ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.1

ื ืึธืš ื–ืขืงืก ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ื“ืขืจืœืื ื’ื˜ ืžืขืœื“ื•ื ื’ OpenSSH 8.1, ืึทืŸ ืึธืคึฟืŸ ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ื“ื•ืจืš ื“ื™ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืก.

ืกืคึผืขืฆื™ืขืœืข ื•ืคืžืขืจืงื–ืึทืžืงื™ื™ื˜ ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’ ืื™ื– ื“ื™ ื™ืœื™ืžืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื•ื•ืึธืก ืึทืคืขืงืฅ ssh, sshd, ssh-add ืื•ืŸ ssh-keygen. ื“ืขืจ ืคึผืจืึธื‘ืœืขื ืื™ื– ืคืึธืจืฉื˜ืขืœืŸ ืื™ืŸ ื“ื™ ืงืึธื“ ืคึฟืึทืจ ืคึผืึทืจืกื™ื ื’ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ืžื™ื˜ ื“ื™ XMSS ื˜ื™ืคึผ ืื•ืŸ ืึทืœืึทื•ื– ืึท ืึทื˜ืึทืงืขืจ ืฆื• ืฆื™ื ื’ืœ ืึท ื™ื ื˜ืึทื“ื–ืฉืขืจ ืœื•ื™ืคืŸ. ื“ื™ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ื– ืื ื’ืขืฆื™ื™ื›ื ื˜ ื•ื•ื™ ืขืงืกืคึผืœื•ื™ื˜ืึทื‘ืึทืœ, ืึธื‘ืขืจ ืคื•ืŸ ืงืœื™ื™ืŸ ื ื•ืฆืŸ, ื–ื™ื ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ XMSS ืฉืœื™ืกืœืขืŸ ืื™ื– ืึทืŸ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฉื˜ืจื™ืš ื•ื•ืึธืก ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ (ื“ื™ ืคึผืึธืจื˜ืึทื˜ื™ื•ื• ื•ื•ืขืจืกื™ืข ื”ืื˜ ื ื™ืฉื˜ ืืคื™ืœื• ืึท ื‘ื•ื™ืขืŸ ืึธืคึผืฆื™ืข ืื™ืŸ ืึทื•ื˜ืึธืงืึธื ืฃ ืฆื• ื’ืขื‘ืŸ XMSS).

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ืื™ืŸ ssh, sshd ืื•ืŸ ssh-agent ืฆื•ื’ืขื’ืขื‘ืŸ ืงืึธื“ ื•ื•ืึธืก ืคึผืจื™ื•ื•ืขื ืฅ ื“ื™ ืึธืคึผื–ื•ืš ืคื•ืŸ ืึท ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ ืื™ืŸ ื‘ืึทืจืึทืŸ ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื–ื™ื™ึทื˜-ืงืึทื ืึทืœ ืื ืคืืœืŸ, ืึทื–ืึท ื•ื•ื™ ืกืคึผืขืงื˜ืขืจ, ืฆืขืœืึธื–ืŸ, ืจืึธื•ื•ื”ืึทืžืžืขืจ ะธ RAMBleed. ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ื–ืขื ืขืŸ ืื™ืฆื˜ ื™ื ืงืจื™ืคึผื˜ื™ื“ ื•ื•ืขืŸ ืœืึธื•ื“ื™ื“ ืื™ืŸ ื–ื›ึผืจื•ืŸ ืื•ืŸ ื“ืขืงืจื™ืคึผื˜ื™ื“ ื‘ืœื•ื™ื– ื•ื•ืขืŸ ื’ืขื•ื•ื™ื™ื ื˜, ืจื•ืขืŸ ื™ื ืงืจื™ืคึผื˜ื™ื“ ื“ื™ ืจืขืฉื˜ ืคื•ืŸ ื“ื™ ืฆื™ื™ื˜. ืžื™ื˜ ื“ืขื ืฆื•ื’ืึทื ื’, ืฆื• ื”ืฆืœื—ื” ืฆื•ืจื™ืงืงืจื™ื’ืŸ ื“ื™ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœ, ื“ืขืจ ืึทื˜ืึทืงืขืจ ืžื•ื–ืŸ ืขืจืฉื˜ืขืจ ืฆื•ืจื™ืงืงืจื™ื’ืŸ ืึท ืจืึทื ื“ืึทืžืœื™ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื™ื ื˜ืขืจืžื™ื“ื™ื™ื˜ ืฉืœื™ืกืœ ืคื•ืŸ 16 ืงื‘ ืื™ืŸ ื’ืจื™ื™ืก, ื’ืขื ื™ืฆื˜ ืฆื• ืขื ืงืจื™ืคึผื˜ ื“ื™ ื”ื•ื™ืคึผื˜ ืฉืœื™ืกืœ, ื•ื•ืึธืก ืื™ื– ืึทื ืœื™ื™ืงืœื™ ื’ืขื’ืขื‘ืŸ ื“ื™ ืึธืคึผื–ื•ืš ื˜ืขื•ืช ืงื•ืจืก ื˜ื™ืคึผื™ืฉ ืคื•ืŸ ืžืึธื“ืขืจืŸ ืื ืคืืœืŸ;
  • ะ’ ssh-keygen ืฆื•ื’ืขืœื™ื™ื’ื˜ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืึท ืกื™ืžืคึผืœืึทืคื™ื™ื“ ืกื›ืขืžืข ืคึฟืึทืจ ืงืจื™ื™ื™ื˜ื™ื ื’ ืื•ืŸ ื•ื•ืขืจืึทืคื™ื™ื™ื ื’ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื–. ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ืงืขื ืขืŸ ื–ื™ื™ืŸ ื‘ืืฉืืคืŸ ืžื™ื˜ ืจืขื’ื•ืœืขืจ SSH ืฉืœื™ืกืœืขืŸ ืกื˜ืึธืจื“ ืื•ื™ืฃ ื“ื™ืกืง ืึธื“ืขืจ ืื™ืŸ ื“ื™ ssh-ืึทื’ืขื ื˜, ืื•ืŸ ื•ื•ืขืจืึทืคื™ื™ื“ ืžื™ื˜ ืขืคึผืขืก ืขื ืœืขืš ืฆื• Authorized_keys ืจืฉื™ืžื” ืคื•ืŸ ื’ื™ืœื˜ื™ืง ืฉืœื™ืกืœืขืŸ. ื ืึทืžืขืกืคึผืึทืกืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ื– ื’ืขื‘ื•ื™ื˜ ืื™ืŸ ื“ื™ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ืฆืขืžื™ืฉื•ื ื’ ื•ื•ืขืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ื’ืขื‘ื™ื˜ืŸ (ืœืžืฉืœ, ืคึฟืึทืจ E- ื‘ืจื™ื•ื• ืื•ืŸ ื˜ืขืงืขืก);
  • ssh-keygen ืื™ื– ืกื•ื•ื™ื˜ืฉื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ rsa-sha2-512 ืึทืœื’ืขืจื™ื“ืึทื ื•ื•ืขืŸ ื•ื•ืึทืœืึทื“ื™ื™ื˜ื™ื ื’ ืกืขืจื˜ื™ืคื™ืงืึทืฅ ืžื™ื˜ ืึท ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืึท RSA ืฉืœื™ืกืœ (ื•ื•ืขืŸ ืืจื‘ืขื˜ืŸ ืื™ืŸ CA ืžืึธื“ืข). ืึทื–ืึท ืกืขืจื˜ื™ืคื™ืงืึทืฅ ื–ืขื ืขืŸ ื ื™ืฉื˜ ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืžื™ื˜ ืจื™ืœื™ืกื™ื– ืื™ื™ื“ืขืจ OpenSSH 7.2 (ืฆื• ืขื ืฉื•ืจ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™, ื“ื™ ื˜ื™ืคึผ ืคื•ืŸ ืึทืœื’ืขืจื™ื“ืึทื ืžื•ื–ืŸ ื–ื™ื™ืŸ ืึธื•ื•ื•ืขืจืจื™ื™ื“, ืœืžืฉืœ ื“ื•ืจืš ืจื•ืคืŸ "ssh-keygen -t ssh-rsa -s ...");
