Skip to content

About

Untrusted-relay, end-to-end encrypted transit for SSH clients and hidden SSH servers. v1 release candidate.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

39 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

OwnTransit

Your SSH. Your keys. Untrusted transit.

Connect two private computers over SSH when neither accepts a public connection. Both connect outward to your Relay. Independent end-to-end encryption keeps even a compromised Relay from reading the stream or impersonating an endpoint.

Role Install on Purpose
Client Your laptop or workstation The computer you connect from
Relay A public Linux VPS Carries encrypted traffic
Target The private Linux SSH machine Delivers authenticated traffic to local SSH

OwnTransit 1.0.5 supports Linux amd64/arm64 and an Apple-silicon Mac Client. SSH must already work on the Target. OwnTransit never configures SSH accounts, keys, permissions or forwarding.

Adding a tunnel to an already running Relay? Visit Target → Relay → Client, once each. Create the Target first and keep its output available. On the Relay, choose New tunnel and paste the public Target ID when asked; creation and approval finish in that visit. Go directly to the Client and paste the private code from the Target. The Relay does not issue a second code. Use Continue a tunnel instead if you already created a Relay draft.

1. Start on the Relay VPS

curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- relay

The installer opens Relay setup when an interactive terminal is available. To open or return to its menu:

sudo owntransit-relay setup

For a new Relay, enter its public URL, such as wss://relay.example/connects (example only). The VPS needs an existing HTTPS site. Choose New tunnel and give it a name. The entry is UNDER CONSTRUCTION; follow its Target step. At the public Target ID prompt, press Enter if the Target has not been created. If it already exists, enter its public ID to approve it now and continue on the Client.

2. On the Target running SSH

Install the Target, then open its menu:

curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- target
sudo owntransit-target setup

Choose New tunnel, an unused local name and the Relay URL. The Target starts and enables its service for reboot. It prints a public Target ID for the Relay and one private otpair2. code for the Client. Keep this output available until the Client has accepted its code; retrieving the code later is recovery, not a required setup step.

Transfer the private code directly to the intended Client through your existing authenticated SSH or console access. Never give it to the Relay.

3. Return to the Relay menu

Run sudo owntransit-relay setup, choose Continue a tunnel, select the draft and enter the public Target ID. Approval is a saved step; the tunnel remains UNDER CONSTRUCTION. Follow the displayed Client step. If you started on the Target and have no draft, choose New tunnel, name it, and enter the public Target ID in the same visit. Do not create another draft for a Target that already has one.

4. On the Client computer

Linux: install, then open setup as your ordinary user without sudo:

curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-linux.sh | sudo sh -s -- client
owntransit-client setup

Apple-silicon Mac: install and open setup without sudo:

curl -fsSL https://github.com/sentrybottale/OwnTransit/releases/download/v1.0.5/install-macos.sh | sh -s -- client
"$HOME/.local/bin/owntransit-client" setup

Choose New tunnel, an unused local name, the Relay URL and the private code from the Target. Run one command at a time; answer prompts before running the next command. Secret input is hidden.

Only the Client's actual authenticated end-to-end check can report TUNNEL READY. Then run its printed SSH command with your own SSH user and independently verified host identity. The printed command includes the executable path and tunnel selection. OpenSSH still decides whether your login is allowed.

Connect over SSH

Run on the Client computer, not inside a shell on the Target. Replace office with the Client's tunnel name and user@target.example with your SSH account and already-verified host label.

Linux:

ssh -o 'ProxyCommand=owntransit-client proxy --tunnel office' user@target.example

Mac:

ssh -o "ProxyCommand=\"$HOME/.local/bin/owntransit-client\" proxy --tunnel office" user@target.example

Add -i /path/to/your/ssh-key if needed. The tunnel selects the Target; the SSH label is for OpenSSH's independent host verification. SCP upload/download examples.

Manage or recover a tunnel

Upgrading from 0.7, 0.8 or an earlier 1.0.x release? Run the new installer for each local role. On the Relay, choose Start or update this relay; on each Target, Continue tunnel starts the installed version. On the Client, Continue tunnel verifies the existing pairing. Do not choose New or replace keys for a software update.

Relay admission hardening: install 1.0.5 on the Relay and choose Start or update this relay for its existing URL. This also reconciles its selected reverse-proxy route. Existing Client/Target pairings remain valid. Upgrade details.

Recovering an expired pending renewal: upgrade both Target and Client to 1.0.4 or later, then Continue their existing tunnel. The Relay needs no upgrade for this fix. Recovery and mixed-version details.

Open the local role's setup menu again.

Choice What it does
New tunnel Creates a separate tunnel with an unused name
Continue tunnel Resumes the saved step; on the Client, checks transport
List tunnels Shows local state, not proof of end-to-end readiness
Remove tunnel Removes the local endpoint connection or Relay admission
Killswitch Client/Target only: permanently disables that pairing
Restore removed tunnel Client/Target only: restores retained, unalarmed state

Endpoint removal keeps private state and can be restored explicitly. A killswitch cannot be undone. Relay removal never triggers an endpoint killswitch. Uninstalling the whole program is a separate installer action; see the installation guide.

Lost the code? On the Target, choose Continue tunnel to retrieve the same unused, unexpired code. Interrupted Client setup uses Continue tunnel too. Keep existing identities during outages and software upgrades. Recovery details.

Security and release scope

The Relay, its host, keys and reverse proxy are assumed compromised. Each endpoint uses outer TLS 1.3 mTLS; an independent inner TLS 1.3 mTLS stream authenticates the endpoints. The Target dials only build-fixed tcp4 127.0.0.1:22, after authorization. OpenSSH adds its own encryption and authentication. OwnTransit is an SSH byte carrier, not a VPN or general proxy.

Installers retain existing pairing state and migrate only recognized managed software/services. The documented Client/Relay/Target commands are the 1.x compatibility baseline. Published versions remain immutable. Do not replace pairings just to update software or mix historical enrollment instructions.

Initial installer delivery trusts GitHub HTTPS; archives are signature-verified. Independent security certification, pristine-host qualification and extended soak testing are not claimed. Keep independent SSH or console recovery access.

Network failures retry automatically with retained pairing and bounded backoff, including HTTP 429 throttling. A broken SSH session still needs a new SSH command; old bytes are never replayed. See operational limits.

Architecture · Security · Protocol compatibility · Roadmap · Contributing · Apache 2.0 license

About

Untrusted-relay, end-to-end encrypted transit for SSH clients and hidden SSH servers. v1 release candidate.

Topics

Resources

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages