sslh on Ubuntu 24.04
بواسطة cloudimg
Open source SSL/SSH multiplexer on Ubuntu 24.04 letting SSH and HTTPS share port 443
sslh is an open source SSL/SSH protocol multiplexer. It listens on a single port, reads the first bytes each client sends to work out which protocol is being spoken, and hands the connection to the matching service. The practical result is that SSH and HTTPS share one port. That matters whenever the network between you and your server only lets 443 out. Hotel, airport and captive portal networks, tightly controlled corporate proxies and restrictive egress firewalls routinely allow 443 and block 22, and with sslh in front an ordinary ssh client reaches your shell over the one port those networks do allow, while a browser hitting the same host and port still gets your web service. It is equally useful when you simply want one exposed port instead of several on an internet facing host.
This cloudimg image compiles the latest stable sslh release from the official upstream source tag on Ubuntu 24.04 LTS and bakes it reproducibly, with the exact version and its provenance recorded on the VM. sslh runs under systemd and drops from root to an unprivileged account as soon as it has bound the port.
This is a working multiplexer the moment it boots, not an empty daemon waiting to be configured. The image ships the backends too, so the appliance demonstrates itself standalone with nothing else to install: SSH is routed to the VM's own OpenSSH server, HTTPS to a local nginx TLS listener serving a status page, and plain HTTP to a local nginx HTTP listener, with an unrecognised protocol catch all. A shipped self test command opens all three protocols against the multiplexed port and reports in one line whether each routed correctly. You then repoint those routes at your own services by editing one configuration file.
No default login and no baked key. sslh is a stateless connection router with no account, no password and no token. The only key material the appliance holds is the TLS certificate of its HTTPS backend, and the shipped image contains no certificate and no private key at all: both are generated on your VM at first boot, so no two instances ever share key material. Both long running services are gated so neither can start before that bootstrap completes.
sslh is licensed under the GPL-2.0, free and open source with no per user or per deployment fee. In line with that licence the image carries the verbatim licence text and the complete corresponding source for the binaries it runs. cloudimg provides the packaging, the systemd integration, the working demonstration backends, the per instance TLS bootstrap, the self test tooling, security patching and 24/7 support with a guaranteed 24 hour response SLA. sslh is an independent open source project by Yves Rutschle and this image is not affiliated with or endorsed by the sslh project.