OpenSSH 10.5 Release

The OpenSSH 10.5 release has been published, the open implementation of a client and server for working with SSH 2.0 and SFTP protocols. Main changes:

  • The portable version of OpenSSH now requires support for elliptic curve cryptography (ECC) in the libcrypto library, including support for the NISTP521 elliptic curve. Such support is included by default in the libcrypto implementations from the LibreSSL, OpenSSL, BoringSSL, and AWS LC projects.
  • In the ssh-keygen utility, when resetting passwords for private keys for FIDO tokens, the touch-required and verify-required flags have been implemented, which require user confirmation.
  • The order of certificate application during public key authentication in the ssh utility has been changed — FIDO keys that do not require user interaction are now applied first, while keys requesting verification via PIN or biometrics are applied last.
  • The command 'ssh -Z user' has been added, which outputs keys in the order they are used for public key authentication.
  • Security issues have been addressed:
    • Fixed improper handling of session binding requests when blocking the SSH Agent, which allowed the SSH Agent to perform operations that should be accessible only locally, such as adding PKCS#11 tokens and using keys bound in settings to specific servers instead of denying access.
    • In the ssh client, a potential use-after-free memory access issue has been resolved, which occurred during SSH connection multiplexing over a single socket when adding a new port forwarding while the client was still waiting for a response to opening the previous forwarding. server The sshd now correctly applies restrictions set through the 'restrict' flag in the authorized_keys file for forwarded tunnels.
    • Linux Mint has released the HWE build with Linux kernel 7.0

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster