ืžื”ื“ื•ืจืช OpenSSH 8.5

ืœืื—ืจ ื—ืžื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ืžื•ืฆื’ืช ื”ื”ืคืฆื” ืฉืœ OpenSSH 8.5, ื™ื™ืฉื•ื ืคืชื•ื— ืฉืœ ืœืงื•ื— ื•ืฉืจืช ืœืขื‘ื•ื“ื” ืขืœ ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP.

ืžืคืชื—ื™ OpenSSH ื”ื–ื›ื™ืจื• ืœื ื• ืืช ื”ื”ืฉื‘ืชื” ื”ืงืจื•ื‘ื” ืฉืœ ืืœื’ื•ืจื™ืชืžื™ื ื‘ืืžืฆืขื•ืช hashes SHA-1 ืขืงื‘ ื”ื™ืขื™ืœื•ืช ื”ืžื•ื’ื‘ืจืช ืฉืœ ื”ืชืงืคื•ืช ื”ืชื ื’ืฉื•ืช ืขื ืงื™ื“ื•ืžืช ื ืชื•ื ื” (ืขืœื•ืช ื‘ื—ื™ืจืช ื”ืชื ื’ืฉื•ืช ืžื•ืขืจื›ืช ื‘ื›-50 ืืœืฃ ื“ื•ืœืจ). ื‘ืื—ืช ื”ืžื”ื“ื•ืจื•ืช ื”ืงืจื•ื‘ื•ืช, ื”ื ืžืชื›ื ื ื™ื ืœื”ืฉื‘ื™ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืืœื’ื•ืจื™ืชื ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ "ssh-rsa", ื”ืžื•ื–ื›ืจ ื‘-RFC ื”ืžืงื•ืจื™ ืขื‘ื•ืจ ืคืจื•ื˜ื•ืงื•ืœ SSH ื•ื ืฉืืจ ื ืคื•ืฅ ื‘ืคื•ืขืœ.

ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืฉื™ืžื•ืฉ ื‘-ssh-rsa ื‘ืžืขืจื›ื•ืช ืฉืœืš, ืืชื” ื™ื›ื•ืœ ืœื ืกื•ืช ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช ssh ืขื ื”ืืคืฉืจื•ืช "-oHostKeyAlgorithms=-ssh-rsa". ื™ื—ื“ ืขื ื–ืืช, ื”ืฉื‘ืชืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช "ssh-rsa" ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืื™ื ื” ืคื™ืจื•ืฉื” ื ื˜ื™ืฉื” ืžื•ื—ืœื˜ืช ืฉืœ ื”ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช RSA, ืฉื›ืŸ ื‘ื ื•ืกืฃ ืœ-SHA-1, ืคืจื•ื˜ื•ืงื•ืœ SSH ืžืืคืฉืจ ืฉื™ืžื•ืฉ ื‘ืืœื’ื•ืจื™ืชืžื™ื ืื—ืจื™ื ืฉืœ ื—ื™ืฉื•ื‘ ื’ื™ื‘ื•ื‘. ื‘ืคืจื˜, ื‘ื ื•ืกืฃ ืœ-"ssh-rsa", ื™ื™ืฉืืจ ืืคืฉืจื™ ืœื”ืฉืชืžืฉ ื‘ื—ื‘ื™ืœื•ืช "rsa-sha2-256" (RSA/SHA256) ื•-"rsa-sha2-512" (RSA/SHA512).

