Skip to content

How to expose socks5 and http proxy with username and password in sslocal? #2017

Description

@kuolemaaa

as title, how do I set it such that i connect to the sslocal via like socks5://myusername:mypassword@mysslocal ??

Activity

  1. database64128 commented on Sep 10, 2025

    @database64128
    Contributor

    For SOCKS5, you need a separate JSON file to specify the username-password pairs. See https://github.com/shadowsocks/shadowsocks-rust#socks5-authentication-configuration.

    HTTP basic auth is not currently supported. You might be interested in other implementations like https://github.com/database64128/shadowsocks-go.

  2. HidingCherry commented on Sep 12, 2026

    @HidingCherry

    For SOCKS5, you need a separate JSON file to specify the username-password pairs. See https://github.com/shadowsocks/shadowsocks-rust#socks5-authentication-configuration.

    Well, yes, but no...

    sslocal -c config.json

    2026-09-12Txxx INFO shadowsocks local 1.25.0 build 2026-08-27T06:18:31.037935705+00:00
    2026-09-12Txxx  WARN could not parse an IP from hosts file ("domain")
    2026-09-12Txxx  INFO shadowsocks socks TCP listening on 127.0.0.1:1080
    2026-09-12Txxx ERROR socks5 tcp client handler error: currently shadowsocks-rust does not support authentication
    

    config.json

    {
        "locals": [{
    //		"protocol": "socks",
    		"local_address": "127.0.0.1",
    		"local_port": 1080,
    
    		// optional below
    		"socks5_auth_config_path": "./auth.socks5.json",
    //		"acl": "./acl",
    	}],
    }

    auth.socks5.json

    {
    	// Password/Username Authentication (RFC1929)
    	"password": {
    		"users": [{
    			"user_name": "user",
    			"password": "pass"
    		}]
    	}
    }
  3. database64128 commented on Sep 12, 2026

    @database64128
    Contributor

    currently shadowsocks-rust does not support authentication

    This is a misleading error message leftover from before shadowsocks-rust gained SOCKS5 authentication support:

    async fn check_auth(&self, stream: &mut TcpStream, handshake_req: &HandshakeRequest) -> io::Result<()> {
    use std::io::Error;
    let allow_none = !self.auth.auth_required();
    for method in handshake_req.methods.iter() {
    match *method {
    socks5::SOCKS5_AUTH_METHOD_PASSWORD => {
    let resp = HandshakeResponse::new(socks5::SOCKS5_AUTH_METHOD_PASSWORD);
    trace!("reply handshake {:?}", resp);
    resp.write_to(stream).await?;
    return self.check_auth_password(stream).await;
    }
    socks5::SOCKS5_AUTH_METHOD_NONE => {
    if !allow_none {
    trace!("none authentication method is not allowed");
    } else {
    let resp = HandshakeResponse::new(socks5::SOCKS5_AUTH_METHOD_NONE);
    trace!("reply handshake {:?}", resp);
    resp.write_to(stream).await?;
    return Ok(());
    }
    }
    _ => {
    trace!("unsupported authentication method {}", method);
    }
    }
    }
    let resp = HandshakeResponse::new(socks5::SOCKS5_AUTH_METHOD_NOT_ACCEPTABLE);
    resp.write_to(stream).await?;
    trace!("reply handshake {:?}", resp);
    Err(Error::other(
    "currently shadowsocks-rust does not support authentication",
    ))
    }

    What actually happened here is that either you forgot to configure your client to use the username and password, or all authentication methods advertised by your client were not supported by shadowsocks-rust.

  4. zonyitoo commented on Sep 25, 2026

    @zonyitoo
    Collaborator

    Run sslocal -vvv and see what method it received.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions