ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 10.3

ื ืืš ื–ืขืงืก ื—ื“ืฉื™ื ืคื•ืŸ ืื ื˜ื•ื•ื™ืงืœื•ื ื’, ืื™ื– OpenSSH 10.3, ืืŸ ืืคืŸ-ืงื•ื•ืืœ ืื™ืžืคืœืขืžืขื ื˜ืืฆื™ืข ืคื•ื ืขื ืงืœื™ืขื ื˜, ืืจื•ื™ืกื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ. ืกืขืจื•ื•ื™ืจืขืจ ืคึฟืึทืจ ื ื•ืฆืŸ ืžื™ื˜ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืŸ. ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ื ืฉื•ื•ืื›ืงื™ื™ื˜ ืื™ื– ืคืืจืจืื›ื˜ืŸ ื’ืขื•ื•ืืจืŸ ื•ื•ืืก ืงืขืŸ ืขืจืœื•ื™ื‘ืŸ ืืŸ ืื˜ืืงื™ืจืขืจ ืžื™ื˜ ืงืื ื˜ืจืืœ ืื™ื‘ืขืจืŸ ื‘ืื ื™ืฆืขืจ ื ืืžืขืŸ ื•ื•ืืก ื•ื•ืขืจื˜ ื’ืขื’ืขื‘ืŸ ื‘ื™ื™ื ืขืคืขื ืขืŸ ื“ืขื ssh ื™ื•ื˜ื™ืœื™ื˜ื™ ืฆื• ืžืขื’ืœื™ืš ืื•ื™ืกืคื™ืจืŸ ืืจื‘ื™ื˜ืจืืจืข ืฉืึธืœ ืงืืžืื ื“ืขืก. ื“ื™ ืฉื•ื•ืื›ืงื™ื™ื˜ ืคืืกื™ืจื˜ ืื•ื™ืฃ ืกื™ืกื˜ืขืžืขืŸ ื•ื•ืืก ื ื™ืฆืŸ ื“ื™ "%u" ืกื•ื‘ืกื˜ื™ื˜ื•ืฆื™ืข ืื™ืŸ ื’ืขื•ื•ื™ืกืข ืงืื ืคื™ื’ื•ืจืืฆื™ืข ื˜ืขืงืข ื“ื™ืจืขืงื˜ื™ื•ื•ืŸ, ื•ื•ื™ ืœืžืฉืœ "Match exec." ื“ื™ ืคืจืื‘ืœืขื ื•ื•ืขืจื˜ ื’ืขืคืืจื–ื›ื˜ ื“ื•ืจืš ื“ื™ ื‘ืืฉื˜ืขื˜ื™ื’ื•ื ื’ ืคื•ืŸ ืกืคืขืฆื™ืขืœืข ืื•ืชื™ื•ืช ืื™ืŸ ื“ืขื ื‘ืื ื™ืฆืขืจ ื ืืžืขืŸ ื ืื›ื“ืขื ื•ื•ืืก %-ืกื•ื‘ืกื˜ื™ื˜ื•ืฆื™ืขืก ื•ื•ืขืจืŸ ื“ื•ืจื›ื’ืขืคื™ืจื˜ ืื™ืŸ ื“ืขื ssh_config ืงืื ืคื™ื’ื•ืจืืฆื™ืข ื˜ืขืงืข.
  • ื ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคืจืื‘ืœืขื ืื™ืŸ sshd ื•ื•ืืก ืื™ื– ื’ืขืคึฟืืจื–ืึทื›ื˜ ื’ืขื•ื•ืึธืจืŸ ื“ื•ืจืš ืื•ืžืจืขื›ื˜ืข ืฆื•ืคึผืึทืกื•ื ื’ ืคึฟื•ืŸ ื“ืขืจ authorized_keys principals="" ืึธืคึผืฆื™ืข ืžื™ื˜ ื“ืขืจ ืจืฉื™ืžื” ืคึฟื•ืŸ ื ืขืžืขืŸ (ืคึผืจื™ื ืฆื™ืคึผืึทืœืŸ) ืื™ืŸ ืึท ืกืขืจื˜ื™ืคึฟื™ืงืึทื˜ ื•ื•ืขืŸ ื“ื™ ื ืขืžืขืŸ ืึทื ื˜ื”ืึทืœื˜ืŸ ื“ืขื "," ื›ืึทืจืึทืงื˜ืขืจ ืื™ื– ืคึฟืึทืจืจื™ื›ื˜ ื’ืขื•ื•ืึธืจืŸ. ืื•ื™ืกื ื™ืฆืŸ ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืคึฟืึธื“ืขืจื˜ ืงื™ื™ืคืœ ื ืขืžืขืŸ ืกืคึผืขืฆื™ืคึฟื™ืฆื™ืจื˜ ืื™ืŸ ื“ืขืจ authorized_keys principals="" ืึธืคึผืฆื™ืข ืื•ืŸ ื“ื™ CA ืฆื• ืึทืจื•ื™ืกื’ืขื‘ืŸ ืึท ืกืขืจื˜ื™ืคึฟื™ืงืึทื˜ ืžื™ื˜ ืงื™ื™ืคืœ ื ืขืžืขืŸ ื’ืขื˜ื™ื™ืœื˜ ืžื™ื˜ ืงืึธืžืขืก (ื“ืึธืก ืื™ื– ื ืึธืจืžืึทืœ ื ื™ืฉื˜ ืขืจืœื•ื™ื‘ื˜). ื“ื™ ื ืึทื˜ื•ืจ ืคึฟืึทืจ ืกืขืจื˜ื™ืคึฟื™ืงืึทื˜ืŸ ืžื™ื˜ ืึท ืœื™ื™ื“ื™ืงืŸ ื ืึธืžืขืŸ ืื™ื– ื’ืขื‘ื™ื˜ืŸ ื’ืขื•ื•ืึธืจืŸ: ืคึฟืจื™ึดืขืจ, ืื™ื– ืึท ืœื™ื™ื“ื™ืงืขืจ ื ืึธืžืขืŸ ื’ืขื•ื•ืขืŸ ื‘ืึทื“ืขืงื˜ ื“ื•ืจืš ืึทืœืข authorized_keys principals="" ืึธืคึผืฆื™ืขืก, ืึธื‘ืขืจ ืื™ืฆื˜ ืื™ื– ืขืก ื ื™ืฉื˜ ื‘ืึทื“ืขืงื˜.
