{"id":38754,"date":"2019-10-31T22:25:45","date_gmt":"2019-10-31T19:25:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/reliz-openssh-8-1\/"},"modified":"2019-10-31T22:25:45","modified_gmt":"2019-10-31T19:25:45","slug":"reliz-openssh-8-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-openssh-8-1","title":{"rendered":"OpenSSH 8.1 ver\u00f6ffentlicht","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Nach sechs Monaten Entwicklungszeit <noindex><a rel=\"nofollow\" href=\"http:\/\/lists.mindrot.org\/pipermail\/openssh-unix-dev\/2019-October\/037966.html\">vorgestellt<\/a><\/noindex> Release <noindex><a rel=\"nofollow\" href=\"http:\/\/www.openssh.com\/\">OpenSSH 8.1<\/a><\/noindex>, einer offenen Implementierung von Client und Server f\u00fcr die Protokolle SSH 2.0 und SFTP. <\/p>\n<p>Besondere Aufmerksamkeit in dieser neuen Version verdient die Behebung einer Sicherheitsanf\u00e4lligkeit, die ssh, sshd, ssh-add und ssh-keygen betrifft. Das Problem besteht im Code zur Analyse von privaten Schl\u00fcsseln des Typs XMSS und erm\u00f6glicht es einem Angreifer, ein Ganzzahlen\u00fcberlauf auszul\u00f6sen. Die Schwachstelle wird als ausnutzbar, aber wenig anwendbar eingestuft, da die Unterst\u00fctzung f\u00fcr XMSS-Schl\u00fcssel zu den experimentellen Funktionen geh\u00f6rt, die standardm\u00e4\u00dfig deaktiviert sind (in der portablen Version gibt es in autoconf nicht einmal eine Build-Option zur Aktivierung von XMSS).<\/p>\n<p>Haupt\u00e4nderungen: <\/p>\n<ul>\n<li class=\"l\"> In ssh, sshd und ssh-agent <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50929\">wurde hinzugef\u00fcgt<\/a><\/noindex> Code, der die Wiederherstellung des sich im Arbeitsspeicher befindlichen privaten Schl\u00fcssels durch Seitenkanalangriffe, wie <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47856\">Spectre, Meltdown<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41340\">RowHammer<\/a><\/noindex> und <noindex><a rel=\"nofollow\" href=\"https:\/\/rambleed.com\/\">RAMBleed<\/a><\/noindex>. Private Schl\u00fcssel werden jetzt beim Laden in den Speicher verschl\u00fcsselt und nur w\u00e4hrend der Verwendung entschl\u00fcsselt, wodurch sie zu anderen Zeiten verschl\u00fcsselt bleiben. Bei diesem Ansatz muss ein Angreifer zuerst einen kryptografisch zuf\u00e4llig erzeugten 16-KB-Zwischenschl\u00fcssel wiederherstellen, der zur Verschl\u00fcsselung des Hauptschl\u00fcssels verwendet wird, was bei der typischen Fehlerquote moderner Angriffe unwahrscheinlich ist;\n<li class=\"l\"> Im  <noindex><a rel=\"nofollow\" href=\"https:\/\/man.openbsd.org\/ssh-keygen.1\">ssh-keygen<\/a><\/noindex>  unterst\u00fctzt jetzt experimentell ein vereinfachtes Verfahren zur Erstellung und Pr\u00fcfung digitaler Signaturen. Digitale Signaturen k\u00f6nnen mit regul\u00e4ren SSH-Schl\u00fcsseln, die auf der Festplatte oder im ssh-agent gespeichert sind, erstellt und \u00e4hnlich dem authorized_keys <noindex><a rel=\"nofollow\" href=\"https:\/\/man.openbsd.org\/ssh-keygen.1#ALLOWED_SIGNERS\">Zugriff auf eine Liste zul\u00e4ssiger Schl\u00fcssel<\/a><\/noindex>. In die digitale Signatur wird Namensrauminformationen eingebettet, um Verwirrung bei der Anwendung in verschiedenen Bereichen (z. B. f\u00fcr E-Mail und Dateien) zu vermeiden;\n<li class=\"l\"> ssh-keygen wird standardm\u00e4\u00dfig auf die Verwendung des rsa-sha2-512-Algorithmus umgestellt, wenn digitale Zertifikate mit einer RSA-Schl\u00fcsselsignatur signiert werden (im CA-Modus). Solche Zertifikate sind nicht kompatibel mit Versionen vor OpenSSH 7.2 (um die Kompatibilit\u00e4t zu gew\u00e4hrleisten, sollte der Algorithmustyp \u00fcberschrieben werden, beispielsweise durch den Aufruf \u201essh-keygen -t ssh-rsa -s ...\u201c);\n<li class=\"l\"> In ssh wird im Ausdruck ProxyCommand die Unterst\u00fctzung f\u00fcr die Expansion des Platzhalters \u201e%n\u201c (der in der Adresszeile angegebene Hostname) implementiert;\n<li class=\"l\"> In den Listen der Verschl\u00fcsselungsalgorithmen f\u00fcr ssh und sshd kann zum Einf\u00fcgen der standardm\u00e4\u00dfig vorgeschlagenen Algorithmen jetzt das Zeichen \u201e^\u201c verwendet werden. Um beispielsweise ssh-ed25519 zur Standardliste hinzuzuf\u00fcgen, kann \u201eHostKeyAlgorithms ^ssh-ed25519\u201c angegeben werden;\n<li class=\"l\"> In ssh-keygen wird beim Abrufen des \u00f6ffentlichen Schl\u00fcssels aus dem privaten Schl\u00fcssel der angeh\u00e4ngte Kommentar ausgegeben;\n<li class=\"l\"> In ssh-keygen wurde die M\u00f6glichkeit hinzugef\u00fcgt, die Option \u201e-v\u201c bei der Durchf\u00fchrung von Schl\u00fcsselermittlungsoperationen zu verwenden (zum Beispiel \u201essh-keygen -vF host\u201c), deren Angabe zu einer klaren Signatur des Hosts f\u00fchrt;\n<li class=\"l\"> Die M\u00f6glichkeit zur Nutzung wurde hinzugef\u00fcgt <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/PKCS_8\">PKCS8<\/a><\/noindex> als alternatives Format zum Speichern privater Schl\u00fcssel auf der Festplatte. Standardm\u00e4\u00dfig wird weiterhin das PEM-Format verwendet, w\u00e4hrend PKCS8 n\u00fctzlich f\u00fcr die Kompatibilit\u00e4t mit Drittanwendungen sein kann.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Quelle: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51640\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u0432 \u043d\u043e\u0432\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0437\u0430\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 ssh, sshd, ssh-add \u0438 ssh-keygen. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043a\u043e\u0434\u0435 \u043f\u0430\u0440\u0441\u0438\u043d\u0433\u0430 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0441 \u0442\u0438\u043f\u043e\u043c XMSS \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0446\u0435\u043b\u043e\u0447\u0438\u0441\u043b\u0435\u043d\u043d\u043e\u0435 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043e\u0442\u043c\u0435\u0447\u0435\u043d\u0430 \u043a\u0430\u043a \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38754","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/de\/blog\/news\/reliz-openssh-8-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"de_DE\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/de\/blog\/news\/reliz-openssh-8-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:25:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:25:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Ver\u00f6ffentlichung von OpenSSH 8.1 | ProHoster","description":"Nach sechsmonatiger Entwicklung wird die Ver\u00f6ffentlichung pr\u00e4sentiert","canonical_url":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-openssh-8-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"de_DE","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.1 | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437","og:url":"https:\/\/prohoster.info\/de\/blog\/news\/reliz-openssh-8-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:25:45+00:00","article:modified_time":"2019-10-31T19:25:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38754","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 23:17:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:04:29","updated":"2026-01-23 23:17:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/comments?post=38754"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/posts\/38754\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/media?parent=38754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/categories?post=38754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/de\/wp-json\/wp\/v2\/tags?post=38754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}