_config containing secrets to a public GitHub issue.


Previous: Package Management · Next: WPS Office

Clone this wiki locally