GitHub introduces new requirements for remote connections to Git

GitHub has announced changes to its service aimed at enhancing the security of the Git protocol used during git push and git pull operations via SSH or the "git://" scheme (access via https:// is unaffected). After the changes take effect, a minimum of OpenSSH version 7.2 (released in 2016) or PuTTY version 0.75 (released this May) will be required to connect to GitHub via SSH. For example, compatibility with the SSH client included in CentOS 6 and Ubuntu 14.04 will be broken, as support for these has already ended.

The changes involve discontinuing support for unencrypted connections to Git (via "git://") and strengthening requirements for SSH keys used to access GitHub. GitHub will stop supporting all DSA keys and deprecated SSH algorithms such as CBC ciphers (aes256-cbc, aes192-cbc, aes128-cbc) and HMAC-SHA-1. Additionally, new requirements for RSA keys are being introduced (the use of SHA-1 will be prohibited) and support for ECDSA and Ed25519 host keys will be implemented.

The changes will be implemented gradually. On September 14, new ECDSA and Ed25519 host keys will be generated. On November 2, support for new RSA keys based on SHA-1 will be discontinued (previously generated keys will continue to work). On November 16, support for host keys based on the DSA algorithm will end. On January 11, 2022, support for old SSH algorithms and the ability to connect unencrypted will be temporarily suspended as an experiment. On March 15, support for old algorithms will be permanently disabled.

Additionally, it is worth noting that a change has been introduced to the OpenSSH codebase that by default disables the processing of RSA keys based on the SHA-1 hash ("ssh-rsa"). Support for RSA keys with SHA-256 and SHA-512 hashes (rsa-sha2-256/512) remains unchanged. The discontinuation of support for "ssh-rsa" keys is due to the effectiveness of collision attacks with a specified prefix (the cost of finding a collision is estimated at around $50,000). To check the application of ssh-rsa in your systems, you can try connecting via ssh with the option "-oHostKeyAlgorithms=-ssh-rsa".

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster