Last active
January 30, 2023 02:17
-
-
Save blacknon/71fc24cc7598bb8f875a7aa7fc095195 to your computer and use it in GitHub Desktop.
goで証明書認証してsshでシェルに接続する検証・サンプルコード
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
package main | |
import ( | |
"fmt" | |
"io" | |
"io/ioutil" | |
"os" | |
"os/signal" | |
"os/user" | |
"strings" | |
"syscall" | |
"golang.org/x/crypto/ssh" | |
"golang.org/x/crypto/ssh/terminal" | |
) | |
func main() { | |
Host := "target.host" | |
Port := "22" | |
User := "user" | |
Cert := "/path/to/cert" | |
Certkey := "/path/to/secret_key" | |
// PATHをフルパスへ変換する | |
usr, _ := user.Current() | |
cert := strings.Replace(Cert, "~", usr.HomeDir, 1) | |
certkey := strings.Replace(Certkey, "~", usr.HomeDir, 1) | |
// 秘密鍵のSignerを作成する | |
keyData, err := ioutil.ReadFile(certkey) | |
if err != nil { | |
fmt.Println(err) | |
os.Exit(1) | |
} | |
keySigner, _ := ssh.ParsePrivateKey(keyData) | |
// 証明書を読み込む | |
certData, err := ioutil.ReadFile(cert) | |
if err != nil { | |
fmt.Println(err) | |
os.Exit(1) | |
} | |
// 証明書から公開鍵を取得する | |
pubkey, _, _, _, err := ssh.ParseAuthorizedKey(certData) | |
if err != nil { | |
fmt.Println(err) | |
os.Exit(1) | |
} | |
// 証明書をデータとして取得 | |
certificate, ok := pubkey.(*ssh.Certificate) | |
if !ok { | |
fmt.Println("ng") | |
os.Exit(1) | |
} | |
// 証明書からsignerを作成する | |
signer, err := ssh.NewCertSigner(certificate, keySigner) | |
// authを作成する | |
var auth []ssh.AuthMethod | |
// ssh.PublicKeys(signers) | |
auth = append(auth, ssh.PublicKeys(signer)) | |
// Create sshClientConfig | |
sshConfig := &ssh.ClientConfig{ | |
User: User, | |
Auth: auth, | |
HostKeyCallback: ssh.InsecureIgnoreHostKey(), | |
} | |
// SSH connect. | |
client, err := ssh.Dial("tcp", Host+":"+Port, sshConfig) | |
// Create Session | |
session, err := client.NewSession() | |
defer session.Close() | |
// キー入力を接続先が認識できる形式に変換する(ここがキモ) | |
fd := int(os.Stdin.Fd()) | |
state, err := terminal.MakeRaw(fd) | |
if err != nil { | |
fmt.Println(err) | |
} | |
defer terminal.Restore(fd, state) | |
// ターミナルサイズの取得 | |
w, h, err := terminal.GetSize(fd) | |
if err != nil { | |
fmt.Println(err) | |
} | |
modes := ssh.TerminalModes{ | |
ssh.ECHO: 1, | |
ssh.TTY_OP_ISPEED: 14400, | |
ssh.TTY_OP_OSPEED: 14400, | |
} | |
err = session.RequestPty("xterm", h, w, modes) | |
if err != nil { | |
fmt.Println(err) | |
} | |
// log := new(bytes.Buffer) | |
logFile, _ := os.OpenFile("./ssh_term_with_log.log", os.O_RDWR|os.O_CREATE|os.O_APPEND, 0600) | |
session.Stdout = io.MultiWriter(os.Stdout, logFile) | |
session.Stderr = io.MultiWriter(os.Stderr, logFile) | |
session.Stdin = os.Stdin | |
err = session.Shell() | |
if err != nil { | |
fmt.Println(err) | |
} | |
// ターミナルサイズの変更検知・処理 | |
signal_chan := make(chan os.Signal, 1) | |
signal.Notify(signal_chan, syscall.SIGWINCH) | |
go func() { | |
for { | |
s := <-signal_chan | |
switch s { | |
case syscall.SIGWINCH: | |
fd := int(os.Stdout.Fd()) | |
w, h, _ = terminal.GetSize(fd) | |
session.WindowChange(h, w) | |
} | |
} | |
}() | |
err = session.Wait() | |
if err != nil { | |
fmt.Println(err) | |
} | |
} |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment