ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.5

ื ืึธืš ืคื™ื ืฃ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’, ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.5, ืึทืŸ ืึธืคึฟืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืื™ื‘ืขืจ ื“ื™ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืก, ืื™ื– ื“ืขืจืœืื ื’ื˜.

ื“ื™ OpenSSH ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืจื™ืžื™ื™ื ื“ื™ื“ ืื•ื ื“ื– ืคื•ืŸ ื“ื™ ืึทืคึผืงืึทืžื™ื ื’ ื“ื™ืงืึทืžื™ืฉืึทื ื™ื ื’ ืคื•ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ื ื™ืฆืŸ SHA-1 ื”ืึทืฉืขืก ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขื•ื•ืืงืกืŸ ืขืคืขืงื˜ื™ื•ื•ืงื™ื™ึทื˜ ืคื•ืŸ ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืื ืคืืœืŸ ืžื™ื˜ ืึท ื’ืขื’ืขื‘ืŸ ืคึผืจืขืคื™ืงืก (ื“ื™ ืคึผืจื™ื™ึทื– ืคื•ืŸ ืกืึทืœืขืงื˜ื™ื ื’ ืึท ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืื™ื– ืขืกื˜ื™ืžืึทื˜ืขื“ ืฆื• ื‘ืขืขืจืขืš $ 50 ื˜ื•ื™ื–ื ื˜). ืื™ืŸ ืื™ื™ื ืขืจ ืคื•ืŸ ื“ื™ ืึทืคึผืงืึทืžื™ื ื’ ืจื™ืœื™ืกื™ื–, ื–ื™ื™ ืคึผืœืึทื ื™ืจืŸ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ื‘ื™ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ "ssh-rsa" ืฆื™ื‘ื•ืจ ืฉืœื™ืกืœ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืึทืœื’ืขืจื™ื“ืึทื, ื•ื•ืึธืก ืื™ื– ื“ืขืจืžืื ื˜ ืื™ืŸ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ RFC ืคึฟืึทืจ ื“ื™ SSH ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ื‘ืœื™ื™ื‘ื˜ ื•ื•ื™ื™ื“ืกืคึผืจืขื“ ืื™ืŸ ืคื™ืจ.

ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ssh-rsa ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขืžืขืŸ, ืื™ืจ ืงืขื ืขืŸ ืคึผืจื•ื‘ื™ืจืŸ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื•ืจืš ssh ืžื™ื˜ ื“ื™ "-oHostKeyAlgorithms=-ssh-rsa" ืึธืคึผืฆื™ืข. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ื“ื™ืกื™ื™ื‘ืึทืœื™ื ื’ "ืฉืฉ-ืจืกืึท" ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ื˜ื•ื˜ ื ื™ืฉื˜ ืžื™ื™ื ืขืŸ ืึท ืคื•ืœืฉื˜ืขื ื“ื™ืง ืึทื‘ืึทื ื“ืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ RSA ืฉืœื™ืกืœืขืŸ, ื•ื•ื™ื™ึทืœ ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• SHA-1, ื“ื™ SSH ืคึผืจืึธื˜ืึธืงืึธืœ ืึทืœืึทื•ื– ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืื ื“ืขืจืข ื”ืึทืฉ ื›ืขื–ืฉื‘ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื–. ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• "ืฉืฉ-ืจืกืึท", ืขืก ื•ื•ืขื˜ ื‘ืœื™ื™ื‘ืŸ ืžืขื’ืœืขืš ืฆื• ื ื•ืฆืŸ ื“ื™ "ืจืกืึท-ืฉืึท2-256" (RSA/SHA256) ืื•ืŸ "ืจืกืึท-ืฉืึท2-512" (RSA/SHA512) ืคึผืขืงืœ.

ืฆื• ื’ืœืึทื˜ ื“ื™ ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ื ื™ื™ึทืข ืึทืœื’ืขืจื™ื“ืึทืžื–, OpenSSH 8.5 ื”ืื˜ ื“ื™ UpdateHostKeys ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืœื™ื™ืึทื ืฅ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื‘ืึทืฉื˜ื™ืžืขืŸ ืฆื• ืžืขืจ ืคืึทืจืœืึธื–ืœืขืš ืึทืœื’ืขืจื™ื“ืึทืžื–. ื ื™ืฆืŸ ื“ืขื ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ, ืึท ืกืคึผืขืฆื™ืขืœ ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ "[ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜]", ืึทืœืึทื•ื™ื ื’ ื“ื™ ืกืขืจื•ื•ืขืจ, ื ืึธืš ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืฆื• ืžื™ื˜ื˜ื™ื™ืœืŸ ื“ืขื ืงืœื™ืขื ื˜ ื•ื•ืขื’ืŸ ืึทืœืข ื‘ื ื™ืžืฆื ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ. ื“ืขืจ ืงืœื™ืขื ื˜ ืงืขื ืขืŸ ืคืึทืจื˜ืจืึทื›ื˜ื  ื–ื™ืš ื“ื™ ืฉืœื™ืกืœืขืŸ ืื™ืŸ ื–ื™ื™ืŸ ~/.ssh/known_hosts ื˜ืขืงืข, ื•ื•ืึธืก ืึทืœืึทื•ื– ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ ืฆื• ื–ื™ื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืื•ืŸ ืžืื›ื˜ ืขืก ื’ืจื™ื ื’ืขืจ ืฆื• ื˜ื•ื™ืฉืŸ ืฉืœื™ืกืœืขืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ.

ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ UpdateHostKeys ืื™ื– ืœื™ืžื™ื˜ืขื“ ื“ื•ืจืš ืขื˜ืœืขื›ืข ืงื™ื™ื•ื•ื™ืึทืฅ ื•ื•ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜: ื“ืขืจ ืฉืœื™ืกืœ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืจืขืคืขืจืขื ืกื˜ ืื™ืŸ ื“ื™ UserKnownHostsFile ืื•ืŸ ื ื™ืฉื˜ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ื™ GlobalKnownHostsFile; ื“ืขืจ ืฉืœื™ืกืœ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืคืึธืจืฉื˜ืขืœืŸ ื‘ืœื•ื™ื– ืื•ื ื˜ืขืจ ืื™ื™ืŸ ื ืึธืžืขืŸ; ืึท ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื–ืึธืœ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜; ืื™ืŸ ื‘ืืงืื ื˜_ื”ืึธืกืฅ ืžืึทืกืงืก ื“ื•ืจืš ื‘ืึทืœืขื‘ืึธืก ื ืึธืžืขืŸ ื–ืึธืœ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜; ื“ื™ VerifyHostKeyDNS ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืคืึทืจืงืจื™ืคึผืœื˜; ื“ืขืจ UserKnownHostsFile ืคึผืึทืจืึทืžืขื˜ืขืจ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืึทืงื˜ื™ื•ื•.

ืจืขืงืึทืžืขื ื“ื™ื“ ืึทืœื’ืขืจื™ื“ืึทืžื– ืคึฟืึทืจ ืžื™ื™ื’ืจื™ื™ืฉืึทืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ rsa-sha2-256/512 ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RFC8332 RSA SHA-2 (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 7.2 ืื•ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜), ssh-ed25519 (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 6.5) ืื•ืŸ ecdsa-sha2-nistp256/384 ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RFC521 ECDSA (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 5656).

ืื ื“ืขืจืข ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ื–ื™ื›ืขืจื”ื™ื™ื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:
    • ื ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืฉื™ื™ึทืขืš-ืคืจื™ื™ ืึท ืฉื•ื™ืŸ ื‘ืืคืจื™ื™ื˜ ื–ื›ึผืจื•ืŸ ื’ืขื’ื ื˜ (ื˜ืึธืคึผืœ-ืคืจื™ื™) ืื™ื– ืคืึทืจืคืขืกื˜ื™ืงื˜ ืื™ืŸ ssh-agent. ื“ื™ ืึทืจื•ื™ืกื’ืขื‘ืŸ ืื™ื– ื’ืขื•ื•ืขืŸ ืคืึธืจืฉื˜ืขืœืŸ ื–ื™ื ื˜ ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.2 ืื•ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ืขืงืกืคึผืœื•ื™ื˜ืึทื“ ืื•ื™ื‘ ืึท ืึทื˜ืึทืงืขืจ ื”ืื˜ ืึทืงืกืขืก ืฆื• ื“ื™ ssh-agent ื›ืึธืœืขืœ ืื•ื™ืฃ ื“ื™ ื”ื™ื’ืข ืกื™ืกื˜ืขื. ื•ื•ืึธืก ืžืื›ื˜ ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ืžืขืจ ืฉื•ื•ืขืจ ืื™ื– ืึทื– ื‘ืœื•ื™ื– ื•ื•ืึธืจืฆืœ ืื•ืŸ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ื‘ืึทื ื™ืฆืขืจ ื”ืึธื‘ืŸ ืฆื•ื˜ืจื™ื˜ ืฆื• ื“ื™ ื›ืึธืœืขืœ. ื“ื™ ืžืขืจืกื˜ ืžืกืชึผืžื ื‘ืึทืคืึทืœืŸ ืกืฆืขื ืึทืจ ืื™ื– ืึทื– ื“ืขืจ ืึทื’ืขื ื˜ ืื™ื– ืจื™ื“ืขืจืขืงื˜ื™ื“ ืฆื• ืึท ื—ืฉื‘ื•ืŸ ื•ื•ืึธืก ืื™ื– ืงืึทื ื˜ืจืึธื•ืœื“ ื“ื•ืจืš ื“ื™ ืึทื˜ืึทืงืขืจ, ืึธื“ืขืจ ืฆื• ืึท ื‘ืึทืœืขื‘ืึธืก ื•ื•ื• ื“ืขืจ ืึทื˜ืึทืงืขืจ ื”ืื˜ ื•ื•ืึธืจืฆืœ ืึทืงืกืขืก.
    • sshd ื”ืื˜ ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื•ืฅ ืงืขื’ืŸ ื“ื•ืจื›ืคืึธืจ ื–ื™ื™ืขืจ ื’ืจื•ื™ืก ืคึผืึทืจืึทืžืขื˜ืขืจืก ืžื™ื˜ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ื ืึธืžืขืŸ ืฆื• ื“ื™ PAM ืกืึทื‘ืกื™ืกื˜ืึทื, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึทืจืฉืคึผืึทืจืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ PAM (Pluggable Authentication Module) ืกื™ืกื˜ืขื ืžืึทื“ื–ืฉื•ืœื–. ืฆื•ื ื‘ื™ื™ืฉืคึผื™ืœ, ื“ืขืจ ืขื ื“ืขืจื•ื ื’ ืคึผืจื™ื•ื•ืขื ืฅ sshd ืคื•ืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื•ื•ื™ ืึท ื•ื•ืขืงื˜ืึธืจ ืฆื• ื’ื•ื•ื•ืจืข ืึท ืœืขืฆื˜ื ืก ื“ื™ืกืงืึทื•ื•ืขืจื“ ื•ื•ืึธืจืฆืœ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ ืื™ืŸ ืกืึธืœืึทืจื™ืก (CVE-2020-14871).
  • ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ื‘ืจื™ื™ืงื™ื ื’ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืขื ื“ืขืจื•ื ื’ืขืŸ:
    • ืื™ืŸ ssh ืื•ืŸ sshd, ืึทืŸ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ืฉืœื™ืกืœ ื•ื•ืขืงืกืœ ืื•ืคึฟืŸ ืื™ื– ืจื™ื“ื™ื–ื™ื™ื ื“ ื•ื•ืึธืก ืื™ื– ืงืขื’ื ืฉื˜ืขืœื™ืง ืฆื• ื’ืขืกื™ื ื’ ืื•ื™ืฃ ืึท ืงื•ื•ืึทื ื˜ื•ื ืงืึธืžืคึผื™ื•ื˜ืขืจ. ืงื•ื•ืึทื ื˜ื•ื ืงืึธืžืคึผื™ื•ื˜ืขืจืก ื–ืขื ืขืŸ ืจืึทื“ื™ืงืึทืœืœื™ ืคืึทืกื˜ืขืจ ืื™ืŸ ืกืึทืœื•ื•ื™ื ื’ ื“ื™ ืคึผืจืึธื‘ืœืขื ืคื•ืŸ ื“ื™ืงืึทืžืคึผืึธื•ื–ื™ื ื’ ืึท ื ืึทื˜ื™ืจืœืขืš ื ื•ืžืขืจ ืื™ืŸ ื”ื•ื™ืคึผื˜ ืกื™ื‘ื•ืช, ื•ื•ืึธืก ืึทื ื“ืขืจืœื™ื™ื– ืžืึธื“ืขืจืŸ ืึทืกื™ืžืžืขื˜ืจื™ืง ืขื ืงืจื™ืคึผืฉืึทืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ืื•ืŸ ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื™ืคืขืงื˜ื™ื•ื•ืœื™ ืกืึทืœื•ื•ื“ ืื•ื™ืฃ ืงืœืึทืกื™ืฉ ืคึผืจืึทืกืขืกืขืจื–. ื“ืขืจ ืื•ืคึฟืŸ ื’ืขื ื™ืฆื˜ ืื™ื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ื™ NTRU ืคึผืจื™ื™ื ืึทืœื’ืขืจื™ื“ืึทื, ื“ืขื•ื•ืขืœืึธืคึผืขื“ ืคึฟืึทืจ ืคึผืึธืกื˜-ืงื•ื•ืึทื ื˜ื•ื ืงืจื™ืคึผื˜ืึธืกื™ืกื˜ืขืžืก, ืื•ืŸ ื“ื™ X25519 ื™ืœื™ืคึผื˜ื™ืง ื•ื™ืกื‘ื™ื™ื’ ืฉืœื™ืกืœ ื•ื•ืขืงืกืœ ืื•ืคึฟืŸ. ืื ืฉื˜ืื˜ [ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜] ื“ืขืจ ืื•ืคึฟืŸ ืื™ื– ืื™ืฆื˜ ื™ื™ื“ืขื ืึทืคื™ื™ื“ ื•ื•ื™ [ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜] (ื“ื™ sntrup4591761 ืึทืœื’ืขืจื™ื“ืึทื ืื™ื– ืจื™ืคึผืœื™ื™ืกื˜ ื“ื•ืจืš sntrup761).
    • ืื™ืŸ ssh ืื•ืŸ sshd, ื“ื™ ืกื“ืจ ืื™ืŸ ื•ื•ืึธืก ืฉื˜ื™ืฆื˜ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืึทืœื’ืขืจื™ื“ืึทืžื– ื–ืขื ืขืŸ ืžื•ื“ื™ืข ืื™ื– ืคืืจืขื ื“ืขืจื˜. ED25519 ืื™ื– ืื™ืฆื˜ ื’ืขืคึฟื™ื ื˜ ืขืจืฉื˜ืขืจ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ECDSA.
    • ืื™ืŸ ssh ืื•ืŸ sshd, ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ TOS / DSCP ืงื•ื•ืึทืœื™ื˜ืขื˜ ืคื•ืŸ ื“ื™ื ืกื˜ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืคึฟืึทืจ ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื• ืกืขืฉืึทื ื– ืื™ื– ืื™ืฆื˜ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ืื™ื™ื“ืขืจ ื’ืจื™ื ื“ืŸ ืึท TCP ืคึฟืึทืจื‘ื™ื ื“ื•ื ื’.
    • ืกื™ืคืขืจ ืฉื˜ื™ืฆืŸ ืื™ื– ืึธืคึผื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ssh ืื•ืŸ sshd [ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜], ื•ื•ืึธืก ืื™ื– ื™ื™ื“ืขื ื™ืงืึทืœ ืฆื• aes256-cbc ืื•ืŸ ืื™ื– ื’ืขื ื™ืฆื˜ ืื™ื™ื“ืขืจ RFC-4253 ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ืื•ื•ื™ืœื™ืงื˜.
    • ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื“ื™ CheckHostIP ืคึผืึทืจืึทืžืขื˜ืขืจ ืื™ื– ืคืึทืจืงืจื™ืคึผืœื˜, ื“ื™ ื ื•ืฅ ืคื•ืŸ ื•ื•ืึธืก ืื™ื– ื ืขื’ืœืึทื“ื–ืฉืึทื‘ืึทืœ, ืึธื‘ืขืจ ื“ื™ ื ื•ืฆืŸ ืื™ื– ื‘ืื˜ื™ื™ื˜ื™ืง ืงืึทืžืคึผืœื™ืงื™ื™ืฅ ืฉืœื™ืกืœ ืจืึธื•ื˜ื™ื™ืฉืึทืŸ ืคึฟืึทืจ ืžื—ื ื•ืช ื”ื™ื ื˜ืขืจ ืžืึทืกืข ื‘ืึทืœืึทื ืกืขืจื–.
  • ืคึผืขืจSourceMaxStartups ืื•ืŸ PerSourceNetBlockSize ืกืขื˜ื˜ื™ื ื’ืก ื–ืขื ืขืŸ ืฆื•ื’ืขื’ืขื‘ืŸ ืฆื• sshd ืฆื• ื‘ืึทื’ืจืขื ืขืฆืŸ ื“ื™ ื™ื ื˜ืขื ืกื™ื˜ื™ ืคื•ืŸ ืงืึทื˜ืขืจ ื”ืึทื ื“ืœืขืจืก ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ื“ืขื ืงืœื™ืขื ื˜ ืึทื“ืจืขืก. ื“ื™ ืคึผืึทืจืึทืžืขื˜ืขืจืก ืœืึธื–ืŸ ืื™ืจ ืฆื• ืžืขืจ ืคื™ื™ื ืœื™ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ื“ื™ ืœื™ืžื™ื˜ ืคื•ืŸ ืคึผืจืึธืฆืขืก ืœืึธื ื˜ืฉื™ื–, ืงืึทืžืคึผืขืจื“ ืžื™ื˜ ื“ื™ ืึทืœื’ืขืžื™ื™ื ืข MaxStartups ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ.
  • ื ื ื™ื™ึทืข LogVerbose ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ssh ืื•ืŸ sshd, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืคืึธืจืคืึทืœื™ ืคืึทืจื’ืจืขืกืขืจืŸ ื“ื™ ืžื“ืจื’ื” ืคื•ืŸ ื“ื™ื‘ืึทื’ื™ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื“ืึทืžืคึผื˜ ืื™ืŸ ื“ื™ ืงืœืึธืฅ, ืžื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืคื™ืœื˜ืขืจ ื“ื•ืจืš ื˜ืขืžืคึผืœืึทื˜ืขืก, ืคืึทื ื’ืงืฉืึทื ื– ืื•ืŸ ื˜ืขืงืขืก.
  • ืื™ืŸ ssh, ื•ื•ืขืŸ ืึทืงืกืขืคึผื˜ื™ื ื’ ืึท ื ื™ื™ึทืข ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœ, ืึทืœืข ื”ืึธืกื˜ื ืึทืžืขืก ืื•ืŸ IP ืึทื“ืจืขืกืขืก ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ืขื ืฉืœื™ืกืœ ื–ืขื ืขืŸ ื’ืขื•ื•ื™ื–ืŸ.
  • ssh ืึทืœืึทื•ื– ื“ื™ UserKnownHostsFile=ืงื™ื™ืŸ ืึธืคึผืฆื™ืข ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ื“ื™ known_hosts ื˜ืขืงืข ื•ื•ืขืŸ ืื™ืจ ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ.
  • ื KnownHostsCommand ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ssh_config ืคึฟืึทืจ ssh, ืึทืœืึทื•ื™ื ื’ ืื™ืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื‘ืืงืื ื˜_ื”ืึธืกื˜ืก ื“ืึทื˜ืŸ ืคึฟื•ืŸ ื“ืขืจ ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ื“ื™ ืกืคึผืขืกืึทืคื™ื™ื“ ื‘ืึทืคึฟืขืœ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืึท PermitRemoteOpen ืึธืคึผืฆื™ืข ืฆื• ssh_config ืคึฟืึทืจ ssh ืฆื• ืœืึธื–ืŸ ืื™ืจ ื‘ืึทื’ืจืขื ืขืฆืŸ ื“ื™ ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ื•ื•ืขืŸ ืื™ืจ ื ื•ืฆืŸ ื“ื™ RemoteForward ืึธืคึผืฆื™ืข ืžื™ื˜ SOCKS.
  • ืื™ืŸ ssh ืคึฟืึทืจ FIDO ืฉืœื™ืกืœืขืŸ, ืึท ืจื™ืคึผื™ื˜ื™ื“ PIN ื‘ืขื˜ืŸ ืื™ื– ืฆื•ื’ืขืฉื˜ืขืœื˜ ืื™ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืคื•ืŸ ืึท ื“ื•ืจื›ืคืึทืœ ืคื•ืŸ ืึท ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืึธืคึผืขืจืึทืฆื™ืข ืจืขื›ื˜ ืฆื• ืึท ืคืึทืœืฉ PIN ืื•ืŸ ื“ืขืจ ื‘ืึทื ื™ืฆืขืจ ืื™ื– ื ื™ืฉื˜ ืคึผืจืึทืžืคึผื˜ื™ื“ ืคึฟืึทืจ ืึท PIN (ืœืžืฉืœ, ื•ื•ืขืŸ ื“ื™ ืจื™ื›ื˜ื™ืง ื‘ื™ืึธืžืขื˜ืจื™ืง ื“ืึทื˜ืŸ ืงืขืŸ ื ื™ืฉื˜ ื–ื™ื™ืŸ ื‘ืืงื•ืžืขืŸ ืื•ืŸ ืžื™ื˜ืœ ื’ืขืคืืœืŸ ืฆื•ืจื™ืง ืฆื• ืžืึทื ื•ืึทืœ PIN ืคึผืึธื–ื™ืฆื™ืข).
  • sshd ืžื•ืกื™ืฃ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื ืึธืš ืกื™ืกื˜ืขื ืจื•ืคื˜ ืฆื• ื“ื™ ืกืขืงืึธืžืคึผ-ื‘ืคึผืฃ-ื‘ืื–ื™ืจื˜ ืคึผืจืึธืฆืขืก ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ืžืขืงืึทื ื™ื–ืึทื ืื•ื™ืฃ ืœื™ื ื•ืงืก.
  • ื“ื™ contrib/ssh-copy-id ื ื•ืฆืŸ ืื™ื– ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’