ื ืื ืืขืงืก ืืืฉืื ืคืื ืื ืืืืืงืืื ื, ืืื OpenSSH 10.3, ืื ืืคื-ืงืืืื ืืืืคืืขืืขื ืืืฆืืข ืคืื ืขื ืงืืืขื ื, ืืจืืืกืืขืืขืื ืืขืืืืจื. ืกืขืจืืืืจืขืจ ืคึฟืึทืจ ื ืืฆื ืืื SSH 2.0 ืืื SFTP ืคึผืจืึธืืึธืงืึธืื. ืืืืคึผื ืขื ืืขืจืื ืืขื:
- ื ืฉืืืืืงืืื ืืื ืคืืจืจืืืื ืืขืืืืจื ืืืืก ืงืขื ืขืจืืืืื ืื ืืืืงืืจืขืจ ืืื ืงืื ืืจืื ืืืืขืจื ืืื ืืฆืขืจ ื ืืืขื ืืืืก ืืืขืจื ืืขืืขืื ืืืื ืขืคืขื ืขื ืืขื ssh ืืืืืืืื ืฆื ืืขืืืื ืืืืกืคืืจื ืืจืืืืจืืจืข ืฉืึธื ืงืืืื ืืขืก. ืื ืฉืืืืืงืืื ืคืืกืืจื ืืืืฃ ืกืืกืืขืืขื ืืืืก ื ืืฆื ืื "%u" ืกืืืกืืืืืฆืืข ืืื ืืขืืืืกืข ืงืื ืคืืืืจืืฆืืข ืืขืงืข ืืืจืขืงืืืืื, ืืื ืืืฉื "Match exec." ืื ืคืจืืืืขื ืืืขืจื ืืขืคืืจืืื ืืืจื ืื ืืืฉืืขืืืืื ื ืคืื ืกืคืขืฆืืขืืข ืืืชืืืช ืืื ืืขื ืืื ืืฆืขืจ ื ืืืขื ื ืืืืขื ืืืืก %-ืกืืืกืืืืืฆืืขืก ืืืขืจื ืืืจืืืขืคืืจื ืืื ืืขื ssh_config ืงืื ืคืืืืจืืฆืืข ืืขืงืข.
- ื ืืืืขืจืืืื ืคืจืืืืขื ืืื sshd ืืืืก ืืื ืืขืคึฟืืจืืึทืื ืืขืืืึธืจื ืืืจื ืืืืจืขืืืข ืฆืืคึผืึทืกืื ื ืคึฟืื ืืขืจ authorized_keys principals="" ืึธืคึผืฆืืข ืืื ืืขืจ ืจืฉืืื ืคึฟืื ื ืขืืขื (ืคึผืจืื ืฆืืคึผืึทืื) ืืื ืึท ืกืขืจืืืคึฟืืงืึทื ืืืขื ืื ื ืขืืขื ืึทื ืืืึทืืื ืืขื "," ืืึทืจืึทืงืืขืจ ืืื ืคึฟืึทืจืจืืื ืืขืืืึธืจื. ืืืืกื ืืฆื ืื ืืืึทืื ืขืจืึทืืืืืื ืคึฟืึธืืขืจื ืงืืืคื ื ืขืืขื ืกืคึผืขืฆืืคึฟืืฆืืจื ืืื ืืขืจ authorized_keys principals="" ืึธืคึผืฆืืข ืืื ืื CA ืฆื ืึทืจืืืกืืขืื ืึท ืกืขืจืืืคึฟืืงืึทื ืืื ืงืืืคื ื ืขืืขื ืืขืืืืื ืืื ืงืึธืืขืก (ืืึธืก ืืื ื ืึธืจืืึทื ื ืืฉื ืขืจืืืืื). ืื ื ืึทืืืจ ืคึฟืึทืจ ืกืขืจืืืคึฟืืงืึทืื ืืื ืึท ืืืืืืงื ื ืึธืืขื ืืื ืืขืืืื ืืขืืืึธืจื: ืคึฟืจืึดืขืจ, ืืื ืึท ืืืืืืงืขืจ ื ืึธืืขื ืืขืืืขื ืืึทืืขืงื ืืืจื ืึทืืข authorized_keys principals="" ืึธืคึผืฆืืขืก, ืึธืืขืจ ืืืฆื ืืื ืขืก ื ืืฉื ืืึทืืขืงื.
- ืืขืคืืงืกื ืึท ืคึผืจืึธืืืขื ืืื scp ืืืื ืึทืจืืืคึฟืืึธืื ืึท ืืขืงืข ืืื ืืืึธืจืฆื ืืื ืืขืจ -O ืึธืคึผืฆืืข ืืื ืึธื ืืขืจ -p ืึธืคึผืฆืืข ืืืึธืื ื ืืฉื ืืืืกืืขืืขืงื ืื setuid/setgid ืคึฟืึธื ืขื.
- ืืื sshd, ืืื ื ืคืจืืืืขื ืืืื ืืื ืืืขื ืืื ECDSA ืฉืืืกืืขื ืืื ืื PubkeyAcceptedAlgorithms ืืื HostbasedAcceptedAlgorithms ืืืจืขืงืืืืื ืืขืืืืจื ืคืืจืจืืืื, ืฆืืืื ืืขื, ืืืื ืก'ืืื ืืขืืืขื ืกืคืขืฆืืคืืฆืืจื ื ECDSA ืืืืืจืืื (ืืืฉื, "ecdsa-sha2-nistp384"), ืืืขืื ืืืข ืื ืืขืจืข ECDSA-ืืืืืจืืข ืืืืืจืืืืขื ืืืื ืื ืืขื ืืืขื ืืืขืจื, ืืคืืื ืืืื ืืื ืืขื ืขื ื ืืฉื ืงืืืจ ืืืืกืืขืจืขืื ื ืืขืืืืจื ืืืก ืืงืฆืขืคืืืจืืืจ.
- ืืืขื ืืขื ืืื ืืขืจืึทืงืืืจื ืืื SSH ืึทืืขื ืื, ืฉืืืฆื ssh ืืื sshd ืืืฆื ืื ืืืืขื ืืืคืืฆืืจืขืจ (ืงืึธืืคึผืึธืื ืืก) ืืืึธืก ืืขื ืขื ืืขืคืื ืืจื ืืืจื IANA ืืื ืืขืจ draft-ietf-sshm-ssh-agent ืกืคึผืขืฆืืคึฟืืงืึทืฆืืข. ืฉืืืฆืข ืคึฟืึทืจ ืคืจืืขืจ ืืขื ืืฆืืข ืืืืขื ืืืคืืฆืืจืขืจ ืืื "@openssh.com" ืืืขืจื ืืึทืืึทืืื.
- ssh-agent ืืืืคืืขืืขื ืืืจื ืื "query" ืขืงืกืืขื ืฉืึทื, ืืขืคืื ืืจื ืืื ืืขืจ draft-ietf-sshm-ssh-agent ืกืคืขืฆืืคืืงืืฆืืข, ืืืึธืก ืขืจืืืืื ืฆื ืืึทืฉืืืืขื ืื ืคึฟืขืึดืงืืืื ืืืึธืก ืืืขืจื ืืขืฉืืืฆื ืืืจื ืืขื ืึทืืขื ื. ืื "-Q" ืึธืคึผืฆืืข ืืื ืฆืืืขืืขืื ืืขืืืึธืจื ืฆืื ssh-add ืืืืืืึทืื ืฆื ืคืจืขืื ืื ืืืกืืข ืคืื โโืืขืฉืืืฆืืข ืคึผืจืึธืืึธืงืึธื ืขืงืกืืขื ืฉืึทื ื.
- ืืื sshd_config, ืงืขื ืืขื ืกืคืขืฆืืคืืฆืืจื ืงืืืคื ืืขืงืขืก ืืื ืืขืจ RevokedKeys ืืืจืขืงืืืืืข, ืืื ืืื ssh_config, ืงืขื ืืขื ืกืคืขืฆืืคืืฆืืจื ืงืืืคื ืืขืงืขืก ืืื ืืขืจ RevokedHostKeys ืืืจืขืงืืืืืข.
- SSH ืืื ืืืฆื ืื ืขืงืกืขืงืื ืงืืืื ื "~I" ืืื ืื ืืคืฆืืข "-O conninfo" ืฆื ืืืืืื ืืื ืคืืจืืืฆืืข ืืืขืื ืืขืจ ืืืฆืืืืขืจ ืคืืจืืื ืืื ื, ืืื ืืืื ืื ืืคืฆืืข "-O channels" ืฆื ืืืืืื ืืื ืคืืจืืืฆืืข ืืืขืื ืืคืขื ืข ืงืื ืืื.
- ืืื sshd, ืื PerSourcePenalties ืืืจืขืงืืืืืข ื ืขืื ืืขืฆื ืืจืืื ืื 'invaliduser' ืืคืฆืืข ืฆื ืืืืื ืฆื ื ืคืืจืฉืคืขืืืืื ื (ืืขืคืืื 5 ืกืขืงืื ืืขืก) ืืืขื ืืขื ืคืจืืืืจื ืืื ืืจืืื ืฆืืืืื ืืื ื ื ืืฉื-ืขืงืืืกืืืจื ืืืงื ืืื ืืฆืขืจ. ืื ืืขืืืขืืงืืื ืฆื ืกืคืขืฆืืคืืฆืืจื ื ืืฉื-ืืื ืฆืข ืฆืื ืคืืจืฉืคืขืืืืื ื ืืืขืจืื ืืื ืฆืืืขืืขืื ืืขืืืืจื.
- ืื GSSAPIDelegateCredentials ืึธืคึผืฆืืข ืืื ืฆืืืขืืขืื ืืขืืืึธืจื ืฆื sshd ืฆื ืงืึธื ืืจืึธืืืจื ืื ืึทืงืกืขืคึผืืึทื ืก ืคืื ืืขืืขืืืจืืข ืงืจืขืืขื ืฉืึทืื ืฆืืืขืฉืืขืื ืืืจื ืืขื ืงืืืขื ื.
- ssh-keygen ืฉืืืฆื ืืืฆื ืฉืจืืืื ED25519 ืฉืืืกืืขื ืืื PKCS8 ืคึฟืึธืจืืึทื.
- ืฆืืืขืืขืื ืฉืืืฆืข ืคืืจ ืืขืจ ed25519 ืืืืืืืืขืจ ืืื ืืขืจืฉืจืืคื ืกืืขืืข, ืืืืคืืขืืขื ืืืจื ืืืจื libcrypto.
ืืงืืจ: opennet.ru
