SSH
Overview
SSH resources allow users to connect to Linux servers via SSH or SFTP through the Mamori web portal or the SSH proxy.
What Mamori needs to SSH to a target
Mamori acts as the SSH client to the target host. To open a session it always needs:
- Target hostname (or IP) and port
- Target account (remote user name), depending on the authentication method
- A way to prove identity to that account — see the methods below
Users connecting through Mamori are multi-factored in the portal (or via the SSH proxy flow) before the outbound session to the target is established.
Authentication methods
| Authentication Method | Access Method | What Mamori uses on the target |
|---|---|---|
| Public Key Authentication | SSH Proxy Web Console | A stored SSH private key. The matching public key must be in the target account’s authorized_keys. |
| Enter Credentials | Web Console | Pre-configured remote username and password. |
| Login Prompt | Web Console only | After MFA, the user is presented with the Linux login prompt and enters credentials there. |
authorized_keys. A public key alone on Mamori is not enough to authenticate to the target.
Connecting via a native SSH client using the ZTNA solution will 2FA and record the TCP access, but it will not record the SSH session.
Create SSH Login
Use the same create flow for every authentication method. Choose the method in the form; only the credential fields change.
Click SSH Logins
Click
Set the common properties
Field Description SSH Connection Name Your reference for the resource Remote Host Target server name or IP address TCP Port Target server port.
Defaults to 22Remote Server Authentication Method Public Key Authentication, Enter Credentials, or Login Prompt Remote User Name Target account name.
Optional for Login PromptIdle time-out (minutes) Idle disconnect.
Defaults to 30Theme Terminal color theme Complete the method-specific fields (see below)
Click Save
Public Key Authentication
Use when the target account trusts an SSH key pair and you want web and SSH proxy access.
Prerequisites
- Create or import an SSH key in Mamori (private key stored; public key available to copy): Keys — SSH
- Install that key’s public key on the target account (for example in
~/.ssh/authorized_keys). You can copy the public key from the Keys grid using the action described on that page.
In the create SSH Login form (above):
- Set Remote Server Authentication Method to Public Key Authentication
- Set Remote User Name to the target account
- Set Private Key to the SSH key stored in Mamori
Enter Credentials
Use when the target accepts a password for the remote account (web console).
In the create SSH Login form (above):
- Set Remote Server Authentication Method to Enter Credentials
- Set Remote User Name and Password for the target account
No additional key setup is required.
Login Prompt
Use when users should type Linux credentials themselves after MFA (web console only).
In the create SSH Login form (above):
- Set Remote Server Authentication Method to Login Prompt
- Optionally set Remote User Name and Password
Grant Access
Manual Grant
- Click SSH Logins
- Find the SSH Login in the grid and click
- Click Manager Assigned Users or Manager Assigned Roles
- For time grants toggled advanced options
- Click on the grantee to add or remove the grant
Setup On-Demand
- Click SSH Logins
- Find the SSH Login in the grid and click
- Click Manage Request Grants
- Click Add Grant
- Enter the grant information
- Click Save
Connecting
Via Web Portal
To connect to a linux server via the web portal
- Login to the Mamori portal
- Click SSH Logins
- Find the SSH Login you want to access
- Click the Connect button
Via SSH Proxy
For instructions on connecting via SSH proxy using native SSH clients, see Access via Proxies - SSH Logins
Session recordings
Recorded SSH and SFTP sessions are available from the connection log. Open a connection and choose View Session Details to replay shell activity or download a video.
View a recording
- Open the Connection log
- Find the SSH connection and click on View Session Details row menu item
- Use the Shell tab to replay the terminal session in the portal
File Transfer (SFTP/SCP) streams show transfer events. They do not include a Shell or Video player.
Download as video (MP4)
To export a recorded SSH shell session as an MP4 file
- Open View Session Details for the SSH connection (see above)
- Select the Video tab (next to Shell)
- Optionally set the Video name and encode options
Field Description Video name File name for the downloaded MP4 Theme Terminal color theme (for example Dracula) Font size Rendered font size Speed Playback speed multiplier Max idle Cap idle time in the video ( None= no limit)FPS Frame rate Quality Encode quality (Low / Standard / High)
- Click Download Video
- A new browser tab opens, shows encode progress, then downloads the MP4
- Keep the progress tab open until the download starts; you can continue working in the portal tab
- Close the progress tab when finished
Encoding can take time for long sessions. You need the same privileges used to view connection session details.