ืžื”ื“ื•ืจืช OpenSSH 8.4

ืœืื—ืจ ืืจื‘ืขื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืฉืœ OpenSSH 8.4, ืžื™ืžื•ืฉ ืœืงื•ื— ื•ืฉืจืช ืคืชื•ื— ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP.

ืฉื™ื ื•ื™ื™ื ืขื™ืงืจื™ื™ื:

  • ืฉื™ื ื•ื™ื™ื ื‘ืื‘ื˜ื—ื”:
    • ื‘-ssh-agent, ื›ืืฉืจ ืžืฉืชืžืฉื™ื ื‘ืžืคืชื—ื•ืช FIDO ืฉืœื ื ื•ืฆืจื• ืขื‘ื•ืจ ืื™ืžื•ืช SSH (ืžื–ื”ื” ื”ืžืคืชื— ืื™ื ื• ืžืชื—ื™ืœ ื‘ืžื—ืจื•ื–ืช "ssh:"), ื›ืขืช ื”ื•ื ื‘ื•ื“ืง ืฉื”ื”ื•ื“ืขื” ืชื™ื—ืชื ื‘ืฉื™ื˜ื•ืช ื”ืžืฉืžืฉื•ืช ื‘ืคืจื•ื˜ื•ืงื•ืœ SSH. ื”ืฉื™ื ื•ื™ ืœื ื™ืืคืฉืจ ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืฉืœ ssh-agent ืœืžืืจื—ื™ื ืžืจื•ื—ืงื™ื ืฉื™ืฉ ืœื”ื ืžืคืชื—ื•ืช FIDO ื›ื“ื™ ืœื—ืกื•ื ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžืคืชื—ื•ืช ืืœื” ืœื™ืฆื™ืจืช ื—ืชื™ืžื•ืช ืขื‘ื•ืจ ื‘ืงืฉื•ืช ืื™ืžื•ืช ืื™ื ื˜ืจื ื˜ (ื”ืžืงืจื” ื”ื”ืคื•ืš, ื›ืืฉืจ ื“ืคื“ืคืŸ ื™ื›ื•ืœ ืœื—ืชื•ื ืขืœ ื‘ืงืฉืช SSH, ืื™ื ื• ื ื›ืœืœ ื‘ืชื—ื™ืœื” ืขืงื‘ ื”ืฉื™ืžื•ืฉ ื‘ืงื™ื“ื•ืžืช "ssh:" ื‘ืžื–ื”ื” ื”ืžืคืชื—).
    • ื™ืฆื™ืจืช ืžืคืชื—ื•ืช ื”-Resident ืฉืœ ssh-keygen ื›ื•ืœืœืช ืชืžื™ื›ื” ื‘ืชื•ืกืฃ credProtect ื”ืžืชื•ืืจ ื‘ืžืคืจื˜ FIDO 2.1, ื”ืžืกืคืง ื”ื’ื ื” ื ื•ืกืคืช ืœืžืคืชื—ื•ืช ืขืœ ื™ื“ื™ ื“ืจื™ืฉืช PIN ืœืคื ื™ ื‘ื™ืฆื•ืข ื›ืœ ืคืขื•ืœื” ืฉืขืœื•ืœื” ืœื’ืจื•ื ืœื—ื™ืœื•ืฅ ืžืคืชื— ื”-Resident ืžื”ืืกื™ืžื•ืŸ.
  • ืฉื™ื ื•ื™ื™ ืชืื™ืžื•ืช ืฉืขืœื•ืœื™ื ืœืฉื‘ื•ืจ:
    • ื›ื“ื™ ืœืชืžื•ืš ื‘-FIDO/U2F, ืžื•ืžืœืฅ ืœื”ืฉืชืžืฉ ื‘ืกืคืจื™ื™ืช libfido2 ืœืคื—ื•ืช ื‘ื’ืจืกื” 1.5.0. ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžื”ื“ื•ืจื•ืช ื™ืฉื ื•ืช ื™ื•ืชืจ ื™ื•ืฉืžื” ื—ืœืงื™ืช, ืืš ื‘ืžืงืจื” ื–ื”, ืคื•ื ืงืฆื™ื•ืช ื›ื’ื•ืŸ ืžืคืชื—ื•ืช ืชื•ืฉื‘, ื‘ืงืฉืช PIN ื•ื—ื™ื‘ื•ืจ ืžืกืคืจ ืืกื™ืžื•ื ื™ื ืœื ื™ื”ื™ื• ื–ืžื™ื ื•ืช.
    • ื‘-ssh-keygen, ื ืชื•ื ื™ ื”ืžืืžืช ื”ื“ืจื•ืฉื™ื ืœืื™ืžื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื”ืžืืฉืจื•ืช ื ื•ืกืคื• ืœืคื•ืจืžื˜ ืฉืœ ืžื™ื“ืข ื”ืื™ืฉื•ืจ, ื ืฉืžืจ ืื•ืคืฆื™ื•ื ืœื™ ื‘ืขืช ื™ืฆื™ืจืช ืžืคืชื— FIDO.
    • ื”-API ื”ืžืฉืžืฉ ื›ืืฉืจ OpenSSH ืžืงื™ื™ื ืื™ื ื˜ืจืืงืฆื™ื” ืขื ื”ืฉื›ื‘ื” ืœื’ื™ืฉื” ืœืืกื™ืžื•ื ื™ FIDO ื”ืฉืชื ื”.
    • ื‘ืขืช ื‘ื ื™ื™ืช ื’ืจืกื” ื ื™ื™ื“ืช ืฉืœ OpenSSH, automake ื ื“ืจืฉ ื›ืขืช ื›ื“ื™ ืœื™ืฆื•ืจ ืืช ืกืงืจื™ืคื˜ ื”ืชืฆื•ืจื” ื•ืงื‘ืฆื™ ื”-build ื”ื ืœื•ื•ื™ื (ืื ื‘ื•ื ื™ื ืžืงื•ื‘ืฅ ืงื•ื“ tar ืฉืคื•ืจืกื, ืื™ืŸ ืฆื•ืจืš ื‘ื™ืฆื™ืจืช ืชืฆื•ืจื” ืžื—ื“ืฉ).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ืžืคืชื—ื•ืช FIDO ื”ื“ื•ืจืฉื™ื ืื™ืžื•ืช PIN ื‘-ssh ื•-ssh-keygen. ื›ื“ื™ ืœื™ืฆื•ืจ ืžืคืชื—ื•ืช ืขื PIN, ื ื•ืกืคื” ืœ-ssh-keygen ืืคืฉืจื•ืช "ืื™ืžื•ืช-ื ื“ืจืฉ". ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช ื›ืืœื”, ืœืคื ื™ ื‘ื™ืฆื•ืข ืคืขื•ืœืช ื™ืฆื™ืจืช ื”ื—ืชื™ืžื”, ื”ืžืฉืชืžืฉ ืžืชื‘ืงืฉ ืœืืฉืจ ืืช ืคืขื•ืœื•ืชื™ื• ืขืœ ื™ื“ื™ ื”ื–ื ืช ืงื•ื“ PIN.
  • ื‘-sshd, ื”ืืคืฉืจื•ืช "verify-required" ืžื™ื•ืฉืžืช ื‘ื”ื’ื“ืจืช authorized_keys, ื”ืžื—ื™ื™ื‘ืช ืฉื™ืžื•ืฉ ื‘ื™ื›ื•ืœื•ืช ืœืื™ืžื•ืช ื ื•ื›ื—ื•ืช ื”ืžืฉืชืžืฉ ื‘ืžื”ืœืš ืคืขื•ืœื•ืช ืขื ื”ืืกื™ืžื•ืŸ. ืชืงืŸ FIDO ืžืกืคืง ืžืกืคืจ ืืคืฉืจื•ื™ื•ืช ืœืื™ืžื•ืช ืฉื›ื–ื”, ืืš ื›ื™ื•ื OpenSSH ืชื•ืžืš ืจืง ื‘ืื™ืžื•ืช ืžื‘ื•ืกืก PIN.
  • sshd ื•-ssh-keygen ื”ื•ืกื™ืคื• ืชืžื™ื›ื” ืœืื™ืžื•ืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื”ืชื•ืืžื•ืช ืืช ืชืงืŸ FIDO Webauthn, ื”ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช FIDO ื‘ื“ืคื“ืคื ื™ ืื™ื ื˜ืจื ื˜.
  • ื‘-ssh ื‘ื”ื’ื“ืจื•ืช CertificateFile,
    ControlPath, IdentityAgent, IdentityFile, LocalForward ื•
    RemoteForward ืžืืคืฉืจ ื”ื—ืœืคื” ืฉืœ ืขืจื›ื™ื ืžืžืฉืชื ื™ ืกื‘ื™ื‘ื” ืฉืฆื•ื™ื ื• ื‘ืคื•ืจืžื˜ "${ENV}".

