Security & data

Trusted hosts (known_hosts)

The first connection to a host captures its public-key fingerprint (SHA-256) and stores it after you confirm. Subsequent connections compare the fingerprint — if it ever changes you get a clear alert.

Manage the list in Settings → Security → Trusted hosts — each entry shows the host, key algorithm (Ed25519, RSA, ECDSA…) and fingerprint, and can be removed.

How the connection is protected

DR-Terminal uses its own SSH implementation, hardened against active attackers and hostile servers:

These protections are on automatically. You only interact with them through the trusted-hosts prompt above.

SSH algorithms (advanced)

Settings → Security → SSH algorithms lets you tune what the client proposes to servers — for a legacy appliance that only speaks an old cipher, or to pin the order you trust. The page has one section per negotiation category:

Algorithms the library ships disabled carry a small amber legacy tag — they stay off until you switch them on. A category can never end up empty: the last enabled algorithm cannot be switched off. Reset next to a section title returns it to the library defaults.

Each saved connection can override the global choice: in the connection form, SSH algorithms → Custom opens the same editor for that host only (Default follows the global setting). Confirming the editor updates the form — Save the connection afterwards. What was actually negotiated — key exchange, host key, cipher, MAC, compression — is shown in the session menu's Connection Info.

New settings apply to connections opened afterwards. A second tab to the same host reuses the live SSH connection and therefore its algorithms — disconnect and reconnect to renegotiate.

Post-quantum warning

A “store now, decrypt later” attacker records today's traffic and decrypts it once quantum computers can break classical key exchange. DR-Terminal prefers post-quantum hybrid key exchange (sntrup761x25519-sha512, mlkem768x25519-sha256 — the same ones OpenSSH ships) and, like OpenSSH, warns when a session ends up on a classical one: a dialog appears once per connection saying that the key exchange is not post-quantum and that the server may need an upgrade. Don't show again switches the warning off for good; it lives in Settings → Security → Post-quantum warning (on by default).

Exported keys

When you convert or export a private key (SSH keys → Convert) and set a passphrase, the encryption uses a strong key-derivation function chosen per format — bcrypt for OpenSSH, PBKDF2 for PKCS#8, Argon2id for PuTTY PPK v3 — and every salt and IV comes from a cryptographically secure random generator. The converter reads and writes OpenSSH, PKCS#8, PKCS#1 and PuTTY PPK (v2/v3), from both PEM and binary DER.

Where secrets live

Passwords, private keys and passphrases never get serialised into connection JSON. They go straight to the platform's secure store:

Encrypted configuration backup

Settings → Configuration → Export backup creates a password-protected .drterminal file. It contains: connections (with credentials), groups, trusted hosts, SSH keys, SFTP bookmarks, command history, highlight rules, snippets, serial and Telnet profiles, SSH algorithm preferences, terminal appearance and settings, and (on mobile) the DevOps keyboard configuration. Import backup restores the same bundle — useful when moving between machines.

Format: JSON encrypted with AES-256-GCM. The password is never stored in the file — it only derives the encryption key (PBKDF2, 100 000 iterations of SHA-256).

Import ~/.ssh/config

On Desktop you can bulk-import hosts from an existing OpenSSH config. The importer parses Host, HostName, User, Port, IdentityFile and ProxyJump entries and adds them as saved connections. Key files referenced by IdentityFile are loaded from disk into SecureStorage.

Log levels

In Settings → Terminal → File log level pick what reaches ~/.dr-terminal/logs/ (Desktop) or the equivalent on mobile. Default: ERROR — minimal noise. For diagnostics switch to DEBUG.

Previous
Desktop CLI
Next
Settings & platforms