ื›ื“ื™ ืœื”ื—ืœื™ืง ืืช ื”ืžืขื‘ืจ ืœืืœื’ื•ืจื™ืชืžื™ื ื—ื“ืฉื™ื, ื‘-OpenSSH 8.5 ืžื•ืคืขืœืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืืช ื”ื’ื“ืจืช UpdateHostKeys, ื”ืžืืคืฉืจืช ืœืœืงื•ื—ื•ืช ืœืขื‘ื•ืจ ืื•ื˜ื•ืžื˜ื™ืช ืœืืœื’ื•ืจื™ืชืžื™ื ืืžื™ื ื™ื ื™ื•ืชืจ. ื‘ืืžืฆืขื•ืช ื”ื’ื“ืจื” ื–ื•, ื”ืจื—ื‘ืช ืคืจื•ื˜ื•ืงื•ืœ ืžื™ื•ื—ื“ืช ืžื•ืคืขืœืช "[ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]", ื”ืžืืคืฉืจ ืœืฉืจืช, ืœืื—ืจ ืื™ืžื•ืช, ืœื™ื™ื“ืข ืืช ื”ืœืงื•ื— ืขืœ ื›ืœ ืžืคืชื—ื•ืช ื”ืžืืจื— ื”ื–ืžื™ื ื™ื. ื”ืœืงื•ื— ื™ื›ื•ืœ ืœืฉืงืฃ ืžืคืชื—ื•ืช ืืœื• ื‘ืงื•ื‘ืฅ ~/.ssh/known_hosts ืฉืœื•, ืžื” ืฉืžืืคืฉืจ ืœืขื“ื›ืŸ ืืช ืžืคืชื—ื•ืช ื”ืžืืจื— ื•ืžืงืœ ืขืœ ืฉื™ื ื•ื™ ื”ืžืคืชื—ื•ืช ื‘ืฉืจืช.

ื”ืฉื™ืžื•ืฉ ื‘-UpdateHostKeys ืžื•ื’ื‘ืœ ืขืœ ื™ื“ื™ ื›ืžื” ืื–ื”ืจื•ืช ืฉืขืฉื•ื™ื•ืช ืœื”ื™ื•ืช ืžื•ืกืจื•ืช ื‘ืขืชื™ื“: ื™ืฉ ืœื”ืคื ื•ืช ืœืžืคืชื— ื‘-UserKnownHostsFile ื•ืœื ืœื”ืฉืชืžืฉ ื‘-GlobalKnownHostsFile; ื”ืžืคืชื— ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืงื™ื™ื ืชื—ืช ืฉื ืื—ื“ ื‘ืœื‘ื“; ืื™ืŸ ืœื”ืฉืชืžืฉ ื‘ืื™ืฉื•ืจ ืžืคืชื— ืžืืจื—; ื‘-known_hosts ืื™ืŸ ืœื”ืฉืชืžืฉ ื‘ืžืกื›ื•ืช ืœืคื™ ืฉื ืžืืจื—; ื™ืฉ ืœื”ืฉื‘ื™ืช ืืช ื”ื’ื“ืจืช VerifyHostKeyDNS; ื”ืคืจืžื˜ืจ UserKnownHostsFile ื—ื™ื™ื‘ ืœื”ื™ื•ืช ืคืขื™ืœ.

ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืžืœืฆื™ื ืœื”ืขื‘ืจื” ื›ื•ืœืœื™ื rsa-sha2-256/512 ืžื‘ื•ืกืก ืขืœ RFC8332 RSA SHA-2 (ื ืชืžืš ืžืื– OpenSSH 7.2 ื•ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ), ssh-ed25519 (ื ืชืžืš ืžืื– OpenSSH 6.5) ื•-ecdsa-sha2-nistp256/384 based ืขืœ RFC521 ECDSA (ื ืชืžืš ืžืื– OpenSSH 5656).

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื:

  • ืฉื™ื ื•ื™ื™ื ื‘ืื‘ื˜ื—ื”:
    • ืคื’ื™ืขื•ืช ืฉื ื’ืจืžื” ืขืœ ื™ื“ื™ ืฉื—ืจื•ืจ ืžื—ื“ืฉ ืฉืœ ืื–ื•ืจ ื–ื™ื›ืจื•ืŸ ืฉื›ื‘ืจ ืฉื•ื—ืจืจ (ืœืœื ื›ืคื•ืœ) ืชื•ืงื ื” ื‘-ssh-agent. ื”ื‘ืขื™ื” ืงื™ื™ืžืช ืžืื– ืฉื—ืจื•ืจื• ืฉืœ OpenSSH 8.2 ื•ืืคืฉืจ ืœื ืฆืœ ืื•ืชื” ืื ืœืชื•ืงืฃ ื™ืฉ ื’ื™ืฉื” ืœืฉืงืข ssh-agent ื‘ืžืขืจื›ืช ื”ืžืงื•ืžื™ืช. ืžื” ืฉืžืงืฉื” ืขืœ ื”ื ื™ืฆื•ืœ ื”ื•ื ืฉืจืง ืœืฉื•ืจืฉ ื•ืœืžืฉืชืžืฉ ื”ืžืงื•ืจื™ ื™ืฉ ื’ื™ืฉื” ืœืฉืงืข. ืชืจื—ื™ืฉ ื”ื”ืชืงืคื” ื”ืกื‘ื™ืจ ื‘ื™ื•ืชืจ ื”ื•ื ืฉื”ืกื•ื›ืŸ ืžื ื•ืชื‘ ืœื—ืฉื‘ื•ืŸ ืฉื ืฉืœื˜ ืขืœ ื™ื“ื™ ื”ืชื•ืงืฃ, ืื• ืœืžืืจื— ืฉื‘ื• ืœืชื•ืงืฃ ื™ืฉ ื’ื™ืฉืช ืฉื•ืจืฉ.
    • sshd ื”ื•ืกื™ืคื” ื”ื’ื ื” ืžืคื ื™ ื”ืขื‘ืจืช ืคืจืžื˜ืจื™ื ื’ื“ื•ืœื™ื ืžืื•ื“ ืขื ืฉื ื”ืžืฉืชืžืฉ ืœืžืขืจื›ืช ื”ืžืฉื ื” PAM, ืžื” ืฉืžืืคืฉืจ ืœื—ืกื•ื ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืžื•ื“ื•ืœื™ ืžืขืจื›ืช PAM (Pluggable Authentication Module). ืœื“ื•ื’ืžื”, ื”ืฉื™ื ื•ื™ ืžื•ื ืข ืž-sshd ืœืฉืžืฉ ื›ื•ื•ืงื˜ื•ืจ ืœื ื™ืฆื•ืœ ืคื’ื™ืขื•ืช ืฉื•ืจืฉ ืฉื”ืชื’ืœืชื” ืœืื—ืจื•ื ื” ื‘- Solaris (CVE-2020-14871).
  • ืฉื™ื ื•ื™ื™ ืชืื™ืžื•ืช ืฉืขืœื•ืœื™ื ืœืฉื‘ื•ืจ:
    • ื‘-ssh ื•-sshd, ืขื•ืฆื‘ื” ืžื—ื“ืฉ ืฉื™ื˜ืช ื”ื—ืœืคืช ืžืคืชื—ื•ืช ื ื™ืกื™ื•ื ื™ืช ืฉืขืžื™ื“ื” ื‘ืคื ื™ ื ื™ื—ื•ืฉื™ื ื‘ืžื—ืฉื‘ ืงื•ื•ื ื˜ื™. ืžื—ืฉื‘ื™ื ืงื•ื•ื ื˜ื™ื™ื ืžื”ื™ืจื™ื ื™ื•ืชืจ ื‘ืื•ืคืŸ ืงื™ืฆื•ื ื™ ื‘ืคืชืจื•ืŸ ื”ื‘ืขื™ื” ืฉืœ ืคื™ืจื•ืง ืžืกืคืจ ื˜ื‘ืขื™ ืœื’ื•ืจืžื™ื ืจืืฉื•ื ื™ื™ื, ืืฉืจ ืขื•ืžื“ืช ื‘ื‘ืกื™ืก ืืœื’ื•ืจื™ืชืžื™ ื”ืฆืคื ื” ื-ืกื™ืžื˜ืจื™ื™ื ืžื•ื“ืจื ื™ื™ื ื•ืื™ื ื ื ื™ืชื ื™ื ืœืคืชืจื•ืŸ ื™ืขื™ืœ ื‘ืžืขื‘ื“ื™ื ืงืœืืกื™ื™ื. ื”ืฉื™ื˜ื” ื‘ื” ื ืขืฉื” ืฉื™ืžื•ืฉ ืžื‘ื•ืกืกืช ืขืœ ืืœื’ื•ืจื™ืชื NTRU Prime, ืฉืคื•ืชื— ืขื‘ื•ืจ ืžืขืจื›ื•ืช ื”ืฆืคื ื” ืคื•ืกื˜-ืงื•ื•ื ื˜ื™ื•ืช, ื•ืฉื™ื˜ืช X25519 ื”ื—ืœืคืช ืžืคืชื—ื•ืช ืขืงื•ืžื” ืืœื™ืคื˜ื™ืช. ื‘ืžืงื•ื [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ] ื”ืฉื™ื˜ื” ืžื–ื•ื”ื” ื›ืขืช ื› [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ] (ืืœื’ื•ืจื™ืชื sntrup4591761 ื”ื•ื—ืœืฃ ื‘-sntrup761).
    • ื‘-ssh ื•-sshd, ื”ืกื“ืจ ืฉื‘ื• ื”ื•ื›ืจื–ื• ืืœื’ื•ืจื™ืชืžื™ ื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ื ืชืžื›ื™ื ื”ืฉืชื ื”. ED25519 ืžื•ืฆืข ื›ืขืช ืจืืฉื•ืŸ ื‘ืžืงื•ื ECDSA.
    • ื‘-ssh ื•ื‘-sshd, ื”ื’ื“ืจืช ืคืจืžื˜ืจื™ ืื™ื›ื•ืช ื”ืฉื™ืจื•ืช ืฉืœ TOS/DSCP ืขื‘ื•ืจ ื”ืคืขืœื•ืช ืื™ื ื˜ืจืืงื˜ื™ื‘ื™ื•ืช ืžืชื‘ืฆืขืช ื›ืขืช ืœืคื ื™ ื™ืฆื™ืจืช ื—ื™ื‘ื•ืจ TCP.
    • ืชืžื™ื›ืช ืฆื•ืคืŸ ื”ื•ืคืกืงื” ื‘-ssh ื•ื‘-sshd [ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ], ื–ื”ื” ืœ-aes256-cbc ื•ื”ื™ื” ื‘ืฉื™ืžื•ืฉ ืœืคื ื™ ืื™ืฉื•ืจ RFC-4253.
    • ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ืคืจืžื˜ืจ CheckHostIP ืžื•ืฉื‘ืช, ืฉื”ืชื•ืขืœืช ื‘ื• ื–ื ื™ื—ื”, ืืš ื”ืฉื™ืžื•ืฉ ื‘ื• ืžืกื‘ืš ืžืฉืžืขื•ืชื™ืช ืืช ืกื™ื‘ื•ื‘ ื”ืžืคืชื—ื•ืช ืขื‘ื•ืจ ืžืืจื—ื™ื ืžืื—ื•ืจื™ ืžืื–ื ื™ ืขื•ืžืกื™ื.
  • ื”ื’ื“ืจื•ืช PerSourceMaxStartups ื•- PerSourceNetBlockSize ื ื•ืกืคื• ืœ-sshd ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ืขื•ืฆืžืช ื”ื”ืฉืงื” ืฉืœ ืžื˜ืคืœื™ื ื‘ื”ืชื‘ืกืก ืขืœ ื›ืชื•ื‘ืช ื”ืœืงื•ื—. ืคืจืžื˜ืจื™ื ืืœื• ืžืืคืฉืจื™ื ืœืš ืœืฉืœื•ื˜ ื‘ืฆื•ืจื” ืขื“ื™ื ื” ื™ื•ืชืจ ื‘ืžื’ื‘ืœื” ืขืœ ื”ืฉืงื•ืช ืชื”ืœื™ื›ื™ื, ื‘ื”ืฉื•ื•ืื” ืœื”ื’ื“ืจื” ื”ื›ืœืœื™ืช ืฉืœ MaxStartups.
