Skip to content

Repository files navigation

Russh

Crate Docs

A low-level, async SSH 2.0 client and server library for Rust / Tokio.

Russh gives you direct access to the SSH protocol: channels, authentication, key exchange, port and socket forwarding. It is written in safe Rust, uses async traits, and supports a broad range of algorithms for wide scale interoperability with real-world servers and clients.

  • Async-native - integrates directly with Tokio, AsyncRead/AsyncWrite channels
  • Broad interoperability - safe algorithms by default, with opt-in support for legacy ones
  • Safety-focused - panics, unwrap/expect and unchecked indexing are denied by default

Getting started

Add russh to your Cargo.toml, choosing a crypto backend feature (see below):

[dependencies]
russh = { version = "0.63", features = ["aws-lc-rs"] }
tokio = { version = "1", features = ["full"] }

Then have a look at the examples:

API documentation is on docs.rs

Crypto backends

Russh requires exactly one crypto backend. Enable the aws-lc-rs or ring crate feature.

# aws-lc-rs (default in most setups)
russh = { version = "0.63", features = ["aws-lc-rs"] }

# or ring (keep `flate2` and `rsa` when disabling default features)
russh = { version = "0.63", default-features = false, features = ["ring", "flate2", "rsa"] }

Supported algorithms

Russh aims for broad interoperability, so it supports both algorithms currently considered safe and a set of older ones that allow connections to older switches etc. Legacy algorithms are opt in.

Key exchange

Recommended

  • mlkem768x25519-sha256 (post-quantum hybrid)
  • curve25519-sha256, curve25519-sha256@libssh.org
  • diffie-hellman-group-exchange-sha256 (GEX)
  • diffie-hellman-group18-sha512, diffie-hellman-group17-sha512, diffie-hellman-group16-sha512, diffie-hellman-group15-sha512
  • diffie-hellman-group14-sha256
  • OpenSSH strict key exchange (Terrapin mitigation)
  • Programmatic group choice support for DH-GEX

Legacy

  • ecdh-sha2-nistp256, ecdh-sha2-nistp384, ecdh-sha2-nistp521
  • diffie-hellman-group14-sha1
  • diffie-hellman-group1-sha1
  • diffie-hellman-group-exchange-sha1 (GEX)

Ciphers

Recommended

  • chacha20-poly1305@openssh.com
  • aes256-gcm@openssh.com, aes128-gcm@openssh.com
  • aes256-ctr, aes192-ctr, aes128-ctr

Legacy

  • aes256-cbc, aes192-cbc, aes128-cbc
  • 3des-cbc (requires the des crate feature)

MACs

Recommended

  • hmac-sha2-256-etm@openssh.com, hmac-sha2-512-etm@openssh.com
  • hmac-sha2-256, hmac-sha2-512

Legacy

  • hmac-sha1-etm@openssh.com
  • hmac-sha1

Compression

  • none
  • zlib, zlib@openssh.com (requires the flate2 crate feature, on by default)

Host keys & public-key authentication

Recommended

  • ssh-ed25519
  • ecdsa-sha2-nistp256, ecdsa-sha2-nistp384, ecdsa-sha2-nistp521
  • rsa-sha2-256, rsa-sha2-512
  • ssh-rsa (SHA-1)
  • OpenSSH certificates

Authentication methods

  • publickey
  • password
  • keyboard-interactive
  • none
  • OpenSSH certificate authentication

Features

  • Local port forwarding (direct-tcpip)
  • Remote port forwarding (forward-tcpip)
  • Local UNIX socket forwarding (direct-streamlocal, client only)
  • Remote UNIX socket forwarding (forward-streamlocal)
  • AsyncRead / AsyncWrite-able channels
  • OpenSSH agent forwarding channels
  • OpenSSH keepalive request handling
  • OpenSSH server-sig-algs extension
  • PuTTY PPK key format
  • Pageant support (Windows)

Safety

Russh is built to withstand malicious/misbehaving peers.

  • deny(clippy::unwrap_used)
  • deny(clippy::expect_used)
  • deny(clippy::indexing_slicing)
  • deny(clippy::panic)

Exceptions are reviewed and justified manually.

Unsafe code

  • cryptovec uses unsafe for faster copying, initialization, and binding to native APIs.

Ecosystem

  • russh-sftp - server-side and client-side SFTP subsystem support for russh; see russh/examples/sftp_server.rs or russh/examples/sftp_client.rs.
  • async-ssh2-tokio - simple high-level API for running commands over SSH.

Adopters

  • HexPatch - A binary patcher and editor written in Rust with a terminal user interface (TUI).
    • Uses russh::client and russh_sftp::client to allow remote editing of files.
  • kartoffels - A game where you're given a potato and your job is to implement a firmware for it.
    • Uses russh::server to deliver the game, using ratatui as the rendering engine.
  • kty - The terminal for Kubernetes.
    • Uses russh::server to deliver the ratatui based TUI and russh_sftp::server to provide scp based file management.
  • lapdev - Self-hosted remote dev environment.
    • Uses russh::server to construct a proxy into your development environment.
  • medusa - A fast and secure multi-protocol honeypot.
    • Uses russh::server to be the basis of the honeypot.
  • rebels-in-the-sky - P2P terminal game about space pirates playing basketball across the galaxy.
    • Uses russh::server to deliver the game, using ratatui as the rendering engine.
  • warpgate - Smart SSH, HTTPS and MySQL bastion that requires no additional client-side software.
    • Uses russh::server in addition to russh::client as part of the smart SSH functionality.
  • Devolutions Gateway - Establish a secure entry point for internal or external segmented networks that require authorized just-in-time (JIT) access.
    • Uses russh::client for the web-based SSH client of the standalone web application.
  • Sandhole - Expose HTTP/SSH/TCP services through SSH port forwarding. A reverse proxy that just works with an OpenSSH client.
    • Uses russh::server for reverse forwarding connections, local forwarding tunnels, and the ratatui based admin interface.
  • Motor OS - A new Rust-based operating system for VMs.
    • Uses russh::server as the base for its own SSH Server.
  • Cubic VM - A lightweight command-line manager for virtual machines.
    • Uses russh::client and russh_sftp::client to access the virtual machine instances.
  • ferrissh - An async SSH CLI scraper library for network device automation in Rust.
    • Uses russh::client for SSH transport, authentication, and interactive PTY sessions.
  • Yazi - Blazing fast terminal file manager written in Rust, based on async I/O.
    • Uses russh::client to implement an async SFTP provider for remote file management.
  • GitArena - Software development platform with built-in VCS, issue tracking and code review.
    • Uses russh::server to allow Git operations over SSH.
  • Calagopus - Fast, efficient and scalable game hosting - built for everyone.
    • Uses russh::server for efficiently implementing SSH shells and SFTP file management.
  • Oryxis - Rust-native SSH client with an encrypted vault, P2P sync and an embedded terminal.
    • Uses russh::client for connections, jump hosts, SOCKS/HTTP/command proxies and SFTP.
  • react-native-ssh - Native SSH client for React Native and Expo.
    • Uses russh::client as the SSH transport implementation behind Nitro Modules bindings.

History

Russh began as a fork of Thrussh by Pierre-Γ‰tienne Meunier, originally extended to provide the SSH backend for Warpgate.

It has since been substantially reworked, and is maintained independently. Russh prioritises safety-by-default and broad algorithm interoperability. Thanks to Pierre-Γ‰tienne and the Thrussh contributors for the original foundation.

Contributors ✨

Thanks goes to these wonderful people (emoji key):

Mihir Samdarshi
Mihir Samdarshi

πŸ“–
Connor Peet
Connor Peet

πŸ’»
KVZN
KVZN

πŸ’»
Adrian MΓΌller (DTT)
Adrian MΓΌller (DTT)

πŸ’»
Simone Margaritelli
Simone Margaritelli

πŸ’»
Joe Grund
Joe Grund

πŸ’»
AspectUnk
AspectUnk

πŸ’»
SimΓ£o Mata
SimΓ£o Mata

πŸ’»
Mariotaku
Mariotaku

πŸ’»
yorkz1994
yorkz1994

πŸ’»
Ciprian Dorin Craciun
Ciprian Dorin Craciun

πŸ’»
Eric Milliken
Eric Milliken

πŸ’»
Swelio
Swelio

πŸ’»
Joshua Benz
Joshua Benz

πŸ’»
Jan Holthuis
Jan Holthuis

πŸ›‘οΈ
mateuszkj
mateuszkj

πŸ’»
Saksham Mittal
Saksham Mittal

πŸ’»
Lucas Kent
Lucas Kent

πŸ’»
Raphael Druon
Raphael Druon

πŸ’»
Maya the bee
Maya the bee

πŸ’»
Milo Mirate
Milo Mirate

πŸ’»
George Hopkins
George Hopkins

πŸ’»
Γ…ke Amcoff
Γ…ke Amcoff

πŸ’»
Brendon Ho
Brendon Ho

πŸ’»
Samuel Ainsworth
Samuel Ainsworth

πŸ’»
Sherlock Holo
Sherlock Holo

πŸ’»
Alessandro Ricottone
Alessandro Ricottone

πŸ’»
T0b1-iOS
T0b1-iOS

πŸ’»
Shoaib Merchant
Shoaib Merchant

πŸ’»
Michael Gleason
Michael Gleason

πŸ’»
Ana Gelez
Ana Gelez

πŸ’»
Tom KΓΆnig
Tom KΓΆnig

πŸ’»
Pierre Barre
Pierre Barre

πŸ’»
Jean-Baptiste Skutnik
Jean-Baptiste Skutnik

πŸ’»
Adam Chappell
Adam Chappell

πŸ’»
Yaroslav Bolyukin
Yaroslav Bolyukin

πŸ’»
Julian
Julian

πŸ’»
Thomas Rampelberg
Thomas Rampelberg

πŸ’»
Kaleb Elwert
Kaleb Elwert

πŸ“–
Gary Guo
Gary Guo

πŸ’»
irvingouj @ Devolutions
irvingouj @ Devolutions

πŸ’»
Toni Peter
Toni Peter

πŸ’»
Nathaniel Bajo
Nathaniel Bajo

πŸ’»
Eric Rodrigues Pires
Eric Rodrigues Pires

πŸ’»
Jerome Gravel-Niquet
Jerome Gravel-Niquet

πŸ’»
Quentin Santos
Quentin Santos

πŸ“–
AndrΓ© Almeida
AndrΓ© Almeida

πŸ’»
Mattias Eriksson
Mattias Eriksson

πŸ’»
Josh McKinney
Josh McKinney

πŸ’»
citorva
citorva

πŸ’»
Eric Seppanen
Eric Seppanen

πŸ’»
Eric Seppanen
Eric Seppanen

πŸ’»
Patryk Wychowaniec
Patryk Wychowaniec

πŸ’»
@RandyMcMillan
@RandyMcMillan

πŸ’»
handewo
handewo

πŸ’»
Chris
Chris

πŸ’»
procr1337
procr1337

πŸ’»
iHsin
iHsin

πŸ’»
Uli Schlachter
Uli Schlachter

πŸ’»
Jacob Van Brunt
Jacob Van Brunt

πŸ’»
lgmugnier
lgmugnier

πŸ’»
Mingwei Samuel
Mingwei Samuel

πŸ’»
Pascal Grange
Pascal Grange

πŸ’»
wyhaya
wyhaya

πŸ’»
Philippe Laflamme
Philippe Laflamme

πŸ’»
Tom
Tom

πŸ’»
vzex
vzex

πŸ’»
Kenny Root
Kenny Root

πŸ’»
MΓ΄she van der Sterre
MΓ΄she van der Sterre

πŸ’»
Lucy
Lucy

πŸ’»
Mark Bundschuh
Mark Bundschuh

πŸ’»
tayu0110
tayu0110

πŸ’»
Roger Knecht
Roger Knecht

πŸ’»
Guilherme Fontes
Guilherme Fontes

πŸ’»
Lyn
Lyn

πŸ’»
Mota-Link
Mota-Link

πŸ’»
Mika Cohen
Mika Cohen

πŸ’»
FranΓ§ois Bernier
FranΓ§ois Bernier

πŸ’»
kpcyrd
kpcyrd

πŸ’»
Corey Leavitt
Corey Leavitt

πŸ’»
wi-adam
wi-adam

πŸ’»
Artem Medvedev
Artem Medvedev

πŸ’»
ztbh
ztbh

πŸ’»
Moder Steven
Moder Steven

πŸ’»
Jeongkyu Shin
Jeongkyu Shin

πŸ’»
PokAhonTAS911
PokAhonTAS911

πŸ’»
ayamir
ayamir

πŸ’»
Luiz Ribeiro
Luiz Ribeiro

πŸ’»
biao29
biao29

πŸ’»
Georg von Zengen
Georg von Zengen

πŸ’»
tluyben
tluyben

πŸ’»
Marko Vejnovic
Marko Vejnovic

πŸ’»
t8y2
t8y2

πŸ’»

This project follows the all-contributors specification. Contributions of any kind welcome!

About

Rust SSH client & server library

Topics

Resources

Security policy

Stars

1.9k stars

Watchers

7 watching

Forks

Releases

Sponsor this project

Packages

Used by

Contributors

Languages