A modern, memory-safe SSH server written in Rust
OxiSH is a modern, memory-safe SSH server written in Rust, designed as a secure alternative to OpenSSH. It is built with a safe sans-I/O protocol core and an abstraction layer for cryptographic primitives, aiming to eliminate the memory safety vulnerabilities that commonly affect C/C++ implementations. The project addresses the need for SSH servers that meet critical security criteria: wide usage, security boundaries, and critical function, as highlighted by the Prossimo project. OxiSH is intended for organizations and individuals seeking a safer SSH server, though it is not yet production-ready and is currently in a public alpha stage, inviting feedback and contributions.
Written entirely in Rust, using a sans-I/O protocol core to avoid memory safety issues inherent in C/C++ SSH servers.
Supports both graviola (default, easy to build, limited to x86-64 and ARM64) and aws-lc-rs (more portable, FIPS mode on Linux) with compile-time selection via Cargo features.
Supports Ed25519 and ECDSA P-256 key authentication only, with no password authentication.
Spawns a child process and connects it to the SSH session for interactive use.
Implements mlkem768x25519-sha256 as primary and curve25519-sha256 as fallback for older clients.
Supports only AES-128-GCM encryption and SHA-256 hashing to reduce attack surface, with intent to add more if needed.
Continuously tested on Linux and macOS against OpenSSH clients in CI.
Offers a small library API for reuse in other Rust applications, beyond the SSH server functionality.
No, OxiSH is not yet production-ready. It is a starting point with limitations, such as no agent forwarding, no SCP/SFTP support, and no password authentication.
It supports public key authentication using Ed25519 or ECDSA P-256 keys only. Password authentication is not implemented.
Not currently. OxiSH is tested on Linux and macOS, and Windows support is not implemented yet, though contributions are welcome.
Two backends are implemented: graviola (default, easier to build but only x86-64 and ARM64) and aws-lc-rs (more portable, can be compiled in FIPS mode on Linux).
No, SCP and SFTP are not supported. Basic shell functionality is the only session type currently available.