tomazbracic

tomazbracic

Erlang's :ssh and key based Reverse Tunnel

:ssh … killing me softly and slowly :slightly_smiling_face:

Does anybody have a working example for using :ssh to do a (public/private) key based ssh reverse tunnel?

Having problems with :ssh and private key. Wasn’t able to connect. Various strange errors, but probably all due to my misconfigured setup. Didn’t find one yet, that I would be able to connect with private key.

Then I tried SSHex, but wan’t able to create a reverse tunnel on connect. I read somewhere that this is not supported.

Then i read about Librarian, with which I was actually able to at least connect, but then unable to create a reverse tunnel.

I need to do a reverse tunnel on initial connect.

If anybody has a working setup for :ssh I would really appreciate it.

Kind regards,
Tomaz

Marked As Solved

tomazbracic

tomazbracic

Thank you @LostKobrakai !!

I solved this togetherwith my coleage @uhrovat

In order to have this as refence I will try to write this in a way that I wish would have this before.

So the usecase is this. I have a Nerves based devices out in the field, connected over closed LTE network. So I can’t really reach devices from my cloud base service or directly from my dev laptop. Though majority of features is supported/implemented with the use of MQTT calls between device and cloud, there is still a great feeling being able to jump on a device and do some system checks or maintenance. In my case latter as I will be dealing with custom data handling and processin solution.

OPENSSH way (tested without nerves on clasic linux box)

1.) I crated ssh reverse tunnel with this on boxA (like gateway on picture)

ssh -i /home/tomaz/.ssh/nemo/user_ssh_key -nN -R 2222:localhost:22 Auser@192.168.x.130

user_ssh_key is a key on a proxy server, and Auser is a user on sshproxy server

2.) On ssh proxy I only added

3.) On my laptop I did

ssh -i gateway-id_rsa tomaz@192.168.x.130 -p 2222

gateway-id_rsa is a key that resolves against the PKI on gateway, and tomaz is a user on gateway.

With this in place I gain access to the “TERMINAL” shell on my boxA - which kind of simulates a real nerves gateway on picture. I do think this is really importnat for later.

:SSH (Erlang way). - still without real Nerves gateway.

I’ve created a reverse tunnel on linux VM box (not actual Nerves gateway)

:ssh library expects file to be one of -> id_rsa, id_dsa or id_ecdsa. ssh — ssh v5.4

I actually had to rename my key to be id_rsa and not some random name even though I tried to point to it

:ok = :ssh.start()

user = ~c"Auser"
userdir = ~c"/home/tomaz/.ssh/nemo"
ssh_option = [{:user, user}, {:silently_accept_hosts, true}, {:user_interaction, false}, {:user_dir, userdir}]

{:ok, conn} = :ssh.connect(String.to_charlist("192.168.x.130"), 22, ssh_option)

:ssh.tcpip_tunnel_from_server(conn, String.to_charlist("192.168.6.130"), 3333, String.to_charlist("localhost"), 22)

And this setup did establish the ssh reverse proxy. I logged everything in /var/log/auth on a sshproxy.

Then on my laptop I did

ssh -i Auser Auser@192.168.x.130 -p 3333

And with that I got access to linux shell (terminal) on the “gateway” linux VM box.

SSH (Erlang way) - NOW ON NERVES DEVICE

Similar approach as previous example but now on actual device.

iex(13)> :ssh.tcpip_tunnel_from_server(conn, String.to_charlist("mydomain"), 3333, String.to_charlist("localhost"), 22)
{:ok, 3334}
iex(14)>

Then from my dev laptop

ssh -i /Users/tomaz/.ssh/nemo/tomaz-id_rsa nerves@192.168.x.130 -p 3333

private key has a public key on a gateway. User is for gateway, and IP is for sshproxy server.

And what I get is wooohooo!!!

Warning: Permanently added '[192.168.x.130]:3333' (ED25519) to the list of known hosts.
Interactive Elixir (1.17.3) - press Ctrl+C to exit (type h() ENTER for help)
████▄▄    ▐███
█▌  ▀▀██▄▄  ▐█
█▌  ▄▄  ▀▀  ▐█   N  E  R  V  E  S
█▌  ▀▀██▄▄  ▐█
███▌    ▀▀████
nemo 0.26.0 (0626c4d3-89d7-5e8d-0584-d8f685366269) arm rpi4
  Serial       : 1000000094278b35
  Uptime       : 2 hours, 44 minutes and 16 seconds
  Clock        : 2024-11-15 12:16:21 UTC
  Temperature  : 29.7°C

  Firmware     : Valid (B)               Applications : 62 started (nemo not started)
  Memory usage : 163 MB (4%)             Part usage   : 493 MB (2%)
  Hostname     : nerves-8b35             Load average : 0.00 0.00 0.00

  eth0         : 192.168.x.163/24, fe80::da3a:ddff:feab:daf2/64

Nerves CLI help: https://hexdocs.pm/nerves/iex-with-nerves.html

Toolshed imported. Run h(Toolshed) for more info.
iex(1)>

currently my gateway is connected with ethernet cable, since my LTE doesn’t have a signal here.

Huge thumbs up to @uhrovat for joining efforts.

Hope this post helps others in the future.

Also Liked

LostKobrakai

LostKobrakai

Take a look at ssh — ssh v5.2.3. SSH in erlang is not wrapping openssh, but is a pure erlang implemenation. Hence you cannot easily translate openssh cli parameters to erlang, you need to translate to how those same features are implemented on erlangs ssh module.

Where Next?

Popular in Questions Top

sergio
In Ruby, I can go: User.find_by(email: "foobar@email.com").update(email: "hello@email.com") How can I do something similar in Elixir? ...
New
Tee
can someone please explain to me how Enum.reduce works with maps
New
bsollish-terakeet
Credo is smart enough to check for (something like) this: assert length(the_list) == 0 with this response: Checking if an enum is empt...
New
myronmarston
The Elixir Typespec docs show the following syntax for keyword lists in typespecs: # ... | [key: type] # keyword lis...
New
shahryarjb
Hello, I have map which I want to convert it to string like this: the map: %{last_name: "tavakkoli", name: "shahryar"} the string I ne...
New
belgoros
I’m not a pro in using Regex and can’t figure out why the following behaviour happens, especially if we take into account the difference ...
New
Codball
Mix format works fine if run from the cmd. I’ve followed this to facilitate the implementation into VSC which involves downloading an ext...
New
Qqwy
Original source of discussion: This topic on the Pragmatic Programmers' Functional Web Development with Elixir, OTP, and Phoenix forum. ...
New
vrod
I am using the Starship cross-shell prompt – it seems pretty nice, but I get some errors: [WARN] - (starship::utils): Executing command ...
New
lanycrost
Hi everyone! I need implement if…else if…else condition from my elixir code, and anymore of this control flow structures not work proper...
New

Other popular topics Top

sergio
I couldn’t find any guides that worked well with Phoenix 1.6.0 and esbuild. I hope this helps people test the waters and eases you into t...
New
SoCreat
i’m a new one to elixir which editor can i use vs code? or atom? Thanks! :smiley:
New
polypush135
As many of you may have realized by now (sorry for all the posts here) I’ve been working on a db problem where I’m trying to aggregate a ...
New
lastday4you
I wanted to check elixir version in phoenix because i found that my elixir is 1.5 but when i use Enum.chunk_by it said the function is un...
New
mcarvalho
What is the difference between System.get_env and Application.get_env? For example, what are best practices to use one versus another.
New
aadeshere1
I have a another noob question about loop. Since elixir is immutable, while loop is not directly possible. total = 10 while total != 0 ...
New
msaraiva
Surface is an experimental library built on top of Phoenix LiveView and its new LiveComponent API that aims to provide a more declarative...
564 42633 214
New
johnnyicon
Hi all, I've just started learning Elixir and Phoenix Framework, so please pardon my n00bness at this stage. I'm trying to use Postg...
New
romenigld
I am trying to run a deploy with docker and I successfully runned with this command: docker build -t romenigld/blog-prod . but when I t...
New
magnetic
Hey :wave:t3: Elixir community, I’ve been learning Elixir, and working on some side projects. My editor of choice is VSCode, and althoug...
New

We're in Beta

About us Mission Statement