Skip to main content

PSSH - SSH Wrapper with Password and TOTP Support

PSSH is a Python-based SSH wrapper that provides automatic password and TOTP (Time-based One-Time Password) support for SSH connections.

Features

  • Automatic password authentication using stored credentials
  • TOTP support for two-factor authentication
  • Non-interactive SSH connections using SSH_ASKPASS
  • Interactive SSH wrapper with automatic credential injection
  • Secure credential storage in ~/.ssh/.sshpt

Installation

From Source

  1. Clone the repository:
git clone <repository-url>
cd pssh
  1. Install the package:
pip install -e .

This will:

  • Install the Python package
  • Create a wssh executable in the project directory
  • Install the pssh command-line tool

Configuration

Create a configuration file at ~/.ssh/.sshpt with your credentials:

{
    "example.com": {
        "password": "your_password_here",
        "totp": "your_totp_secret_here"
    },
    "another-server.com": {
        "password": "another_password"
    }
}

Configuration Options

  • password: The password for the SSH connection
  • totp: The TOTP secret key for two-factor authentication

Usage

Method 1: Using the wssh executable

The wssh executable works as a drop-in replacement for ssh:

./wssh user@example.com

This will:

  1. Set SSH_ASKPASS to use the Python script
  2. Automatically provide passwords and TOTP codes when prompted
  3. Fall back to interactive prompts if credentials are not configured

Method 2: Using the pssh command

pssh user@example.com

This runs the interactive SSH wrapper that automatically injects credentials.

Method 3: Manual SSH_ASKPASS setup

You can also set up SSH_ASKPASS manually:

export SSH_ASKPASS="python /path/to/pssh/main.py"
ssh user@example.com

How It Works

  1. SSH_ASKPASS Mode: When SSH prompts for a password, the Python script is called with the SSH arguments. It parses the hostname and looks up credentials in the configuration file.

  2. Interactive Mode: The script spawns an SSH process and automatically responds to password and TOTP prompts using stored credentials.

  3. Credential Storage: Credentials are stored in JSON format in ~/.ssh/.sshpt. Make sure this file has appropriate permissions (600).

Security Considerations

  • Store the configuration file with restricted permissions: chmod 600 ~/.ssh/.sshpt
  • Consider using a password manager or encrypted storage for sensitive credentials
  • The TOTP secret should be kept secure and not shared

Requirements

  • Python 3.9+
  • pexpect
  • pyotp

License

MIT License

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

py_askpass-0.0.0.tar.gz (3.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

py_askpass-0.0.0-py3-none-any.whl (4.1 kB view details)

Uploaded Python 3

File details

Details for the file py_askpass-0.0.0.tar.gz.

File metadata

  • Download URL: py_askpass-0.0.0.tar.gz
  • Upload date:
  • Size: 3.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.14

File hashes

Hashes for py_askpass-0.0.0.tar.gz
Algorithm Hash digest
SHA256 97748e43968ba97ce4d873a0add17b382a65f7e81f10ad0ac697f8d9a94fb7dd
MD5 453af71ef13304cc99b3d6f1b4c867ab
BLAKE2b-256 85d5b87bf01a196710a2bf74e8de0e3d706153813a9f897a238d137ccd9a1fe1

See more details on using hashes here.

File details

Details for the file py_askpass-0.0.0-py3-none-any.whl.

File metadata

  • Download URL: py_askpass-0.0.0-py3-none-any.whl
  • Upload date:
  • Size: 4.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.1.0 CPython/3.10.14

File hashes

Hashes for py_askpass-0.0.0-py3-none-any.whl
Algorithm Hash digest
SHA256 01ff52e7a4b2a10b585071fb468674d1c79d65dacd3212df43f3cb30f863301b
MD5 49132fbbeb58bf01c4f1b21f7b014a30
BLAKE2b-256 18727f1b8acf091afe4691b4904eea6b7a4156ffc67f41d3a1b1a44dfe758034

See more details on using hashes here.

Release history Release notifications | RSS feed

This release

0.0.0 This release

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page