github timhartmann7/omnyssh v1.1.4
OmnySSH v1.1.4

4 hours ago

Bug Fixes

  • macOS: the app from the .dmg opens instead of being "damaged". It carried only the signature the linker puts on the executable, which does not cover the rest of the app, so macOS called a downloaded copy damaged and offered no way to open it. The whole app is now signed, ad hoc, and macOS shows its usual warning for an app it cannot verify: open it once from System Settings, Privacy & Security, Open Anyway. The app is still not notarized. A copy installed with install.sh was never affected.
  • A changed host key says so, and names the file to fix. When a server's key no longer matched the one saved for it, as after reinstalling a VM or when another machine takes over an address, the connection failed with "Unknown server key", which reads as the opposite of what happened and pointed nowhere. It now says the host key has changed, shows the new key's SHA256 fingerprint, names the known_hosts file holding the old one and gives the ssh-keygen -R command that removes it, to run once you have checked that fingerprint on the server itself. The text on the dashboard card can be selected, so the command can be copied. A known_hosts that OmnySSH cannot parse is named in the error too.
  • Windows: host keys are kept in %USERPROFILE%\.ssh\known_hosts, shared with OpenSSH. OmnySSH kept its own list in %USERPROFILE%\ssh\known_hosts, without the dot, a folder nothing else uses and nobody thinks to look in, so a key you had already accepted in PowerShell's ssh meant nothing to it and a stale one could only be removed there. Keys are now checked against, and new ones saved to, the file Windows OpenSSH uses. Keys saved in the old file are still honoured and never quietly replaced.
  • Host keys are matched the way ssh matches them. A known_hosts holding an old and a new line for the same host refused the connection over the old line; one matching line is now enough. When the file knows a host by one key type, OmnySSH asks the server for that type first, so a host saved with only its ECDSA key, as ssh before 8.5 and Windows 10's built-in client saved them, is checked against that key instead of being taken as a new one. Host names are matched regardless of case, since ssh writes them in lower case.
  • The local file pane can switch drives (Windows). The desktop app's local pane started in your home folder and could climb no higher than the root of drive C:, so files on any other drive, mapped network drives included, could not be uploaded, and nothing could be downloaded to them. A drive selector next to Upload now lists every drive letter, and the local Refresh button picks up a drive plugged in since. In the terminal app, d in the file manager moves the local panel to the next drive. macOS and Linux have a single root and are unchanged.
  • Hosts with an IdentityFile log in with that key first, however many keys the SSH agent holds. With an agent holding many keys, as password managers such as Bitwarden, 1Password and KeePassXC set up, OmnySSH offered them all in the agent's order whatever the host's IdentityFile said, and the server hung up after its MaxAuthTries (three to six attempts) before the right key came up, with "no key was accepted and no password is saved". Adding a key to the agent could take hosts offline that had worked the day before. The agent key matching the host's IdentityFile now goes first, as with ssh: the file itself when it names a .pub, else the .pub beside it, else the public half of the private key, which needs no passphrase. IdentitiesOnly yes in a host's block of ~/.ssh/config limits the login to that key and leaves the default ~/.ssh/id_* keys out, and it is read from there even for a host you have since edited in OmnySSH. A key the server has already turned down through the agent is not offered again from its file, except an RSA key, which some servers, such as older Dropbear, accept only the way the file offers it. The same change ends the passphrase prompt some of these hosts showed for a key the agent held all along. IdentityAgent is still not followed, and IdentitiesOnly under Host * or Match is not read.

Don't miss a new omnyssh release

NewReleases is sending notifications on new releases.