  • ssh ื•-ssh-agent ื”ื•ืกื™ืคื• ืชืžื™ื›ื” ื‘ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” $SSH_ASKPASS_REQUIRE, ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœื”ืคืขื™ืœ ืื• ืœื”ืฉื‘ื™ืช ืืช ื”ืงืจื™ืื” ssh-askpass.
  • ื‘-ssh ื‘-ssh_config ื‘ื”ื ื—ื™ื™ืช AddKeysToAgent, ื ื•ืกืคื” ื”ื™ื›ื•ืœืช ืœื”ื’ื‘ื™ืœ ืืช ืชืงื•ืคืช ื”ืชื•ืงืฃ ืฉืœ ืžืคืชื—. ืœืื—ืจ ืฉื”ืžื’ื‘ืœื” ืฉืฆื•ื™ื ื” ืคื’, ื”ืžืคืชื—ื•ืช ื ืžื—ืงื™ื ืื•ื˜ื•ืžื˜ื™ืช ืž-ssh-agent.
  • ื‘-scp ื•ื‘-sftp, ื‘ืืžืฆืขื•ืช ื”ื“ื’ืœ "-A", ืืชื” ื™ื›ื•ืœ ื›ืขืช ืœืืคืฉืจ ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืœ-scp ื•-sftp ื‘ืืžืฆืขื•ืช ssh-agent (ื ื™ืชื•ื‘ ืžื—ื“ืฉ ืžื•ืฉื‘ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ื‘ื”ื—ืœืคืช '%k' ื‘ื”ื’ื“ืจื•ืช ssh, ื”ืžืฆื™ื™ื ืช ืืช ืฉื ืžืคืชื— ื”ืžืืจื—. ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืชื›ื•ื ื” ื–ื• ื›ื“ื™ ืœื”ืคื™ืฅ ืžืคืชื—ื•ืช ืœืงื‘ืฆื™ื ื ืคืจื“ื™ื (ืœื“ื•ื’ืžื”, "UserKnownHostsFile ~/.ssh/known_hosts.d/%k").
  • ืืคืฉืจ ืืช ื”ืฉื™ืžื•ืฉ ื‘ืคืขื•ืœืช "ssh-add -d -" ื›ื“ื™ ืœืงืจื•ื ืžืคืชื—ื•ืช ืž-stdin ืฉืืžื•ืจื™ื ืœื”ื™ืžื—ืง.
  • ื‘-sshd, ื”ื”ืชื—ืœื” ื•ื”ืกื™ื•ื ืฉืœ ืชื”ืœื™ืš ื’ื™ื–ื•ื ื”ื—ื™ื‘ื•ืจ ื‘ืื™ื ืœื™ื“ื™ ื‘ื™ื˜ื•ื™ ื‘ื™ื•ืžืŸ, ื”ืžื•ืกื“ืจ ื‘ืืžืฆืขื•ืช ืคืจืžื˜ืจ MaxStartups.

