Skip to content

System.NotSupportedException: Key 'OPENSSH' is not supported. #485

Description

@mauroa

A NotSupportedException is thrown when generating SSH keys with the "ssh-keygen" command on a Mac with macOS Mojave 10.14.1. With lower versions it's working fine.

Exception:

System.NotSupportedException: Key 'OPENSSH' is not supported.
at Renci.SshNet.PrivateKeyFile.Open(Stream privateKey, String passPhrase)
at Renci.SshNet.PrivateKeyFile..ctor(String fileName, String passPhrase)

Inspecting the generated private key I can see that the header starts with:

"-----BEGIN OPENSSH PRIVATE KEY-----"

Also, If I inspect a private key generated in a Mac with a lower macOS version, I can see something like:

"-----BEGIN RSA PRIVATE KEY-----"

The following code in this repo tries to match a Regex to detect they key name and act based on it. For this reason, It doesn't recognize "OPENSSH" as a valid private key name and it fails:

switch (keyName)
{
case "RSA":
_key = new RsaKey(decryptedData);
HostKey = new KeyHostAlgorithm("ssh-rsa", _key);
break;
case "DSA":
_key = new DsaKey(decryptedData);
HostKey = new KeyHostAlgorithm("ssh-dss", _key);
break;
case "SSH2 ENCRYPTED":
var reader = new SshDataReader(decryptedData);
var magicNumber = reader.ReadUInt32();
if (magicNumber != 0x3f6ff9eb)
{
throw new SshException("Invalid SSH2 private key.");
}
reader.ReadUInt32(); // Read total bytes length including magic number
var keyType = reader.ReadString(SshData.Ascii);
var ssh2CipherName = reader.ReadString(SshData.Ascii);
var blobSize = (int)reader.ReadUInt32();
byte[] keyData;
if (ssh2CipherName == "none")
{
keyData = reader.ReadBytes(blobSize);
}
else if (ssh2CipherName == "3des-cbc")
{
if (string.IsNullOrEmpty(passPhrase))
throw new SshPassPhraseNullOrEmptyException("Private key is encrypted but passphrase is empty.");
var key = GetCipherKey(passPhrase, 192 / 8);
var ssh2Сipher = new TripleDesCipher(key, new CbcCipherMode(new byte[8]), new PKCS7Padding());
keyData = ssh2Сipher.Decrypt(reader.ReadBytes(blobSize));
}
else
{
throw new SshException(string.Format("Cipher method '{0}' is not supported.", cipherName));
}
// TODO: Create two specific data types to avoid using SshDataReader class
reader = new SshDataReader(keyData);
var decryptedLength = reader.ReadUInt32();
if (decryptedLength > blobSize - 4)
throw new SshException("Invalid passphrase.");
if (keyType == "if-modn{sign{rsa-pkcs1-sha1},encrypt{rsa-pkcs1v2-oaep}}")
{
var exponent = reader.ReadBigIntWithBits();//e
var d = reader.ReadBigIntWithBits();//d
var modulus = reader.ReadBigIntWithBits();//n
var inverseQ = reader.ReadBigIntWithBits();//u
var q = reader.ReadBigIntWithBits();//p
var p = reader.ReadBigIntWithBits();//q
_key = new RsaKey(modulus, exponent, d, p, q, inverseQ);
HostKey = new KeyHostAlgorithm("ssh-rsa", _key);
}
else if (keyType == "dl-modp{sign{dsa-nist-sha1},dh{plain}}")
{
var zero = reader.ReadUInt32();
if (zero != 0)
{
throw new SshException("Invalid private key");
}
var p = reader.ReadBigIntWithBits();
var g = reader.ReadBigIntWithBits();
var q = reader.ReadBigIntWithBits();
var y = reader.ReadBigIntWithBits();
var x = reader.ReadBigIntWithBits();
_key = new DsaKey(p, q, g, y, x);
HostKey = new KeyHostAlgorithm("ssh-dss", _key);
}
else
{
throw new NotSupportedException(string.Format("Key type '{0}' is not supported.", keyType));
}
break;
default:
throw new NotSupportedException(string.Format(CultureInfo.CurrentCulture, "Key '{0}' is not supported.", keyName));

Thanks.

Activity

  1. darinkes commented on Dec 5, 2018

    @darinkes
    Collaborator

    Please see #496, which adds OPENSSH-Format for ed25519 Keys.
    What kind of key you used? Can't find on a quick search what MacOS ssh-keygen generates by default.

    The usual default is: If invoked without any arguments, ssh-keygen will generate an RSA key.
    (https://man.openbsd.org/ssh-keygen)

  2. darinkes commented on Dec 5, 2018

    @darinkes
    Collaborator

    Ah! I see now. Yeah, the default format was changed. Will see if my PR can be updated to support more than just ed25519 Keys.

  3. drieseng commented on Dec 5, 2018

    @drieseng
    Member

    @darinkes Please submit a separate PR for this.

  4. darinkes commented on Dec 5, 2018

    @darinkes
    Collaborator

    @drieseng sure! first finish the big one.

    @mauroa If you want to give it a shot: https://github.com/darinkes/SSH.NET-1/tree/openssh_format_rsa

  5. gojimmypi commented on Feb 11, 2019

    @gojimmypi

    @darinkes - cool you are working on openssh; wondering about the status of your changes? will it include Message Authentication Code (HMAC)? perhaps I can help?

  6. darinkes commented on Feb 12, 2019

    @darinkes
    Collaborator

    @gojimmypi I'm waiting for upstream to catch up with current PRs, before creating new ones.

  7. ssougnez commented on Jun 7, 2019

    @ssougnez

    Is there any advancement on this one ?
    I really need to be able to connect through SFTP via OpenSSH key :-)

  8. nukadelic commented on Jun 20, 2019

    @nukadelic

    Same here, failed to support generated ssh via ssh-keygen -t rsa

    Edit: Using puttygen and exporting under different format fixed my issue, here is a neat article:
    https://lluisfranco.com/2017/11/29/how-to-connect-via-sftp-using-ssh-net/

  9. watsonsong commented on Jul 5, 2019

    @watsonsong

    The same problem. Is there any plan to support OPENSSH keyname?

  10. darinkes commented on Jul 5, 2019

    @darinkes
    Collaborator

    The same problem. Is there any plan to support OPENSSH keyname?

    Yes, the diff is ready for an PR. But @drieseng is currently busy with other projects.
    You can check out and test the diff from here: #485 (comment)

  11. drieseng commented on Jul 5, 2019

    @drieseng
    Member

    @darinkes Please submit a PR for this. If you make sure there's sufficient test coverage, I'll do my best to review it :p

  12. drieseng commented on Jul 5, 2019

    @drieseng
    Member

    @darinkes ... and thx!

  13. darinkes commented on Jul 5, 2019

    @darinkes
    Collaborator

    @drieseng The diff is based on the Elliptic Curves Branch, cause OPENSSH format was needed there already partially.

  14. michael-andreev commented on Jun 6, 2020

    @michael-andreev

    Having the same problem. Could you tell the current status of this issue?

  15. yhjhoo commented on Jun 22, 2020

    @yhjhoo

    for me, this lib works in mac but no in windows 2012R2

  16. drieseng commented on Jun 27, 2020

    @drieseng
    Member

    This is now supported in 2020.0.0-beta1.

  17. added this to the 2020.0.0-beta1 milestone on Jun 27, 2020
  18. aibars commented on Nov 2, 2020

    @aibars

    I added 2020.0.0-beta1 but now the error is openssh key type: ssh-rsa is not supported

  19. Arhisan commented on Nov 20, 2020

    @Arhisan

    the same for me Renci.SshNet.Common.SshException: openssh key type: ssh-rsa is not supported

  20. darkoperator commented on Nov 20, 2020

    @darkoperator
  21. ramondeklein commented on Feb 3, 2021

    @ramondeklein

    Same here... The new-style OpenSSH key format is not supported. This issue is closed, but it should be open.

    @darinkes I saw your fork from 31-1-2021. Does it support the new key format and will you create a PR for this library?

  22. darinkes commented on Feb 3, 2021

    @darinkes
    Collaborator

    @ramondeklein already there #614

  23. h0wXD commented on Apr 30, 2021

    @h0wXD

    @ramondeklein Have you tried checking out develop, building it locally, and adding the netstandard2.0 dll as reference to your project? This works for me. I am getting the same error "Renci.SshNet.Common.SshException: 'openssh key type: ssh-rsa is not supported'" when using the latest nuget package 2020.0.1.

  24. stevenxi commented on Jun 21, 2021

    @stevenxi

    hi @h0wXD , @jkmyklebust ,

    I've got the same error, but found the quick solution.

    Just need to convert the key's format from --OPENSSH to --RSA:

    ssh-keygen -p -P "" -N "" -m pem -f \path\to\key\file

    This will convert your current key.

  25. Mansimar30 commented on Jun 21, 2021

    @Mansimar30

    Hey, I am getting the same issue : Renci.SshNet.Common.SshException: openssh key type: ssh-rsa is not supported.

    Here's how key was generated : ssh-keygen -t rsa -b 4096

    Did anybody resolve it?

  26. stevenxi commented on Jun 21, 2021

    @stevenxi

    @Mansimar30 ,

    Please see my reply above, use ssh-keygen to convert your key.

  27. dbrennand commented on Aug 23, 2021

    @dbrennand

    Hi all, I hit this issue when using POSH-SSH. Documented in issue: darkoperator/Posh-SSH#388

    I worked around this issue by creating my SSH key with the -m PEM option.

    Example: ssh-keygen -f ~/.ssh/id_rsa -m PEM -t rsa

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions