Skip to content
  • MangoFly

    A self-hosted WireGuard mesh. Devices connect straight to each other; the coordination server is one binary and a SQLite file, and never sees their traffic.

    encrypted WireGuard · peer to peerLaptopbehind home NATServerin a datacentrePhoneon mobile datacoordination serverone binary · one SQLite filecontrol plane only (TLS)keys · tunnel addresses · peer lists · sealed ICE candidatesholds no private keys · carries no traffic · cannot decryptdatacontrol
  • MangoDock

    Docker management with nothing on the hosts. Reaches each daemon over an ordinary SSH session — no agent to install, no port to open.

    The MangoDock dashboard showing three host cards with container state counts, CPU and memory gauges, a usage history and recent events
  • MangoWiFi

    A Wi-Fi 6/7/8 test bench. One binary runs as Console or Agent either side of the access point under test, measuring latency under real load.

    AP under testWi-Fi 6 / 6E / 7Agentstation side · real radioLAN receiveriperf3 -sConsoleUI · orchestrates · probes
  • Blog
  • Nothing phones home

    No telemetry, no analytics, no crash reporter, no account login. Check it with a packet capture on your own network.

    Download MangoSSH
  • Project
  • Download
  • Chapter 11 of 12

    Troubleshooting & Known Limitations

    A quick-lookup table for common symptoms, plus a short list of things that are current, deliberate limitations rather than bugs. Every row links back to the use case with the full explanation and step-by-step fix.

    Troubleshooting Index

    Purpose

    • Jump straight to the right use case for a symptom you're seeing, instead of reading the whole guide top to bottom.
    • Blank/white screen on launch Front-end regression after an update — restart the app fully (full quit, not just closing the window); see Getting Started.
    • "Permission denied (publickey)" Wrong key/passphrase, or the public key isn't in the server's authorized_keys — see SSH: Password & Key-Based Authentication.
    • Unexpected host-key / certificate trust prompt Expected on a genuinely new host; suspicious on one you've connected to before — see SSH: Host Key Trust (TOFU) & Certificate Revocation.
    • RDP black screen after connect Usually an NLA/Domain field mismatch — see RDP: Basic RDP Connection.
    • A saved host "disappeared" Almost always a different active Profile, or a Host-visibility group filter — see Getting Started: Profiles and Session Management: Organizing Connections with Groups.
    • Group credential/bastion inheritance not applying Host has no group, the wrong group, or its own explicit value already set (which always wins) — see SSH: Groups & Inherited Credentials.
    • AI Assistant says "not configured" after adding a key Reopen the panel once (availability re-checks per open, not cached); confirm Enable is checked and a real model ID is set — see Automation: AI Assistant.
    • Garbled/escape-code text in a terminal export or preview A too-narrow ANSI-stripping pattern — fixed in current builds; confirm you're up to date — see Session Management: Recording, Exporting, Searching & Command History.
    • Locked out of Personal Vault / Team Vault / Cloud Vault Each tier's master password / device keys / recovery code is non-recoverable by design — see Vault System & Password Manager.
    • Monitor graphs empty or mixed between hosts Confirm the shell supports the underlying probe commands; per-session history isolation is fixed in current builds — see Monitoring & Diagnostics: Monitor.
    • Audit Log "Verify integrity" reports a break Take this seriously — investigate what touched the underlying log file rather than dismissing it — see Monitoring & Diagnostics: The Tamper-Evident Audit Log.
    • Deployed/deauthorized a key and now can't connect Always deploy the new key before removing the old one — see Monitoring & Diagnostics: Key Lifecycle.
    • MCP tool call refused Tripped the policy denylist deliberately — see Automation: MCP Server.

    Known Limitations

    Purpose

    Things that are current, intentional constraints of this build — not bugs to report, though worth knowing before you rely on them.

    • PKCS#11 hardware-token auth is RSA-only in the current release — ECDSA tokens aren't yet supported.
    • Windows Hello / Secure Enclave SSH keys use RSA 2048 on Windows (a real, tested limitation of the current Windows NGC API surface) and ECDSA P-256 on macOS Secure Enclave — the two platforms deliberately use different algorithms for this reason.
    • Multi-monitor RDP is explicitly experimental — behavior may be inconsistent across setups.
    • "Follow server sshd log" is POSIX-target-only — not available for Windows RDP/SSH targets.
    • Password Manager entries are Personal-Vault-only for now — not yet shared through Team Vault, Self Hosting Vault, or Cloud Vault.
    • Team Vault, Self Hosting Vault, and Cloud Vault are all non-recoverable by design if every device and recovery code is lost — this is the intended tradeoff of genuine zero-knowledge encryption, not an oversight.
    • Cloud Vault (hosted) is in beta with manually-toggled paying-tier access rather than live billing.
    • The macOS Secure Enclave and Touch ID code paths are implemented against documented Apple APIs but, at the time of writing, verified primarily on Windows — if something behaves unexpectedly on macOS specifically, it's worth reporting with details.