Skip to content

SSHGate v0.4.0

Choose a tag to compare

@github-actions github-actions released this 05 Sep 11:08
· 23 commits to main since this release
6e3995f

Security hardening for SSHGate's connection gate, observation storage, and control-plane synchronization.

Changes

  • Rejected clients receive a cached SSH identification and never open a backend connection. Allowed clients verify the real backend identification before forwarding KEXINIT.
  • Bound backend dialing and handshake reads/writes, and cap the initial SSH packet at 32 KiB.
  • Upgrade to Gatekit v0.5.0: metadata is capped at 64 KiB, IP/port/sighting history at 128 values per collection, fingerprint counts are enforced transactionally, and observation uploads use bounded pages.
  • Require HTTPS control-plane endpoints and reject redirects. Include CA certificates in the scratch container.
  • Remove the completed one-time randomized-port migration scripts.
  • Include the Go 1.27 build-toolchain update and blocking error/lint checks landed since v0.3.1.

Upgrade notes

  • Each backend must be reachable when SSHGate starts, because its identification is probed once per route.
  • If an sshd upgrade changes the backend identification, the first allowed connection refreshes the cache and closes; retry the connection.
  • Existing databases retain verdicts, labels, and counts, but excess history and oversized metadata are removed. SQLite may retain freed pages for reuse.
  • Configure the final HTTPS control-plane URL directly; HTTP and redirects are rejected.
  • Fingerprints remain spoofable and are not authentication. Backend SSH authentication is unchanged.

Artifacts

Linux amd64 and arm64 binaries and SHA256SUMS are attached. Container images are published to ghcr.io/kilo666mj/sshgate:0.4.0 and :latest for linux/amd64 and linux/arm64.

Validation includes race tests, vet, pinned lint, module verification, a vulnerability scan, a local container build, and a real OpenSSH key exchange. Gatekit's security change also passed CodeQL.