OpenSSH 9.2 ืฉื•ื—ืจืจ ืขื ืชื™ืงื•ืŸ ืœืคื’ื™ืขื•ืช ื˜ืจื•ื ืื™ืžื•ืช

ืคื•ืจืกื ื”ืžื”ื“ื•ืจื” ืฉืœ OpenSSH 9.2, ื™ื™ืฉื•ื ืคืชื•ื— ืฉืœ ืœืงื•ื— ื•ืฉืจืช ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP. ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืžื‘ื˜ืœืช ืคื’ื™ืขื•ืช ืฉืžื•ื‘ื™ืœื” ืœืฉื—ืจื•ืจ ื›ืคื•ืœ ืฉืœ ื–ื™ื›ืจื•ืŸ ื‘ืฉืœื‘ ื”ืื™ืžื•ืช ืžืจืืฉ. ืจืง ืžื”ื“ื•ืจืช OpenSSH 9.1 ืžื•ืฉืคืขืช; ื”ื‘ืขื™ื” ืœื ืžื•ืคื™ืขื” ื‘ื’ืจืกืื•ืช ืงื•ื“ืžื•ืช.

ื›ื“ื™ ืœื™ืฆื•ืจ ืชื ืื™ื ืœื‘ื™ื˜ื•ื™ ืฉืœ ืคื’ื™ืขื•ืช, ืžืกืคื™ืง ืœืฉื ื•ืช ืืช ื”ื‘ืื ืจ ืฉืœ ืœืงื•ื— SSH ืœ-"SSH-2.0-FuTTYSH_9.1p1" ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ื”ื“ื’ืœื™ื "SSH_BUG_CURVE25519PAD" ื•-"SSH_OLD_DHGEX", ื”ืชืœื•ื™ื™ื ื‘ื’ืจืกืช ื”-SSH ืœึธืงื•ึผื—ึท. ืœืื—ืจ ื”ื’ื“ืจืช ื”ื“ื’ืœื™ื ื”ืœืœื•, ื”ื–ื™ื›ืจื•ืŸ ืขื‘ื•ืจ ืžืื’ืจ "options.kex_algorithms" ืžืชืคื ื” ืคืขืžื™ื™ื - ื‘ืขืช ื‘ื™ืฆื•ืข ื”ืคื•ื ืงืฆื™ื” do_ssh2_kex() ื”ืงื•ืจืืช compat_kex_proposal(), ื•ื‘ืขืช ื‘ื™ืฆื•ืข ื”ืคื•ื ืงืฆื™ื” do_authentication2() ืืฉืจ ืงื•ืจืืช input_userauth_request(), mm_getpw ), copy_set_server_options() ืœืื•ืจืš ื”ืฉืจืฉืจืช , assemble_algorithms() ื•-kex_assemble_names().

ื™ืฆื™ืจืช ื ื™ืฆื•ืœ ืขื‘ื•ื“ื” ืขื‘ื•ืจ ื”ืคื’ื™ืขื•ืช ื ื—ืฉื‘ืช ื›ื‘ืœืชื™ ืกื‘ื™ืจื”, ืžื›ื™ื•ื•ืŸ ืฉืชื”ืœื™ืš ื”ื ื™ืฆื•ืœ ืžืกื•ื‘ืš ืžื“ื™ - ืกืคืจื™ื•ืช ื”ืงืฆืืช ื–ื™ื›ืจื•ืŸ ืžื•ื“ืจื ื™ื•ืช ืžืกืคืงื•ืช ื”ื’ื ื” ืžืคื ื™ ืฉื—ืจื•ืจ ื›ืคื•ืœ ืฉืœ ื–ื™ื›ืจื•ืŸ, ื•ืชื”ืœื™ืš ื”ืื™ืฉื•ืจ ืžืจืืฉ ืฉื‘ื• ื”ืฉื’ื™ืื” ืงื™ื™ืžืช ืคื•ืขืœ ืขื ื”ืจืฉืื•ืช ืžื•ืคื—ืชื•ืช ื‘ืงื•ื‘ืฅ ืžื‘ื•ื“ื“ ืกื‘ื™ื‘ืช ืืจื’ื– ื—ื•ืœ.

