Limits & Troubleshooting
Current, deliberate constraints, and where to look when something is wrong.
Known limitations
- PKCS#11 hardware-token authentication is RSA-only in the current release; ECDSA tokens are not yet supported.
- Windows Hello SSH keys use RSA 2048 on Windows; Secure Enclave keys on macOS use ECDSA P-256.
- Multi-monitor RDP is explicitly experimental and may behave inconsistently across setups.
- MangoSSH Direct is Windows-host-only and captures the interactive desktop session, so it cannot reach a locked or logged-out machine.
Common symptoms
- A saved host disappeared — Almost always a different active profile, or a host-visibility group filter.
- Permission denied (publickey) — Wrong key or passphrase, or the public key is not in the server's authorized_keys.
- RDP connects to a black screen — Usually an NLA or Domain field mismatch.
- An unexpected host-key prompt — Expected on a genuinely new host; worth investigating on one you have used before.
- Locked out of a vault — Each tier's master password, device keys and recovery code are non-recoverable by design.
The full symptom index, with the cause and fix for each, is in the Troubleshooting chapter.
Full detail
Step-by-step instructions, how to check each one worked, and what to do when it did not.