ืžื”ื“ื•ืจืช OpenSSH 8.6 ืขื ืชื™ืงื•ืŸ ืคื’ื™ืขื•ืช

ืคื•ืจืกื ื”ืžื”ื“ื•ืจื” ืฉืœ OpenSSH 8.6, ื™ื™ืฉื•ื ืคืชื•ื— ืฉืœ ืœืงื•ื— ื•ืฉืจืช ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP. ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžื‘ื˜ืœืช ื ืงื•ื“ืช ืชื•ืจืคื” ื‘ื™ื™ืฉื•ื ื”ื”ื ื—ื™ื” LogVerbose, ืฉื”ื•ืคื™ืขื” ื‘ืžื”ื“ื•ืจื” ื”ืงื•ื“ืžืช ื•ืžืืคืฉืจืช ืœื”ื’ื‘ื™ืจ ืืช ืจืžืช ื”ืžื™ื“ืข ื‘ืื’ื™ื ื”ืžื•ื–ืจื ื‘ื™ื•ืžืŸ, ื›ื•ืœืœ ื™ื›ื•ืœืช ืกื™ื ื•ืŸ ืœืคื™ ืชื‘ื ื™ื•ืช, ืคื•ื ืงืฆื™ื•ืช ื•ืงื‘ืฆื™ื ื”ืงืฉื•ืจื™ื ืœืงื•ื“ ืฉื”ื•ืคืขืœ ืขื ื”ืจืฉืื•ืช ืื™ืคื•ืก ื‘ืชื”ืœื™ืš sshd ืžื‘ื•ื“ื“ ื‘ืกื‘ื™ื‘ืช ืืจื’ื– ื—ื•ืœ.

ืชื•ืงืฃ ื”ืžืฉื™ื’ ืฉืœื™ื˜ื” ืขืœ ืชื”ืœื™ืš ื—ืกืจ ื”ืจืฉืื•ืช ื‘ืืžืฆืขื•ืช ืคื’ื™ืขื•ืช ืฉืขื“ื™ื™ืŸ ืœื ื™ื“ื•ืขื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ื‘ืขื™ื™ืช LogVerbose ื›ื“ื™ ืœืขืงื•ืฃ ืืจื’ื– ื—ื•ืœ ื•ืœืชืงื•ืฃ ืชื”ืœื™ืš ืฉืคื•ืขืœ ืขื ื”ืจืฉืื•ืช ื’ื‘ื•ื”ื•ืช. ื”ืคื’ื™ืขื•ืช ืฉืœ LogVerbose ื ื—ืฉื‘ืช ืœื ืกื‘ื™ืจ ืฉืชืชืจื—ืฉ ื‘ืคื•ืขืœ ืžื›ื™ื•ื•ืŸ ืฉื”ื’ื“ืจืช LogVerbose ืžื•ืฉื‘ืชืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื•ื‘ื“ืจืš ื›ืœืœ ื ืขืฉื” ื‘ื” ืฉื™ืžื•ืฉ ืจืง ื‘ืžื”ืœืš ืื™ืชื•ืจ ื‘ืื’ื™ื. ื”ืžืชืงืคื” ืžื—ื™ื™ื‘ืช ื’ื ืžืฆื™ืืช ืคื’ื™ืขื•ืช ื—ื“ืฉื” ื‘ืชื”ืœื™ืš ืœื ืžื•ื’ืŸ.

ืฉื™ื ื•ื™ื™ื ื‘-OpenSSH 8.6 ืฉืื™ื ื ืงืฉื•ืจื™ื ืœืคื’ื™ืขื•ืช:

  • ืชื•ืกืฃ ืคืจื•ื˜ื•ืงื•ืœ ื—ื“ืฉ ื”ื•ื˜ืžืข ื‘-sftp ื•-sftp-server "[ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]", ื”ืžืืคืฉืจ ืœืœืงื•ื— SFTP ืœืงื‘ืœ ืžื™ื“ืข ืขืœ ื”ื”ื’ื‘ืœื•ืช ื”ืžื•ื’ื“ืจื•ืช ืขืœ ื”ืฉืจืช, ื›ื•ืœืœ ื”ื’ื‘ืœื•ืช ืขืœ ื’ื•ื“ืœ ื”ื—ื‘ื™ืœื” ื”ืžืจื‘ื™ ื•ืคืขื•ืœื•ืช ื›ืชื™ื‘ื” ื•ืงืจื™ืื”. ื‘-sftp, ื”ืจื—ื‘ื” ื—ื“ืฉื” ืžืฉืžืฉืช ืœื‘ื—ื™ืจืช ื’ื•ื“ืœ ื”ื‘ืœื•ืง ื”ืื•ืคื˜ื™ืžืœื™ ื‘ืขืช ื”ืขื‘ืจืช ื ืชื•ื ื™ื.
  • ื”ื’ื“ืจืช ModuliFile ื ื•ืกืคื” ืœ-sshd_config ืขื‘ื•ืจ sshd, ื”ืžืืคืฉืจืช ืœืš ืœืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืœืงื•ื‘ืฅ "moduli" ื”ืžื›ื™ืœ ืงื‘ื•ืฆื•ืช ืขื‘ื•ืจ DH-GEX.
  • ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” TEST_SSH_ELAPSED_TIMES ื ื•ืกืฃ ืœื‘ื“ื™ืงื•ืช ื™ื—ื™ื“ื” ื›ื“ื™ ืœืืคืฉืจ ืคืœื˜ ืฉืœ ื”ื–ืžืŸ ืฉื—ืœืฃ ืžืื– ื›ืœ ื‘ื“ื™ืงื” ื‘ื•ืฆืขื”.
  • ืžืžืฉืง ื‘ืงืฉืช ื”ืกื™ืกืžื” ืฉืœ GNOME ืžื—ื•ืœืง ืœืฉืชื™ ืืคืฉืจื•ื™ื•ืช, ืื—ืช ืขื‘ื•ืจ GNOME2 ื•ืื—ืช ืขื‘ื•ืจ GNOME3 (contrib/gnome-ssk-askpass3.c). ื’ืจืกื” ืฉืœ GNOME3 ืœืฉื™ืคื•ืจ ืชืื™ืžื•ืช Wayland ืžืฉืชืžืฉืช ื‘ืงืจื™ืื” ืœ-gdk_seat_grab() ื‘ืขืช ืฉืœื™ื˜ื” ื‘ืœื›ื™ื“ืช ืžืงืœื“ืช ื•ืขื›ื‘ืจ.
  • soft-disallow ืฉืœ ืงืจื™ืืช ื”ืžืขืจื›ืช fstatat64 ื ื•ืกืคื” ืœืืจื’ื– ื”ื—ื•ืœ ืžื‘ื•ืกืก seccomp-bpf ื”ืžืฉืžืฉ ื‘ืœื™ื ื•ืงืก.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”