Remote File System
A remote file system via SSHFS establishes a connection between a drive on your local machine and your virtual machine.
Once connected, any data you write from your local machine is copied to the virtual drive inside your VM.
This gives you a one-way method to move data into your VM, alongside SFTP transfers.
Mount Remote File System via SSHFS in macOS
- Ensure your macOS is updated to the latest version before starting.
- Install both macFUSE and SSHFS on your local machine.
- A separate license may be required for non-personal or commercial use of "macFUSE" and "SSHFS".
- Your Linux VM must be properly configured for SFTP to work.
Download macFUSE
- Open the macFUSE Stable Release download link in your browser.
- In the pop-up, click Save to download the macFUSE.dmg installer locally.
- In your downloads directory, click to open the macFUSE installer.
Install macFUSE
- Double-click the icon Install macFUSE.
- In the prompt, click Allow.
- Click Continue to proceed.
- View the license agreement, then click Continue.
- In the pop-up, click Agree.
- Click Install.
- In the pop-up, enter your Mac password.
- Click Install Software.
Enable System Extension in Mac
- In the new pop-up, click Open System Settings.
- Once in settings, navigate to Privacy & Security section.
- Under the Security subsection, click Enable System Extensions....
- Enter your password to confirm.
- In the new pop-up, click Shut Down.
Set Security Utility at Startup
- Once your Mac is shut down, hold the Start button until you see "Additional Startup Options" on the screen.
- Click the icon Options from the boot list.
- Select your user account in Mac.
- Click Next.
- In the prompt, enter your Mac password.
- Click Continue.
- In the new window, navigate to Utilities in the top taskbar.
- Select Startup Security Utility.
Set Security Policy for kernel Extensions
- Next, select your Macintosh HD where your macOS is located.
- Click the Security Policy button in the bottom right.
- In the prompt, tick the Reduced Security option.
- Tick the box to Allow user management of kernel extensions from identified developers.
- Click OK to restart your Mac.
After you set the security policy, you can also manually restart your Mac.
Download SSHFS
- Once restarted, open the SSHFS Stable Release download link in your browser.
- In your downloads directory, click to open the SSHFS installer.
Install SSHFS
- In the installer prompt, click Continue.
- View the license agreement, then click Continue.
- In the pop-up, click Agree.
- Click Install.
- In the pop-up, enter your Mac password.
- Click Install Software.
- Once installed, click Close.
- In the pop-up, click Move to bin to delete the installer locally.
- Go to Apps and open Terminal.
Copy-paste SFTP Command from your Virtual Machine
- Navigate to Apps and open the Connect Application.
- Log into your institution's secure enclave.
- Go to the Virtual Machines icon in the top left taskbar.
- Click the Virtual Machines Table Overview section in the top left panel.
- In the left panel, select the virtual machine you want to mirror files to.
- Next, click the SFTP to VM card.
- In the pop-up, click the Copy button next to Mac/Linux SSHFS field.
Do not close the Connect Application pop-up.
- Paste the SSHFS command into your local machine's terminal.
- Press Enter.
- An authenticity message with an SHA256 key fingerprint is displayed.
- Type yes and press Enter to proceed.
- Go to the Connect Application pop-up.
- Click the Copy button next to the Password field.
- Paste the password into the local machine's terminal and press Enter.
- A system extension block pop-up may be displayed.
- Click Allow.
- Restart your local machine if asked.
If the terminal fails to connect your local drive to your VM drive after pasting the password, close the connection pop-up in the secure enclave interface, reopen it by clicking SFTP to VM, and enter the newly generated password into the terminal.
- Go to Finder.
- Locate the virtual drive in your drives directory.
- Double-click the virtual drive to open it.
- Drag-and-drop files from your local machine to the virtual drive.
To save data in other parts of your directory tree, use symlinks (shortcuts that point to another location on the filesystem).
The Mac/Linux SSHFS Command Mechanism Explained
tiCrypt gives you this command to copy, but never runs it for you. The VM drive is mounted on your computer only when you run the command yourself, in your own terminal.
Syntax:
mkdir -p ~/_ticrypt_vm_drive; umount ~/_ticrypt_vm_drive; sshfs -o volname="YOUR VM NAME" -o follow_symlinks -p YOUR_PORT USER@localhost:/DRIVE_PATH ~/_ticrypt_vm_drive
| Part | What it does |
|---|---|
mkdir -p ~/_ticrypt_vm_drive | Creates an empty folder in your home folder for the drive to appear in. Nothing is stored there. |
umount ~/_ticrypt_vm_drive | Disconnects any drive left mounted there from an earlier session. |
sshfs -o volname="EL" | Mounts the VM drive and names it "EL" in Finder, in this example. |
-o follow_symlinks | Follows symlinks in the VM, so you can reach access directories outside your home directory. |
-p 12345 john@localhost:/DRIVE_PATH | Connects as john on port 12345 and opens the drive at /DRIVE_PATH in the VM. |
~/_ticrypt_vm_drive | The folder from the first step, where the drive appears. |
The remote file system is an inbound path. Files you drop into the mount are streamed directly into the VM, so nothing is written to your local disk along the way, and the mount gives you no route to pull data back out of the enclave. Use it to get data in; use the Vault for anything that needs to come out, so the export is logged.
Debug
The mount opens in your home directory in the VM and follows symlinks (shortcuts to another location). To put data somewhere else in the VM, create a symlink in your home directory that points there.
Unmount local drive from Remote File System in Mac OS
tiCrypt automatically unmounts previously mounted local drives when the Linux/Mac SSHFS command runs in the terminal.
Method One
- Go to Finder.
- Find the drive in the sidebar under Locations, or in your home folder as
_ticrypt_vm_drive. - Right-click the virtual drive.
- From the options, select Eject.
As a best practice, eject your virtual drive from the remote file system after each session.
Method Two
- Go to Apps in Mac.
- Open a local terminal.
- In the terminal, run
diskutil unmount force ~/_ticrypt_vm_drive. - Check that the terminal reports the drive as unmounted.
If that fails, run the same command with the drive's full path, for example diskutil unmount force /Users/john/_ticrypt_vm_drive.
Mount Remote File System via SSHFS in Windows
- Ensure your Windows is updated before starting.
- Install either WinFsp and SSHFS or SFTP Drive and SSHFS on your local machine.
- A separate license may be required for non-personal or commercial use of "WinFsp", "SFTP Drive 2024" and "SSHFS".
- Your Windows VM must be properly configured for SFTP to work.
Method One
Download WINFSP
- Open the WINFSP download link in your browser.
- Navigate to Downloads in your browser, and click to open the WINSFSP.exe installer.
Install WINFSP
- In the new prompt, click Next.
- View the installation path and click Next.
- Click Install.
- In the pop-up, click Yes to allow WINFSP to make changes to your device.
- Once installed, click Finish.
Download SSHFS
- Open the SSHFS download link in your browser.
- Navigate to Downloads in your browser, and click to open the SSHFS.exe installer.
Install SSHFS
- In the new prompt, click Next.
- View the installation path and click Next.
- Click Install.
- In the pop-up, click Yes to allow SSHFS to make changes to your device.
- Once installed, click Finish.
Map Network Drive
- Go to file explorer in This-PC.
- Right-click on This-PC icon in the left panel.
- From the options, select Map network drive....
- A prompt appears.
Copy-paste SFTP Command from your Virtual Machine
- Navigate to Start menu.
- Search and open the Connect Application.
- Log into your institution's secure enclave.
- Go to the Virtual Machines icon in the top left taskbar.
- Click the Virtual Machines Table Overview section on the top left panel.
- In the left panel, select the virtual machine you want to mirror files to.
- Next, click the SFTP to VM card.
- In the pop-up, click the Copy button next to Windows SSHFS field.
Do not close the Connect Application pop-up.
- Paste the SSHFS command into your local Map network drive prompt, in the Folder field.
- Click Finish.
- A new prompt will require your local host password.
Login to your Local Host
- Go to the Connect Application pop-up.
- Click the copy button next to Password field.
- Paste the password into the local host prompt.
- Click OK.
- Your secure VM directory will open in File Explorer, and any changes made there will be mirrored in your secure enclave VM.
Method Two
Download SFTP Drive
- Open the SFTP Drive download link in your browser.
- Navigate to Downloads in your browser, and click to open the SFTPDrive2024.exe installer.
Install SFTP Drive
- In the new prompt, click Yes to allow the app to make changes to your device.
- Then, click Next.
- View the license agreement and click I Agree.
- View the installation path and click Next.
- Click Next.
- Click Install.
- Once installed, click Finish to run the SFTP Drive.
Open New Connection
- In the new prompt, click New in the top right.
- In the pop-up, under Drive, in the Drive Name field, enter your secure enclave's name. (lowercase)
- Next, type localhost in the Remote Host field.
Copy-paste SFTP Commands from your Virtual Machine
- Navigate to Start menu.
- Search and open the Connect Application.
- Log into your institution's secure enclave.
- Go to the Virtual Machines icon in the top left taskbar.
- Click the Virtual Machines Table Overview section on the top left panel.
- In the left panel, select the virtual machine you want to mirror files to.
- Next, click the SFTP to VM card.
- In the pop-up, click the Copy button next to remote port, username and password.
- Then paste your remote port, username and password into the corresponding fields.
Do not close the Connect Application pop-up.
Test SSH Connection
- Click Test SSH Connection button in the bottom left corner.
- In the pop-up click Yes to confirm connection.
- In the new pop-up, click OK.
Connect via SSH
- In the SFTP Drive prompt, click OK to connect.
- In the pop-up, click Yes to connect the drive now.
- Your secure VM directory will open in File Explorer in This-PC directory, and any changes made there will be mirrored in your secure enclave VM.
Unmount local drive from Remote File System in Windows
Method One
tiCrypt automatically disconnects previously mounted local drives when the Windows SSHFS command runs in the terminal.
- Go to File Explorer in This-PC.
- Right-click the secure VM directory.
- From the options, select Disconnect.
As a best practice, always disconnect your local drive from the remote file system after each session.
Method Two
- Go to SFTP Drive prompt.
- Select the running connected drive from the list.
- Click Disconnect in the right panel.
To reconnect the drive, open the Connect Application and copy-paste the new port and password in the SFTP Drive prompt, select the drive and click Connect in the right panel.