  • ื ื•ืกืคื” ื”ื’ื“ืจื” ื—ื“ืฉื” ืฉืœ LogVerbose ืœ-ssh ื•ืœ-sshd, ื”ืžืืคืฉืจืช ืœื”ืขืœื•ืช ื‘ื›ื•ื— ืืช ืจืžืช ื”ืžื™ื“ืข ื‘ืื’ื™ื ื”ืžื•ื–ืจื ื‘ื™ื•ืžืŸ, ืขื ื™ื›ื•ืœืช ืกื™ื ื•ืŸ ืœืคื™ ืชื‘ื ื™ื•ืช, ืคื•ื ืงืฆื™ื•ืช ื•ืงื‘ืฆื™ื.
  • ื‘-ssh, ื‘ืขืช ืงื‘ืœืช ืžืคืชื— ืžืืจื— ื—ื“ืฉ, ืžื•ืฆื’ื™ื ื›ืœ ืฉืžื•ืช ื”ืžืืจื—ื™ื ื•ื›ืชื•ื‘ื•ืช ื”-IP ื”ืžืฉื•ื™ื›ื•ืช ืœืžืคืชื—.
  • ssh ืžืืคืฉืจ ืœืืคืฉืจื•ืช UserKnownHostsFile=none ืœื”ืฉื‘ื™ืช ืืช ื”ืฉื™ืžื•ืฉ ื‘ืงื•ื‘ืฅ ื”-known_hosts ื‘ืขืช ื–ื™ื”ื•ื™ ืžืคืชื—ื•ืช ืžืืจื—.
  • ื”ื’ื“ืจืช KnownHostsCommand ื ื•ืกืคื” ืœ-ssh_config ืขื‘ื•ืจ ssh, ื”ืžืืคืฉืจืช ืœืš ืœืงื‘ืœ ื ืชื•ื ื™ known_hosts ืžื”ืคืœื˜ ืฉืœ ื”ืคืงื•ื“ื” ืฉืฆื•ื™ื ื”.
  • ื ื•ืกืคื” ืืคืฉืจื•ืช PermitRemoteOpen ืœ-ssh_config ืขื‘ื•ืจ ssh ื›ื“ื™ ืœืืคืฉืจ ืœืš ืœื”ื’ื‘ื™ืœ ืืช ื”ื™ืขื“ ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ืืคืฉืจื•ืช RemoteForward ืขื SOCKS.
  • ื‘-ssh ืขื‘ื•ืจ ืžืคืชื—ื•ืช FIDO, ื‘ืงืฉืช PIN ื—ื•ื–ืจืช ืžืกื•ืคืงืช ื‘ืžืงืจื” ืฉืœ ื›ืฉืœ ื‘ืคืขื•ืœืช ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืขืงื‘ PIN ืฉื’ื•ื™ ื•ื”ืžืฉืชืžืฉ ืœื ื”ืชื‘ืงืฉ ืœื”ื–ื™ืŸ PIN (ืœื“ื•ื’ืžื”, ื›ืืฉืจ ืœื ื ื™ืชืŸ ื”ื™ื” ืœื”ืฉื™ื’ ืืช ื”ื ืชื•ื ื™ื ื”ื‘ื™ื•ืžื˜ืจื™ื™ื ื”ื ื›ื•ื ื™ื ื•ื” ื”ืžื›ืฉื™ืจ ื—ื–ืจ ืœื”ื–ื ืช PIN ื™ื“ื ื™).
  • sshd ืžื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืงืจื™ืื•ืช ืžืขืจื›ืช ื ื•ืกืคื•ืช ืœืžื ื’ื ื•ืŸ ื‘ื™ื“ื•ื“ ืชื”ืœื™ื›ื™ื ืžื‘ื•ืกืก seccomp-bpf ื‘ืœื™ื ื•ืงืก.
  • ื›ืœื™ ื”ืฉื™ืจื•ืช contrib/ssh-copy-id ืขื•ื“ื›ืŸ.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”