SSH Connection

Utilities Targets Requires: signed in

Configure secure SSH access to the target device.

Configures communication with the display over SSH — key files, login names, etc. for communicating securely with the shell on the target. This is used for Prep Target, as well as other tools such as viewing journals. Host Name / IP is shared with Toolkit Connection — changing it here changes it there too.

Fields: Host Name / IP, Login Name, SSH Key File (to create one, use the Project Editor to generate a DeviceKey, added to your ~/.ssh/), and Signing Key (to create one, use the Project Editor to generate a SigningKey for app signing).

While this tab is selected, the Actions panel becomes SSH Actions, offering Lock Target and Unlock Target in addition to Add/Remove Display.

The same address and login name also let anyone on the network connect to the display over SSH — until the target is locked. See Connecting over SSH below.

Connecting over SSH

Watch video walkthrough

  1. To connect to the display over SSH — here with WinSCP — you need its address and login name. Both are on the SSH Connection tab: note the Host Name / IP — here, 192.168.7.1 — and the Login Name — here, root.

    The Host Name / IP and Login Name on the SSH Connection tab
    The Host Name / IP and Login Name on the SSH Connection tab
  2. Open WinSCP. In the Login dialog, with New Site selected, leave File protocol set to SFTP — the SSH File Transfer Protocol, which runs over SSH.

    WinSCP's Login dialog, with SFTP as the file protocol
    WinSCP's Login dialog, with SFTP as the file protocol
  3. Enter the Host Name / IP from the toolkit as Host name, leave Port number at 22, and enter the Login Name as User name. Click Login.

    The Login dialog filled in with the display's address and login name
    The Login dialog filled in with the display's address and login name
  4. The first time you connect to a display, WinSCP warns that the server is unknown and asks whether to add its host key to the cache. Check that the address shown is your display's, then click Accept. WinSCP remembers the key, so this doesn't appear again for the same display.

    WinSCP asking whether to trust the display's host key
    WinSCP asking whether to trust the display's host key
  5. On an unlocked display, WinSCP connects without asking for a password — the status bar shows SFTP-3. The left pane shows your PC (here, the PackageOutput folder) and the right pane shows the display's file system, starting in /home/root/. Drag files between the panes to copy them.

    WinSCP connected to the display over SSH
    WinSCP connected to the display over SSH
Note: An unlocked display accepts SSH logins as root without a password, so anyone on the same network can read or replace files on it. Use Lock Target to disable password-based logins before the display leaves your bench.

Lock Target

Watch video walkthrough

  1. Lock Target replaces the display's password-less logins with a key: afterwards, only someone holding the matching private key can connect over SSH. First choose the key. On the SSH Connection tab, click SSH Key File.

    The SSH Key File dropdown on the SSH Connection tab
    The SSH Key File dropdown on the SSH Connection tab
  2. The list shows every key found in your ~/.ssh folder. Select the device key to lock with — here, DeviceDemoKey, created in New Device Key.

    Choosing DeviceDemoKey from the SSH Key File list
    Choosing DeviceDemoKey from the SSH Key File list
  3. With the key selected, click Lock Target in SSH Actions.

    DeviceDemoKey selected, ready to lock
    DeviceDemoKey selected, ready to lock
  4. A confirmation explains what it does: disables password-based logins, and installs device and application keys (if selected). Click Yes.

    The Lock Target confirmation dialog
    The Lock Target confirmation dialog
  5. The app switches to Console while it adds the key to the display. This only takes a moment.

    The Console while Lock Target runs
    The Console while Lock Target runs
  6. It then returns to the SSH Connection tab with a Lock Display Complete dialog. Click Ok.

    The Lock Display Complete dialog
    The Lock Display Complete dialog
  7. Back on the SSH Connection tab, SSH Key File now shows OpenView instead of the key you chose — you'll fix that after the reboot. Click Console to review the full log.

    Back on the SSH Connection tab after locking
    Back on the SSH Connection tab after locking
  8. The log confirms Device Locked to KeyFile with the path to DeviceDemoKey, and that the target is now available over SSH as root@OpenView. Close the Console with its X.

    The Console log after Lock Target
    The Console log after Lock Target
  9. The lock doesn't take effect until the display restarts — until then, it still accepts password-less logins. Click the Reboot Display icon at the bottom right.

    The Reboot Display icon in the status bar
    The Reboot Display icon in the status bar
  10. Once the display reconnects, SSH Key File still shows OpenView: after a lock, the toolkit switches it to a key named after the connection, even though you locked with a different key. Click it to change it back.

    SSH Key File showing OpenView after the lock
    SSH Key File showing OpenView after the lock
  11. The list now includes OpenView as well, even though no key file by that name exists. Select the key you locked with — here, DeviceDemoKey — so the toolkit's own SSH actions, such as Prep Target and Unlock Target, can still connect.