ื‘ื ื•ืกืฃ ืœืคื’ื™ืขื•ืช ืฉืฆื•ื™ื ื”, ื”ืžื”ื“ื•ืจื” ื”ื—ื“ืฉื” ืžืชืงื ืช ื’ื ืฉืชื™ ื‘ืขื™ื•ืช ืื‘ื˜ื—ื” ื ื•ืกืคื•ืช:

  • ืื™ืจืขื” ืฉื’ื™ืื” ื‘ืขืช ืขื™ื‘ื•ื“ ื”ื”ื’ื“ืจื” "PermitRemoteOpen", ืžื” ืฉื’ืจื ืœื”ืชืขืœืžื•ืช ืžื”ืืจื’ื•ืžื ื˜ ื”ืจืืฉื•ืŸ ืื ื”ื•ื ืฉื•ื ื” ืžื”ืขืจื›ื™ื "any" ื•-"none". ื”ื‘ืขื™ื” ืžื•ืคื™ืขื” ื‘ื’ืจืกืื•ืช ื—ื“ืฉื•ืช ื™ื•ืชืจ ืž-OpenSSH 8.7 ื•ื’ื•ืจืžืช ืœื“ื™ืœื•ื’ ืขืœ ื”ืกื™ืžื•ืŸ ื›ืืฉืจ ืฆื•ื™ื ื” ืจืง ื”ืจืฉืื” ืื—ืช.
  • ืชื•ืงืฃ ื”ืฉื•ืœื˜ ื‘ืฉืจืช ื”-DNS ื”ืžืฉืžืฉ ืœืคืชืจื•ืŸ ืฉืžื•ืช ื™ื›ื•ืœ ืœื”ืฉื™ื’ ื”ื—ืœืคื” ืฉืœ ืชื•ื•ื™ื ืžื™ื•ื—ื“ื™ื (ืœื“ื•ื’ืžื”, "*") ืœืงื‘ืฆื™ ื™ื“ื•ืขื™ื_ืžืืจื—ื™ื ืื ื”ืืคืฉืจื•ื™ื•ืช CanonicalizeHostname ื•-CanonicalizePermittedCNAMEs ืžื•ืคืขืœื•ืช ื‘ืชืฆื•ืจื”, ื•ืคื•ืชืจ ื”ืžืขืจื›ืช ืื™ื ื• ื‘ื•ื“ืง ืืช ื ื›ื•ื ื•ืช ืชื’ื•ื‘ื•ืช ืžืฉืจืช ื”-DNS. ื”ื”ืชืงืคื” ื ื—ืฉื‘ืช ืœื ืกื‘ื™ืจื” ืžื›ื™ื•ื•ืŸ ืฉื”ืฉืžื•ืช ื”ืžื•ื—ื–ืจื™ื ื—ื™ื™ื‘ื™ื ืœื”ืชืื™ื ืœืชื ืื™ื ืฉืฆื•ื™ื ื• ื“ืจืš CanonicalizePermittedCNAMEs.

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื:

  • ื”ื’ื“ืจืช EnableEscapeCommandline ื ื•ืกืคื” ืœ-ssh_config ืขื‘ื•ืจ ssh ื›ื“ื™ ืœืฉืœื•ื˜ ืื ืขื™ื‘ื•ื“ ื‘ืฆื“ ื”ืœืงื•ื— ืฉืœ ืจืฆืฃ ื”-escape "~C" ื”ืžืกืคืง ืืช ืฉื•ืจืช ื”ืคืงื•ื“ื” ืžื•ืคืขืœ. ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื”ื˜ื™ืคื•ืœ ื‘-"~C" ืžื•ืฉื‘ืช ื›ืขืช ื›ื“ื™ ืœื”ืฉืชืžืฉ ื‘ื‘ื™ื“ื•ื“ ื”ื“ื•ืง ื™ื•ืชืจ ืฉืœ ืืจื’ื– ื—ื•ืœ, ืฉืขืœื•ืœ ืœืฉื‘ื•ืจ ืžืขืจื›ื•ืช ื”ืžืฉืชืžืฉื•ืช ื‘-"~C" ืœื”ืขื‘ืจืช ื™ืฆื™ืื•ืช ื‘ื–ืžืŸ ืจื™ืฆื”.
  • ื”ื ื—ื™ื™ืช ChannelTimeout ื ื•ืกืคื” ืœ-sshd_config ืขื‘ื•ืจ sshd ื›ื“ื™ ืœื”ื’ื“ื™ืจ ืืช ืคืกืง ื”ื–ืžืŸ ืฉืœ ื—ื•ืกืจ ื”ืคืขื™ืœื•ืช ืฉืœ ื”ืขืจื•ืฅ (ืขืจื•ืฆื™ื ืฉื‘ื”ื ืœื ื ืจืฉืžื” ืชืขื‘ื•ืจื” ื‘ืžืฉืš ื”ื–ืžืŸ ืฉืฆื•ื™ืŸ ื‘ื”ื ื—ื™ื” ื™ื™ืกื’ืจื• ืื•ื˜ื•ืžื˜ื™ืช). ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืคืกืงื™ ื–ืžืŸ ืฉื•ื ื™ื ืขื‘ื•ืจ ื”ืคืขืœื”, X11, ืกื•ื›ืŸ ื•ื”ืคื ื™ื” ืžื—ื“ืฉ ืฉืœ ืชื ื•ืขื”.
  • ื”ื”ื ื—ื™ื” UnusedConnectionTimeout ื ื•ืกืคื” ืœ-sshd_config ืขื‘ื•ืจ sshd, ื•ืžืืคืฉืจืช ืœืš ืœื”ื’ื“ื™ืจ ืคืกืง ื–ืžืŸ ืœืกื™ื•ื ื—ื™ื‘ื•ืจื™ ืœืงื•ื— ืฉื”ื™ื• ืœืœื ืขืจื•ืฆื™ื ืคืขื™ืœื™ื ื‘ืžืฉืš ื–ืžืŸ ืžืกื•ื™ื.
  • ื”ืืคืฉืจื•ืช "-V" ื ื•ืกืคื” ืœ-sshd ื›ื“ื™ ืœื”ืฆื™ื’ ืืช ื”ื’ืจืกื”, ื‘ื“ื•ืžื” ืœืืคืฉืจื•ืช ื”ื“ื•ืžื” ื‘ืœืงื•ื— ssh.
  • ื”ื•ืกืคื” ืืช ื”ืฉื•ืจื” "Host" ืœืคืœื˜ ืฉืœ "ssh -G", ื”ืžืฉืงืคืช ืืช ื”ืขืจืš ืฉืœ ืืจื’ื•ืžื ื˜ ืฉื ื”ืžืืจื—.
  • ื”ืืคืฉืจื•ืช "-X" ื ื•ืกืคื” ืœ-scp ื•ืœ-sftp ื›ื“ื™ ืœืฉืœื•ื˜ ื‘ืคืจืžื˜ืจื™ื ืฉืœ ืคืจื•ื˜ื•ืงื•ืœ SFTP ื›ื’ื•ืŸ ื’ื•ื“ืœ ืžืื’ืจ ื”ื”ืขืชืงื” ื•ืžืกืคืจ ื”ื‘ืงืฉื•ืช ื”ืžืžืชื™ื ื•ืช.
  • ssh-keyscan ืžืืคืฉืจ ืกืจื™ืงื” ืฉืœ ื˜ื•ื•ื—ื™ ื›ืชื•ื‘ื•ืช CIDR ืžืœืื™ื, ืœืžืฉืœ "ssh-keyscan 192.168.0.0/24".

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”