ืฉื—ืจื•ืจ ืฉืœ OpenSSH 8.9 ืขื ื‘ื™ื˜ื•ืœ ืคื’ื™ืขื•ืช ื‘-sshd

ืœืื—ืจ ืฉื™ืฉื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื—, ื”ื•ืฆื’ื” ื”ืžื”ื“ื•ืจื” ืฉืœ OpenSSH 8.9, ืžื™ืžื•ืฉ ืœืงื•ื— ื•ืฉืจืช ืคืชื•ื— ืœืขื‘ื•ื“ื” ืขืœ ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP. ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืฉืœ sshd ืžืชืงื ืช ืคื’ื™ืขื•ืช ืฉืขืœื•ืœื” ืœืืคืฉืจ ื’ื™ืฉื” ืœื ืžืื•ืžืชืช. ื”ื‘ืขื™ื” ื ื’ืจืžืช ืขืœ ื™ื“ื™ ื”ืฆืคืช ืžืกืคืจื™ื ืฉืœืžื™ื ื‘ืงื•ื“ ื”ืื™ืžื•ืช, ืืš ื ื™ืชืŸ ืœื ืฆืœ ืื•ืชื” ืจืง ื‘ืฉื™ืœื•ื‘ ืขื ืฉื’ื™ืื•ืช ืœื•ื’ื™ื•ืช ืื—ืจื•ืช ื‘ืงื•ื“.

ื‘ืžืชื›ื•ื ืชื” ื”ื ื•ื›ื—ื™ืช, ืœื ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ื›ืืฉืจ ืžืฆื‘ ื”ืคืจื“ืช ื”ื”ืจืฉืื•ืช ืžื•ืคืขืœ, ืฉื›ืŸ ื”ื‘ื™ื˜ื•ื™ ืฉืœื” ื ื—ืกื ืขืœ ื™ื“ื™ ื‘ื“ื™ืงื•ืช ื ืคืจื“ื•ืช ื”ืžื‘ื•ืฆืขื•ืช ื‘ืงื•ื“ ื”ืžืขืงื‘ ืฉืœ ื”ืคืจื“ืช ื”ื”ืจืฉืื•ืช. ืžืฆื‘ ื”ืคืจื“ืช ื”ืจืฉืื•ืช ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืžืื– 2002 ืžืื– OpenSSH 3.2.2, ื•ื”ื™ื” ื—ื•ื‘ื” ืžืื– ืฉื—ืจื•ืจื• ืฉืœ OpenSSH 7.5 ืฉืคื•ืจืกื ื‘-2017. ื‘ื ื•ืกืฃ, ื‘ื’ืจืกืื•ืช ื ื™ื™ื“ื•ืช ืฉืœ OpenSSH ื”ื—ืœ ืžื”ื’ืจืกื” 6.5 (2014), ื”ืคื’ื™ืขื•ืช ื ื—ืกืžืช ืขืœ ื™ื“ื™ ืงื•ืžืคื™ืœืฆื™ื” ืขื ื”ื›ืœืœืช ื“ื’ืœื™ ื”ื’ื ื” ืขืœ ื’ืœื™ืฉื” ืฉืœืžื™ื.

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื:

  • ื”ื’ืจืกื” ื”ื ื™ื™ื“ืช ืฉืœ OpenSSH ื‘-sshd ื”ืกื™ืจื” ืืช ื”ืชืžื™ื›ื” ื”ืžืงื•ืจื™ืช ืœื’ื™ื‘ื•ื‘ ืกื™ืกืžืื•ืช ื‘ืืžืฆืขื•ืช ืืœื’ื•ืจื™ืชื MD5 (ื”ืžืืคืฉืจ ืงื™ืฉื•ืจ ืขื ืกืคืจื™ื•ืช ื—ื™ืฆื•ื ื™ื•ืช ื›ื’ื•ืŸ libxcrypt ืœื—ื–ื•ืจ).
  • ssh, sshd, ssh-add ื•-ssh-agent ืžื™ื™ืฉืžื™ื ืชืช-ืžืขืจื›ืช ื›ื“ื™ ืœื”ื’ื‘ื™ืœ ืืช ื”ื”ืขื‘ืจื” ื•ื”ืฉื™ืžื•ืฉ ื‘ืžืคืชื—ื•ืช ืฉื ื•ืกืคื• ืœ-ssh-agent. ืชืช ื”ืžืขืจื›ืช ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ื›ืœืœื™ื ืฉืงื•ื‘ืขื™ื ื›ื™ืฆื“ ื•ื”ื™ื›ืŸ ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืžืคืชื—ื•ืช ื‘-ssh-agent. ืœื“ื•ื’ืžื”, ื›ื“ื™ ืœื”ื•ืกื™ืฃ ืžืคืชื— ืฉื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ืจืง ื›ื“ื™ ืœืืžืช ื›ืœ ืžืฉืชืžืฉ ืฉืžืชื—ื‘ืจ ืœืžืืจื— scylla.example.org, ื”ืžืฉืชืžืฉ perseus ืœืžืืจื— cetus.example.org, ื•ื”ืžืฉืชืžืฉ medea ืœืžืืจื— charybdis.example.org ืขื ื ื™ืชื•ื‘ ืžื—ื“ืฉ ื“ืจืš ืžืืจื— ื‘ื™ื ื™ื™ื scylla.example.org, ืืชื” ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ื‘ืคืงื•ื“ื” ื”ื‘ืื”: $ ssh-add -h "[ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]ยป \ -h ยซscylla.example.orgยป \ -h ยซscylla.example.org>[ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]ยป \ ~/.ssh/id_ed25519
  • ื‘-ssh ื•-sshd, ืืœื’ื•ืจื™ืชื ื”ื™ื‘ืจื™ื“ื™ ื ื•ืกืฃ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืœืจืฉื™ืžืช KexAlgorithms, ืฉืงื•ื‘ืข ืืช ื”ืกื“ืจ ืฉื‘ื• ื ื‘ื—ืจื•ืช ืฉื™ื˜ื•ืช ื”ื—ืœืคืช ืžืคืชื—.[ืžื•ื’ืŸ ื‘ื“ื•ื"ืœ]"(ECDH/x25519 + NTRU Prime), ืขืžื™ื“ ื‘ืคื ื™ ื‘ื—ื™ืจื” ื‘ืžื—ืฉื‘ื™ื ืงื•ื•ื ื˜ื™ื™ื. ื‘-OpenSSH 8.9, ืฉื™ื˜ืช ื”ืžืฉื ื•ืžืชืŸ ื”ื–ื• ื ื•ืกืคื” ื‘ื™ืŸ ืฉื™ื˜ื•ืช ECDH ื•-DH, ืืš ื”ื™ื ืžืชื•ื›ื ื ืช ืœื”ื™ื•ืช ืžื•ืคืขืœืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ื‘ืžื”ื“ื•ืจื” ื”ื‘ืื”.
  • ssh-keygen, ssh ื•-ssh-agent ืฉื™ืคืจื• ืืช ื”ื˜ื™ืคื•ืœ ื‘ืžืคืชื—ื•ืช ืืกื™ืžื•ืŸ FIDO ื”ืžืฉืžืฉื™ื ืœืื™ืžื•ืช ืžื›ืฉื™ืจ, ื›ื•ืœืœ ืžืคืชื—ื•ืช ืœืื™ืžื•ืช ื‘ื™ื•ืžื˜ืจื™.
  • ื ื•ืกืคื” ืคืงื•ื“ืช "ssh-keygen -Y match-principals" ืœ-ssh-keygen ื›ื“ื™ ืœื‘ื“ื•ืง ืฉืžื•ืช ืžืฉืชืžืฉ ื‘ืงื•ื‘ืฅ ื”- allownamelist.
  • ssh-add ื•-ssh-agent ืžืกืคืงื™ื ืืช ื”ื™ื›ื•ืœืช ืœื”ื•ืกื™ืฃ ืžืคืชื—ื•ืช FIDO ื”ืžื•ื’ื ื™ื ื‘ืงื•ื“ PIN ืœ-ssh-agent (ื‘ืงืฉืช ื”-PIN ืžื•ืฆื’ืช ื‘ื–ืžืŸ ื”ืื™ืžื•ืช).
  • ssh-keygen ืžืืคืฉืจ ื‘ื—ื™ืจื” ื‘ืืœื’ื•ืจื™ืชื hashing (sha512 ืื• sha256) ื‘ืžื”ืœืš ื™ืฆื™ืจืช ื—ืชื™ืžื”.
  • ื‘-ssh ื•-sshd, ื›ื“ื™ ืœืฉืคืจ ืืช ื”ื‘ื™ืฆื•ืขื™ื, ื ืชื•ื ื™ ื”ืจืฉืช ื ืงืจืื™ื ื™ืฉื™ืจื•ืช ืœืžืื’ืจ ืฉืœ ืžื ื•ืช ื ื›ื ืกื•ืช, ืชื•ืš ืขืงื™ืคืช ื—ืฆื™ืฆื” ื‘ื™ื ื™ื™ื ื‘ืขืจื™ืžื”. ืžื™ืงื•ื ื™ืฉื™ืจ ืฉืœ ื”ื ืชื•ื ื™ื ืฉื”ืชืงื‘ืœื• ืœืชื•ืš ืžืื’ืจ ืขืจื•ืฅ ืžื™ื•ืฉื ื‘ืื•ืคืŸ ื“ื•ืžื”.
  • ื‘-ssh, ื”ื•ืจืืช PubkeyAuthentication ื”ืจื—ื™ื‘ื” ืืช ืจืฉื™ืžืช ื”ืคืจืžื˜ืจื™ื ื”ื ืชืžื›ื™ื (yes|no|unbound|host-bound) ื›ื“ื™ ืœืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื‘ื—ื•ืจ ืืช ืกื™ื•ืžืช ื”ืคืจื•ื˜ื•ืงื•ืœ ืœืฉื™ืžื•ืฉ.

ื‘ืžื”ื“ื•ืจื” ืขืชื™ื“ื™ืช, ืื ื• ืžืชื›ื ื ื™ื ืœืฉื ื•ืช ืืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื›ืœื™ ื”ืฉื™ืจื•ืช scp ืœืฉื™ืžื•ืฉ ื‘-SFTP ื‘ืžืงื•ื ื‘ืคืจื•ื˜ื•ืงื•ืœ SCP/RCP ืžื“ื•ืจ ืงื•ื“ื. SFTP ืžืฉืชืžืฉ ื‘ืฉื™ื˜ื•ืช ื˜ื™ืคื•ืœ ืฉืžื•ืช ืฆืคื•ื™ื•ืช ื™ื•ืชืจ ื•ืื™ื ื• ืžืฉืชืžืฉ ื‘ืขื™ื‘ื•ื“ ืžืขื˜ืคืช ืฉืœ ื“ืคื•ืกื™ ื’ืœื•ื‘ ื‘ืฉืžื•ืช ืงื‘ืฆื™ื ื‘ืฆื“ ื”ืžืืจื— ื”ืฉื ื™, ืžื” ืฉื™ื•ืฆืจ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื”. ื‘ืคืจื˜, ื‘ืขืช ืฉื™ืžื•ืฉ ื‘-SCP ื•-RCP, ื”ืฉืจืช ืžื—ืœื™ื˜ ืื™ืœื• ืงื‘ืฆื™ื ื•ืกืคืจื™ื•ืช ืœืฉืœื•ื— ืœืœืงื•ื—, ื•ื”ืœืงื•ื— ื‘ื•ื“ืง ืจืง ืืช ื ื›ื•ื ื•ืช ืฉืžื•ืช ื”ืื•ื‘ื™ื™ืงื˜ื™ื ื”ืžื•ื—ื–ืจื™ื, ืžื” ืฉื‘ื”ื™ืขื“ืจ ื‘ื“ื™ืงื•ืช ืžืชืื™ืžื•ืช ื‘ืฆื“ ื”ืœืงื•ื—, ืžืืคืฉืจ ืืช ืฉืจืช ื›ื“ื™ ืœื”ืขื‘ื™ืจ ืฉืžื•ืช ืงื‘ืฆื™ื ืื—ืจื™ื ื”ืฉื•ื ื™ื ืžืืœื” ื”ืžื‘ื•ืงืฉื™ื. ืœืคืจื•ื˜ื•ืงื•ืœ SFTP ืื™ืŸ ื‘ืขื™ื•ืช ืืœื•, ืืš ืื™ื ื• ืชื•ืžืš ื‘ื”ืจื—ื‘ืช ื ืชื™ื‘ื™ื ืžื™ื•ื—ื“ื™ื ื›ื’ื•ืŸ "~/". ื›ื“ื™ ืœื˜ืคืœ ื‘ื”ื‘ื“ืœ ื”ื–ื”, ื”ืžื”ื“ื•ืจื” ื”ืงื•ื“ืžืช ืฉืœ OpenSSH ื”ืฆื™ื’ื” ื”ืจื—ื‘ื” ื—ื“ืฉื” ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ SFTP ืœื ืชื™ื‘ื™ ~/ ื•~user/ ื‘ื™ื™ืฉื•ื ืฉืจืช SFTP.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”