{"id":144216,"date":"2025-10-06T17:11:54","date_gmt":"2025-10-06T15:11:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-openssh-10-1"},"modified":"2025-10-06T17:11:54","modified_gmt":"2025-10-06T15:11:54","slug":"reliz-openssh-10-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-openssh-10-1","title":{"rendered":"Lanzamiento de OpenSSH 10.1.","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Se ha publicado la versi\u00f3n OpenSSH 10.1, una implementaci\u00f3n abierta de cliente y servidor para trabajar con los protocolos SSH 2.0 y SFTP.       <\/p>\n<p>Principales cambios:      <\/p>\n<ul>\n<li class=\"l\"> Se ha solucionado un problema de seguridad que permite a un atacante inyectar comandos shell a trav\u00e9s de manipulaciones con caracteres especiales en el nombre de usuario o URI, que podr\u00edan ejecutarse al ejecutar el comando especificado en la configuraci\u00f3n &#171;ProxyCommand&#187; y que contiene una sustituci\u00f3n &#171;%u&#187;. El problema solo afecta a sistemas que permiten la sustituci\u00f3n de nombres de usuario o URIs provenientes de fuentes no confiables al iniciar ssh.\n<p>Para bloquear ataques similares, se proh\u00edbe el uso de caracteres de control en los nombres de usuario proporcionados al iniciar desde la l\u00ednea de comandos o sustituidos en la configuraci\u00f3n a trav\u00e9s de secuencias %-de. Tambi\u00e9n se proh\u00edbe el uso del car\u00e1cter nulo (&#171;&#092;0&#187;) en ssh:\/\/ URIs. Se hace una excepci\u00f3n solo para los nombres definidos en el archivo de configuraci\u00f3n (se asume que estos datos son de confianza).    <\/p>\n<li class=\"l\"> Se ha agregado soporte para claves ed25519 almacenadas en tokens PKCS#11 en las utilidades ssh y ssh-agent.\n<li class=\"l\"> Se ha a\u00f1adido la configuraci\u00f3n RefuseConnection al archivo de configuraci\u00f3n ssh_config, que finaliza el proceso con un mensaje de error sin intentar establecer una conexi\u00f3n en la secci\u00f3n activa.        Match host foo       RefuseConnection &#171;el host foo ya no est\u00e1 en uso, con\u00e9ctese al host bar&#187;\n<li class=\"l\"> Se han agregado manejadores de se\u00f1al SIGINFO a ssh y sshd para registrar informaci\u00f3n sobre la sesi\u00f3n y el canal activo.\n<li class=\"l\"> En sshd, si se rechaza la autenticaci\u00f3n del usuario mediante un certificado, se asegura que se registre en el log no solo la raz\u00f3n del bloqueo del acceso, sino tambi\u00e9n informaci\u00f3n exhaustiva para identificar el certificado problem\u00e1tico.\n<li class=\"l\"> Se ha a\u00f1adido una verificaci\u00f3n del n\u00famero de pantalla X11, en relaci\u00f3n con el desplazamiento especificado en la directiva X11DisplayOffset en sshd.\n<li class=\"l\"> Se han a\u00f1adido capacidades de medici\u00f3n de rendimiento a la suite de pruebas unitarias, que se activan al ejecutar &#171;make UNITTEST_BENCHMARK=yes&#187; en OpenBSD o &#171;make unit-bench&#187; en otros sistemas.  <\/ul>\n<p>Cambios que pueden romper la compatibilidad hacia atr\u00e1s:  <\/p>\n<ul>\n<li class=\"l\"> Se ha a\u00f1adido una advertencia en ssh al utilizar un algoritmo de negociaci\u00f3n de claves que no es resistente a la recuperaci\u00f3n en una computadora cu\u00e1ntica. La advertencia se incluye debido al riesgo de ataques futuros utilizando vol\u00famenes de tr\u00e1fico previamente guardados. Para desactivar la advertencia, se ha agregado la opci\u00f3n WarnWeakCrypto en ssh_config.          Match host unsafe.example.com         WarnWeakCrypto no\n<li class=\"l\"> Se ha modificado significativamente el tratamiento de los par\u00e1metros de calidad del servicio DSCP (IPQoS) en ssh y sshd. Ahora, la clase EF (Expedited Forwarding) se establece de forma predeterminada para el tr\u00e1fico interactivo, priorizando su procesamiento en redes inal\u00e1mbricas. Para el tr\u00e1fico no interactivo, se utiliza la clase predeterminada de la sistema operativo. La clase de tr\u00e1fico se puede modificar mediante la configuraci\u00f3n de IPQoS en ssh_config y sshd_config. Los par\u00e1metros ToS (tipo de servicio) para IPv4 en la directiva IPQoS se han declarado obsoletos (DSCP ha reemplazado a ToS).\n<li class=\"l\"> En ssh-add, al agregar un certificado al ssh-agent, se ha implementado el establecimiento del tiempo de vida del certificado en un valor que es 5 minutos mayor que el plazo de validez del certificado (para la eliminaci\u00f3n autom\u00e1tica del certificado caducado). Se ha a\u00f1adido la opci\u00f3n &#171;-N&#187; en ssh-add para desactivar este comportamiento.\n<li class=\"l\"> Se ha eliminado el soporte para claves XMSS, que se hab\u00eda marcado como experimental y nunca se hab\u00eda incluido de forma predeterminada.\n<li class=\"l\"> Los sockets Unix, creados por los procesos ssh-agent y sshd, se han trasladado del directorio \/tmp a ~\/ .ssh\/agent, lo que garantiza que no se pueda acceder a esos sockets desde procesos aislados, que tienen acceso limitado al sistema de archivos, pero tienen acceso a \/tmp.            <\/ul>\n<p>En futuras versiones, se declarar\u00e1n obsoletas las entradas DNS SHA1 SSHFP debido a problemas con la fiabilidad de la funci\u00f3n hash SHA1. Estas entradas ser\u00e1n ignoradas y el comando &#171;ssh-keygen -r&#187; generar\u00e1 \u00fanicamente entradas SHA256 SSHFP.<br \/>\n<br \/>Fuente: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64007\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f: \u0423\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c shell-\u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441\u043e \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u0430\u043c\u0438 \u0432 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u043b\u0438 URI, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u043b\u0438 \u0431\u044b\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u044b \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b, \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u0439 \u0447\u0435\u0440\u0435\u0437 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 &#171;ProxyCommand&#187; \u0438 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 &#171;%u&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u044b, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-144216","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/es\/blog\/news\/reliz-openssh-10-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"es_ES\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/es\/blog\/news\/reliz-openssh-10-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Lanzamiento de OpenSSH 10.1 | ProHoster","description":"Se ha publicado la versi\u00f3n OpenSSH 10.1, una implementaci\u00f3n abierta de cliente y servidor para trabajar con los protocolos SSH 2.0 y SFTP.","canonical_url":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-openssh-10-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"es_ES","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/es\/blog\/news\/reliz-openssh-10-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-06T15:11:54+00:00","article:modified_time":"2025-10-06T15:11:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"144216","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 15:10:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:10:23","updated":"2026-01-23 15:10:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/144216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/comments?post=144216"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/posts\/144216\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/media?parent=144216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/categories?post=144216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/es\/wp-json\/wp\/v2\/tags?post=144216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}