  • ื’ืขืคื™ืงืกื˜ ืึท ืคึผืจืึธื‘ืœืขื ืื™ืŸ scp ื•ื•ืื• ืึทืจื•ื™ืคึฟืœืึธื“ืŸ ืึท ื˜ืขืงืข ื•ื•ื™ ื•ื•ืึธืจืฆืœ ืžื™ื˜ ื“ืขืจ -O ืึธืคึผืฆื™ืข ืื•ืŸ ืึธืŸ ื“ืขืจ -p ืึธืคึผืฆื™ืข ื•ื•ืึธืœื˜ ื ื™ืฉื˜ ืื•ื™ืกื’ืขืžืขืงื˜ ื“ื™ setuid/setgid ืคึฟืึธื ืขืŸ.
  • ืื™ืŸ sshd, ืื™ื– ื ืคืจืื‘ืœืขื ืžื™ื˜ืŸ ื”ืื ื“ืœืขืŸ ืžื™ื˜ ECDSA ืฉืœื™ืกืœืขืŸ ืื™ืŸ ื“ื™ PubkeyAcceptedAlgorithms ืื•ืŸ HostbasedAcceptedAlgorithms ื“ื™ืจืขืงื˜ื™ื•ื•ืŸ ื’ืขื•ื•ืืจืŸ ืคืืจืจืื›ื˜ืŸ, ืฆื•ืœื™ื‘ ื“ืขื, ืื•ื™ื‘ ืก'ืื™ื– ื’ืขื•ื•ืขืŸ ืกืคืขืฆื™ืคื™ืฆื™ืจื˜ ื ECDSA ืืœื’ืืจื™ื˜ื (ืœืžืฉืœ, "ecdsa-sha2-nistp384"), ื•ื•ืขืœืŸ ืืœืข ืื ื“ืขืจืข ECDSA-ื‘ืื–ื™ืจื˜ืข ืืœื’ืืจื™ื˜ืžืขืŸ ืื•ื™ืš ืื ื’ืขื ื•ืžืขืŸ ื•ื•ืขืจืŸ, ืืคื™ืœื• ืื•ื™ื‘ ื–ื™ื™ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืงืœืืจ ืื•ื™ืกื’ืขืจืขื›ื ื˜ ื’ืขื•ื•ืืจืŸ ืืœืก ืืงืฆืขืคื˜ื™ืจื‘ืืจ.
  • ื•ื•ืขืŸ ืžืขืŸ ืื™ื ื˜ืขืจืึทืงื˜ื™ืจื˜ ืžื™ื˜ SSH ืึทื’ืขื ื˜ืŸ, ืฉื˜ื™ืฆืŸ ssh ืื•ืŸ sshd ืื™ืฆื˜ ื“ื™ ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ (ืงืึธื“ืคึผืึธื™ื ื˜ืก) ื•ื•ืึธืก ื–ืขื ืขืŸ ื“ืขืคื™ื ื™ืจื˜ ื“ื•ืจืš IANA ืื™ืŸ ื“ืขืจ draft-ietf-sshm-ssh-agent ืกืคึผืขืฆื™ืคึฟื™ืงืึทืฆื™ืข. ืฉื˜ื™ืฆืข ืคึฟืึทืจ ืคืจื™ืขืจ ื’ืขื ื•ืฆื˜ืข ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืขืจ ื•ื•ื™ "@openssh.com" ื•ื•ืขืจื˜ ื‘ืึทื”ืึทืœื˜ืŸ.
  • ssh-agent ืื™ืžืคืœืขืžืขื ื˜ื™ืจื˜ ื“ื™ "query" ืขืงืกื˜ืขื ืฉืึทืŸ, ื“ืขืคื™ื ื™ืจื˜ ืื™ืŸ ื“ืขืจ draft-ietf-sshm-ssh-agent ืกืคืขืฆื™ืคื™ืงืืฆื™ืข, ื•ื•ืึธืก ืขืจืœื•ื™ื‘ื˜ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ื“ื™ ืคึฟืขื™ึดืงื™ื™ื˜ืŸ ื•ื•ืึธืก ื•ื•ืขืจืŸ ื’ืขืฉื˜ื™ืฆื˜ ื“ื•ืจืš ื“ืขื ืึทื’ืขื ื˜. ื“ื™ "-Q" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื•ื ssh-add ื™ื•ื˜ื™ืœืึทื˜ื™ ืฆื• ืคืจืขื’ืŸ ื“ื™ ืœื™ืกื˜ืข ืคื•ืŸ โ€‹โ€‹ื’ืขืฉื˜ื™ืฆื˜ืข ืคึผืจืึธื˜ืึธืงืึธืœ ืขืงืกื˜ืขื ืฉืึทื ื–.
  • ืื™ืŸ sshd_config, ืงืขืŸ ืžืขืŸ ืกืคืขืฆื™ืคื™ืฆื™ืจืŸ ืงื™ื™ืคืœ ื˜ืขืงืขืก ืื™ืŸ ื“ืขืจ RevokedKeys ื“ื™ืจืขืงื˜ื™ื•ื•ืข, ืื•ืŸ ืื™ืŸ ssh_config, ืงืขืŸ ืžืขืŸ ืกืคืขืฆื™ืคื™ืฆื™ืจืŸ ืงื™ื™ืคืœ ื˜ืขืงืขืก ืื™ืŸ ื“ืขืจ RevokedHostKeys ื“ื™ืจืขืงื˜ื™ื•ื•ืข.
  • SSH ื”ืื˜ ืื™ืฆื˜ ืืŸ ืขืงืกืขืงื•ื˜ ืงืืžืื ื“ "~I" ืื•ืŸ ืืŸ ืืคืฆื™ืข "-O conninfo" ืฆื• ื•ื•ื™ื™ื–ืŸ ืื™ื ืคืืจืžืืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขืจ ืื™ืฆื˜ื™ื’ืขืจ ืคืืจื‘ื™ื ื“ื•ื ื’, ื•ื•ื™ ืื•ื™ืš ืืŸ ืืคืฆื™ืข "-O channels" ืฆื• ื•ื•ื™ื™ื–ืŸ ืื™ื ืคืืจืžืืฆื™ืข ื•ื•ืขื’ืŸ ืืคืขื ืข ืงืื ืืœืŸ.
  • ืื™ืŸ sshd, ื“ื™ PerSourcePenalties ื“ื™ืจืขืงื˜ื™ื•ื•ืข ื ืขืžื˜ ื™ืขืฆื˜ ืืจื™ื™ืŸ ื“ื™ 'invaliduser' ืืคืฆื™ืข ืฆื• ืœื™ื™ื’ืŸ ืฆื• ื ืคืืจืฉืคืขื˜ื™ื’ื•ื ื’ (ื“ืขืคืืœื˜ 5 ืกืขืงื•ื ื“ืขืก) ื•ื•ืขืŸ ืžืขืŸ ืคืจื•ื‘ื™ืจื˜ ื–ื™ืš ืืจื™ื™ื ืฆื•ืœืื’ืŸ ืžื™ื˜ ื ื ื™ืฉื˜-ืขืงื–ื™ืกื˜ื™ืจื ื“ื™ืงืŸ ื‘ืื ื™ืฆืขืจ. ื“ื™ ืžืขื’ืœืขื›ืงื™ื™ื˜ ืฆื• ืกืคืขืฆื™ืคื™ืฆื™ืจืŸ ื ื™ืฉื˜-ื’ืื ืฆืข ืฆืืœ ืคืืจืฉืคืขื˜ื™ื’ื•ื ื’ ื•ื•ืขืจื˜ืŸ ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืืจืŸ.
  • ื“ื™ GSSAPIDelegateCredentials ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขื’ืขื‘ืŸ ื’ืขื•ื•ืึธืจืŸ ืฆื• sshd ืฆื• ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืึทืงืกืขืคึผื˜ืึทื ืก ืคื•ืŸ ื“ืขืœืขื’ื™ืจื˜ืข ืงืจืขื“ืขื ืฉืึทืœื– ืฆื•ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš ื“ืขื ืงืœื™ืขื ื˜.
  • ssh-keygen ืฉื˜ื™ืฆื˜ ืื™ืฆื˜ ืฉืจื™ื™ื‘ืŸ ED25519 ืฉืœื™ืกืœืขืŸ ืื™ืŸ PKCS8 ืคึฟืึธืจืžืึทื˜.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืข ืคืืจ ื“ืขืจ ed25519 ื“ื™ื’ื™ื˜ืืœืขืจ ืื•ื ื˜ืขืจืฉืจื™ืคื˜ ืกื›ืขืžืข, ืื™ืžืคืœืขืžืขื ื˜ื™ืจื˜ ื“ื•ืจืš libcrypto.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’