    Reselecting DeviceDemoKey
    Reselecting DeviceDemoKey
  12. The display is now locked. It only accepts SSH logins using DeviceDemoKey — connecting without the key is refused.

    The SSH Connection tab with DeviceDemoKey selected on a locked display
    The SSH Connection tab with DeviceDemoKey selected on a locked display
Note: If SSH Key File is (None) when you click Lock Target, the toolkit generates a new key named after the connection (here, OpenView) in ~/.ssh/Ahsoka/ and locks the display to that instead.
Note: Keep the private key safe: once a display is locked, SSH access requires it. Lock Target tests the key before it disables password logins.

Connect with a Key

Watch video walkthrough

  1. Once a display is locked, connecting over SSH needs the private key it was locked with — here, DeviceDemoKey (see Download Key to get it onto your machine). In WinSCP's Login dialog, enter the display's Host name and User name as in Connecting over SSH, then click Advanced....

    The Login dialog with the display's address and login name, and the Advanced button
    The Login dialog with the display's address and login name, and the Advanced button
  2. In Advanced Site Settings, click Authentication under SSH.

    The Authentication page under SSH in Advanced Site Settings
    The Authentication page under SSH in Advanced Site Settings
  3. Click the ... button next to Private key file.

    The browse button for Private key file
    The browse button for Private key file
  4. The file picker only lists PuTTY (.ppk) keys by default, but the toolkit saves keys in OpenSSH format. Browse to your ~/.ssh/Ahsoka folder and change the file type to All Files.

    Switching the file type to All Files
    Switching the file type to All Files
  5. Select the private key — DeviceDemoKey, not DeviceDemoKey.pub — and click Open.

    DeviceDemoKey selected in the file picker
    DeviceDemoKey selected in the file picker
  6. WinSCP only uses PuTTY-format keys, so it offers to convert this one. Click OK.

    WinSCP offering to convert the OpenSSH key to PuTTY format
    WinSCP offering to convert the OpenSSH key to PuTTY format
  7. Save the converted copy next to the original — here, DeviceDemoKey.ppk — then click Save. The original key file isn't changed.

    Saving the converted key as DeviceDemoKey.ppk
    Saving the converted key as DeviceDemoKey.ppk
  8. WinSCP confirms the key was converted and saved. Click OK.

    The confirmation that the key was converted
    The confirmation that the key was converted
  9. Private key file now points at the .ppk file. Click OK to close Advanced Site Settings.

    Private key file set to DeviceDemoKey.ppk
    Private key file set to DeviceDemoKey.ppk
  10. Back in the Login dialog, click Login.

    Back in the Login dialog, ready to log in with the key
    Back in the Login dialog, ready to log in with the key
  11. WinSCP connects using the key, with no password, and the right pane shows the display's /home/root/ folder.

    WinSCP connected to the locked display with DeviceDemoKey
    WinSCP connected to the locked display with DeviceDemoKey
Note: Next time, pick DeviceDemoKey.ppk directly — it's already in PuTTY format, so there's no conversion step. Click Save in the Login dialog to keep the host, user name and key as a saved site.

Unlock Target

Watch video walkthrough

  1. Unlock Target reverses Lock Target: it leaves any keys in place but allows password-less logins again. It connects to the display with the key it's locked with, so check that SSH Key File shows that key — here, DeviceDemoKey. Then click Unlock Target.

    The Unlock Target button, with DeviceDemoKey selected
    The Unlock Target button, with DeviceDemoKey selected
  2. A confirmation explains that it leaves any keys in place but allows standard logins. Click Yes.

    The Unlock Display confirmation dialog
    The Unlock Display confirmation dialog
  3. There's no progress screen or completion dialog — the app stays on the SSH Connection tab. Click Console to see what happened.

    Back on the SSH Connection tab right after confirming
    Back on the SSH Connection tab right after confirming
  4. The log shows Beginning Device Unlock Process and Device Unlocked. Close the Console with its X.

    The Console log after Unlock Target
    The Console log after Unlock Target
  5. Like the lock, the unlock doesn't take effect until the display restarts — until then, it still only accepts logins with the key. Click the Reboot Display icon at the bottom right.

    The Reboot Display icon in the status bar
    The Reboot Display icon in the status bar
  6. Once the display reconnects, it's unlocked: it accepts SSH logins as root without a key or password again, as in Connecting over SSH. Unlike Lock Target, SSH Key File keeps the key you had selected.

    The SSH Connection tab after the display reconnects, unlocked
    The SSH Connection tab after the display reconnects, unlocked
Note: Until a target is locked, it can be reached over SSH without a password — see Connecting over SSH. Unlock Target reopens that access, so lock the display again before it leaves your bench.