ืฉื—ืจื•ืจ ืฉืœ OpenSSH 8.2 ืขื ืชืžื™ื›ื” ื‘ืืกื™ืžื•ื ื™ ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ FIDO/U2F

ืœืื—ืจ ืืจื‘ืขื” ื—ื•ื“ืฉื™ื ืฉืœ ืคื™ืชื•ื— ื”ืฆื™ื’ ืฉื—ืจื•ืจ OpenSSH 8.2, ืžื™ืžื•ืฉ ืœืงื•ื— ื•ืฉืจืช ืคืชื•ื— ืœืขื‘ื•ื“ื” ื‘ืืžืฆืขื•ืช ืคืจื•ื˜ื•ืงื•ืœื™ SSH 2.0 ื•-SFTP.

ืฉื™ืคื•ืจ ืžืจื›ื–ื™ ื‘ืžื”ื“ื•ืจืช OpenSSH 8.2 ื”ื™ื” ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ ื‘ืืžืฆืขื•ืช ืžื›ืฉื™ืจื™ื ื”ืชื•ืžื›ื™ื ื‘ืคืจื•ื˜ื•ืงื•ืœ U2F, ืฉืคื•ืชื— ืขืœ ื™ื“ื™ ื”ื‘ืจื™ืช FIDO. U2F ืžืืคืฉืจ ื™ืฆื™ืจืช ืืกื™ืžื•ื ื™ ื—ื•ืžืจื” ื‘ืขืœื•ืช ื ืžื•ื›ื” ื›ื“ื™ ืœืืžืช ืืช ื”ื ื•ื›ื—ื•ืช ื”ืคื™ื–ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ, ืชื•ืš ืื™ื ื˜ืจืืงืฆื™ื” ืื™ืชื ื‘ืืžืฆืขื•ืช USB, Bluetooth ืื• NFC. ืžื›ืฉื™ืจื™ื ื›ืืœื” ืžืงื•ื“ืžื™ื ื›ืืžืฆืขื™ ืœืื™ืžื•ืช ื“ื•-ื’ื•ืจืžื™ ื‘ืืชืจื™ ืื™ื ื˜ืจื ื˜, ื›ื‘ืจ ื ืชืžื›ื™ื ืขืœ ื™ื“ื™ ื”ื“ืคื“ืคื ื™ื ื”ื’ื“ื•ืœื™ื ื•ืžื™ื•ืฆืจื™ื ืขืœ ื™ื“ื™ ื™ืฆืจื ื™ื ืฉื•ื ื™ื, ื›ื•ืœืœ Yubico, Feitian, Thetis ื•ืงื ืกื™ื ื’ื˜ื•ืŸ.

ื›ื“ื™ ืœื™ืฆื•ืจ ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืžื›ืฉื™ืจื™ื ื”ืžืืฉืจื™ื ืืช ื ื•ื›ื—ื•ืช ื”ืžืฉืชืžืฉ, ื ื•ืกืคื• ืœ-OpenSSH ืกื•ื’ื™ ืžืคืชื—ื•ืช ื—ื“ืฉื™ื "ecdsa-sk" ื•-"ed25519-sk, ื”ืžืฉืชืžืฉื™ื ื‘ืืœื’ื•ืจื™ืชืžื™ ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ECDSA ื•-Ed25519, ื‘ืฉื™ืœื•ื‘ ืขื ื”-hash SHA-256. ื ื”ืœื™ื ืœืื™ื ื˜ืจืืงืฆื™ื” ืขื ืืกื™ืžื•ื ื™ื ืžืžื•ืงืžื™ื ื‘ืกืคืจื™ื™ืช ื‘ื™ื ื™ื™ื, ื”ื ื˜ืขื ืช ื‘ืื•ืคืŸ ื“ื•ืžื” ืœืกืคืจื™ื™ื” ืœืชืžื™ื›ื” ื‘-PKCS#11 ื•ืžื”ื•ื•ื” ืขื˜ื™ืคื” ืขืœ ื’ื‘ื™ ื”ืกืคืจื™ื™ื” libfido2, ื”ืžืกืคืง ื›ืœื™ื ืœืชืงืฉื•ืจืช ืขื ืืกื™ืžื•ื ื™ื ื“ืจืš USB (ื ืชืžื›ื™ื ืคืจื•ื˜ื•ืงื•ืœื™ FIDO U2F/CTAP 1 ื•-FIDO 2.0/CTAP 2). ืกืคืจื™ื™ืช ื‘ื™ื ื™ื™ื libsk-libfido2 ืฉื”ื•ื›ื ื” ืขืœ ื™ื“ื™ ืžืคืชื—ื™ OpenSSH ื›ืœื•ืœ ืœืชื•ืš ื”ืœื™ื‘ื” libfido2, ื›ืžื• ื’ื ืžื ื”ืœ ื”ืชืงืŸ HID ืขื‘ื•ืจ OpenBSD.

ื›ื“ื™ ืœืืžืช ื•ืœื™ืฆื•ืจ ืžืคืชื—, ืขืœื™ืš ืœืฆื™ื™ืŸ ืืช ื”ืคืจืžื˜ืจ "SecurityKeyProvider" ื‘ื”ื’ื“ืจื•ืช ืื• ืœื”ื’ื“ื™ืจ ืืช ืžืฉืชื ื” ื”ืกื‘ื™ื‘ื” SSH_SK_PROVIDER, ื”ืžืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืœืกืคืจื™ื™ื” ื”ื—ื™ืฆื•ื ื™ืช libsk-libfido2.so (ื™ื™ืฆื•ื SSH_SK_PROVIDER=/path/to/libsk-libfido2. ื›ืš). ืืคืฉืจ ืœื‘ื ื•ืช openssh ืขื ืชืžื™ื›ื” ืžื•ื‘ื ื™ืช ื‘ืกืคืจื™ื™ืช ื”ืฉื›ื‘ื•ืช (--with-security-key-builtin), ื‘ืžืงืจื” ื–ื” ืฆืจื™ืš ืœื”ื’ื“ื™ืจ ืืช ื”ืคืจืžื˜ืจ "SecurityKeyProvider=internal".
ืœืื—ืจ ืžื›ืŸ ืขืœื™ืš ืœื”ืคืขื™ืœ ืืช "ssh-keygen -t ecdsa-sk" ืื•, ืื ื”ืžืคืชื—ื•ืช ื›ื‘ืจ ื ื•ืฆืจื• ื•ื”ื•ื’ื“ืจื•, ืœื”ืชื—ื‘ืจ ืœืฉืจืช ื‘ืืžืฆืขื•ืช "ssh". ื›ืืฉืจ ืืชื” ืžืคืขื™ืœ ืืช ssh-keygen, ืฆืžื“ ื”ืžืคืชื—ื•ืช ืฉื ื•ืฆืจ ื™ื™ืฉืžืจ ื‘-"~/.ssh/id_ecdsa_sk" ื•ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื• ื‘ื“ื•ืžื” ืœืžืคืชื—ื•ืช ืื—ืจื™ื.

ื™ืฉ ืœื”ืขืชื™ืง ืืช ื”ืžืคืชื— ื”ืฆื™ื‘ื•ืจื™ (id_ecdsa_sk.pub) ืœืฉืจืช ื‘ืงื•ื‘ืฅ authorized_keys. ื‘ืฆื“ ื”ืฉืจืช, ืจืง ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืžืื•ืžืชืช, ื•ืื™ื ื˜ืจืืงืฆื™ื” ืขื ืืกื™ืžื•ื ื™ื ืžืชื‘ืฆืขืช ื‘ืฆื“ ื”ืœืงื•ื— (ืื™ืŸ ืฆื•ืจืš ืœื”ืชืงื™ืŸ libsk-libfido2 ื‘ืฉืจืช, ืืš ื”ืฉืจืช ื—ื™ื™ื‘ ืœืชืžื•ืš ื‘ืกื•ื’ ื”ืžืคืชื— "ecdsa-sk") . ื”ืžืคืชื— ื”ืคืจื˜ื™ ืฉื ื•ืฆืจ (id_ecdsa_sk) ื”ื•ื ื‘ืขืฆื ื™ื“ื™ืช ืžืคืชื—, ื•ื™ื•ืฆืจ ืžืคืชื— ืืžื™ืชื™ ืจืง ื‘ืฉื™ืœื•ื‘ ืขื ื”ืจืฆืฃ ื”ืกื•ื“ื™ ื”ืžืื•ื—ืกืŸ ื‘ืฆื“ ื”ืืกื™ืžื•ืŸ ืฉืœ U2F. ืื ืžืคืชื— id_ecdsa_sk ื ื•ืคืœ ืœื™ื“ื™ื• ืฉืœ ืชื•ืงืฃ, ื›ื“ื™ ืœืขื‘ื•ืจ ืื™ืžื•ืช ื”ื•ื ื™ืฆื˜ืจืš ืœืงื‘ืœ ื’ื™ืฉื” ื’ื ืœืืกื™ืžื•ืŸ ื”ื—ื•ืžืจื”, ืฉื‘ืœืขื“ื™ื• ื”ืžืคืชื— ื”ืคืจื˜ื™ ื”ืžืื•ื—ืกืŸ ื‘ืงื•ื‘ืฅ id_ecdsa_sk ื—ืกืจ ืชื•ืขืœืช.

ื‘ื ื•ืกืฃ, ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ื‘ืขืช ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ื›ืœืฉื”ืŸ ืขื ืžืงืฉื™ื (ื”ืŸ ื‘ืžื”ืœืš ื”ื™ืฆื™ืจื” ื•ื”ืŸ ื‘ืžื”ืœืš ื”ืื™ืžื•ืช), ื ื“ืจืฉ ืื™ืฉื•ืจ ืžืงื•ืžื™ ืœื ื•ื›ื—ื•ืช ื”ืคื™ื–ื™ืช ืฉืœ ื”ืžืฉืชืžืฉ, ืœืžืฉืœ, ืžื•ืฆืข ืœื’ืขืช ื‘ื—ื™ื™ืฉืŸ ืขืœ ื”ืืกื™ืžื•ืŸ, ืžื” ืฉืžืงืฉื” ืขืœ ืœื‘ืฆืข ื”ืชืงืคื•ืช ืžืจื—ื•ืง ืขืœ ืžืขืจื›ื•ืช ืขื ืืกื™ืžื•ืŸ ืžื—ื•ื‘ืจ. ื›ืงื• ื”ื’ื ื” ื ื•ืกืฃ, ื ื™ืชืŸ ืœืฆื™ื™ืŸ ืกื™ืกืžื” ื’ื ื‘ืฉืœื‘ ื”ืืชื—ื•ืœ ืฉืœ ssh-keygen ื›ื“ื™ ืœื’ืฉืช ืœืงื•ื‘ืฅ ื”ืžืคืชื—.

ื”ื’ืจืกื” ื”ื—ื“ืฉื” ืฉืœ OpenSSH ื’ื ื”ื›ืจื™ื–ื” ืขืœ ื”ื•ืฆืื” ืžืฉื™ืžื•ืฉ ื‘ืงืจื•ื‘ ืฉืœ ืืœื’ื•ืจื™ืชืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-hash SHA-1 ืขืงื‘ ืงื™ื“ื•ื ื”ืืคืงื˜ื™ื‘ื™ื•ืช ืฉืœ ื”ืชืงืคื•ืช ื”ืชื ื’ืฉื•ืช ืขื ืงื™ื“ื•ืžืช ื ืชื•ื ื” (ืขืœื•ืช ื‘ื—ื™ืจืช ื”ืชื ื’ืฉื•ืช ื ืืžื“ืช ื‘ื›-45 ืืœืฃ ื“ื•ืœืจ). ื‘ืื—ืช ื”ืžื”ื“ื•ืจื•ืช ื”ืงืจื•ื‘ื•ืช, ื”ื ืžืชื›ื ื ื™ื ืœื”ืฉื‘ื™ืช ื›ื‘ืจื™ืจืช ืžื—ื“ืœ ืืช ื”ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืืœื’ื•ืจื™ืชื ื”ื—ืชื™ืžื” ื”ื“ื™ื’ื™ื˜ืœื™ืช ืฉืœ ืžืคืชื— ืฆื™ื‘ื•ืจื™ "ssh-rsa", ื”ืžื•ื–ื›ืจ ื‘-RFC ื”ืžืงื•ืจื™ ืขื‘ื•ืจ ืคืจื•ื˜ื•ืงื•ืœ SSH ื•ื ืฉืืจ ื ืคื•ืฅ ื‘ืคื•ืขืœ (ื›ื“ื™ ืœื‘ื“ื•ืง ืืช ื”ืฉื™ืžื•ืฉ ืฉืœ ssh-rsa ื‘ืžืขืจื›ื•ืช ืฉืœืš, ืืชื” ื™ื›ื•ืœ ืœื ืกื•ืช ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช ssh ืขื ื”ืืคืฉืจื•ืช "-oHostKeyAlgorithms=-ssh-rsa").

ื›ื“ื™ ืœื”ื—ืœื™ืง ืืช ื”ืžืขื‘ืจ ืœืืœื’ื•ืจื™ืชืžื™ื ื—ื“ืฉื™ื ื‘-OpenSSH, ื‘ืžื”ื“ื•ืจื” ืขืชื™ื“ื™ืช ื”ื’ื“ืจืช UpdateHostKeys ืชื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, ืฉืชืขื‘ื™ืจ ืื•ื˜ื•ืžื˜ื™ืช ืœืงื•ื—ื•ืช ืœืืœื’ื•ืจื™ืชืžื™ื ืืžื™ื ื™ื ื™ื•ืชืจ. ืืœื’ื•ืจื™ืชืžื™ื ืžื•ืžืœืฆื™ื ืœื”ืขื‘ืจื” ื›ื•ืœืœื™ื rsa-sha2-256/512 ืžื‘ื•ืกืก ืขืœ RFC8332 RSA SHA-2 (ื ืชืžืš ืžืื– OpenSSH 7.2 ื•ืžืฉืžืฉ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ), ssh-ed25519 (ื ืชืžืš ืžืื– OpenSSH 6.5) ื•-ecdsa-sha2-nistp256/384 based ืขืœ RFC521 ECDSA (ื ืชืžืš ืžืื– OpenSSH 5656).

ื‘-OpenSSH 8.2, ื”ื™ื›ื•ืœืช ืœื”ืชื—ื‘ืจ ื‘ืืžืฆืขื•ืช "ssh-rsa" ืขื“ื™ื™ืŸ ื–ืžื™ื ื”, ืืš ืืœื’ื•ืจื™ืชื ื–ื” ื”ื•ืกืจ ืžืจืฉื™ืžืช CASignatureAlgorithms, ื”ืžื’ื“ื™ืจื” ืืช ื”ืืœื’ื•ืจื™ืชืžื™ื ื”ืžื•ืชืจื™ื ืœื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืขืœ ืชืขื•ื“ื•ืช ื—ื“ืฉื•ืช. ื‘ืื•ืคืŸ ื“ื•ืžื”, ื”ืืœื’ื•ืจื™ืชื diffie-hellman-group14-sha1 ื”ื•ืกืจ ืžืืœื’ื•ืจื™ืชืžื™ ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืฉืœ ื”ื—ืœืคืช ืžืคืชื—ื•ืช ื”ื ืชืžื›ื™ื. ื™ืฆื•ื™ืŸ ื›ื™ ื”ืฉื™ืžื•ืฉ ื‘-SHA-1 ื‘ืชืขื•ื“ื•ืช ื›ืจื•ืš ื‘ืกื™ื›ื•ืŸ ื ื•ืกืฃ, ืฉื›ืŸ ืœืชื•ืงืฃ ื™ืฉ ื–ืžืŸ ื‘ืœืชื™ ืžื•ื’ื‘ืœ ืœื—ืคืฉ ื”ืชื ื’ืฉื•ืช ืขื‘ื•ืจ ืชืขื•ื“ื” ืงื™ื™ืžืช, ื‘ืขื•ื“ ืฉื–ืžืŸ ื”ื”ืชืงืคื” ืขืœ ืžืคืชื—ื•ืช ืžืืจื— ืžื•ื’ื‘ืœ ืขืœ ื™ื“ื™ ืคืกืง ื–ืžืŸ ื”ื—ื™ื‘ื•ืจ (LoginGraceTime ).

ื”ืคืขืœืช ssh-keygen ื”ื™ื ื›ืขืช ื‘ืจื™ืจืช ื”ืžื—ื“ืœ ืœืืœื’ื•ืจื™ืชื rsa-sha2-512, ืฉื ืชืžืš ืžืื– OpenSSH 7.2, ืžื” ืฉืขืฉื•ื™ ืœื™ืฆื•ืจ ื‘ืขื™ื•ืช ืชืื™ืžื•ืช ื‘ืขืช ื ื™ืกื™ื•ืŸ ืœืขื‘ื“ ืื™ืฉื•ืจื™ื ื—ืชื•ืžื™ื ื‘-OpenSSH 8.2 ื‘ืžืขืจื›ื•ืช ืฉืžืจื™ืฆื•ืช ืžื”ื“ื•ืจื•ืช OpenSSH ื™ืฉื ื•ืช ื™ื•ืชืจ (ื›ื“ื™ ืœืขืงื•ืฃ ืืช ื”ื‘ืขื™ื” ื›ืืฉืจ ื›ืืฉืจ ืžืชื™ ื™ืฆื™ืจืช ื—ืชื™ืžื”, ืืชื” ื™ื›ื•ืœ ืœืฆื™ื™ืŸ ื‘ืžืคื•ืจืฉ "ssh-keygen -t ssh-rsa" ืื• ืœื”ืฉืชืžืฉ ื‘ืืœื’ื•ืจื™ืชืžื™ื ecdsa-sha2-nistp256/384/521, ื”ื ืชืžื›ื™ื ืžืื– OpenSSH 5.7).

ืฉื™ื ื•ื™ื™ื ื ื•ืกืคื™ื:

  • ื”ื•ืจืืช Include ื ื•ืกืคื” ืœ-sshd_config, ื”ืžืืคืฉืจืช ืœืš ืœื›ืœื•ืœ ืืช ื”ืชื•ื›ืŸ ืฉืœ ืงื‘ืฆื™ื ืื—ืจื™ื ื‘ืžื™ืงื•ื ื”ื ื•ื›ื—ื™ ืฉืœ ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” (ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ืžืกื›ื•ืช ื’ืœื•ื‘ ื‘ืขืช ืฆื™ื•ืŸ ืฉื ื”ืงื•ื‘ืฅ);
  • ืืคืฉืจื•ืช ื”-"no-touch-required" ื ื•ืกืคื” ืœ-ssh-keygen, ืืฉืจ ืžืฉื‘ื™ืชื” ืืช ื”ืฆื•ืจืš ืœืืฉืจ ืคื™ื–ื™ืช ื’ื™ืฉื” ืœืืกื™ืžื•ืŸ ื‘ืขืช โ€‹โ€‹ื™ืฆื™ืจืช ื”ืžืคืชื—;
  • ื”ื•ืจืืช PubkeyAuthOptions ื ื•ืกืคื” ืœ-sshd_config, ื”ืžืฉืœื‘ืช ืืคืฉืจื•ื™ื•ืช ืฉื•ื ื•ืช ื”ืงืฉื•ืจื•ืช ืœืื™ืžื•ืช ืžืคืชื— ืฆื™ื‘ื•ืจื™. ื ื›ื•ืŸ ืœืขื›ืฉื™ื•, ืจืง ื”ื“ื’ืœ "ืœืœื ืžื’ืข ื ื“ืจืฉ" ื ืชืžืš ื›ื“ื™ ืœื“ืœื’ ืขืœ ื‘ื“ื™ืงื•ืช ื ื•ื›ื—ื•ืช ืคื™ื–ื™ื•ืช ืœืื™ืžื•ืช ืืกื™ืžื•ืŸ. ื‘ืื ืœื•ื’ื™ื”, ื”ืืคืฉืจื•ืช "ืœืœื ืžื’ืข-ื ื“ืจืฉ" ื ื•ืกืคื” ืœืงื•ื‘ืฅ authorized_keys;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช "-O write-attestation=/path" ืœ-ssh-keygen ื›ื“ื™ ืœืืคืฉืจ ื›ืชื™ื‘ืช ืื™ืฉื•ืจื™ FIDO ื ื•ืกืคื™ื ื‘ืขืช ื™ืฆื™ืจืช ืžืคืชื—ื•ืช. OpenSSH ืขื“ื™ื™ืŸ ืœื ืžืฉืชืžืฉ ื‘ืชืขื•ื“ื•ืช ืืœื”, ืืš ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื”ืŸ ืžืื•ื—ืจ ื™ื•ืชืจ ื›ื“ื™ ืœื•ื•ื“ื ืฉื”ืžืคืชื— ืžืžื•ืงื ื‘ื—ื ื•ืช ื—ื•ืžืจื” ืžื”ื™ืžื ื”;
  • ื‘ื”ื’ื“ืจื•ืช ssh ื•-sshd, ื›ืขืช ื ื™ืชืŸ ืœื”ื’ื“ื™ืจ ืืช ืžืฆื‘ ืชืขื“ื•ืฃ ื”ืชืขื‘ื•ืจื” ื‘ืืžืฆืขื•ืช ื”ื•ืจืืช IPQoS LE DSCP (ื”ืชื ื”ื’ื•ืช ื ืžื•ื›ื” ื™ื•ืชืจ ืฉืœ ืžืืžืฅ ืคืจ-ื”ื•ืค);
  • ื‘-ssh, ื‘ืขืช ื”ื’ื“ืจืช ื”ืขืจืš "AddKeysToAgent=yes", ืื ื”ืžืคืชื— ืื™ื ื• ืžื›ื™ืœ ืฉื“ื” ื”ืขืจื”, ื”ื•ื ื™ืชื•ื•ืกืฃ ืœ-ssh-agent ื”ืžืฆื™ื™ืŸ ืืช ื”ื ืชื™ื‘ ืœืžืคืชื— ื›ื”ืขืจื”. IN
    ssh-keygen ื•-ssh-agent ืžืฉืชืžืฉื™ื ื›ืขืช ื‘ืชื•ื•ื™ื•ืช PKCS#11 ื•ื‘ืฉื ื”ื ื•ืฉื X.509 ื‘ืžืงื•ื ื‘ื ืชื™ื‘ ื”ืกืคืจื™ื™ื” ื›ื”ืขืจื•ืช ื‘ืžืคืชื—;

  • ื ื•ืกืคื” ืืช ื”ื™ื›ื•ืœืช ืœื™ื™ืฆื PEM ืขื‘ื•ืจ ืžืคืชื—ื•ืช DSA ื•-ECDSA ืœ-ssh-keygen;
  • ื ื•ืกืฃ ืงื•ื‘ืฅ ื”ืคืขืœื” ื—ื“ืฉ, ssh-sk-helper, ื”ืžืฉืžืฉ ืœื‘ื•ื“ื“ ืืช ืกืคืจื™ื™ืช ื”ื’ื™ืฉื” ืœืืกื™ืžื•ื ื™ื FIDO/U2F;
  • ื ื•ืกืคื” ืืคืฉืจื•ืช ื‘ื ื™ื™ื” ืฉืœ "--with-zlib" ืœ-ssh ื•-sshd ืœื”ื™ื“ื•ืจ ืขื ืชืžื™ื›ื” ื‘ืกืคืจื™ื™ืช zlib;
  • ื‘ื”ืชืื ืœื“ืจื™ืฉืช RFC4253, ืื–ื”ืจื” ืœื’ื‘ื™ ื—ืกื™ืžืช ื’ื™ืฉื” ืขืงื‘ ื—ืจื™ื’ื” ืžืžื’ื‘ืœื•ืช MaxStartups ืžืกื•ืคืงืช ื‘ื‘ืื ืจ ื”ืžื•ืฆื’ ื‘ืžื”ืœืš ื”ื—ื™ื‘ื•ืจ. ื›ื“ื™ ืœืคืฉื˜ ืืช ื”ืื‘ื—ื•ืŸ, ื›ื•ืชืจืช ื”ืชื”ืœื™ืš sshd, ื”ื ืจืื™ืช ื‘ืขืช ืฉื™ืžื•ืฉ ื‘ื›ืœื™ ื”ืฉื™ืจื•ืช ps, ืžืฆื™ื’ื” ื›ืขืช ืืช ืžืกืคืจ ื”ื—ื™ื‘ื•ืจื™ื ื”ืžืื•ืžืชื™ื ื›ืขืช ื•ืืช ื”ืžืฆื‘ ืฉืœ ืžื’ื‘ืœืช MaxStartups;
  • ื‘-ssh ื•ื‘-ssh-agent, ื‘ืขืช ืงืจื™ืื” ืœืชื•ื›ื ื™ืช ืœื”ืฆื™ื’ ื”ื–ืžื ื” ืขืœ ื”ืžืกืš, ื”ืžืฆื•ื™ื ืช ื‘ืืžืฆืขื•ืช $SSH_ASKPASS, ื›ืขืช ืžืฉื•ื“ืจ ื‘ื ื•ืกืฃ ื“ื’ืœ ืขื ืกื•ื’ ื”ื”ื–ืžื ื”: "ืื™ืฉื•ืจ" - ืชื™ื‘ืช ืื™ืฉื•ืจ (ื›ืŸ/ืœื), "ืื™ืŸ" " - ื”ื•ื“ืขืช ืžื™ื“ืข, "ืจื™ืง" - ื‘ืงืฉืช ืกื™ืกืžื”;
  • ื ื•ืกืคื” ืคืขื•ืœืช ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ื—ื“ืฉื” "find-principals" ืœ-ssh-keygen ื›ื“ื™ ืœื—ืคืฉ ื‘ืงื•ื‘ืฅ ื”ื—ืชื•ืžื™ื ื”ืžื•ืชืจื™ื ืขื‘ื•ืจ ื”ืžืฉืชืžืฉ ื”ืžืฉื•ื™ืš ืœื—ืชื™ืžื” ื“ื™ื’ื™ื˜ืœื™ืช ืฉืฆื•ื™ื ื”;
  • ืชืžื™ื›ื” ืžืฉื•ืคืจืช ื‘ื‘ื™ื“ื•ื“ ืชื”ืœื™ื›ื™ sshd ื‘-Linux ื‘ืืžืฆืขื•ืช ืžื ื’ื ื•ืŸ seccomp: ื”ืฉื‘ืชืช ืงืจื™ืื•ืช ืžืขืจื›ืช IPC, ืžืชืŸ ืืคืฉืจื•ืช clock_gettime64(), clock_nanosleep_time64 ื•-clock_nanosleep().

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”