Frequently Asked Questions
Everything you need to know about OSH Zero Trust SSH Access.
OSH is a Zero Trust Privileged Access Management (PAM) platform that enables secure remote server access without exposing static SSH keys or relying on legacy VPNs. It combines the OSH-Client, OSH-Signer mobile app, and OSH CA Gateway to verify every connection before access is granted.
Every SSH session follows a strict Zero Trust workflow:
- User requests SSH access via OSH-Client.
- Policy is validated by the OSH CA Gateway.
- An authorized approver reviews the request on OSH-Signer.
- A short-lived SSH certificate is issued.
- Secure Just-In-Time (JIT) SSH access is established.
No connection is trusted by default.
No. OSH completely eliminates the security risks of sharing or managing long-lived SSH private keys across engineering teams. Authentication is handled using temporary, ephemeral certificates issued automatically after policy validation and administrative approval.
Yes. OSH serves as a modern bastion host alternative and VPN replacement by delivering secure remote access without static SSH keys or open inbound ports. Organizations can enforce identity verification, approval workflows, and policy-based access through a centralized gateway
OSH supports multi-platform enterprise environments across all components:
- Desktop/Client: macOS, Windows, Ubuntu Linux
- Mobile Approval: iPhone / iOS (OSH-Signer)
- Certificate Gateway: Linux Server / Cloud Infrastructure
This allows engineers to securely access infrastructure from the devices they already use.
Yes. Every privileged access request can enforce a multi-factor approval workflow before a connection is established. Approvers receive instant push notifications on the OSH-Signer mobile app (backed by Secure Enclave), where they can review, approve, or reject SSH access in seconds.
The OSH CA Gateway is the core component that validates requests, enforces access policies, and issues short-lived SSH certificates after successful approval. It acts as the trust layer between users and your infrastructure.
Yes. OSH is designed for enterprises that require secure privileged access, centralized policy management, audit trails, and Zero Trust security across cloud, hybrid, and on-premises infrastructure.
Yes. Every access request, approval action, and SSH session can be audited, providing organizations with complete visibility into privileged access activities.
You can get started in three simple steps:
- Download the OSH applications for your OS and mobile device.
- Follow the step-by-step setup in our OSH Documentation.
- Or book a live enterprise demo with our security team.