SSHBlackbox features
SSH (Secure Shell) is the standard for secure remote access over the internet and secure file transfer. SSH offers flexible authentication, encryption and compression schemes for better performance of internet communications.
SSH Protocol implementation contains the following features, common to both client-side and server-side components:
- support for SSH 2 protocol
in client and server components;
- support for SSH 1 protocol in client components;
- support for public-key, host-based, password-based, keyboard-interactive, OpenPGP key and X.509 certificate authentication
;
- support for use of multiple authentication types at the same time
;
- flexible support for key validation
;
- support for RSA and DSA public key algorithms
;
- data encryption with AES (128 to 256 bit), Triple DES (3DES), DES, Blowfish, Twofish, Serpent (128 to 256 bit), CAST128 algorithms
;
- integrity checking using SHA1 and MD5 algorithms
;
- ZLib compression
;
- asynchronous operation mode which lets you easily build synchronous and asynchronous applications
;
- data transfer using events/callbacks, i.e. possibility to secure not only socket-based, but also other types of data exchange
SSH Tunnels are supported by client-side and server-side components. Support options include:
- support for shell, command, port forwarding (local and remote), X11 and custom subsystem tunnels
;
- support for SFTP subsystem (SFTPBlackbox is required);
- support for dynamic tunnels (SSH2 only). With dynamic tunnels one can create and close logical connections within single SSH connection
;
- possibility to create custom subsystem handlers
SSH Keys management lets you create and manage SSH keys, necessary to authenticate the clients and servers in SSH mode. Key management offers:
- generation of RSA and DSA (DSS) keys;
- saving and loading of SSH keys in OpenSSH, IETF and PuTTY formats;
- support for key length from 512 to 16384 bytes;
ElSimpleSSHClient is a basic SSH client, which encapsulates several SSH components inside and offers:
- shell or command tunnel inside
;
- (optional) built-in TCP socket with support for WebTunneling (HTTP CONNECT) and SOCKS proxies
;
- synchronous interface
PKI Infrastructure - besides SSH features, SSHBlackbox includes PKIBlackbox and offers all features of that package
Asynchronous operation mode, on the other hand, gives you flexibility and complete control over your application communications.
Synchronous operation mode gives you a linear programming approach without complicated callback functions. This approach saves your development time and reduces the number of errors. Simple SecureBlackbox components can be used for reliable data transfer no matter what type of proxy or firewall is used to protect the network. You can process huge files and not be bound by restrictions of 32-bit environments. This feature works on both 32-bit and 64-bit systems without any limitations. Cryptographic hardware gains more and more popularity every day. If your software deals with X.509 certificates or PKI in general (RSA keys etc.), it is time to support cryptocards and USB tokens. SecureBlackbox was written from the ground up by EldoS Corporation developers. It doesn't use third-party code to implement its cryptographic functions. This means that you are not bound by CryptoAPI or OpenSSL version when you need to use certain algorithm.At the same time it's possible to plug third-party security libraries and hardware modules by utilizing the pluggable architecture of SecureBlackbox. No royalties means the licensing procedure which is clear and easy to understand and manage. Pay for the license once and use it for development and deployment with no other payments. We provide free technical support via web-based Forum and HelpDesk. Support is available for everyone, and the requests from clients who purchased a license are given priority. Also you can use our extensive knowledgebase. With SecureBlackbox you can create and convert SSH keys without the need for external key management software. SSHBlackbox package includes functions that let you generate and manage SSH keys in several formats. SecureBlackbox is the only component collection that lets you build SSH servers as well as SSH clients. With the wide choice of encryption, authentication and key exchange algorithms supported by SSHBlackbox, you will be able to meet the security requirements and get compatibility with the wide choice of differently configured servers and clients. SSH and SFTP protocols offer the number of very useful features, which don't actually require TCP transport. The protocols can be used with any low-level transport protocols, and SecureBlackbox makes this possible. SSH protocol can transport many connections of different types over one secured SSH connection. Tunnels are the types of simultaneous transport that you can use. It's handy to have an SFTP tunnel used in parallel with SSH shell tunnel so that you can transfer files and operate remote system at the same time.
SecureBlackbox supports all types of tunnels, defined by SSH protocol specification.
SSH protocol can transport many connections of different types over one secured SSH connection. Tunnels are the types of simultaneous transport that you can use. Ability to open and close connections on-the-fly extends your possibilities and adds flexibility to your application. SSH protocol can transport many connections of different types over one secured SSH connection. Tunnels are the types of simultaneous transport that you can use. Ability to create custom tunnel types (subsystems) extends your possibilities and adds flexibility to your application. Shell and command tunnels are used to execute commands on the remote system by using terminal / shell application (in shell tunnels) or by executing the commands directly (using command tunnels). Support for both types of tunnels adds flexibility to your application by letting you execute commands without parsing the shell prompts and extra messages or emulating a full-featured terminal. With extensive authentication support you can build multi-level authentication schemes, thus increasing security and reducing the risks when the sensitive resources are accessed.