De release van OpenSSH 10.1 is gepubliceerd, een open-source implementatie van client en server voor het werken met de SSH 2.0- en SFTP-protocollen.
Belangrijkste wijzigingen:
- Een beveiligingsprobleem is opgelost, waardoor een aanvaller shell-opdrachten kon invoegen via manipulatie van speciale tekens in de gebruikersnaam of URI, die konden worden uitgevoerd bij het uitvoeren van het commando dat was opgegeven via de instelling ‘ProxyCommand’ en dat een substitutie ‘%u’ bevatte. Dit probleem is alleen van toepassing op systemen die bij het starten van ssh de gebruikersnamen of URI's die uit onbetrouwbare bronnen zijn verkregen, toestaan.
Om dergelijke aanvallen te blokkeren, is het gebruik van besturingssymbolen in gebruikersnamen die bij het starten in de opdrachtregel worden opgegeven of in de instellingen worden ingesloten via %-sequenties, verboden. Het gebruik van een null-teken (‘\0’) in ssh:// URI's is ook verboden. Uitzondering is gemaakt voor namen die in het configuratiebestand zijn opgegeven (ervan uitgaande dat de gegevens in het configuratiebestand betrouwbaar zijn).
- In de ssh- en ssh-agent-tools is ondersteuning toegevoegd voor ed25519-sleutels die zijn opgeslagen in PKCS#11-tokens.
- In het configuratiebestand ssh_config is de instelling RefuseConnection toegevoegd, waarbij tijdens de verwerking in de actieve sectie het proces wordt beëindigd met de uitvoer van een foutmelding zonder te proberen verbinding te maken. Match host foo RefuseConnection ‘host foo is niet langer in gebruik, verbind met host bar’
- In ssh en sshd zijn signal handlers voor SIGINFO toegevoegd voor het loggen van sessie-informatie en actieve kanalen.
- In sshd, in het geval dat de authenticatie van een gebruiker via een certificaat wordt afgewezen, wordt er niet alleen een logentry over de reden van het blokkeren van de toegang weergegeven, maar ook uitgebreide informatie voor het identificeren van het problematische certificaat.
- In sshd is een controle van het X11-displaynummer toegevoegd, met betrekking tot de offset die is opgegeven in de X11DisplayOffset-directive.
- De set unit-tests heeft mogelijkheden voor prestatiemetingen gekregen, geactiveerd door ‘make UNITTEST_BENCHMARK=yes’ uit te voeren in OpenBSD of ‘make unit-bench’ in andere systemen.
Veranderingen die potentieel de achterwaartse compatibiliteit kunnen schaden:
- In SSH is added a warning output when connecting with the key agreement algorithm that is not resistant to brute force attacks by quantum computers. The warning is added due to the risk of attacks in the future using previously saved traffic dumps. To disable the warning, the WarnWeakCrypto option has been added in ssh_config. Match host unsafe.example.com WarnWeakCrypto no
- In SSH and SSHD, the processing of DSCP (IPQoS) quality of service parameters has been significantly changed. For interactive traffic, the EF (Expedited Forwarding) class is now set by default for priority handling in wireless networks. For non-interactive traffic, the class used in the operating system is set by default. The traffic class can be changed using the IPQoS settings in ssh_config and sshd_config. The ToS (type-of-service) parameters for IPv4 in the IPQoS directive are deprecated (DSCP has replaced ToS).
- In ssh-add, when adding a certificate to the ssh-agent, the lifetime of the certificate is set to a value 5 minutes longer than the certificate's expiration time (for automatic removal of expired certificates). To disable this behavior in ssh-add, the "-N" option has been added.
- Support for XMSS keys, which was marked experimental and never enabled by default, has been removed.
- Unix sockets created by the ssh-agent and sshd processes have been moved from the /tmp directory to ~/.ssh/agent, which ensures that access through these sockets from isolated processes with restricted filesystem access, but open access to /tmp, is not possible.
In future releases, SHA1 SSHFP DNS records will be deprecated due to issues with the reliability of the SHA1 hash function. These records will be ignored, and the "ssh-keygen -r" command will generate only SHA256 SSHFP records.
Bron: opennet.ru