  • ืื™ืŸ ssh, ื“ื™ ืคึผืจืึธืงืกื™ืงืึธืžืึทื ื“ ืื•ื™ืกื“ืจื•ืง ืื™ืฆื˜ ืฉื˜ื™ืฆื˜ ื™ืงืกืคึผืึทื ืฉืึทืŸ ืคื•ืŸ ื“ื™ "% n" ืกืึทื‘ืกื˜ื™ื˜ื•ืฉืึทืŸ (ื“ื™ ื”ืึธืกื˜ื ืึทืžืข ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ ืึทื“ืจืขืก ื‘ืึทืจ);
  • ืื™ืŸ ื“ื™ ืจืฉื™ืžื•ืช ืคื•ืŸ ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ืคึฟืึทืจ ssh ืื•ืŸ sshd, ืื™ืจ ืงืขื ืขืŸ ืื™ืฆื˜ ื ื•ืฆืŸ ื“ื™ "^" ื›ืึทืจืึทืงื˜ืขืจ ืฆื• ืึทืจื™ื™ึทื ืœื™ื™ื’ืŸ ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืึทืœื’ืขืจื™ื“ืึทืžื–. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืฆื• ืœื™ื™ื’ืŸ ssh-ed25519 ืฆื• ื“ื™ ืคืขืœื™ืงื™ื™ึทื˜ ืจืฉื™ืžื”, ืื™ืจ ืงืขื ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ "HostKeyAlgorithms ^ssh-ed25519";
  • ssh-keygen ื’ื™ื˜ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’ ืึทื˜ืึทื˜ืฉื˜ ืฆื• ื“ื™ ืฉืœื™ืกืœ ื•ื•ืขืŸ ื™ืงืกื˜ืจืึทืงื˜ื™ื ื’ ืึท ืฆื™ื‘ื•ืจ ืฉืœื™ืกืœ ืคื•ืŸ ืึท ืคึผืจื™ื•ื•ืึทื˜ ืื™ื™ื ืขืจ;
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ "-v" ืคืึธืŸ ืื™ืŸ ssh-keygen ื•ื•ืขืŸ ืคึผืขืจืคืึธืจืžื™ื ื’ ืฉืœื™ืกืœ ืœื•ืงืึทืคึผ ืึทืคึผืขืจื™ื™ืฉืึทื ื– (ืœืžืฉืœ, "ssh-keygen -vF host"), ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื•ื•ืึธืก ืจืขื–ื•ืœื˜ืึทื˜ืŸ ืื™ืŸ ืึท ื•ื•ื™ื–ืฉืึทื•ื•ืึทืœ ื‘ืึทืœืขื‘ืึธืก ื›ืกื™ืžืข;
  • ืฆื•ื’ืขื’ืขื‘ืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ PKCS8 ื•ื•ื™ ืึทืŸ ืึธืœื˜ืขืจื ืึทื˜ื™ื•ื• ืคึฟืึธืจืžืึทื˜ ืคึฟืึทืจ ืกื˜ืึธืจื™ื ื’ ืคึผืจื™ื•ื•ืึทื˜ ืฉืœื™ืกืœืขืŸ ืื•ื™ืฃ ื“ื™ืกืง. ื“ื™ PEM ืคึฟืึธืจืžืึทื˜ ื”ืืœื˜ ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ืื•ืŸ PKCS8 ืงืขืŸ ื–ื™ื™ืŸ ื ื•ืฆื™ืง ืคึฟืึทืจ ื“ืขืจื’ืจื™ื™ื›ืŸ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืžื™ื˜ ื“ืจื™ื˜-ืคึผืึทืจื˜ื™ื™ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’