CH-J Server Managerserver management over SSH
Menu
PROJECT DOCUMENTATION

How Server Manager works

An overview of the Core application, secure connections, installable plugins, and distribution channels for Windows, macOS, and Linux.

Current branch0.0.2-alpha.20261011.1 · Alpha

Biometric unlock and security

First unlock the Vault with its master password. Enable biometric unlock in Settings → Security and approve system authentication. Subsequent logins offer the platform unlock button alongside the master-password form.

macOS protects the derived key in Keychain with the current Touch ID fingerprints. Windows Hello + current-user DPAPI and Ubuntu fprintd + Secret Service provide convenience unlock; credential storage on these platforms is not cryptographically bound to biometrics. Ubuntu requires a supported reader, enrolled fingerprint and secure desktop keyring.

Automatic locking is optional (Never / 1 / 5 / 10 / 15 / 30 / 60 minutes), defaulting to 15 minutes when enabled. Locking disconnects SSH sessions, closes plugins and stops diagnostics. Use the master password if system authentication fails. Actual fingerprint, face and PIN authentication still requires interactive testing on supported hardware.

If macOS reports EHOSTUNREACH while SSH works in Terminal, allow CH-J Server Manager in System Settings → Privacy & Security → Local Network and restart the app. The new Ubuntu package aligns the application icon, desktop launcher and window identity.

Biometric unlock and security

Core separates the user interface, privileged operations, server sessions, and plugins. Every boundary validates inputs and permitted capabilities.

  • Local secrets are authenticated and encrypted.
  • First-seen and changed SSH host keys require confirmation.
  • Renderer and plugin windows run sandboxed without Node integration.
  • Application updates require size, SHA-512 and a valid OpenPGP signature.

Backups before risky operations

Before changing, deleting or updating important data, arrange appropriate backups and verify recovery. Operational guidance is informational and is not part of the license; the application does not guarantee backup existence or recoverability.

Operational backup guidance →
TLS and update trust in the current alpha

The current alpha relaxes certificate-authority verification only for the explicitly allowlisted update host https://sm.ch-j.de. Application update files still always require a valid detached OpenPGP signature checked against the bundled CH-J key, the correct size and SHA-512. A signature protects package origin and integrity; it does not replace TLS confidentiality and connection authentication.

COMMUNITY

Discussion has its own space

Create a topic, share an experience or problem, and reply to other community members.

Open community