GitHub nthuav qhia cov cai tshiab rau kev txuas mus rau Git remotely

GitHub tshaj tawm cov kev hloov pauv rau cov kev pabcuam cuam tshuam txog kev ntxiv dag zog rau kev ruaj ntseg ntawm Git raws tu qauv siv thaum lub sijhawm git thawb thiab git rub cov haujlwm ntawm SSH lossis "git: //" scheme (thov ntawm https:// yuav tsis cuam tshuam los ntawm kev hloov). Thaum cov kev hloov pauv tau siv, txuas rau GitHub ntawm SSH yuav xav tau tsawg kawg yog OpenSSH version 7.2 (tso tawm hauv 2016) lossis PuTTY version 0.75 (tso tawm thaum lub Tsib Hlis xyoo no). Piv txwv li, kev sib raug zoo nrog SSH tus neeg siv khoom suav nrog CentOS 6 thiab Ubuntu 14.04, uas tsis muaj kev txhawb nqa lawm, yuav tawg.

Cov kev hloov pauv suav nrog kev tshem tawm kev txhawb nqa rau kev hu tsis tau nkag mus rau Git (ntawm "git: //") thiab cov kev xav tau ntxiv rau SSH cov yuam sij siv thaum nkag mus rau GitHub. GitHub yuav tsum tsis txhob txhawb txhua tus yuam sij DSA thiab cov txheej txheem SSH qub xws li CBC ciphers (aes256-cbc, aes192-cbc aes128-cbc) thiab HMAC-SHA-1. Tsis tas li ntawd, cov kev xav tau ntxiv tau raug qhia rau cov yuam sij RSA tshiab (kev siv SHA-1 yuav raug txwv) thiab kev txhawb nqa rau ECDSA thiab Ed25519 tus tswv cov yuam sij raug coj los siv.

Cov kev hloov pauv yuav pib maj mam. Thaum lub Cuaj Hlis 14, ECDSA tshiab thiab Ed25519 tus tswv lag luam yuav raug tsim tawm. Thaum Lub Kaum Ib Hlis 2, kev txhawb nqa rau SHA-1-raws li RSA cov yuam sij tshiab yuav raug txiav tawm (yav dhau los cov yuam sij tsim tawm yuav ua haujlwm ntxiv). Thaum Lub Kaum Ib Hlis 16, kev txhawb nqa rau tus tswv yuam sij raws li DSA algorithm yuav raug txiav tawm. Thaum Lub Ib Hlis 11, 2022, kev txhawb nqa rau cov laus SSH algorithms thiab kev muaj peev xwm nkag mus yam tsis muaj encryption yuav raug txiav ib ntus raws li kev sim. Thaum Lub Peb Hlis 15, kev txhawb nqa rau cov txheej txheem qub yuav raug kaw tag nrho.

Tsis tas li ntawd, peb tuaj yeem nco ntsoov tias qhov kev hloov pauv tau ua rau OpenSSH codebase uas cuam tshuam kev ua haujlwm ntawm RSA yuam sij raws li SHA-1 hash ("ssh-rsa"). Kev them nyiaj yug rau RSA yuam sij nrog SHA-256 thiab SHA-512 hashes (rsa-sha2-256/512) tseem tsis hloov. Qhov kev txiav tawm ntawm kev txhawb nqa rau "ssh-rsa" cov yuam sij yog vim qhov ua tau zoo ntawm kev sib tsoo tawm tsam nrog cov lus qhia ua ntej (tus nqi ntawm kev xaiv kev sib tsoo yog kwv yees li ntawm 50 txhiab daus las). Txhawm rau kuaj kev siv ssh-rsa ntawm koj lub tshuab, koj tuaj yeem sim txuas ntawm ssh nrog "-oHostKeyAlgorithms =-ssh-rsa" kev xaiv.

Tau qhov twg los: opennet.ru

Ntxiv ib saib