{"id":38754,"date":"2019-10-31T22:25:45","date_gmt":"2019-10-31T19:25:45","guid":{"rendered":"https:\/\/prohoster.info\/blog\/reliz-openssh-8-1\/"},"modified":"2019-10-31T22:25:45","modified_gmt":"2019-10-31T19:25:45","slug":"reliz-openssh-8-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/fr\/blog\/news\/reliz-openssh-8-1","title":{"rendered":"Publication d'OpenSSH 8.1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Apr\u00e8s six mois de d\u00e9veloppement <noindex><a rel=\"nofollow\" href=\"http:\/\/lists.mindrot.org\/pipermail\/openssh-unix-dev\/2019-October\/037966.html\">pr\u00e9sent\u00e9<\/a><\/noindex> la sortie <noindex><a rel=\"nofollow\" href=\"http:\/\/www.openssh.com\/\">OpenSSH 8.1<\/a><\/noindex>, une mise en \u0153uvre ouverte du client et du serveur pour travailler avec les protocoles SSH 2.0 et SFTP. <\/p>\n<p>Une attention particuli\u00e8re dans cette nouvelle version est accord\u00e9e \u00e0 la correction d'une vuln\u00e9rabilit\u00e9 touchant ssh, sshd, ssh-add et ssh-keygen. Le probl\u00e8me r\u00e9side dans le code de parsing des cl\u00e9s priv\u00e9es de type XMSS et permet \u00e0 un attaquant d'initier un d\u00e9passement d'entier. La vuln\u00e9rabilit\u00e9 est consid\u00e9r\u00e9e comme exploitable, mais peu applicable, car le support des cl\u00e9s XMSS rel\u00e8ve de fonctionnalit\u00e9s exp\u00e9rimentales d\u00e9sactiv\u00e9es par d\u00e9faut (dans la version portable, autoconf ne pr\u00e9voit m\u00eame pas d'option de compilation pour activer XMSS).<\/p>\n<p>Principales modifications : <\/p>\n<ul>\n<li class=\"l\"> Dans ssh, sshd et ssh-agent <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=50929\">ajout\u00e9<\/a><\/noindex> un code qui emp\u00eache la r\u00e9cup\u00e9ration de la cl\u00e9 priv\u00e9e alors qu'elle est en m\u00e9moire, \u00e0 la suite d'attaques par canaux lat\u00e9raux tels que <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=47856\">Spectre, Meltdown<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=41340\">RowHammer<\/a><\/noindex> et <noindex><a rel=\"nofollow\" href=\"https:\/\/rambleed.com\/\">RAMBleed<\/a><\/noindex>. Les cl\u00e9s priv\u00e9es sont d\u00e9sormais chiffr\u00e9es lors de leur chargement en m\u00e9moire et ne sont d\u00e9chiffr\u00e9es qu'au moment de leur utilisation, restant chiffr\u00e9es le reste du temps. Avec une telle approche, pour qu'un attaquant r\u00e9ussisse \u00e0 r\u00e9cup\u00e9rer la cl\u00e9 priv\u00e9e, il doit d'abord reconstruire une cl\u00e9 interm\u00e9diaire g\u00e9n\u00e9r\u00e9e al\u00e9atoirement de 16 Ko, utilis\u00e9e pour chiffrer la cl\u00e9 principale, ce qui est peu probable compte tenu du taux d'erreur de r\u00e9cup\u00e9ration observ\u00e9 dans les attaques modernes.\n<li class=\"l\"> Dans  <noindex><a rel=\"nofollow\" href=\"https:\/\/man.openbsd.org\/ssh-keygen.1\">ssh-keygen<\/a><\/noindex>  ajoute un support exp\u00e9rimental pour un sch\u00e9ma simplifi\u00e9 de cr\u00e9ation et de v\u00e9rification des signatures num\u00e9riques. Les signatures num\u00e9riques peuvent \u00eatre cr\u00e9\u00e9es \u00e0 l'aide de cl\u00e9s SSH ordinaires stock\u00e9es sur disque ou dans ssh-agent, et v\u00e9rifi\u00e9es \u00e0 l'aide d'une liste similaire \u00e0 authorized_keys <noindex><a rel=\"nofollow\" href=\"https:\/\/man.openbsd.org\/ssh-keygen.1#ALLOWED_SIGNERS\">de cl\u00e9s autoris\u00e9es<\/a><\/noindex>. La signature num\u00e9rique incorpore des informations sur l'espace de noms pour \u00e9viter toute confusion lors de son utilisation dans diff\u00e9rents domaines (par exemple, pour les e-mails et les fichiers);\n<li class=\"l\"> ssh-keygen est maintenant par d\u00e9faut configur\u00e9 pour utiliser l'algorithme rsa-sha2-512 lors de la signature de certificats avec une cl\u00e9 RSA (en mode CA). De tels certificats ne sont pas compatibles avec les versions ant\u00e9rieures \u00e0 OpenSSH 7.2 (pour assurer la compatibilit\u00e9, il convient de red\u00e9finir le type d'algorithme, par exemple en appelant \u00ab ssh-keygen -t ssh-rsa -s ... \u00bb);\n<li class=\"l\"> Dans ssh, l'expression ProxyCommand prend en charge l'expansion du substitut \u00ab %n \u00bb (le nom d'h\u00f4te sp\u00e9cifi\u00e9 dans la barre d'adresse);\n<li class=\"l\"> Dans les listes d'algorithmes de chiffrement pour ssh et sshd, il est d\u00e9sormais possible d'utiliser le symbole \u00ab ^ \u00bb pour ins\u00e9rer des algorithmes par d\u00e9faut sugg\u00e9r\u00e9s. Par exemple, pour ajouter ssh-ed25519 \u00e0 la liste par d\u00e9faut, vous pouvez sp\u00e9cifier \u00ab HostKeyAlgorithms ^ssh-ed25519 \u00bb;\n<li class=\"l\"> Dans ssh-keygen, l'affichage du commentaire associ\u00e9 \u00e0 la cl\u00e9 est d\u00e9sormais pr\u00e9vu lors de l'extraction de la cl\u00e9 publique \u00e0 partir de la cl\u00e9 priv\u00e9e ;\n<li class=\"l\"> ssh-keygen a ajout\u00e9 la possibilit\u00e9 d'utiliser le drapeau \u00ab -v \u00bb lors des op\u00e9rations de recherche de cl\u00e9s (par exemple, \u00ab ssh-keygen -vF host \u00bb), dont l'inclusion entra\u00eene l'affichage d'une signature visuelle de l'h\u00f4te;\n<li class=\"l\"> Ajout de la possibilit\u00e9 d'utiliser <noindex><a rel=\"nofollow\" href=\"https:\/\/en.wikipedia.org\/wiki\/PKCS_8\">PKCS8<\/a><\/noindex> comme format alternatif pour le stockage des cl\u00e9s priv\u00e9es sur disque. Par d\u00e9faut, le format PEM continue d'\u00eatre utilis\u00e9, mais PKCS8 peut s'av\u00e9rer utile pour assurer la compatibilit\u00e9 avec des applications tierces.\n<\/ul>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source : <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=51640\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 8.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0442\u0434\u0435\u043b\u044c\u043d\u043e\u0433\u043e \u0432\u043d\u0438\u043c\u0430\u043d\u0438\u044f \u0432 \u043d\u043e\u0432\u043e\u043c \u0432\u044b\u043f\u0443\u0441\u043a\u0435 \u0437\u0430\u0441\u043b\u0443\u0436\u0438\u0432\u0430\u0435\u0442 \u0443\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0438\u0435 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438, \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u044e\u0449\u0435\u0439 ssh, sshd, ssh-add \u0438 ssh-keygen. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u043f\u0440\u0438\u0441\u0443\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0432 \u043a\u043e\u0434\u0435 \u043f\u0430\u0440\u0441\u0438\u043d\u0433\u0430 \u0437\u0430\u043a\u0440\u044b\u0442\u044b\u0445 \u043a\u043b\u044e\u0447\u0435\u0439 \u0441 \u0442\u0438\u043f\u043e\u043c XMSS \u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u0438\u043d\u0438\u0446\u0438\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u0446\u0435\u043b\u043e\u0447\u0438\u0441\u043b\u0435\u043d\u043d\u043e\u0435 \u043f\u0435\u0440\u0435\u043f\u043e\u043b\u043d\u0435\u043d\u0438\u0435. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043e\u0442\u043c\u0435\u0447\u0435\u043d\u0430 \u043a\u0430\u043a \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0438\u0440\u0443\u0435\u043c\u0430\u044f, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-38754","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/fr\/blog\/news\/reliz-openssh-8-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"fr_FR\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/fr\/blog\/news\/reliz-openssh-8-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:25:45+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:25:45+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Version OpenSSH 8.1 | ProHoster","description":"Apr\u00e8s six mois de d\u00e9veloppement, la version est pr\u00e9sent\u00e9e","canonical_url":"https:\/\/prohoster.info\/fr\/blog\/news\/reliz-openssh-8-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"fr_FR","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 8.1 | ProHoster","og:description":"\u041f\u043e\u0441\u043b\u0435 \u0448\u0435\u0441\u0442\u0438 \u043c\u0435\u0441\u044f\u0446\u0435\u0432 \u0440\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u043a\u0438 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u0435\u043d \u0440\u0435\u043b\u0438\u0437","og:url":"https:\/\/prohoster.info\/fr\/blog\/news\/reliz-openssh-8-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:25:45+00:00","article:modified_time":"2019-10-31T19:25:45+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"38754","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 23:17:20","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 01:04:29","updated":"2026-01-23 23:17:20","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38754","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/comments?post=38754"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/posts\/38754\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/media?parent=38754"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/categories?post=38754"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/fr\/wp-json\/wp\/v2\/tags?post=38754"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}