{"id":144216,"date":"2025-10-06T17:11:54","date_gmt":"2025-10-06T15:11:54","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/reliz-openssh-10-1"},"modified":"2025-10-06T17:11:54","modified_gmt":"2025-10-06T15:11:54","slug":"reliz-openssh-10-1","status":"publish","type":"post","link":"https:\/\/prohoster.info\/nl\/blog\/news\/reliz-openssh-10-1","title":{"rendered":"OpenSSH 10.1 vrijgegeven","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>De release van OpenSSH 10.1 is gepubliceerd, een open-source implementatie van client en server voor het werken met de SSH 2.0- en SFTP-protocollen.       <\/p>\n<p>Belangrijkste wijzigingen:      <\/p>\n<ul>\n<li class=\"l\"> Er is een beveiligingsprobleem verholpen waardoor een aanvaller shell-opdrachten kon invoegen via manipulatie van speciale tekens in de gebruikersnaam of URI, die uitgevoerd konden worden bij het uitvoeren van de opdracht gespecificeerd in de 'ProxyCommand'-instelling en die het substitutiepatroon '%u' bevatte. Het probleem doet zich alleen voor op systemen die bij het starten van ssh gebruikersnamen of URI's uit onbetrouwbare bronnen accepteren.\n<p>Om dergelijke aanvallen te voorkomen, is het gebruik van controlekarakters in gebruikersnamen die bij de opstart in de opdrachtregel worden gespecificeerd of die in instellingen via %-sequenties worden vervangen, verboden. Ook is het gebruik van het null- teken ('') in ssh:\/\/ URI's verboden. Uitzondering wordt alleen gemaakt voor namen die in het configuratiebestand zijn opgegeven (ervan uitgaande dat deze configuratiegegevens betrouwbaar zijn).    <\/p>\n<li class=\"l\"> In de ssh- en ssh-agent-tools is ondersteuning toegevoegd voor ed25519-sleutels die zijn opgeslagen in PKCS#11-tokens.\n<li class=\"l\"> De instelling RefuseConnection is toegevoegd aan het ssh_config-configuratiebestand, waarvan de verwerking in de actieve sectie het be\u00ebindigen van het proces zonder poging tot verbinding op basis van een foutmelding omvat. Match host foo RefuseConnection 'host foo is niet meer in gebruik, maak verbinding met host bar'\n<li class=\"l\"> In ssh en sshd zijn signal handlers voor SIGINFO toegevoegd voor het loggen van sessie-informatie en actieve kanalen.\n<li class=\"l\"> In sshd, in het geval dat de authenticatie van een gebruiker via een certificaat wordt afgewezen, wordt er niet alleen een logentry over de reden van het blokkeren van de toegang weergegeven, maar ook uitgebreide informatie voor het identificeren van het problematische certificaat.\n<li class=\"l\"> In sshd is een controle van het X11-displaynummer toegevoegd, met betrekking tot de offset die is opgegeven in de X11DisplayOffset-directive.\n<li class=\"l\"> In de eenheidsproefset zijn prestatiemetingmogelijkheden toegevoegd die worden geactiveerd bij het uitvoeren van 'make UNITTEST_BENCHMARK=yes' in OpenBSD of 'make unit-bench' in andere systemen.  <\/ul>\n<p>Veranderingen die potentieel de achterwaartse compatibiliteit kunnen schaden:  <\/p>\n<ul>\n<li class=\"l\"> In SSH is added a warning output when connecting with the key agreement algorithm that is not resistant to brute force attacks by quantum computers. The warning is added due to the risk of attacks in the future using previously saved traffic dumps. To disable the warning, the WarnWeakCrypto option has been added in ssh_config. Match host unsafe.example.com WarnWeakCrypto no\n<li class=\"l\"> In SSH and SSHD, the processing of DSCP (IPQoS) quality of service parameters has been significantly changed. For interactive traffic, the EF (Expedited Forwarding) class is now set by default for priority handling in wireless networks. For non-interactive traffic, the class used in the operating system is set by default. The traffic class can be changed using the IPQoS settings in ssh_config and sshd_config. The ToS (type-of-service) parameters for IPv4 in the IPQoS directive are deprecated (DSCP has replaced ToS).\n<li class=\"l\"> In ssh-add, bij het toevoegen van een certificaat aan de ssh-agent, is ge\u00efmplementeerd dat de levensduur van het certificaat wordt ingesteld op een waarde die 5 minuten langer is dan de geldigheidsduur van het certificaat (om automatisch het verlopen certificaat te verwijderen). Om dit gedrag in ssh-add uit te schakelen, is de optie '-N' toegevoegd.\n<li class=\"l\"> Support for XMSS keys, which was marked experimental and never enabled by default, has been removed.