{"id":123456,"date":"2025-04-10T03:05:07","date_gmt":"2025-04-10T01:05:07","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-openssh-10-0"},"modified":"2025-04-10T03:05:07","modified_gmt":"2025-04-10T01:05:07","slug":"reliz-openssh-10-0","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-0","title":{"rendered":"Rilascio di OpenSSH 10.0","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stata pubblicata la versione OpenSSH 10.0, un'implementazione open-source di client e server per lavorare con i protocolli SSH 2.0 e SFTP. Le principali modifiche includono:      <\/p>\n<ul>\n<li class=\"l\"> \u00c8 stata rimossa la supporto per le firme digitali basate sull'algoritmo DSA, il cui livello di sicurezza non \u00e8 conforme agli attuali standard. I costi per continuare a supportare un algoritmo DSA insicuro non giustificano la spesa e la sua rimozione incoragger\u00e0 la cessazione del supporto per DSA in altre implementazioni SSH e librerie crittografiche. Per impostazione predefinita, l'uso delle chiavi DSA \u00e8 cessato gi\u00e0 nel 2015.\n<li class=\"l\"> \u00c8 proseguita la separazione di sshd in diversi file eseguibili. In OpenSSH 9.8, \u00e8 stato separato il processo sshd-session, che svolge compiti legati alla gestione delle sessioni. In OpenSSH 10.0, il codice che esegue l'autenticazione \u00e8 stato trasferito dal processo sshd-session a un processo separato chiamato sshd-auth. Il processo sshd-auth consente di isolare ulteriormente i dati legati all'autenticazione nello spazio di indirizzamento di un processo separato, impedendo cos\u00ec l'accesso a tali dati in memoria in caso di attacchi al codice utilizzato per gestire le fasi di connessione fino al completamento dell'autenticazione. Inoltre, questa modifica ridurr\u00e0 leggermente il consumo di memoria, poich\u00e9 il codice legato all'autenticazione \u00e8 ora presente in memoria solo durante l'autenticazione e viene scaricato al termine del processo sshd-auth.\n<li class=\"l\"> In ssh, a hybrid key exchange algorithm \"mlkem768x25519-sha256\", resilient to attacks by quantum computers, is used. It combines X25519 ECDH and the ML-KEM algorithm (CRYSTALS-Kyber), which has been standardized by the National Institute of Standards and Technology (NIST). ML-KEM employs cryptographic methods based on lattice theory problems, the solving times of which are similar on both classical and quantum computers.\n<li class=\"l\"> The ssh_config directives SetEnv and User now support substitution \"%-token\" and environment variable expansion.\n<li class=\"l\"> Support for the expression \"Match version\" has been added to ssh_config and sshd_config, allowing settings to be applied based on the existing OpenSSH version; for example, to bind to OpenSSH 10, one can specify \"Match version OpenSSH_10.*\".\n<li class=\"l\"> In ssh_config \u00e8 stata aggiunta la supporto per le espressioni:\n<ul>\n<li class=\"l\"> \"Match sessiontype\" allows settings to be applied based on the type of requested session: \"shell\" for interactive sessions, \"exec\" for command execution, \"subsystem\" for sftp, and \"none\" for tunnels and traffic redirection.\n<li class=\"l\"> \"Match command\" is used to bind actions to commands specified in the command line for execution via ssh.\n<li class=\"l\"> 'Match tagged \"\"' and 'Match command \"\"' are for binding to empty tags and executing ssh without specifying a command.    <\/ul>\n<li class=\"l\"> In sshd_config \u00e8 consentito l'uso di maschere nei percorsi dei file specificati nelle direttive AuthorizedKeysFile e AuthorizedPrincipalsFile.\n<li class=\"l\"> Support for the option \"VersionAddendum\" has been added to the ssh client for appending arbitrary text to the version string (previously this option was only available for) <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/it\/server\/dts-los-angeles\/\"   title=\"server\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"3959\">server<\/a> sshd).\n<li class=\"l\"> In scp and sftp utilities, the setting \"ControlMaster no\" is transmitted to prohibit the use of existing connections when reconnecting to a host.\n<li class=\"l\"> Support for the implementation of the Diffie-Hellman algorithm in finite fields is disabled in sshd by default, leading to the removal of \"diffie-hellman-group*\" and \"diffie-hellman-group-exchange-*\" methods from the KEXAlgorithms list. Compared to the elliptic curve-based Diffie-Hellman algorithm, the remote implementation is slower and requires additional computational resources for the same security level.\n<li class=\"l\"> In ssh, quando si sceglie un cifrario per la connessione, il modo AES-GCM \u00e8 ora pi\u00f9 preferibile rispetto all'AES-CTR. Di default, \u00e8 impostata una lista di priorit\u00e0 nella scelta dei cifrari: Chacha20\/Poly1305, AES-GCM (128\/256) e AES-CTR (128\/192\/256).\n<li class=\"l\"> In ssh-agent \u00e8 stata implementata la rimozione di tutte le chiavi caricate al ricevimento del segnale SIGUSR1.\n<li class=\"l\"> In ssh-keygen \u00e8 stata aggiunta la supporto per token FIDO che non restituiscono dati di attestazione, come WinHello.\n<li class=\"l\"> An option \"-Owebsafe-allow=...\" has been added to ssh-agent to override the whitelist of FIDO applications.\n<li class=\"l\"> \u00c8 stata aggiunta un'utilit\u00e0 sperimentale regress\/misc\/ssh-verify-attestation per la verifica dei dati di attestazione FIDO, generati opzionalmente da ssh-keygen durante la registrazione delle chiavi FIDO.\n<li class=\"l\"> In ssh-keygen, using \"-\" instead of a filename is now allowed.\n<li class=\"l\"> In ssh-agent e nella versione portatile di OpenSSH \u00e8 stata aggiunta la supporto per l'attivazione tramite socket in stile systemd, implementata utilizzando il meccanismo LISTEN_PID\/LISTEN_FDS.\n<li class=\"l\"> Nella versione portatile:\n<ul>\n<li class=\"l\"> \u00c8 stata implementata la supporto per la libreria crittografica AWS-LC (AWS libcrypto).\n<li class=\"l\"> In sshd \u00e8 stata aggiunta la supporto per wtmpdb, un equivalente di wtmp, non soggetto al problema del 2038.\n<li class=\"l\"> In sshd, an option \"--with-linux-memlock-onfault\" has been added to pin sshd in memory (preventing swapping to disk).\n<li class=\"l\"> \u00c8 stata aggiunta l'opzione &#171;&#8212;with-security-key-standalone&#187; per la costruzione di una libreria autonoma sk-libfido2.\n<li class=\"l\"> Le impostazioni di compilazione per RHEL 6 sono state rimosse dalla specifica del pacchetto RPM.    <\/ul>\n<li class=\"l\"> Modifica in sshd relativa alla sicurezza: la direttiva DisableForwarding non vietava correttamente il forwarding del protocollo X11 e le richieste al ssh-agent. Il forwarding X11 \u00e8 disabilitato per impostazione predefinita sul lato server, mentre il forwarding del ssh-agent \u00e8 disabilitato sul lato client.  <\/ul>\n<p>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=63042\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.0, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f: \u0423\u0434\u0430\u043b\u0435\u043d\u0430 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0430 \u0446\u0438\u0444\u0440\u043e\u0432\u044b\u0445 \u043f\u043e\u0434\u043f\u0438\u0441\u0435\u0439 \u043d\u0430 \u0431\u0430\u0437\u0435 \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430 DSA, \u0443\u0440\u043e\u0432\u0435\u043d\u044c \u0437\u0430\u0449\u0438\u0442\u044b \u043a\u043e\u0442\u043e\u0440\u044b\u0445 \u043d\u0435 \u0441\u043e\u043e\u0442\u0432\u0435\u0442\u0441\u0442\u0432\u0443\u0435\u0442 \u0441\u043e\u0432\u0440\u0435\u043c\u0435\u043d\u043d\u044b\u043c \u0442\u0440\u0435\u0431\u043e\u0432\u0430\u043d\u0438\u044f\u043c. \u0417\u0430\u0442\u0440\u0430\u0442\u044b \u043d\u0430 \u043f\u0440\u043e\u0434\u043e\u043b\u0436\u0435\u043d\u0438\u0435 \u0441\u043e\u043f\u0440\u043e\u0432\u043e\u0436\u0434\u0435\u043d\u0438\u044f \u043d\u0435\u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0433\u043e \u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0430 DSA \u043d\u0435 \u043e\u043f\u0440\u0430\u0432\u0434\u044b\u0432\u0430\u044e\u0442 \u0441\u0435\u0431\u044f \u0438 \u0435\u0433\u043e \u0443\u0434\u0430\u043b\u0435\u043d\u0438\u0435 \u043f\u043e\u0437\u0432\u043e\u043b\u0438\u0442 \u0441\u0442\u0438\u043c\u0443\u043b\u0438\u0440\u043e\u0432\u0430\u0442\u044c \u043f\u0440\u0435\u043a\u0440\u0430\u0449\u0435\u043d\u0438\u0435 \u043f\u043e\u0434\u0434\u0435\u0440\u0436\u043a\u0438 DSA \u0432 \u0434\u0440\u0443\u0433\u0438\u0445 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-123456","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.0, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-0\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.0 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.0, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-0\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-04-10T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-04-10T01:05:07+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Rilascio OpenSSH 10.0 | ProHoster","description":"Rilasciata la versione OpenSSH 10.0, implementazione open-source del client e del server per il funzionamento sui protocolli SSH 2.0 e SFTP.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-0","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.0 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.0, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-0","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-04-10T01:05:07+00:00","article:modified_time":"2025-04-10T01:05:07+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"123456","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-22 15:50:24","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 12:07:19","updated":"2026-02-22 15:50:24","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/123456","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=123456"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/123456\/revisions"}],"predecessor-version":[{"id":162488,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/123456\/revisions\/162488"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=123456"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=123456"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=123456"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}