SSH

Overview

SSH resources allow users to connect to Linux servers via SSH or SFTP through the Mamori web portal or the SSH proxy.

What Mamori needs to SSH to a target

Mamori acts as the SSH client to the target host. To open a session it always needs:

  • Target hostname (or IP) and port
  • Target account (remote user name), depending on the authentication method
  • A way to prove identity to that account — see the methods below

Users connecting through Mamori are multi-factored in the portal (or via the SSH proxy flow) before the outbound session to the target is established.

Authentication methods

Authentication MethodAccess MethodWhat Mamori uses on the target
Public Key AuthenticationSSH Proxy
Web Console
A stored SSH private key. The matching public key must be in the target account’s authorized_keys.
Enter CredentialsWeb ConsolePre-configured remote username and password.
Login PromptWeb Console onlyAfter MFA, the user is presented with the Linux login prompt and enters credentials there.
For Public Key Authentication, Mamori must hold the SSH private key (the matching public key is available from that stored key). The target host only needs the public key in authorized_keys. A public key alone on Mamori is not enough to authenticate to the target.
Recorded SSH sessions are only available from the Mamori web portal and via SSH Proxy.

Connecting via a native SSH client using the ZTNA solution will 2FA and record the TCP access, but it will not record the SSH session.


Create SSH Login

Use the same create flow for every authentication method. Choose the method in the form; only the credential fields change.

Click SSH Logins

Click

Set the common properties

FieldDescription
SSH Connection NameYour reference for the resource
Remote HostTarget server name or IP address
TCP PortTarget server port.
Defaults to 22
Remote Server Authentication MethodPublic Key Authentication, Enter Credentials, or Login Prompt
Remote User NameTarget account name.
Optional for Login Prompt
Idle time-out (minutes)Idle disconnect.
Defaults to 30
ThemeTerminal color theme

Complete the method-specific fields (see below)

Click Save

Public Key Authentication

Use when the target account trusts an SSH key pair and you want web and SSH proxy access.

Prerequisites

  • Create or import an SSH key in Mamori (private key stored; public key available to copy): Keys — SSH
  • Install that key’s public key on the target account (for example in ~/.ssh/authorized_keys). You can copy the public key from the Keys grid using the action described on that page.

In the create SSH Login form (above):

  • Set Remote Server Authentication Method to Public Key Authentication
  • Set Remote User Name to the target account
  • Set Private Key to the SSH key stored in Mamori

Enter Credentials

Use when the target accepts a password for the remote account (web console).

In the create SSH Login form (above):

  • Set Remote Server Authentication Method to Enter Credentials
  • Set Remote User Name and Password for the target account

No additional key setup is required.

Login Prompt

Use when users should type Linux credentials themselves after MFA (web console only).

In the create SSH Login form (above):

  • Set Remote Server Authentication Method to Login Prompt
  • Optionally set Remote User Name and Password
Login Prompt is only supported for Web SSH logins (not the SSH proxy).




Grant Access

Manual Grant

  • Click SSH Logins
  • Find the SSH Login in the grid and click
  • Click Manager Assigned Users or Manager Assigned Roles
  • For time grants toggled advanced options
  • Click on the grantee to add or remove the grant

Setup On-Demand

  • Click SSH Logins
  • Find the SSH Login in the grid and click
  • Click Manage Request Grants
  • Click Add Grant
  • Enter the grant information
  • Click Save




Connecting

Via Web Portal

To connect to a linux server via the web portal

  • Login to the Mamori portal
  • Click SSH Logins
  • Find the SSH Login you want to access
  • Click the Connect button

Via SSH Proxy

For instructions on connecting via SSH proxy using native SSH clients, see Access via Proxies - SSH Logins




Session recordings

Recorded SSH and SFTP sessions are available from the connection log. Open a connection and choose View Session Details to replay shell activity or download a video.

View a recording

  • Open the Connection log
  • Find the SSH connection and click on View Session Details row menu item
  • Use the Shell tab to replay the terminal session in the portal

File Transfer (SFTP/SCP) streams show transfer events. They do not include a Shell or Video player.

Download as video (MP4)

To export a recorded SSH shell session as an MP4 file

  • Open View Session Details for the SSH connection (see above)
  • Select the Video tab (next to Shell)
  • Optionally set the Video name and encode options
FieldDescription
Video nameFile name for the downloaded MP4
ThemeTerminal color theme (for example Dracula)
Font sizeRendered font size
SpeedPlayback speed multiplier
Max idleCap idle time in the video (None = no limit)
FPSFrame rate
QualityEncode quality (Low / Standard / High)
  • Click Download Video
  • A new browser tab opens, shows encode progress, then downloads the MP4
  • Keep the progress tab open until the download starts; you can continue working in the portal tab
  • Close the progress tab when finished
Video export is available for shell streams only (not SFTP/SCP).

Encoding can take time for long sessions. You need the same privileges used to view connection session details.
Edit this page on GitHub Updated at Fri, Sep 18, 2026