ืžืคืชื—ื™ OpenSSH ื’ื ื ื–ื›ืจื• ื‘ื‘ื™ื˜ื•ืœ ื”ืงืจื•ื‘ ืฉืœ ืืœื’ื•ืจื™ืชืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-hash SHA-1 ืขืงื‘ ืงื™ื“ื•ื ื”ืืคืงื˜ื™ื‘ื™ื•ืช ืฉืœ ื”ืชืงืคื•ืช ื”ืชื ื’ืฉื•ืช ืขื ืงื™ื“ื•ืžืช ื ืชื•ื ื” (ืขืœื•ืช ื‘ื—ื™ืจืช ื”ืชื ื’ืฉื•ืช ื ืืžื“ืช ื‘ื›-45 ืืœืฃ ื“ื•ืœืจ). ื‘ืื—ืช ื”ืžื”ื“ื•ืจื•ืช ื”ืงืจื•ื‘ื•ืช, ื”ื ืžืชื›ื ื ื™ื ืœื”ืฉื‘ื™ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืืœื’ื•ืจื™ืชื ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ืžืคืชื— ืฆื™ื‘ื•ืจื™ "ssh-rsa", ื”ืžื•ื–ื›ืจ ื‘-RFC ื”ืžืงื•ืจื™ ืขื‘ื•ืจ ืคืจื•ื˜ื•ืงื•ืœ SSH ื•ื ืฉืืจ ื ืคื•ืฅ ื‘ืคื•ืขืœ (ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืฉื™ืžื•ืฉ ืฉืœ ssh-rsa ื‘ืžืขืจื›ื•ืช ืฉืœืš, ืืชื” ื™ื›ื•ืœ ืœื ืกื•ืช ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช ssh ืขื ื”ืืคืฉืจื•ืช "-oHostKeyAlgorithms=-ssh-rsa").

ื›ื“ื™ ืœื”ื—ืœื™ืง ืืช ื”ืžืขื‘ืจ ืœืืœื’ื•ืจื™ืชืžื™ื ื—ื“ืฉื™ื ื‘-OpenSSH, ื”ืžื”ื“ื•ืจื” ื”ื‘ืื” ืชืืคืฉืจ ืืช ื”ื’ื“ืจืช UpdateHostKeys ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืฉืชืขื‘ื™ืจ ืื•ื˜ื•ืžื˜ื™ืช ืœืงื•ื—ื•ืช ืœืืœื’ื•ืจื™ืชืžื™ื ืืžื™ื ื™ื ื™ื•ืชืจ. ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืžืœืฆื™ื ืœื”ืขื‘ืจื” ื›ื•ืœืœื™ื rsa-sha2-256/512 ืžื‘ื•ืกืก ืขืœ RFC8332 RSA SHA-2 (ื ืชืžืš ืžืื– OpenSSH 7.2 ื•ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ), ssh-ed25519 (ื ืชืžืš ืžืื– OpenSSH 6.5) ื•-ecdsa-sha2-nistp256/384 based ืขืœ RFC521 ECDSA (ื ืชืžืš ืžืื– OpenSSH 5656).

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”