\n<li class=\"l\"> Unix sockets created by the ssh-agent and sshd processes have been moved from the \/tmp directory to ~\/.ssh\/agent, which ensures that access through these sockets from isolated processes with restricted filesystem access, but open access to \/tmp, is not possible.            <\/ul>\n<p>In toekomstige releases zullen DNS-records SHA1 SSHFP verouderd worden verklaard vanwege problemen met de betrouwbaarheid van de hashfunctie SHA1. Deze records zullen worden genegeerd en het commando 'ssh-keygen -r' zal alleen SHA256 SSHFP-records genereren.<br \/>\n<br \/>Bron: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=64007\">opennet.ru<\/a> <\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP. \u041e\u0441\u043d\u043e\u0432\u043d\u044b\u0435 \u0438\u0437\u043c\u0435\u043d\u0435\u043d\u0438\u044f: \u0423\u0441\u0442\u0440\u0430\u043d\u0435\u043d\u0430 \u043f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0441 \u0431\u0435\u0437\u043e\u043f\u0430\u0441\u043d\u043e\u0441\u0442\u044c\u044e, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0430\u044f \u0430\u0442\u0430\u043a\u0443\u044e\u0449\u0435\u043c\u0443 \u043f\u043e\u0434\u0441\u0442\u0430\u0432\u0438\u0442\u044c shell-\u043a\u043e\u043c\u0430\u043d\u0434\u044b \u0447\u0435\u0440\u0435\u0437 \u043c\u0430\u043d\u0438\u043f\u0443\u043b\u044f\u0446\u0438\u0438 \u0441\u043e \u0441\u043f\u0435\u0446\u0441\u0438\u043c\u0432\u043e\u043b\u0430\u043c\u0438 \u0432 \u0438\u043c\u0435\u043d\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044f \u0438\u043b\u0438 URI, \u043a\u043e\u0442\u043e\u0440\u044b\u0435 \u043c\u043e\u0433\u043b\u0438 \u0431\u044b\u0442\u044c \u0432\u044b\u043f\u043e\u043b\u043d\u0435\u043d\u044b \u043f\u0440\u0438 \u0437\u0430\u043f\u0443\u0441\u043a\u0435 \u043a\u043e\u043c\u0430\u043d\u0434\u044b, \u0443\u043a\u0430\u0437\u0430\u043d\u043d\u043e\u0439 \u0447\u0435\u0440\u0435\u0437 \u043d\u0430\u0441\u0442\u0440\u043e\u0439\u043a\u0443 &#171;ProxyCommand&#187; \u0438 \u0441\u043e\u0434\u0435\u0440\u0436\u0430\u0449\u0435\u0439 \u043f\u043e\u0434\u0441\u0442\u0430\u043d\u043e\u0432\u043a\u0443 &#171;%u&#187;. \u041f\u0440\u043e\u0431\u043b\u0435\u043c\u0430 \u0437\u0430\u0442\u0440\u0430\u0433\u0438\u0432\u0430\u0435\u0442 \u0442\u043e\u043b\u044c\u043a\u043e \u0441\u0438\u0441\u0442\u0435\u043c\u044b, [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-144216","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/nl\/blog\/news\/reliz-openssh-10-1\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"nl_NL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/nl\/blog\/news\/reliz-openssh-10-1\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2025-10-06T15:11:54+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47OpenSSH 10.1 Release | ProHoster","description":"De release van OpenSSH 10.1 is gepubliceerd, een open-source implementatie van client en server voor het werken met de SSH 2.0- en SFTP-protocollen.","canonical_url":"https:\/\/prohoster.info\/nl\/blog\/news\/reliz-openssh-10-1","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"nl_NL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u043b\u0438\u0437 OpenSSH 10.1 | ProHoster","og:description":"\u041e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043d \u0440\u0435\u043b\u0438\u0437 OpenSSH 10.1, \u043e\u0442\u043a\u0440\u044b\u0442\u043e\u0439 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043b\u0438\u0435\u043d\u0442\u0430 \u0438 \u0441\u0435\u0440\u0432\u0435\u0440\u0430 \u0434\u043b\u044f \u0440\u0430\u0431\u043e\u0442\u044b \u043f\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0430\u043c SSH 2.0 \u0438 SFTP.","og:url":"https:\/\/prohoster.info\/nl\/blog\/news\/reliz-openssh-10-1","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2025-10-06T15:11:54+00:00","article:modified_time":"2025-10-06T15:11:54+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"144216","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-23 15:10:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2026-01-23 15:10:23","updated":"2026-01-23 15:10:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/144216","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/comments?post=144216"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/144216\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media?parent=144216"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/categories?post=144216"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/tags?post=144216"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}