{"id":144216,"date":"2025-10-06T17:11:54","date_gmt":"2025-10-06T15:11:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-openssh-10-1"},"modified":"2025-10-06T17:11:54","modified_gmt":"2025-10-06T15:11:54","slug":"reliz-openssh-10-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-1","title":{"rendered":"Rilascio di OpenSSH 10.1","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>\u00c8 stato rilasciato OpenSSH 10.1, un'implementazione open source del client e del server per il funzionamento con i protocolli SSH 2.0 e SFTP.       <\/p>\n<p>Variazioni principali:      <\/p>\n<ul>\n<li class=\"l\"> Risolta una vulnerabilit\u00e0 di sicurezza che consentiva a un attaccante di iniettare comandi shell tramite manipolazioni con caratteri speciali nel nome utente o nell'URI, che potevano essere eseguiti al momento dell'esecuzione del comando specificato tramite l'impostazione &#171;ProxyCommand&#187; e contenente la sostituzione &#171;%u&#187;. Il problema riguarda solo i sistemi che consentono, al momento dell'avvio di ssh, la sostituzione dei nomi utente o URI provenienti da fonti non fidate.\n<p>Per bloccare tali attacchi, \u00e8 vietato l'uso di caratteri di controllo nei nomi utente specificati al momento dell'avvio nella riga di comando o sostituiti nelle impostazioni tramite sequenze di tipo %. \u00c8 inoltre vietato l'uso del carattere nullo (&#171;&#092;0&#187;) nell'URI ssh:\/\/. L'eccezione \u00e8 fatta solo per i nomi specificati nel file di configurazione (si presume che i dati in questo file di configurazione siano affidabili).    <\/p>\n<li class=\"l\"> Nelle utility ssh e ssh-agent \u00e8 stata aggiunta la supporto per le chiavi ed25519 memorizzate in token PKCS#11.\n<li class=\"l\"> Nel file di configurazione ssh_config \u00e8 stata aggiunta l'impostazione RefuseConnection, che interrompe l'elaborazione nella sezione attiva terminando il processo con la visualizzazione di un messaggio di errore senza tentare di stabilire una connessione.        Match host foo       RefuseConnection &#171;il host foo non \u00e8 pi\u00f9 in uso, connettiti all'host bar&#187;\n<li class=\"l\"> In ssh e sshd sono stati aggiunti gestori del segnale SIGINFO per registrare informazioni sulla sessione e sul canale attivo.\n<li class=\"l\"> In sshd, in caso di mancata autenticazione dell'utente tramite certificato, vengono registrati non solo i motivi del rifiuto, ma anche informazioni dettagliate per identificare il certificato problematico.\n<li class=\"l\"> In sshd \u00e8 stato aggiunto un controllo del numero di visualizzazione X11 rispetto all'offset specificato nella direttiva X11DisplayOffset.\n<li class=\"l\"> Nel set di unit test sono state aggiunte funzionalit\u00e0 per la misurazione delle prestazioni, attivabili avviando &#171;make UNITTEST_BENCHMARK=yes&#187; in OpenBSD o &#171;make unit-bench&#187; negli altri sistemi.  <\/ul>\n<p>Modifiche che potrebbero interrompere la retrocompatibilit\u00e0:  <\/p>\n<ul>\n<li class=\"l\"> In ssh, a warning has been added when using a key agreement algorithm that is not resistant to brute-force attacks on quantum computers during the connection setup. The warning has been added due to the risk of future attacks using previously saved traffic dumps. To disable the warning, the WarnWeakCrypto option has been added to ssh_config. Match host unsafe.example.com WarnWeakCrypto no\n<li class=\"l\"> In ssh and sshd, the handling of DSCP (IPQoS) quality of service parameters has been significantly changed. For interactive traffic, the EF (Expedited Forwarding) class is now set by default for more prioritized processing in wireless networks. For non-interactive traffic, the class is set to the default used by the operating system. The traffic class can be changed using the IPQoS setting in ssh_config and sshd_config. ToS (type-of-service) parameters for IPv4 in the IPQoS directive have been deprecated (DSCP has replaced ToS).\n<li class=\"l\"> In ssh-add, durante l'aggiunta di un certificato a ssh-agent, \u00e8 stata implementata la possibilit\u00e0 di impostare il tempo di vita del certificato a un valore superiore di 5 minuti rispetto alla scadenza del certificato (per la rimozione automatica dei certificati scaduti). Per disabilitare questo comportamento, in ssh-add \u00e8 stata aggiunta l'opzione &#171;-N&#187;.\n<li class=\"l\"> Support for XMSS keys has been removed, which was marked as experimental and was never enabled by default.\n<li class=\"l\"> Unix sockets created by the ssh-agent and sshd processes have been moved from the \/tmp directory to ~\/.ssh\/agent, which ensures that these sockets cannot be accessed by isolated processes that have restricted access to the filesystem but have access to \/tmp.            <\/ul>\n<p>Nei futuri rilasci, le registrazioni DNS SHA1 SSHFP saranno dichiarate obsolete a causa di problemi di affidabilit\u00e0 della funzione hash SHA1. Queste registrazioni saranno ignorate e il comando &#171;ssh-keygen -r&#187; generer\u00e0 solo registrazioni SHA256 SSHFP.<br \/>\n<br \/>Fonte: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64007\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f: \u0423\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c shell-\u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441\u043e \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u0430\u043c\u0438 \u0432 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u043b\u0438 URI, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u043b\u0438 \u0431\u044b\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u044b \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b, \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u0439 \u0447\u0435\u0440\u0435\u0437 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 &#171;ProxyCommand&#187; \u0438 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 &#171;%u&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u044b, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-144216","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-1\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47 OpenSSH 10.1 Release | ProHoster","description":"\u00c8 stato rilasciato OpenSSH 10.1, un'implementazione open source del client e del server per il funzionamento con i protocolli SSH 2.0 e SFTP.","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/reliz-openssh-10-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-06T15:11:54+00:00","article:modified_time":"2025-10-06T15:11:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"144216","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 15:10:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:10:23","updated":"2026-01-23 15:10:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/144216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=144216"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/144216\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=144216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=144216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=144216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}