ืžื”ื“ื•ืจืช OpenSSH 8.0

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ OpenSSH 8.0, ืžื™ืžื•ืฉ ืœืงื•ื— ื•ืฉืจืช ืคืชื•ื— ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ืชืžื™ื›ื” ื ื™ืกื™ื•ื ื™ืช ื‘ืฉื™ื˜ืช ื”ื—ืœืคืช ืžืคืชื—ื•ืช ืขืžื™ื“ื” ื‘ืคื ื™ ื”ืชืงืคื•ืช ื‘ื›ื•ื— ื’ืก ืขืœ ืžื—ืฉื‘ ืงื•ื•ื ื˜ื™ ื ื•ืกืคื” ืœ-ssh ื•ืœ-sshd. ืžื—ืฉื‘ื™ื ืงื•ื•ื ื˜ื™ื™ื ืžื”ื™ืจื™ื ื‘ืื•ืคืŸ ืงื™ืฆื•ื ื™ ื‘ืคืชืจื•ืŸ ื”ื‘ืขื™ื” ืฉืœ ืคื™ืจื•ืง ืžืกืคืจ ื˜ื‘ืขื™ ืœื’ื•ืจืžื™ื ืจืืฉื•ื ื™ื™ื, ืืฉืจ ืขื•ืžื“ืช ื‘ื‘ืกื™ืก ืืœื’ื•ืจื™ืชืžื™ ื”ืฆืคื ื” ื-ืกื™ืžื˜ืจื™ื™ื ืžื•ื“ืจื ื™ื™ื ื•ืื™ื ื ื ื™ืชื ื™ื ืœืคืชืจื•ืŸ ื™ืขื™ืœ ื‘ืžืขื‘ื“ื™ื ืงืœืืกื™ื™ื. ื”ืฉื™ื˜ื” ื”ืžื•ืฆืขืช ืžื‘ื•ืกืกืช ืขืœ ื”ืืœื’ื•ืจื™ืชื NTRU Prime (ืคื•ื ืงืฆื™ื” ntrup4591761), ืฉืคื•ืชื—ื” ืขื‘ื•ืจ ืžืขืจื›ื•ืช ื”ืฆืคื ื” ืคื•ืกื˜-ืงื•ื•ื ื˜ื™ื•ืช, ื•ืฉื™ื˜ืช ื”ื—ืœืคืช ืžืคืชื— ืขืงื•ืžื” ืืœื™ืคื˜ื™ืช X25519;
  • ื‘-sshd, ื”ื ื—ื™ื•ืช ListenAddress ื•- PermitOpen ืื™ื ืŸ ืชื•ืžื›ื•ืช ืขื•ื“ ื‘ืชื—ื‘ื™ืจ "ืžืืจื—/ืคื•ืจื˜" ืžื“ื•ืจ ืงื•ื“ื, ืฉื™ื•ืฉื ื‘ืฉื ืช 2001 ื›ื—ืœื•ืคื” ืœ-"host:port" ื›ื“ื™ ืœืคืฉื˜ ืืช ื”ืขื‘ื•ื“ื” ืขื IPv6. ื‘ืชื ืื™ื ืžื•ื“ืจื ื™ื™ื, ื”ืชื—ื‘ื™ืจ "[::6]:1" ื”ื•ืงื ืขื‘ื•ืจ IPv22, ื•ืœืขืชื™ื ืงืจื•ื‘ื•ืช "ืžืืจื—/ื™ืฆื™ืื”" ืžื‘ื•ืœื‘ืœ ืขื ืฆื™ื•ืŸ ืจืฉืช ื”ืžืฉื ื” (CIDR);
  • ssh, ssh-agent ื•-ssh-add ืชื•ืžื›ื™ื ื›ืขืช ื‘ืžืคืชื—ื•ืช ECDSA ื‘ืืกื™ืžื•ื ื™ PKCS#11;
  • ื‘-ssh-keygen, ื’ื•ื“ืœ ืžืคืชื— RSA ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ื”ื•ื’ื“ืœ ืœ-3072 ืกื™ื‘ื™ื•ืช, ื‘ื”ืชืื ืœื”ืžืœืฆื•ืช ื”ื—ื“ืฉื•ืช ืฉืœ NIST;
  • ssh ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ื”ื’ื“ืจื” "PKCS11Provider=none" ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ื”ื ื—ื™ื” PKCS11Provider ืฉืฆื•ื™ื ื” ื‘-ssh_config;
  • sshd ืžืกืคืง ืชืฆื•ื’ืช ื™ื•ืžืŸ ืฉืœ ืžืฆื‘ื™ื ืฉื‘ื”ื ื”ื—ื™ื‘ื•ืจ ืžื•ืคืกืง ื‘ืขืช ื ื™ืกื™ื•ืŸ ืœื‘ืฆืข ืคืงื•ื“ื•ืช ื—ืกื•ืžื•ืช ืขืœ ื™ื“ื™ ื”ื”ื’ื‘ืœื” "ForceCommand=internal-sftp" ื‘-sshd_config;
  • ื‘-ssh, ื‘ืขืช ื”ืฆื’ืช ื‘ืงืฉื” ืœืืฉืจ ืงื‘ืœืช ืžืคืชื— ืžืืจื— ื—ื“ืฉ, ื‘ืžืงื•ื ืชื’ื•ื‘ืช "ื›ืŸ", ืžืชืงื‘ืœืช ื›ืขืช ื˜ื‘ื™ืขืช ื”ืืฆื‘ืข ื”ื ื›ื•ื ื” ืฉืœ ื”ืžืคืชื— (ื‘ืชื’ื•ื‘ื” ืœื”ื–ืžื ื” ืœืืฉืจ ืืช ื”ื—ื™ื‘ื•ืจ, ื”ืžืฉืชืžืฉ ื™ื›ื•ืœ ืœื”ืขืชื™ืง ืืช Hash ื”ืชื™ื™ื—ืกื•ืช ืฉื”ืชืงื‘ืœ ื‘ื ืคืจื“ ื“ืจืš ื”ืœื•ื—, ื›ื“ื™ ืœื ืœื”ืฉื•ื•ืช ืื•ืชื• ื‘ืื•ืคืŸ ื™ื“ื ื™);
  • ssh-keygen ืžืกืคืง ื”ื’ื“ืœื” ืื•ื˜ื•ืžื˜ื™ืช ืฉืœ ืžืกืคืจ ืจืฆืฃ ื”ืื™ืฉื•ืจ ื‘ืขืช ื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืขื‘ื•ืจ ืžืกืคืจ ืื™ืฉื•ืจื™ื ื‘ืฉื•ืจืช ื”ืคืงื•ื“ื”;
  • ืืคืฉืจื•ืช ื—ื“ืฉื” "-J" ื ื•ืกืคื” ืœ-scp ื•ืœ-sftp, ื”ืžืงื‘ื™ืœื” ืœื”ื’ื“ืจืช ProxyJump;
  • ื‘-ssh-agent, ssh-pkcs11-helper ื•-ssh-add, ื ื•ืกืฃ ืขื™ื‘ื•ื“ ืฉืœ ืืคืฉืจื•ืช ืฉื•ืจืช ื”ืคืงื•ื“ื” "-v" ื›ื“ื™ ืœื”ื’ื“ื™ืœ ืืช ืชื•ื›ืŸ ื”ืžื™ื“ืข ืฉืœ ื”ืคืœื˜ (ื›ืืฉืจ ืžืฆื•ื™ืŸ, ืืคืฉืจื•ืช ื–ื• ืžื•ืขื‘ืจืช ืœืชื”ืœื™ื›ื™ ืฆืืฆื, ืขื‘ื•ืจ ืœื“ื•ื’ืžื”, ื›ืืฉืจ ssh-pkcs11-helper ื ืงืจื ืž-ssh-agent );
  • ื”ืืคืฉืจื•ืช "-T" ื ื•ืกืคื” ืœ-ssh-add ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืชืืžืชื ืฉืœ ืžืคืชื—ื•ืช ื‘-ssh-agent ืœื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื™ืฆื™ืจื” ื•ืื™ืžื•ืช ืฉืœ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช;
  • sftp-server ืžื™ื™ืฉื ืชืžื™ื›ื” ื‘ืกื™ื•ืžืช ืคืจื•ื˜ื•ืงื•ืœ "lsetstat at openssh.com", ืฉืžื•ืกื™ืคื” ืชืžื™ื›ื” ื‘ืคืขื•ืœืช SSH2_FXP_SETSTAT ืขื‘ื•ืจ SFTP, ืืš ืœืœื ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "-h" ืœ-sftp ื›ื“ื™ ืœื”ืคืขื™ืœ ืคืงื•ื“ื•ืช chown/chgrp/chmod ืขื ื‘ืงืฉื•ืช ืฉืื™ื ืŸ ืžืฉืชืžืฉื•ืช ื‘ืงื™ืฉื•ืจื™ื ืกืžืœื™ื™ื;
  • sshd ืžืกืคืง ื”ื’ื“ืจื” ืฉืœ ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $SSH_CONNECTION ืขื‘ื•ืจ PAM;
  • ืขื‘ื•ืจ sshd, ืžืฆื‘ ื”ืชืืžื” "Match final" ื ื•ืกืฃ ืœ-ssh_config, ื”ื“ื•ืžื” ืœ-"Match canonical", ืืš ืื™ื ื• ื“ื•ืจืฉ ื ื•ืจืžืœื™ื–ืฆื™ื” ืฉืœ ืฉื ืžืืจื— ื›ื“ื™ ืœื”ื™ื•ืช ืคืขื™ืœ;
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืงื™ื“ื•ืžืช '@' ืœ-sftp ื›ื“ื™ ืœื‘ื˜ืœ ืืช ื”ืชืจื’ื•ื ืฉืœ ื”ืคืœื˜ ืฉืœ ืคืงื•ื“ื•ืช ื”ืžื‘ื•ืฆืขื•ืช ื‘ืžืฆื‘ ืืฆื•ื•ื”;
  • ื›ืืฉืจ ืืชื” ืžืฆื™ื’ ืืช ื”ืชื•ื›ืŸ ืฉืœ ืชืขื•ื“ื” ื‘ืืžืฆืขื•ืช ื”ืคืงื•ื“ื”
    "ssh-keygen -Lf /path/certificate" ืžืฆื™ื’ ื›ืขืช ืืช ื”ืืœื’ื•ืจื™ืชื ื”ืžืฉืžืฉ ืืช ื”-CA ืœืื™ืžื•ืช ื”ืื™ืฉื•ืจ;

  • ืชืžื™ื›ื” ืžืฉื•ืคืจืช ื‘ืกื‘ื™ื‘ืช Cygwin, ืœืžืฉืœ ืžืชืŸ ื”ืฉื•ื•ืื” ืœื ืชืœื•ื™ืช ืจื™ืฉื™ื•ืช ืฉืœ ืฉืžื•ืช ืงื‘ื•ืฆื•ืช ื•ืžืฉืชืžืฉื™ื. ืชื”ืœื™ืš sshd ื‘ื™ืฆื™ืืช Cygwin ืฉื•ื ื” ืœ-cygsshd ื›ื“ื™ ืœืžื ื•ืข ื”ืคืจืขื” ืœื™ืฆื™ืืช OpenSSH ืฉืกื•ืคืงื” ืขืœ ื™ื“ื™ ืžื™ืงืจื•ืกื•ืคื˜;
  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื‘ื ื•ืช ืขื ืขื ืฃ OpenSSL 3.x ื”ื ื™ืกื™ื•ื ื™;
  • ืžื—ื•ืกืœ ืคื’ื™ืขื•ืช (CVE-2019-6111) ื‘ื™ื™ืฉื•ื ืชื•ื›ื ื™ืช ื”ืฉื™ืจื•ืช scp, ื”ืžืืคืฉืจืช ืœื“ืจื•ืก ืงื‘ืฆื™ื ืฉืจื™ืจื•ืชื™ื™ื ื‘ืกืคืจื™ื™ืช ื”ื™ืขื“ ื‘ืฆื“ ื”ืœืงื•ื— ื‘ืขืช ื’ื™ืฉื” ืœืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ืชื•ืงืฃ. ื”ื‘ืขื™ื” ื”ื™ื ืฉื‘ืฉื™ืžื•ืฉ ื‘-SCP ื”ืฉืจืช ืžื—ืœื™ื˜ ืื™ืœื• ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืœืฉืœื•ื— ืœืœืงื•ื—, ื•ื”ืœืงื•ื— ืจืง ื‘ื•ื“ืง ืืช ื ื›ื•ื ื•ืช ืฉืžื•ืช ื”ืื•ื‘ื™ื™ืงื˜ื™ื ื”ืžื•ื—ื–ืจื™ื. ื‘ื“ื™ืงืช ืฆื“ ื”ืœืงื•ื— ืžื•ื’ื‘ืœืช ืจืง ืœื—ืกื™ืžืช ื ืกื™ืขื•ืช ืžืขื‘ืจ ืœืกืคืจื™ื™ื” ื”ื ื•ื›ื—ื™ืช ("../"), ืืš ืื™ื ื” ืœื•ืงื—ืช ื‘ื—ืฉื‘ื•ืŸ ื”ืขื‘ืจืช ืงื‘ืฆื™ื ืขื ืฉืžื•ืช ืฉื•ื ื™ื ืžืืœื” ืฉื”ืชื‘ืงืฉื• ื‘ืžืงื•ืจ. ื‘ืžืงืจื” ืฉืœ ื”ืขืชืงื” ืจืงื•ืจืกื™ื‘ื™ืช (-r), ื‘ื ื•ืกืฃ ืœืฉืžื•ืช ื”ืงื‘ืฆื™ื, ื ื™ืชืŸ ื’ื ืœื‘ืฆืข ืžื ื™ืคื•ืœืฆื™ื•ืช ื‘ืฉืžื•ืช ืฉืœ ืกืคืจื™ื•ืช ืžืฉื ื” ื‘ืฆื•ืจื” ื“ื•ืžื”. ืœื“ื•ื’ืžื”, ืื ื”ืžืฉืชืžืฉ ืžืขืชื™ืง ืงื‘ืฆื™ื ืœืกืคืจื™ื™ืช ื”ื‘ื™ืช, ื”ืฉืจืช ื”ื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ ื™ื›ื•ืœ ืœื™ื™ืฆืจ ืงื‘ืฆื™ื ืขื ื”ืฉืžื•ืช .bash_aliases ืื• .ssh/authorized_keys ื‘ืžืงื•ื ื”ืงื‘ืฆื™ื ื”ืžื‘ื•ืงืฉื™ื, ื•ื”ื ื™ื™ืฉืžืจื• ืขืœ ื™ื“ื™ ื›ืœื™ ื”ืฉื™ืจื•ืช scp ื‘ืงื•ื‘ืฅ ืฉืœ ื”ืžืฉืชืžืฉ ืกืคืจื™ื™ืช ื”ื‘ื™ืช.

    ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื”, ืขื•ื“ื›ืŸ ื›ืœื™ ื”ืฉื™ืจื•ืช scp ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ื”ืชืืžื” ื‘ื™ืŸ ืฉืžื•ืช ื”ืงื‘ืฆื™ื ื”ืžื‘ื•ืงืฉื™ื ืœืืœื” ืฉื ืฉืœื—ื• ืขืœ ื™ื“ื™ ื”ืฉืจืช, ื”ืžืชื‘ืฆืขืช ื‘ืฆื“ ื”ืœืงื•ื—. ื–ื” ืขืœื•ืœ ืœื’ืจื•ื ืœื‘ืขื™ื•ืช ื‘ืขื™ื‘ื•ื“ ื”ืžืกื›ื”, ืžื›ื™ื•ื•ืŸ ืฉืชื•ื•ื™ ื”ืจื—ื‘ืช ื”ืžืกื›ื” ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ืžืขื•ื‘ื“ื™ื ื‘ืฆื•ืจื” ืฉื•ื ื” ื‘ืฆื“ ื”ืฉืจืช ื•ื”ืœืงื•ื—. ื‘ืžืงืจื” ืฉื”ื‘ื“ืœื™ื ื›ืืœื” ื’ื•ืจืžื™ื ืœืœืงื•ื— ืœื”ืคืกื™ืง ืœืงื‘ืœ ืงื‘ืฆื™ื ื‘-scp, ื ื•ืกืคื” ื”ืืคืฉืจื•ืช "-T" ื›ื“ื™ ืœื”ืฉื‘ื™ืช ืืช ื”ื‘ื“ื™ืงื” ื‘ืฆื“ ื”ืœืงื•ื—. ื›ื“ื™ ืœืชืงืŸ ืืช ื”ื‘ืขื™ื” ื‘ืžืœื•ืื”, ื ื“ืจืฉ ืขื™ื‘ื•ื“ ืจืขื™ื•ื ื™ ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ scp, ืฉื”ื•ื ืขืฆืžื• ื›ื‘ืจ ืžื™ื•ืฉืŸ, ื•ืœื›ืŸ ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืžืงื•ื ื–ืืช ื‘ืคืจื•ื˜ื•ืงื•ืœื™ื ืžื•ื“ืจื ื™ื™ื ื™ื•ืชืจ ื›ื’ื•ืŸ sftp ื•-rsync.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”