Skip to content

About

macOS (host) side of a Touch ID sudo bridge used by a Linux or macOS server over a reverse SSH tunnel

Resources

Stars

0 stars

Watchers

0 watching

Forks

Repository files navigation

RemoteSudoTouch

RemoteSudoTouch is a macOS SwiftUI manager app for the macOS side of a Touch ID sudo bridge used by a Linux or macOS server over a reverse SSH tunnel.

The problem this is solving: you're on your Mac and you're SSH'ed into a remote Mac or Linux server. Any sudo calls on those remote servers will prompt you with the local Touch ID dialog box on your local Mac to approve the sudo.

RemoteSudoTouch screenshot

The Linux helper package lives here: RemoteSudoTouchLinux

The macOS rsudo wrapper client lives here: RemoteSudoTouchMacos

Quick start

If you just want to try the app, you do not need to build it from source.

This repo may already include a prebuilt installer package in dist/:

  • dist/RemoteSudoTouch-<version>.pkg

You can install that .pkg directly and skip the Xcode build step.

Targets

  • RemoteSudoTouch: macOS SwiftUI app that installs and manages the bridge.
  • RemoteSudoTouchAgent: macOS command-line tool that listens on localhost, prompts with Touch ID, and returns JSON approval responses.

What the app installs

  • ~/Library/Application Support/RemoteSudoTouch/RemoteSudoTouchAgent
  • ~/Library/Application Support/RemoteSudoTouch/RemoteSudoTouch-agent.sh
  • ~/Library/Application Support/RemoteSudoTouch/RemoteSudoTouch-ssh-tunnel-<host>.sh
  • ~/Library/Application Support/RemoteSudoTouch/installer-config.json
  • ~/Library/LaunchAgents/net.pomace.remotesudotouch.agent.plist
  • ~/Library/LaunchAgents/net.pomace.remotesudotouch.tunnel.<host>.plist

Service model

  • On Linux, the PAM helper connects to /run/remote-sudo-touch.sock.
  • A local Linux socket-activated bridge forwards that request to 127.0.0.1:9876.
  • The Linux machine must establish a path back through the reverse SSH tunnel to the Mac.
  • The macOS tunnel LaunchAgent runs ssh -NT -R 127.0.0.1:<remotePort>:127.0.0.1:<localPort> user@host.
  • The macOS agent LaunchAgent runs the bundled RemoteSudoTouchAgent --port <localPort>.
  • Each configured server gets its own tunnel script and LaunchAgent.
  • Tunnel scripts perform periodic end-to-end health checks and let launchd restart the tunnel if it goes stale.

Xcode notes

  • Open RemoteSudoTouch.xcodeproj in Xcode.
  • App Sandbox is disabled in build settings because the app writes into ~/Library/LaunchAgents and ~/Library/Application Support.
  • The app target depends on RemoteSudoTouchAgent and embeds its built binary into app resources.
  • Set your signing team in Xcode before archiving.

Packaging

  • scripts/build-pkg.sh builds a Release archive, creates a component package, and wraps it in a final installer package.
  • scripts/release-pkg.sh builds a signed installer package, submits it for notarization, staples the ticket, and validates the final artifact.
  • By default it produces an unsigned installer in dist/RemoteSudoTouch-<version>.pkg.
  • The repo may also already include a prebuilt installer in dist/, which can be used directly without rebuilding the package first.
  • To sign the installer package, set one or both of these environment variables before running it:
    • PKG_SIGNING_IDENTITY="Developer ID Installer: ..."
    • APP_SIGNING_IDENTITY="Developer ID Application: ..."
  • Example:
./scripts/build-pkg.sh
APP_SIGNING_IDENTITY="Developer ID Application: Pomace Development Group, LLC" \
PKG_SIGNING_IDENTITY="Developer ID Installer: Pomace Development Group, LLC" \
./scripts/build-pkg.sh

To build, notarize, staple, and validate in one step:

APP_SIGNING_IDENTITY="Developer ID Application: Pomace Development Group, LLC (BAHC65VR5A)" \
PKG_SIGNING_IDENTITY="Developer ID Installer: Pomace Development Group, LLC (BAHC65VR5A)" \
NOTARY_KEYCHAIN_PROFILE="RemoteSudoTouchNotary" \
./scripts/release-pkg.sh

First run checklist

  1. Build the project once so the embedded RemoteSudoTouchAgent binary exists in the app bundle resources.
  2. Launch the app and fill in the Linux username, hostname, SSH key path, and ports.
  3. Run Validate SSH before applying configuration if the host has not been contacted from this Mac yet.
  4. Click Install the first time, then Apply Changes after later edits to rewrite support files and reload services.

Limitations

  • The manager currently accepts new host keys with StrictHostKeyChecking=accept-new.
  • The app assumes user-scoped launchctl bootstrap gui/<uid>.
  • The binary is copied from built products into app resources; verify the target dependency and copy phase remain intact if you edit the project.

About

macOS (host) side of a Touch ID sudo bridge used by a Linux or macOS server over a reverse SSH tunnel

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages