Skip to content

Instantly share code, notes, and snippets.

@blacknon
Last active January 30, 2023 02:17
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save blacknon/71fc24cc7598bb8f875a7aa7fc095195 to your computer and use it in GitHub Desktop.
Save blacknon/71fc24cc7598bb8f875a7aa7fc095195 to your computer and use it in GitHub Desktop.
goで証明書認証してsshでシェルに接続する検証・サンプルコード
package main
import (
"fmt"
"io"
"io/ioutil"
"os"
"os/signal"
"os/user"
"strings"
"syscall"
"golang.org/x/crypto/ssh"
"golang.org/x/crypto/ssh/terminal"
)
func main() {
Host := "target.host"
Port := "22"
User := "user"
Cert := "/path/to/cert"
Certkey := "/path/to/secret_key"
// PATHをフルパスへ変換する
usr, _ := user.Current()
cert := strings.Replace(Cert, "~", usr.HomeDir, 1)
certkey := strings.Replace(Certkey, "~", usr.HomeDir, 1)
// 秘密鍵のSignerを作成する
keyData, err := ioutil.ReadFile(certkey)
if err != nil {
fmt.Println(err)
os.Exit(1)
}
keySigner, _ := ssh.ParsePrivateKey(keyData)
// 証明書を読み込む
certData, err := ioutil.ReadFile(cert)
if err != nil {
fmt.Println(err)
os.Exit(1)
}
// 証明書から公開鍵を取得する
pubkey, _, _, _, err := ssh.ParseAuthorizedKey(certData)
if err != nil {
fmt.Println(err)
os.Exit(1)
}
// 証明書をデータとして取得
certificate, ok := pubkey.(*ssh.Certificate)
if !ok {
fmt.Println("ng")
os.Exit(1)
}
// 証明書からsignerを作成する
signer, err := ssh.NewCertSigner(certificate, keySigner)
// authを作成する
var auth []ssh.AuthMethod
// ssh.PublicKeys(signers)
auth = append(auth, ssh.PublicKeys(signer))
// Create sshClientConfig
sshConfig := &ssh.ClientConfig{
User: User,
Auth: auth,
HostKeyCallback: ssh.InsecureIgnoreHostKey(),
}
// SSH connect.
client, err := ssh.Dial("tcp", Host+":"+Port, sshConfig)
// Create Session
session, err := client.NewSession()
defer session.Close()
// キー入力を接続先が認識できる形式に変換する(ここがキモ)
fd := int(os.Stdin.Fd())
state, err := terminal.MakeRaw(fd)
if err != nil {
fmt.Println(err)
}
defer terminal.Restore(fd, state)
// ターミナルサイズの取得
w, h, err := terminal.GetSize(fd)
if err != nil {
fmt.Println(err)
}
modes := ssh.TerminalModes{
ssh.ECHO: 1,
ssh.TTY_OP_ISPEED: 14400,
ssh.TTY_OP_OSPEED: 14400,
}
err = session.RequestPty("xterm", h, w, modes)
if err != nil {
fmt.Println(err)
}
// log := new(bytes.Buffer)
logFile, _ := os.OpenFile("./ssh_term_with_log.log", os.O_RDWR|os.O_CREATE|os.O_APPEND, 0600)
session.Stdout = io.MultiWriter(os.Stdout, logFile)
session.Stderr = io.MultiWriter(os.Stderr, logFile)
session.Stdin = os.Stdin
err = session.Shell()
if err != nil {
fmt.Println(err)
}
// ターミナルサイズの変更検知・処理
signal_chan := make(chan os.Signal, 1)
signal.Notify(signal_chan, syscall.SIGWINCH)
go func() {
for {
s := <-signal_chan
switch s {
case syscall.SIGWINCH:
fd := int(os.Stdout.Fd())
w, h, _ = terminal.GetSize(fd)
session.WindowChange(h, w)
}
}
}()
err = session.Wait()
if err != nil {
fmt.Println(err)
}
}
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment