Vydané zdroje
Stáhnout zdroje ZIP
CH-J Server Manager
Procházejte adresáře a soubory konkrétního vydání aplikace.
Zdroje jsou zveřejněny pod CH-J Proprietary Software License 1.14. Jejich dostupnost nemění licenční podmínky ani neposkytuje další oprávnění.
1
# CH-J Server Manager3
CH-J Server Manager is a desktop SSH and SFTP client for Linux server administration and a local file hash calculator and checksum verification tool for Windows, macOS, and Linux. It combines server profiles, an interactive terminal, file management, monitoring, log inspection, user administration, NGINX management, and 49 hashing algorithms in one Electron application.5
The project is currently in **alpha**. It is suitable for testing, but some planned features and production distribution requirements are not complete yet. The internal name "Core" refers to the current application architecture; the product name remains CH-J Server Manager.7
## Download9
Download the latest alpha build for your platform:11
| Platform | Architecture | Package |12
| --- | --- | --- |13
| macOS | Apple Silicon (`arm64`) | [Download for macOS](https://www.sm.ch-j.de/download.php?channel=alpha&platform=mac&arch=arm64) |14
| Windows | `x64` | [Download for Windows](https://www.sm.ch-j.de/download.php?channel=alpha&platform=win&arch=x64) |15
| Ubuntu/Debian | `x64` | [Download for Ubuntu](https://www.sm.ch-j.de/download.php?channel=alpha&platform=ubuntu&arch=x64) |17
Additional builds and release channels are available on the [CH-J Server Manager website](https://www.sm.ch-j.de/de/servermanager/).19
Alpha distribution notes:21
- macOS builds currently target Apple Silicon only. Test builds may be ad hoc signed and can require manual approval in **Privacy & Security** until Developer ID signing and notarization are enabled.22
- Windows builds use an NSIS installer.23
- Ubuntu/Debian builds use a `.deb` package. For an initial installation, use `sudo apt install ./<downloaded-file>.deb` if the graphical software center rejects the package as coming from an unknown publisher.24
- Back up important connection details before testing an alpha update.26
## Latest alpha changes28
This release adds the integrated Server Diagnostics workspace (CS/DE/EN), reliable Monaco remote-file saves with recovery and conflict detection, and separate SSH RTT and ICMP measurements. Hash & Checksum, plugin windows and existing server profiles remain supported. See [remote editor and latency details](docs/remote-editor-latency.md) and [diagnostics capabilities and limits](docs/server-diagnostics.md).30
All platform packages use version `0.0.2-alpha.20261011.1` and build ID `core-20261011T114645Z-f5edc312d101`. This release integrates CH-J Proprietary Software License 1.14, complete CS/DE/EN operational guidance and mandatory license consent with a data-loss and backup acknowledgment before first use and after updates. Detached `.asc` signatures are produced with the CH-J signing subkey on a YubiKey; [SHA512SUMS](https://www.sm.ch-j.de/files/apps/builds/core-20261011T114645Z-f5edc312d101/SHA512SUMS) and its [OpenPGP signature](https://www.sm.ch-j.de/files/apps/builds/core-20261011T114645Z-f5edc312d101/SHA512SUMS.asc) cover all four artifacts.32
## Source code and Ubuntu repository34
[Browse the application source](https://www.sm.ch-j.de/source.php?build=core-20261011T114645Z-f5edc312d101) on the CH-J website, with directories, file views, line links and a complete source archive. Source availability does not grant rights beyond the [CH-J Proprietary Software License 1.14](https://www.sm.ch-j.de/license.php). The [GitHub repository](https://github.com/ch-j-code/CH-J-Servermanager) contains only this README; the source and release downloads are hosted on the CH-J website.36
Ubuntu amd64 users can install and update through the signed [CH-J APT alpha repository](https://www.sm.ch-j.cz/apt/). See [key verification, repository setup and installation](docs/apt-repository.md). APT installations display operational guidance and require license acceptance when the application first starts and after updates. Use APT for updates to repository installations and avoid starting the application updater during an APT transaction.38
## Vault security and platform fixes40
Optional Touch ID, Windows Hello (including PIN) and Ubuntu fingerprint unlock integrate with the existing encrypted Vault, with master-password fallback, CS/DE/EN settings, inactivity locking and optional focus locking. Windows and Linux provide convenience unlock; macOS uses biometric-gated Keychain access. **Locking disconnects SSH sessions and closes plugins.** Native hardware authentication still needs interactive verification. See [setup, dependencies, platform security differences and verification](docs/biometric-unlock.md).42
