Skip to content

Feature: If is possible to improve security with ssh public key #17

Description

@MajorOli

User stories

To manage a server with full permissions we need the serveradmin (query)
In my opinion its risky to use then without any other security features like fail2ban.
So proof it is possible to implement ssh public key usage?

Activity

  1. self-assigned this
    on Oct 15, 2025
  2. MajorOli commented on Sep 17, 2026

    @MajorOli
    CollaboratorAuthor

    The TeamSpeak 3 / 6 ServerQuery SSH service uses its own RSA key pair for encryption and server authentication with the client:

    • Server host key: The private host key (e.g., ssh_host_rsa_key) is stored on the server and is loaded or generated at startup.
    • Protection against man-in-the-middle (MitM) attacks: During the SSH handshake, the client (e.g., via phpseclib3 / TSssh) receives the server’s public key and can verify it (e.g., via fingerprint verification or host key comparison)
    • Transmission encryption: All ServerQuery communication is thus end-to-end encrypted via SSH (AES/ChaCha20, RSA/SHA-256).

    Direct SSH ServerQuery with host key encryption (port 10022): This feature is already built in and works directly via serverquery+ssh://.

    Automatic SSH Handshake

    $this->ssh->setPreferredAlgorithms([
        'hostkey' => ['rsa-sha2-512', 'rsa-sha2-256', 'ssh-rsa'],
    ]);

    So, as option we can compare the HostKey-Fingerprint

  3. linked a pull request that will close this issueadd-verify-server-fingerprint #33on Sep 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions