ืžื”ื“ื•ืจืช OpenSSH 8.1

ืœืื—ืจ ืฉื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ OpenSSH 8.1, ืžื™ืžื•ืฉ ืœืงื•ื— ื•ืฉืจืช ืคืชื•ื— ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP.

ืชืฉื•ืžืช ืœื‘ ืžื™ื•ื—ื“ืช ื‘ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ื”ื™ื ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช ื”ืžืฉืคื™ืขื” ืขืœ ssh, sshd, ssh-add ื•-ssh-keygen. ื”ื‘ืขื™ื” ืงื™ื™ืžืช ื‘ืงื•ื“ ืœื ื™ืชื•ื— ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ืžืกื•ื’ XMSS ื•ืžืืคืฉืจืช ืœืชื•ืงืฃ ืœื”ืคืขื™ืœ ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื. ื”ืคื’ื™ืขื•ืช ืžืกื•ืžื ืช ื›ื ื™ืชื ืช ืœื ื™ืฆื•ืœ, ืืš ืžื•ืขื™ืœื” ืžืขื˜, ืฉื›ืŸ ืชืžื™ื›ื” ื‘ืžืคืชื—ื•ืช XMSS ื”ื™ื ืชื›ื•ื ื” ื ื™ืกื™ื•ื ื™ืช ื”ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ (ืœื’ืจืกื” ื”ื ื™ื™ื“ืช ืื™ืŸ ืืคื™ืœื• ืืคืฉืจื•ืช build ื‘-autoconf ื›ื“ื™ ืœืืคืฉืจ ืืช XMSS).

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ื‘-ssh, sshd ื•-ssh-agent ื”ื•ืกื™ืฃ ืงื•ื“ ืฉืžื•ื ืข ืฉื—ื–ื•ืจ ืฉืœ ืžืคืชื— ืคืจื˜ื™ ืฉื ืžืฆื ื‘-RAM ื›ืชื•ืฆืื” ืžื”ืชืงืคื•ืช ืฉืœ ืขืจื•ืฅ ืฆื“ื“ื™, ื›ื’ื•ืŸ ืกืคืงื˜ืจื•ื, ื”ืชื›ื”, RowHammer ะธ ื–ื™ื›ืจื•ืŸ ื“ื. ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ืžื•ืฆืคื ื™ื ื›ืขืช ื›ืืฉืจ ื”ื ื ื˜ืขื ื™ื ืœื–ื™ื›ืจื•ืŸ ื•ืžืคื•ืขื ื—ื™ื ืจืง ื›ืืฉืจ ื”ื ื‘ืฉื™ืžื•ืฉ, ื ืฉืืจื™ื ืžื•ืฆืคื ื™ื ื‘ืฉืืจ ื”ื–ืžืŸ. ื‘ื’ื™ืฉื” ื–ื•, ื›ื“ื™ ืœืฉื—ื–ืจ ื‘ื”ืฆืœื—ื” ืืช ื”ืžืคืชื— ื”ืคืจื˜ื™, ืขืœ ื”ืชื•ืงืฃ ืœืฉื—ื–ืจ ืชื—ื™ืœื” ืžืคืชื— ื‘ื™ื ื™ื™ื ืฉื ื•ืฆืจ ื‘ืืงืจืื™ ื‘ื’ื•ื“ืœ 16 KB, ื”ืžืฉืžืฉ ืœื”ืฆืคื ืช ื”ืžืคืชื— ื”ืจืืฉื™, ื“ื‘ืจ ืฉืื™ื ื• ืกื‘ื™ืจ ื‘ื”ืชื—ืฉื‘ ื‘ืฉื™ืขื•ืจ ืฉื’ื™ืื•ืช ื”ืฉื—ื–ื•ืจ ื”ืื•ืคื™ื™ื ื™ ืœืžืชืงืคื•ืช ืžื•ื“ืจื ื™ื•ืช;
  • ะ’ ssh-keygen ื ื•ืกืคื” ืชืžื™ื›ื” ื ื™ืกื™ื•ื ื™ืช ืœืชื›ื ื™ืช ืคืฉื•ื˜ื” ืœื™ืฆื™ืจื” ื•ืื™ืžื•ืช ืฉืœ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช. ื ื™ืชืŸ ืœื™ืฆื•ืจ ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื‘ืืžืฆืขื•ืช ืžืคืชื—ื•ืช SSH ืจื’ื™ืœื™ื ื”ืžืื•ื—ืกื ื™ื ื‘ื“ื™ืกืง ืื• ื‘-ssh-agent, ื•ืœืืžืช ื‘ืืžืฆืขื•ืช ืžืฉื”ื• ื”ื“ื•ืžื” ืœ-autorized_keys ืจืฉื™ืžื” ืฉืœ ืžืคืชื—ื•ืช ื—ื•ืงื™ื™ื. ืžื™ื“ืข ืขืœ ืžืจื—ื‘ ื”ืฉืžื•ืช ืžื•ื‘ื ื” ื‘ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ื›ื“ื™ ืœืžื ื•ืข ื‘ืœื‘ื•ืœ ื‘ืฉื™ืžื•ืฉ ื‘ืื–ื•ืจื™ื ืฉื•ื ื™ื (ืœื“ื•ื’ืžื”, ืขื‘ื•ืจ ื“ื•ืืจ ืืœืงื˜ืจื•ื ื™ ื•ืงื‘ืฆื™ื);
  • ssh-keygen ื”ื•ื—ืœืฃ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืฉื™ืžื•ืฉ ื‘ืืœื’ื•ืจื™ืชื rsa-sha2-512 ื‘ืขืช ืื™ืžื•ืช ืื™ืฉื•ืจื™ื ืขื ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื”ืžื‘ื•ืกืกืช ืขืœ ืžืคืชื— RSA (ื‘ืขืช ืขื‘ื•ื“ื” ื‘ืžืฆื‘ CA). ืื™ืฉื•ืจื™ื ื›ืืœื” ืื™ื ื ืชื•ืืžื™ื ืœืžื”ื“ื•ืจื•ืช ืœืคื ื™ OpenSSH 7.2 (ื›ื“ื™ ืœื”ื‘ื˜ื™ื— ืชืื™ืžื•ืช, ื™ืฉ ืœืขืงื•ืฃ ืืช ืกื•ื’ ื”ืืœื’ื•ืจื™ืชื, ืœืžืฉืœ ืขืœ ื™ื“ื™ ืงืจื™ืื” "ssh-keygen -t ssh-rsa -s ...");
  • ื‘-ssh, ื‘ื™ื˜ื•ื™ ProxyCommand ืชื•ืžืš ื›ืขืช ื‘ื”ืจื—ื‘ื” ืฉืœ ื”ื—ืœืคืช "%n" (ืฉื ื”ืžืืจื— ืฉืฆื•ื™ืŸ ื‘ืฉื•ืจืช ื”ื›ืชื•ื‘ืช);
  • ื‘ืจืฉื™ืžื•ืช ืฉืœ ืืœื’ื•ืจื™ืชืžื™ ื”ื”ืฆืคื ื” ืขื‘ื•ืจ ssh ื•-sshd, ื›ืขืช ืชื•ื›ืœ ืœื”ืฉืชืžืฉ ื‘ืชื• "^" ื›ื“ื™ ืœื”ื›ื ื™ืก ืืช ืืœื’ื•ืจื™ืชืžื™ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ. ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœื”ื•ืกื™ืฃ ssh-ed25519 ืœืจืฉื™ืžืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ "HostKeyAlgorithms ^ssh-ed25519";
  • ssh-keygen ืžืกืคืง ืคืœื˜ ืฉืœ ื”ืขืจื” ื”ืžืฆื•ืจืคืช ืœืžืคืชื— ื‘ืขืช ื—ื™ืœื•ืฅ ืžืคืชื— ืฆื™ื‘ื•ืจื™ ืžืžืคืชื— ืคืจื˜ื™;
  • ื”ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ื“ื’ืœ "-v" ื‘-ssh-keygen ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื—ื™ืคื•ืฉ ืžืคืชื— (ืœื“ื•ื’ืžื”, "ssh-keygen -vF host"), ืชื•ืš ืฆื™ื•ืŸ ืžื” ื’ื•ืจื ืœื—ืชื™ืžืช ืžืืจื— ื—ื–ื•ืชื™ืช;
  • ื ื•ืกืคื” ื™ื›ื•ืœืช ืฉื™ืžื•ืฉ PKCS8 ื›ืคื•ืจืžื˜ ื—ืœื•ืคื™ ืœืื—ืกื•ืŸ ืžืคืชื—ื•ืช ืคืจื˜ื™ื™ื ื‘ื“ื™ืกืง. ืคื•ืจืžื˜ PEM ืžืžืฉื™ืš ืœื”ื™ื•ืช ื‘ืฉื™ืžื•ืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื•-PKCS8 ืขืฉื•ื™ ืœื”ื™ื•ืช ืฉื™ืžื•ืฉื™ ืœื”ืฉื’ืช ืชืื™ืžื•ืช ืขื ื™ื™ืฉื•ืžื™ ืฆื“ ืฉืœื™ืฉื™.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”