On macOS, `EHOSTUNREACH` for local SSH servers may require allowing **CH-J Server Manager** under **System Settings → Privacy & Security → Local Network**, then restarting the app. This build declares the usage reason and explains the error. Ubuntu packages include standard icon sizes and a matching desktop/window identity.44
## Features46
- encrypted local vault using scrypt and AES-256-GCM;47
- server profiles with password and private-key SSH authentication;48
- mandatory SHA-256 SSH host-key verification and explicit handling of changed host keys;49
- multiple SSH sessions and an interactive terminal;50
- file browsing, editing, upload, download, deletion, and ZIP/TAR/TAR.GZ export through a restricted SFTP interface;51
- Czech, German, and English user interfaces;52
- installable first-party plugins for System Monitor, Key Generator, Log Viewer, Users, File Manager, and NGINX Manager;53
- integrated Server Diagnostics: ICMP, traceroute, DNS, HTTP/1.1/2/3 capability tests, server timings, compression, TLS, TCP ports, local history and JSON/CSV/TXT exports;54
- a bundled local Hash & Checksum tool in the sidebar for calculation, verification, comparison, and checksum manifests;55
- sandboxed plugin windows with capability-based access to Core services;56
- dark title bars on Windows and Linux, plugin windows kept above the main window, and a bottom bar for collapsed plugins;57
- alpha, beta, and stable update channels;58
- application updates protected by size checks, SHA-512, and mandatory detached OpenPGP signatures.60
## Server Diagnostics62
Open **Server Diagnostics** between **Plugins** and **Hash & Checksum**. Enter a hostname, IPv4, IPv6 or HTTP(S)/WS(S) URL, choose Auto / IPv4 / IPv6 / Both, and run the overview or an individual tool. No SSH connection or external plugin is required. Results update while probes run, and individual tools or the entire run can be stopped.64
The module includes per-packet ICMP graphs/statistics, progressive traceroute, twelve DNS record types with TTL and consistency observations, independently negotiated HTTP versions, request phase timings and warm/cold connections, verified gzip/deflate/Brotli (and runtime-supported zstd), TLS 1.2/1.3 certificate inspection, bounded TCP port tests, an SSH host-key handshake without authentication, security-header/redirect checks and an optional WebSocket handshake. It supports Czech, German and English and local light/dark/system themes.66
HTTP/3 requires a separately available curl build with HTTP3/QUIC and `--http3-only` (7.88+). Success requires an actual HTTP/3 result over UDP/443; otherwise the UI reports unavailable, unsupported or error with a reason. `Alt-Svc` and HTTP/2 fallback never establish HTTP/3 support. DNSSEC is explicitly **not validated**; DS/DNSKEY records are observations. ICMP failures do not label a server offline.68
History stays in the application's local data directory. JSON/CSV/TXT reports omit bodies, cookies, authentication metadata and URL queries. Import JSON, reopen or compare saved runs from History. No new npm dependencies are required; OS ping/traceroute tools and optional HTTP3-enabled curl provide the platform-specific capabilities.70
See [implementation, IPC, limits and verification](docs/server-diagnostics.md). Run `npm test` for deterministic network tests and `npm run test:diagnostics:ui` for the Electron UI smoke test (requires a graphical desktop).72
## Hash & Checksum74
Calculate file hashes, verify checksums, and compare local files with 49 algorithms, including SHA-256, SHA-512, SHA-3, BLAKE3, and xxHash. The built-in hashing tool supports HEX and Base64 output and GNU, BSD, and SFV checksum manifests.76
Open **Hash & Checksum** from the left sidebar, directly below **Server Diagnostics**, after unlocking the vault. The tool is bundled with the application, opens in its own window, and does not appear in the installed-plugin list.78
The interface follows the application's saved language setting: **Czech, German, or English**. Saving a language change updates an already open Hash window, including controls, progress, result statuses, errors, and native file-dialog labels, while preserving selected files, algorithms, parameters, and results.80
Available functions:82
- **Calculate:** hash a single file, multiple files, or a directory, optionally including subdirectories. Use the recommended selection (SHA-256, SHA-512, and BLAKE3), select individual algorithms, or select all 49 at once. Directory symlinks are skipped.83
- **Output and parameters:** display digests as lowercase HEX, uppercase HEX, or Base64. Configure output length for SHAKE and KangarooTwelve, seeds for xxHash and MurmurHash3, and hexadecimal keys for SipHash and HighwayHash. An empty key field uses an all-zero key.84
- **Verify:** compare a file with an expected HEX or Base64 digest using a selected fixed-length algorithm. HEX comparison ignores letter case and surrounding whitespace. Suggested algorithms based on HEX length are hints, not definitive identification.85
- **Compare Files:** compare the calculated digests of two files using one or more fixed-length algorithms.86
- **Manifests:** generate and verify GNU, BSD, and SFV checksum lists with relative paths. Generation requires a fixed-length algorithm without a key or seed; SFV requires CRC32. Verification supports automatic algorithm detection or a manual override when the digest length is ambiguous.87
- **Progress and results:** view processed bytes, percentage, throughput, elapsed time, estimated remaining time, and per-file statuses; cancel a running job; copy an individual digest or all results; export results to a text file.89
### Supported algorithms91
The complete list of **49 supported algorithms** is shown below. Algorithm IDs match the result table and exported results.93
| Algorithm | ID | Output size (bits) |94
| --- | --- | --- |95
| SHA-224 | `sha224` | 224 |96
| SHA-256 | `sha256` | 256 |97
| SHA-384 | `sha384` | 384 |98
| SHA-512 | `sha512` | 512 |99
| SHA-512/224 | `sha512-224` | 224 |100
| SHA-512/256 | `sha512-256` | 256 |101
| SHA3-224 | `sha3-224` | 224 |102
| SHA3-256 | `sha3-256` | 256 |103
| SHA3-384 | `sha3-384` | 384 |104
| SHA3-512 | `sha3-512` | 512 |105
| SHAKE128 | `shake128` | Variable (default 256) |106
| SHAKE256 | `shake256` | Variable (default 512) |107
| BLAKE2b-512 | `blake2b-512` | 512 |108
| BLAKE2s-256 | `blake2s-256` | 256 |109
| BLAKE3 | `blake3` | 256 |110
| KangarooTwelve | `kangaroo-twelve` | Variable (default 256) |111
| RIPEMD-160 | `ripemd160` | 160 |112
| Whirlpool | `whirlpool` | 512 |113
| Tiger | `tiger` | 192 |114
| Tiger2 | `tiger2` | 192 |115
| MD5 | `md5` | 128 |116
| SHA-1 | `sha1` | 160 |117
| XXH32 | `xxh32` | 32 |118
| XXH64 | `xxh64` | 64 |119
| XXH3-64 | `xxh3-64` | 64 |120
| XXH3-128 | `xxh3-128` | 128 |121
| MurmurHash3 x86 32 | `murmur3-x86-32` | 32 |122
| MurmurHash3 x86 128 | `murmur3-x86-128` | 128 |123
| MurmurHash3 x64 128 | `murmur3-x64-128` | 128 |124
| CityHash32 | `cityhash32` | 32 |125
| CityHash64 | `cityhash64` | 64 |126
| CityHash128 | `cityhash128` | 128 |127
| FarmHash32 | `farmhash32` | 32 |128
| FarmHash64 | `farmhash64` | 64 |129
| FarmHash128 | `farmhash128` | 128 |130
| HighwayHash64 | `highwayhash64` | 64 |131
| HighwayHash128 | `highwayhash128` | 128 |132
| HighwayHash256 | `highwayhash256` | 256 |133
| SipHash-2-4 | `siphash-2-4` | 64 |134
| FNV-1 32 | `fnv1-32` | 32 |135
| FNV-1 64 | `fnv1-64` | 64 |136
| FNV-1a 32 | `fnv1a-32` | 32 |137
| FNV-1a 64 | `fnv1a-64` | 64 |138
| CRC-16/CCITT-FALSE | `crc16-ccitt-false` | 16 |139
| CRC-32/ISO-HDLC | `crc32` | 32 |140
| CRC-32C/Castagnoli | `crc32c` | 32 |141
| CRC-64/ECMA-182 | `crc64-ecma` | 64 |142
| CRC-64/XZ | `crc64-xz` | 64 |143
| Adler-32 | `adler32` | 32 |145
SHAKE128, SHAKE256, and KangarooTwelve allow an output length of **16–1024 bytes**. Their defaults are 32, 64, and 32 bytes respectively. BLAKE3 currently produces a fixed 256-bit digest.147
MD5 and SHA-1 are included only for legacy compatibility. xxHash, MurmurHash3, CityHash, FarmHash, HighwayHash, SipHash, FNV, CRC, and Adler-32 are not offered as cryptographic integrity proofs.149
### Plugin API151
The current Plugin API is `1.2.0`. Plugins requiring `^1.0.0` or `^1.1.0` remain compatible. Hash & Checksum is a bundled first-party plugin and uses only the narrow `local.hash` permission.153
Core owns every native file, directory, manifest, and export dialog. It gives the sandboxed plugin opaque, plugin-owned selection tokens rather than raw paths, rejects tokens belonging to another plugin, and keeps filesystem access out of the renderer. Hash jobs run in worker threads, stream bounded chunks, support progress and cancellation, and verify stable file identity before returning results. Directory enumeration skips symlinks. Manifest verification rejects symlink escapes, traversal, absolute paths, drive paths, and UNC paths.155
Hashing is local-only: the plugin has no network, SSH, or SFTP hashing capability and does not upload file contents or digests. It supports individual files, batches, recursive directories, file comparison, and GNU, BSD, and SFV manifests across 49 algorithms. MD5 and SHA-1 are retained only for legacy compatibility; fast hashes and checksums are explicitly non-cryptographic.157
## Security159
Update verification is performed in the Electron main process and fails closed. The application downloads the selected artifact and its detached `.asc` signature, checks the expected size and SHA-512 hash, and verifies the signature with the bundled CH-J public key. Immediately before installation, it re-checks the same private-cache files to reduce time-of-check/time-of-use risk. The renderer cannot supply an artifact path, public key, fingerprint, or a forged verification result.161
The long-term update trust anchor is the primary OpenPGP fingerprint:163
```text164
0D92 778A D8EC F85C 80E3 9248 48F2 433A D9CD F453165
```167
To verify a download manually, obtain the bundled [public key](ch-j-signing-public.asc), check that its primary fingerprint matches the value above, and import it with `gpg --import ch-j-signing-public.asc`. Verify the downloaded manifest with `gpg --verify SHA512SUMS.asc SHA512SUMS`, then check the files with `shasum -a 512 -c SHA512SUMS` (macOS) or `sha512sum -c SHA512SUMS` (Linux). Windows PowerShell provides `Get-FileHash -Algorithm SHA512 <file>`. Each installer also has a detached `.asc` signature that can be checked with `gpg --verify <file>.asc <file>`.169
Valid signing subkeys may be rotated as long as they remain cryptographically bound to this primary key and are valid for signing. Revoked, expired, unknown, malformed, or otherwise invalid keys and signatures block installation.171
The alpha service is still undergoing distribution hardening. In particular, standard CA verification for the explicitly allowlisted update host is temporarily relaxed in test mode, and macOS production signing/notarization is not yet enabled. OpenPGP verification remains mandatory for application update artifacts, but alpha builds should not be treated as production releases.173
When connecting to a server for the first time, verify the displayed SSH host-key fingerprint through another trusted channel. If a known host key changes, verify both the old and new fingerprints before accepting the replacement.175
## Getting started177
On first launch, choose the interface language, review the operational guidance, accept the license and acknowledge the data-loss and backup notice, then create a vault master password. Then add a profile under **Servers** and connect from **Terminal**.179
The vault password cannot be recovered. **Forgot password / reset vault** deletes encrypted server profiles, saved SSH passwords, trusted host fingerprints, and other encrypted data. Update settings and installed plugins are preserved.181
Private-key passphrases are intentionally not stored and must be entered for each connection. An SSH account password can optionally be stored in the encrypted vault.183
## Current limitations185
The following features are planned but not yet available:187
- migration of data from older application versions;188
- resumable SFTP transfer queues and sudo-assisted saves;189
- remote archive extraction;190
- SSH jump hosts and port forwarding;191
- Safe Mode and additional tools.193
This list is not exhaustive. Behavior and data formats may still change during the alpha phase.195
## Standalone application source197
This `app/` directory is the complete, self-contained desktop application source tree. It can be copied into an otherwise empty working directory and used for dependency installation, testing, development startup, and supported platform builds without any sibling source projects.199
The application communicates with an update service through its public HTTPS contract and supports independently distributed plugin packages through Plugin API 1.2. External services, plugin sources, and release tooling are not runtime, test, or build dependencies. Bundled first-party plugins in `src/main/firstPartyPlugins/` and the internal plugin framework in `src/main/plugins/` are included in this application tree.201
## Development203
Requirements:205
- Node.js 24 LTS (24.18 or newer);206
- npm;207
- the native toolchain required by Electron dependencies on the host platform.209
Use an authorised copy of the supplied application sources and a separate `node_modules` installation on each operating system:211
```bash212
cd /path/to/supplied/app213
npm ci214
npm test215
npm start216
```218
The application sources use one shared `package.json` and one shared `package-lock.json` for all supported platforms. Build on the target operating system with:220
```bash221
npm run build:mac222
npm run build:win223
npm run build:linux224
```226
The configured outputs are a macOS DMG (`arm64`), a Windows NSIS installer (`x64`), and a Debian package (`x64`). The macOS build also creates an application ZIP for initial website distribution. Generated packages are written to `app/dist/`. The release preparation step synchronises the license and guidance, generates third-party notices and assigns a new build ID.228
## Topics230
Remote editor saves, sudo authorization, recovery, latency definitions and the231
remaining external File Manager UI integration are documented in232
[Remote editor and latency monitoring](docs/remote-editor-latency.md).234
[#ssh](https://github.com/topics/ssh) · [#sftp](https://github.com/topics/sftp) · [#server-management](https://github.com/topics/server-management) · [#hash-calculator](https://github.com/topics/hash-calculator) · [#checksum](https://github.com/topics/checksum) · [#file-integrity](https://github.com/topics/file-integrity) · [#sha256](https://github.com/topics/sha256) · [#sha512](https://github.com/topics/sha512) · [#sha3](https://github.com/topics/sha3) · [#blake3](https://github.com/topics/blake3) · [#xxhash](https://github.com/topics/xxhash) · [#electron](https://github.com/topics/electron) · [#linux](https://github.com/topics/linux) · [#macos](https://github.com/topics/macos) · [#windows](https://github.com/topics/windows)236
## License238
This edition of CH-J Server Manager is expressly distributed under the **CH-J Proprietary Software License, version 1.14** (October 11, 2026). See the [complete license](LICENSE). Commercial and non-commercial use are free of license fees indefinitely under its terms. Third-party materials retain their separate licenses and notices; this application license does not replace them.240
The license integration described here applies to newly built packages. Existing published downloads retain their original contents and licensing information.242
Before installation, the website displays the complete operational guidance in the selected language and requires an explicit Continue step before downloading an application package. Interactive Windows NSIS installation displays the guidance before the complete license and requires license acceptance. macOS DMG displays guidance before the license in the system prompt. Application ZIP, Debian/Ubuntu and silent installation have no reliable pre-installation dialog; the application displays the guidance before license acceptance at first launch. Every platform requires per-user acceptance before using a new or updated build, including updates with the same version number. The required checkbox combines license consent with acknowledgment of data-loss risks, the need for appropriate backups before risky operations, and the fact that the application does not guarantee backup existence or recoverability. Declining exits the application. The acceptance record is local; no activation or reporting is required. See [license acceptance and packaging](docs/license-acceptance.md).244
The application bundles [documentation](docs/README.md), including [Provozní bezpečnost a zálohování (česky)](docs/provozni-bezpecnost-a-zalohovani.md), [Operational Safety and Backup Guidance (English)](docs/operational-safety-and-backup-guidance.md) and [Betriebssicherheit und Datensicherung (Deutsch)](docs/betriebssicherheit-und-datensicherung.md). Displaying these recommendations is mandatory before proceeding; following them remains optional. They are informational and non-binding, are not part of the license and do not require separate acceptance. The application displays them again before license acceptance after every update, or if the bundled guidance changes. They are available in the application under **Settings → Licenses and documentation** and on the [website license page](https://www.sm.ch-j.de/license.php?lang=en).SHA-256: 1afb020b5aeb62316961bc58465f283a376d5e02c440ee4ccaf5727e4ad8bb2b
SHA-256 archivu: 5ac91caf4fa32a6fdb114f2430deed486fbe7489d5eea343d1f034169fafb5e0