<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Skavanagh</id>
		<title>OWASP - User contributions [en]</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Skavanagh"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php/Special:Contributions/Skavanagh"/>
		<updated>2026-04-03T18:44:19Z</updated>
		<subtitle>User contributions</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=236446</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=236446"/>
				<updated>2017-12-27T20:11:52Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: Blanked the page&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=234656</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=234656"/>
				<updated>2017-10-26T10:57:36Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: Add release&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-09-20: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.02 KeyBox v2.90.02]&lt;br /&gt;
* 2017-09-05: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.01 KeyBox v2.90.01]&lt;br /&gt;
* 2017-06-04: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.00 KeyBox v2.90.00]&lt;br /&gt;
* 2017-03-19: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.89.00 KeyBox v2.89.00]&lt;br /&gt;
* 2017-03-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.02 KeyBox v2.88.02]&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=232898</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=232898"/>
				<updated>2017-09-06T01:29:11Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: Added new release&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-09-05: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.01 KeyBox v2.90.01]&lt;br /&gt;
* 2017-06-04: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.00 KeyBox v2.90.00]&lt;br /&gt;
* 2017-03-19: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.89.00 KeyBox v2.89.00]&lt;br /&gt;
* 2017-03-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.02 KeyBox v2.88.02]&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=230367</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=230367"/>
				<updated>2017-06-04T15:07:24Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: added new release&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-06-04: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.90.00 KeyBox v2.90.00]&lt;br /&gt;
* 2017-03-19: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.89.00 KeyBox v2.89.00]&lt;br /&gt;
* 2017-03-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.02 KeyBox v2.88.02]&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227615</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227615"/>
				<updated>2017-03-19T11:55:16Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: added new release link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-03-19: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.89.00 KeyBox v2.89.00]&lt;br /&gt;
* 2017-03-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.02 KeyBox v2.88.02]&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227614</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227614"/>
				<updated>2017-03-18T22:35:17Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: added release link&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-03-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.02 KeyBox v2.88.02]&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227176</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=227176"/>
				<updated>2017-03-09T00:35:10Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-01-28: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.01 KeyBox v2.88.01]&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=224662</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=224662"/>
				<updated>2017-01-04T01:17:57Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2017-01-01: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.88.00 KeyBox v2.88.00]&lt;br /&gt;
* 2016-11-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.01 KeyBox v2.87.01]&lt;br /&gt;
* 2016-10-22: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.87.00 KeyBox v2.87.00]&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=219956</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=219956"/>
				<updated>2016-08-02T00:59:36Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2016-07-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.86.00 KeyBox v2.86.00]&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=215860</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=215860"/>
				<updated>2016-04-24T10:48:06Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2016-04-24: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.03 KeyBox v2.85.03]&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=212512</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=212512"/>
				<updated>2016-04-06T00:56:59Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2016-03-29: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.02 KeyBox v2.85.02]&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=204958</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=204958"/>
				<updated>2015-12-10T01:43:55Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-12-09: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.01 KeyBox v2.85.01]&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=204858</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=204858"/>
				<updated>2015-12-08T00:28:10Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-11-30: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.85.00 KeyBox v2.85.00]&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=203321</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=203321"/>
				<updated>2015-11-12T02:55:38Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-11-06: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.01 KeyBox v2.84.01]&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=201589</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=201589"/>
				<updated>2015-10-04T00:58:17Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-10-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.84.00 KeyBox v2.84.00]&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=195861</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=195861"/>
				<updated>2015-06-08T01:06:59Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-06-07: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.02 KeyBox v2.83.02]&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=194917</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=194917"/>
				<updated>2015-05-16T11:50:00Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-05-16: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.01 KeyBox v2.83.01]&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=193962</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=193962"/>
				<updated>2015-04-26T11:49:18Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. Web-based administration is combined with management and distribution of user's public SSH keys. Key management and administration is based on profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=193829</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=193829"/>
				<updated>2015-04-22T00:28:27Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-04-21: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.83.00 KeyBox v2.83.00]&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192369</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192369"/>
				<updated>2015-03-29T11:18:12Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at [http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192368</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192368"/>
				<updated>2015-03-29T11:17:49Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* How do I import my own SSL cert?&lt;br /&gt;
&lt;br /&gt;
::keytool -keystore keystore -import -alias jetty -file mycert.crt&lt;br /&gt;
::then just replace the keystore in the jetty/etc/ directory and you set the passwords in the jetty/modules/ssl.mod file (see [http://www.eclipse.org/jetty/documentation/current/configuring-security-secure-passwords.html Configuring Security Secure Passwords] to set the password format)&lt;br /&gt;
::More information can be found at -[http://wiki.eclipse.org/Jetty/Howto/Configure_SSL How to Configure SSL]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192344</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192344"/>
				<updated>2015-03-28T01:37:25Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg|500px]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-Arch.jpg&amp;diff=192343</id>
		<title>File:KeyBox-Arch.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-Arch.jpg&amp;diff=192343"/>
				<updated>2015-03-28T01:35:09Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: Skavanagh uploaded a new version of &amp;amp;quot;File:KeyBox-Arch.jpg&amp;amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Keybox Architecture diagram&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192342</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192342"/>
				<updated>2015-03-28T01:33:44Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Terminals.png|400px]]&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;br/&amp;gt;&lt;br /&gt;
[[File:KeyBox-Arch.jpg]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-ManageUsers.png&amp;diff=192341</id>
		<title>File:KeyBox-ManageUsers.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-ManageUsers.png&amp;diff=192341"/>
				<updated>2015-03-28T01:23:36Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: KeyBox screenshot - Manage Users&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;KeyBox screenshot - Manage Users&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-DisableKeys.png&amp;diff=192340</id>
		<title>File:KeyBox-DisableKeys.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-DisableKeys.png&amp;diff=192340"/>
				<updated>2015-03-28T01:23:20Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: KeyBox screenshot - Disable SSH Keys&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;KeyBox screenshot - Disable SSH Keys&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-DefineKeys.png&amp;diff=192339</id>
		<title>File:KeyBox-DefineKeys.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-DefineKeys.png&amp;diff=192339"/>
				<updated>2015-03-28T01:22:40Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: KeyBox screenshot - Define SSH Keys&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;KeyBox screenshot - Define SSH Keys&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192338</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=192338"/>
				<updated>2015-03-28T01:19:02Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[File:KeyBox-Arch.jpg]]&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-Terminals.png&amp;diff=192337</id>
		<title>File:KeyBox-Terminals.png</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-Terminals.png&amp;diff=192337"/>
				<updated>2015-03-28T01:15:04Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: KeyBox screenshot - Terminals&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;KeyBox screenshot - Terminals&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=File:KeyBox-Arch.jpg&amp;diff=192336</id>
		<title>File:KeyBox-Arch.jpg</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=File:KeyBox-Arch.jpg&amp;diff=192336"/>
				<updated>2015-03-28T01:14:23Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: Keybox Architecture diagram&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Keybox Architecture diagram&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191398</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191398"/>
				<updated>2015-03-13T23:44:10Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-13: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.82.00 KeyBox v2.82.00]&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191356</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191356"/>
				<updated>2015-03-13T13:35:31Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox/blob/master/README.md README]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191355</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191355"/>
				<updated>2015-03-13T13:34:45Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191354</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191354"/>
				<updated>2015-03-13T13:34:25Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Links */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
*[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
*[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191353</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191353"/>
				<updated>2015-03-13T13:34:05Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Repository */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Links ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
[http://sshkeybox.com Website]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191352</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191352"/>
				<updated>2015-03-13T13:33:09Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191351</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191351"/>
				<updated>2015-03-13T13:31:33Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found - [http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191350</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191350"/>
				<updated>2015-03-13T13:31:13Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* FAQs */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
* I have a reverse-proxy that already terminates TLS/SSL, how do I disable TLS/SSL?&lt;br /&gt;
&lt;br /&gt;
::In the jetty directory edit the start.ini file and set&lt;br /&gt;
&lt;br /&gt;
::--module=https&lt;br /&gt;
&lt;br /&gt;
::to&lt;br /&gt;
&lt;br /&gt;
::--module=http&lt;br /&gt;
&lt;br /&gt;
::and change jetty.port=8443 to the needed port to be and restart. More information on jetty can be found:[http://www.eclipse.org/jetty/documentation/current/ Jetty Documentation]&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191349</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191349"/>
				<updated>2015-03-13T13:21:20Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Minimum Viable Product */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
Currently packaged along with a web-server and can be downloaded from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191348</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191348"/>
				<updated>2015-03-13T13:20:30Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191347</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191347"/>
				<updated>2015-03-13T13:20:20Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Contributors */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Special Thanks==&lt;br /&gt;
&lt;br /&gt;
[http://www.jcraft.com/jsch JSch] Java Secure Channel - by [https://github.com/ymnk ymnk]&lt;br /&gt;
&lt;br /&gt;
[https://github.com/chjj/term.js terms.js] A terminal written in javascript - by [https://github.com/chjj chjj]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191346</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191346"/>
				<updated>2015-03-13T13:05:05Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: Release - [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191345</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191345"/>
				<updated>2015-03-13T13:04:37Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Repository */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191344</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191344"/>
				<updated>2015-03-13T13:04:23Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Quick Download */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191343</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191343"/>
				<updated>2015-03-13T13:04:00Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Description */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191342</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191342"/>
				<updated>2015-03-13T13:03:04Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* Related Projects */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Repository ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox KeyBox on Github]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191341</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191341"/>
				<updated>2015-03-13T13:01:46Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191340</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191340"/>
				<updated>2015-03-13T13:01:14Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00] Released&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 KeyBox v2.76.00] Released&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191339</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191339"/>
				<updated>2015-03-13T13:00:45Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* News and Events */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
* 2015-03-03: [https://github.com/skavanagh/KeyBox/releases/tag/v2.80.00 KeyBox v2.80.00 Released]&lt;br /&gt;
* 2015-02-25: [https://github.com/skavanagh/KeyBox/releases/tag/v2.76.00 v2.76.00 Released]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191338</id>
		<title>OWASP KeyBox</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_KeyBox&amp;diff=191338"/>
				<updated>2015-03-13T12:53:27Z</updated>
		
		<summary type="html">&lt;p&gt;Skavanagh: /* OWASP KeyBox Project */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Main=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;div style=&amp;quot;width:100%;height:160px;border:0,margin:0;overflow: hidden;&amp;quot;&amp;gt;[[File:OWASP_Project_Header.jpg|link=]]&amp;lt;/div&amp;gt;&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;padding: 0;margin:0;margin-top:10px;text-align:left;&amp;quot; |-&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
Instructions are in RED text and should be removed from your document by deleting the text with the span tags. This document is intended to serve as an example of what is required of an OWASP project wiki page. The text in red serves as instructions, while the text in black serves as an example. Text in black is expected to be replaced entirely with information specific to your OWASP project.&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==OWASP KeyBox Project==&lt;br /&gt;
&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. It combines key management and administration through profiles assigned to defined users. KeyBox layers TLS/SSL on top of SSH and can act as a bastion host.&lt;br /&gt;
&lt;br /&gt;
==Description==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox is a web-based SSH console that centrally manages administrative access to systems. KeyBox combines key management and administration through profiles assigned to defined users.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
Administrators can login using two-factor authentication with&lt;br /&gt;
[https://fedorahosted.org/freeotp FreeOTP]&lt;br /&gt;
or&lt;br /&gt;
[https://github.com/google/google-authenticator Google Authenticator]&lt;br /&gt;
. From there they can create and manage public SSH keys or connect to their assigned systems through a web-shell. Commands can be shared across shells to make patching easier and eliminate redundant command execution.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;p&amp;gt;&lt;br /&gt;
KeyBox layers TLS/SSL on top of SSH and acts as a bastion host for administration. Protocols are stacked (TLS/SSL + SSH) so infrastructure cannot be exposed through tunneling / port forwarding. More details can be found in the following whitepaper: [http://www.sans.org/reading-room/whitepapers/vpns/security-implications-ssh-1180 The Security Implications of SSH]. Also, SSH key management is enabled by default to prevent unmanaged public keys and enforce best practices.&lt;br /&gt;
&amp;lt;/p&amp;gt;&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Licensing==&lt;br /&gt;
[https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;border-right: 1px dotted gray;padding-right:25px;&amp;quot; |&lt;br /&gt;
&lt;br /&gt;
== Quick Download ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	[https://github.com/skavanagh/KeyBox/releases Download now]&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Project Leader ==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
== Related Projects ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can link to other OWASP Projects that are similar to yours. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Classifications==&lt;br /&gt;
&lt;br /&gt;
   {| width=&amp;quot;200&amp;quot; cellpadding=&amp;quot;2&amp;quot;&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [[File:Project_Type_Files_TOOL.jpg|link=https://www.owasp.org/index.php/Category:OWASP_Tool]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot; rowspan=&amp;quot;2&amp;quot;| [[File:Owasp-incubator-trans-85.png|link=https://www.owasp.org/index.php/OWASP_Project_Stages#tab=Incubator_Projects|Incubator Project]]&lt;br /&gt;
   |-&lt;br /&gt;
   | align=&amp;quot;center&amp;quot; valign=&amp;quot;top&amp;quot; width=&amp;quot;50%&amp;quot;| [[File:Owasp-defenders-small.png|link=Defenders]]&lt;br /&gt;
   |-&lt;br /&gt;
   | colspan=&amp;quot;2&amp;quot; align=&amp;quot;center&amp;quot;  | [https://tldrlegal.com/license/apache-license-2.0-%28apache-2.0%29 Apache 2.0]&lt;br /&gt;
   |}&lt;br /&gt;
&lt;br /&gt;
| valign=&amp;quot;top&amp;quot;  style=&amp;quot;padding-left:25px;width:200px;&amp;quot; | &lt;br /&gt;
&lt;br /&gt;
== News and Events ==&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	This is where you can provide project updates, links to any events like conference presentations, Project Leader interviews, case studies on successful project implementations, and articles written about your project. &lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
=FAQs=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!-- Instructions are in RED and should be removed from your document by deleting the text with the span tags.--&amp;gt;&lt;br /&gt;
&amp;lt;span style=&amp;quot;color:#ff0000&amp;quot;&amp;gt;&lt;br /&gt;
	Many projects have &amp;quot;Frequently Asked Questions&amp;quot; documents or pages. However, the point of such a document is not the questions. ''The point of a document like this are the '''answers'''''. The document contains the answers that people would otherwise find themselves giving over and over again. The idea is that rather than laboriously compose and post the same answers repeatedly, people can refer to this page with pre-prepared answers. Use this space to communicate your projects 'Frequent Answers.'&lt;br /&gt;
&amp;lt;/span&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Acknowledgements =&lt;br /&gt;
&lt;br /&gt;
==Contributors==&lt;br /&gt;
&lt;br /&gt;
[mailto:sean.p.kavanagh6@gmail.com Sean Kavanagh]&lt;br /&gt;
&lt;br /&gt;
= Road Map and Getting Involved =&lt;br /&gt;
&lt;br /&gt;
==Road Map==&lt;br /&gt;
&lt;br /&gt;
Add ability to save session and command line information to a large data store so it can be audited and reviewed.  Compute and flag irregularities that could point security issues or improper use.  Deploy to embedded network devices to act as a proxy for SSH connections.&lt;br /&gt;
&lt;br /&gt;
==Getting Involved==&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Minimum Viable Product=&lt;br /&gt;
&lt;br /&gt;
It's currently packaged along with a web-server and can be downloaded by consumers from github&lt;br /&gt;
&lt;br /&gt;
[https://github.com/skavanagh/KeyBox/releases https://github.com/skavanagh/KeyBox/releases]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
__NOTOC__ &amp;lt;headertabs /&amp;gt; &lt;br /&gt;
&lt;br /&gt;
[[Category:OWASP Project]]  [[Category:OWASP_Builders]] [[Category:OWASP_Defenders]]  [[Category:OWASP_Tool]]&lt;/div&gt;</summary>
		<author><name>Skavanagh</name></author>	</entry>

	</feed>