2 * Copyright (c) 2013 Cisco Systems, Inc. and others. All rights reserved.
4 * This program and the accompanying materials are made available under the
5 * terms of the Eclipse Public License v1.0 which accompanies this distribution,
6 * and is available at http://www.eclipse.org/legal/epl-v10.html
8 package org.opendaylight.netconf.ssh;
10 import io.netty.channel.local.LocalAddress;
11 import io.netty.channel.nio.NioEventLoopGroup;
13 import java.io.IOException;
14 import java.net.InetSocketAddress;
15 import java.util.concurrent.ExecutorService;
16 import java.util.concurrent.Executors;
17 import java.util.concurrent.ScheduledExecutorService;
18 import org.apache.sshd.common.util.security.SecurityUtils;
19 import org.apache.sshd.common.util.threads.ThreadUtils;
20 import org.apache.sshd.server.keyprovider.AbstractGeneratorHostKeyProvider;
21 import org.opendaylight.netconf.auth.AuthProvider;
22 import org.opendaylight.netconf.util.NetconfConfiguration;
23 import org.osgi.framework.InvalidSyntaxException;
24 import org.slf4j.Logger;
25 import org.slf4j.LoggerFactory;
27 public class NetconfSSHProvider {
28 private static final Logger LOG = LoggerFactory.getLogger(NetconfSSHProvider.class);
30 private static final java.lang.String ALGORITHM = "RSA";
31 private static final int KEY_SIZE = 4096;
32 public static final int POOL_SIZE = 8;
33 private static final int DEFAULT_IDLE_TIMEOUT = Integer.MAX_VALUE;
35 private final AuthProvider authProvider;
36 private final NetconfConfiguration netconfConfiguration;
38 private ScheduledExecutorService minaTimerExecutor;
39 private NioEventLoopGroup clientGroup;
40 private ExecutorService nioExecutor;
42 private SshProxyServer server;
44 public NetconfSSHProvider(final AuthProvider authProvider,
45 final NetconfConfiguration netconfConfiguration) {
47 this.authProvider = authProvider;
48 this.netconfConfiguration = netconfConfiguration;
51 // Called via blueprint
52 @SuppressWarnings("unused")
53 public void init() throws IOException, InvalidSyntaxException {
54 minaTimerExecutor = Executors.newScheduledThreadPool(POOL_SIZE,
55 runnable -> new Thread(runnable, "netconf-ssh-server-mina-timers"));
56 clientGroup = new NioEventLoopGroup();
57 nioExecutor = ThreadUtils.newFixedThreadPool("netconf-ssh-server-nio-group", POOL_SIZE);
58 server = startSSHServer();
61 // Called via blueprint
62 @SuppressWarnings("unused")
63 public void destroy() throws IOException {
68 if (nioExecutor != null) {
69 nioExecutor.shutdownNow();
72 if (clientGroup != null) {
73 clientGroup.shutdownGracefully();
76 if (minaTimerExecutor != null) {
77 minaTimerExecutor.shutdownNow();
81 private SshProxyServer startSSHServer()
82 throws IOException, InvalidSyntaxException {
84 final InetSocketAddress sshSocketAddress = netconfConfiguration.getSshServerAddress();
85 LOG.info("Starting netconf SSH server at {}", sshSocketAddress);
87 final LocalAddress localAddress = NetconfConfiguration.NETCONF_LOCAL_ADDRESS;
89 final String path = netconfConfiguration.getPrivateKeyPath();
90 LOG.trace("Starting netconf SSH server with path to ssh private key {}", path);
92 final SshProxyServer sshProxyServer = new SshProxyServer(minaTimerExecutor, clientGroup, nioExecutor);
93 final AbstractGeneratorHostKeyProvider keyPairProvider = SecurityUtils.createGeneratorHostKeyProvider(null);
94 keyPairProvider.setAlgorithm(ALGORITHM);
95 keyPairProvider.setKeySize(KEY_SIZE);
96 keyPairProvider.setFile(new File(path));
98 new SshProxyServerConfigurationBuilder()
99 .setBindingAddress(sshSocketAddress)
100 .setLocalAddress(localAddress)
101 .setAuthenticator(authProvider)
102 .setKeyPairProvider(keyPairProvider)
103 .setIdleTimeout(DEFAULT_IDLE_TIMEOUT)
104 .createSshProxyServerConfiguration());
105 return sshProxyServer;