ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.7

ื ืึธืš ืคื™ืจ ื—ื“ืฉื™ื ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’, ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.7, ืึทืŸ ืึธืคึฟืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืื™ื‘ืขืจ ื“ื™ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืก, ืื™ื– ื’ืขื•ื•ืขืŸ ื“ืขืจืœืื ื’ื˜.

ื”ื•ื™ืคึผื˜ ืขื ื“ืขืจื•ื ื’ืขืŸ:

  • ืึทืŸ ื™ืงืกืคึผืขืจืžืขื ืึทืœ ื“ืึทื˜ืŸ ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืžืึธื“ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ืกืงืคึผ ื ื™ืฆืŸ ื“ื™ SFTP ืคึผืจืึธื˜ืึธืงืึธืœ ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ืขื ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ SCP / RCP ืคึผืจืึธื˜ืึธืงืึธืœ. SFTP ื ื™ืฆื˜ ืžืขืจ ืคึผืจื™ื“ื™ืงื˜ืึทื‘ืึทืœ ื ืึธืžืขืŸ ื”ืึทื ื“ืœื™ื ื’ ืžืขื˜ื”ืึธื“ืก ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื ื•ืฆืŸ ืฉืึธืœ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื’ืœืึธื‘ ืคึผืึทื˜ืขืจื ื– ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื‘ืึทืœืขื‘ืึธืก ื–ื™ื™ึทื˜, ื•ื•ืึธืก ืงืจื™ื™ื™ืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก. ืฆื• ื’ืขื‘ืŸ SFTP ืื™ืŸ ืกืงืคึผ, ื“ื™ "-s" ืคืึธืŸ ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜, ืึธื‘ืขืจ ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜ ืขืก ืื™ื– ืคึผืœืึทื ื ืขื“ ืฆื• ื‘ืึทืฉื˜ื™ืžืขืŸ ืฆื• ื“ืขื ืคึผืจืึธื˜ืึธืงืึธืœ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜.
  • sftp-server ื™ืžืคึผืœืึทืžืึทื ืฅ ื™ืงืกื˜ืขื ืฉืึทื ื– ืฆื• ื“ื™ SFTP ืคึผืจืึธื˜ืึธืงืึธืœ ืฆื• ื™ืงืกืคึผืึทื ื“ ื“ื™ ~/ ืื•ืŸ ~ ื‘ืึทื ื™ืฆืขืจ/ ืคึผืึทื˜ืก, ื•ื•ืึธืก ืื™ื– ื ื™ื™ื˜ื™ืง ืคึฟืึทืจ ืกืงืคึผ.
  • ื“ื™ ืกืงืคึผ ื ื•ืฆืŸ ื”ืื˜ ื’ืขื‘ื™ื˜ืŸ ื“ืขื ื ืึทื˜ื•ืจ ื•ื•ืขืŸ ืงืึทืคึผื™ื™ื ื’ ื˜ืขืงืขืก ืฆื•ื•ื™ืฉืŸ ืฆื•ื•ื™ื™ ื•ื•ื™ื™ึทื˜ ืžื—ื ื•ืช (ืœืžืฉืœ, "scp host-a:/path host-b:"), ื•ื•ืึธืก ืื™ื– ืื™ืฆื˜ ื“ื•ืจื›ื’ืขืงืึธื›ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ื“ื•ืจืš ืึท ื™ื ื˜ืขืจืžื™ื“ื™ื™ื˜ ื”ื™ื’ืข ื‘ืึทืœืขื‘ืึธืก, ื•ื•ื™ ื•ื•ืขืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ื“ื™ " -3" ืคืึธืŸ. ื“ืขืจ ืฆื•ื’ืึทื ื’ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ื•ืžื ื™ื™ื˜ื™ืง ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืฆื• ื“ืขืจ ืขืจืฉื˜ืขืจ ื‘ืึทืœืขื‘ืึธืก ืื•ืŸ ื“ืจื™ื™ึทื™ืง ื™ื ื˜ืขืจืคึผืจื™ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื˜ืขืงืข ื ืขืžืขืŸ ืื™ืŸ ื“ื™ ืฉืึธืœ (ืื•ื™ืฃ ื“ืขืจ ืžืงื•ืจ, ื“ืขืกื˜ื™ื ื™ื™ืฉืึทืŸ ืื•ืŸ ื”ื™ื’ืข ืกื™ืกื˜ืขื ื–ื™ื™ึทื˜), ืื•ืŸ ื•ื•ืขืŸ ืื™ืจ ื ื•ืฆืŸ SFTP, ืขืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื ื•ืฆืŸ ืึทืœืข ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ ืžืขื˜ื”ืึธื“ืก ื•ื•ืขืŸ ืึทืงืกืขืกื™ื ื’ ื•ื•ื™ื™ึทื˜. ืžื—ื ื•ืช, ืื•ืŸ ื ื™ื˜ ื ืึธืจ ื ื™ื˜-ื™ื ื˜ืขืจืึทืงื˜ื™ื•ื• ืžืขื˜ื”ืึธื“ืก. ื“ื™ "-ืจ" ืึธืคึผืฆื™ืข ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ื•ืžืงืขืจืŸ ื“ื™ ืึทืœื˜ ื ืึทื˜ื•ืจ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ForkAfterAuthentication ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืฆื• ssh ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืฆื• ื“ื™ "-f" ืคืึธืŸ.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืกื˜ื“ื™ื ื•ืœืœ ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืฆื• ssh, ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืฆื• ื“ื™ "-n" ืคืึธืŸ.
  • ื SessionType ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืื™ื– ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฆื• ssh, ื“ื•ืจืš ื•ื•ืึธืก ืื™ืจ ืงืขื ืขืŸ ืฉื˜ืขืœืŸ ืžืึธื“ืขืก ืงืึธืจืึทืกืคึผืึทื ื“ื™ื ื’ ืฆื• ื“ื™ "-N" (ืงื™ื™ืŸ ืกืขืกื™ืข) ืื•ืŸ "-s" (ืกื•ื‘ืกื™ืกื˜ืขื) ืคืœืึทื’ืก.
  • ssh-keygen ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืึท ืฉืœื™ืกืœ ื’ื™ืœื˜ื™ืงื™ื™ึทื˜ ืžืขื”ืึทืœืขืš ืื™ืŸ ืฉืœื™ืกืœ ื˜ืขืงืขืก.
  • ืฆื•ื’ืขื’ืขื‘ืŸ "-Oprint-pubkey" ืคืึธืŸ ืฆื• ssh-keygen ืฆื• ื“ืจื•ืงืŸ ื“ื™ ืคื•ืœ ืขืคื ื˜ืœืขืš ืฉืœื™ืกืœ ื•ื•ื™ ืึท ื˜ื™ื™ืœ ืคื•ืŸ ื“ื™ sshsig ื›ืกื™ืžืข.
  • ืื™ืŸ ssh ืื•ืŸ sshd, ื‘ื™ื™ื“ืข ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจืก ื–ืขื ืขืŸ ืืจื™ื‘ืขืจื’ืขืคืืจืŸ ืฆื• ื ื•ืฆืŸ ืึท ืžืขืจ ืจื™ืกื˜ืจื™ืงื˜ื™ื•ื• ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืคึผืึทืจืกืขืจ ื•ื•ืึธืก ื ื™ืฆื˜ ืฉืึธืœ-ื•ื•ื™ ื›ึผืœืœื™ื ืคึฟืึทืจ ื”ืึทื ื“ืœื™ื ื’ ืงื•ื•ืึธื˜ืขืก, ืกืคึผื™ื™ืกืึทื– ืื•ืŸ ืึทื ื˜ืœื•ื™ืคืŸ ืื•ืชื™ื•ืช. ื“ืขืจ ื ื™ื™ึทืข ืคึผืึทืจืกืขืจ ืื•ื™ืš ื ื™ืฉื˜ ืื™ื’ื ืึธืจื™ืจืŸ ืคืจื™ืขืจ ื’ืขืžืื›ื˜ ืึทืกืึทืžืคึผืฉืึทื ื–, ืึทื–ืึท ื•ื•ื™ ืึธื•ืžื™ื˜ื™ื ื’ ืึทืจื’ื•ืžืขื ื˜ืŸ ืื™ืŸ ืึธืคึผืฆื™ืขืก (ืœืžืฉืœ, ื“ื™ ื“ืขื ื™ื•ืกืขืจืก ื“ื™ืจืขืงื˜ื™ื•ื• ืงืขื ืขืŸ ื ื™ื˜ ืžืขืจ ื–ื™ื™ืŸ ืœื™ื™ื“ื™ืง), ืึทื ืงืœืึธื•ื–ื“ ืงื•ื•ืึธื˜ืขืก ืื•ืŸ ืกืคึผืขืฆื™ืคื™ืฆื™ืจืŸ ืงื™ื™ืคืœ = ืื•ืชื™ื•ืช.
  • ื•ื•ืขืŸ ื ื™ืฆืŸ SSHFP DNS ืจืขืงืึธืจื“ืก ื•ื•ืขืŸ ื•ื•ืขืจืึทืคื™ื™ื™ื ื’ ืฉืœื™ืกืœืขืŸ, ssh ืื™ืฆื˜ ื˜ืฉืขืงืก ืึทืœืข ื•ื•ืึธืก ืจื™ื›ื˜ืŸ ืจืขืงืึธืจื“ืก, ื ื™ื˜ ื ืึธืจ ื™ืขื ืข ืžื™ื˜ ืึท ืกืคึผืขืฆื™ืคื™ืฉ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ื˜ื™ืคึผ.
  • ืื™ืŸ ssh-keygen, ื•ื•ืขืŸ ื“ื–ืฉืขื ืขืจื™ื™ื˜ื™ื ื’ ืึท FIDO ืฉืœื™ืกืœ ืžื™ื˜ ื“ื™ -Ochallenge ืึธืคึผืฆื™ืข, ื“ื™ ื’ืขื‘ื•ื™ื˜-ืื™ืŸ ืฉื™ื›ื˜ืข ืื™ื– ืื™ืฆื˜ ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื›ืึทืฉื™ื ื’, ืืœื ื•ื•ื™ libfido2, ื•ื•ืึธืก ืึทืœืึทื•ื– ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืึทืจื•ื™ืกืจื•ืคืŸ ืกื™ืงื•ื•ืึทื ืกื™ื– ื’ืจืขืกืขืจ ืึธื“ืขืจ ืงืœืขื ืขืจืขืจ ื•ื•ื™ 32 ื‘ื™ื˜ืขืก.
  • ืื™ืŸ sshd, ื•ื•ืขืŸ ืคึผืจืึทืกืขืกื™ื ื’ ื™ื ื•ื•ื™ื™ืจืึทื ืžืขื ืึทืœ = "..." ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื– ืื™ืŸ Authorized_keys ื˜ืขืงืขืก, ื“ืขืจ ืขืจืฉื˜ืขืจ ื’ืœื™ื™ึทื›ืŸ ืื™ื– ืื™ืฆื˜ ืื ื’ืขื ื•ืžืขืŸ ืื•ืŸ ืขืก ืื™ื– ืึท ืฉื™ืขื•ืจ ืคื•ืŸ 1024 ื™ื ื•ื•ื™ื™ืจืึทื ืžืขื ืึทืœ ื•ื•ืขืจื™ืึทื‘ืึทืœื– ื ืขืžืขืŸ.

ื“ื™ OpenSSH ื“ืขื•ื•ืขืœืึธืคึผืขืจืก ืื•ื™ืš ื’ืขื•ื•ืืจื ื˜ ื•ื•ืขื’ืŸ ื“ื™ ื“ื™ืงืึทืžืคึผืึธื•ื–ื™ืฉืึทืŸ ืคื•ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื– ื ื™ืฆืŸ SHA-1 ื”ืึทืฉืขืก ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขื•ื•ืืงืกืŸ ืขืคืขืงื˜ื™ื•ื•ืงื™ื™ึทื˜ ืคื•ืŸ ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืื ืคืืœืŸ ืžื™ื˜ ืึท ื’ืขื’ืขื‘ืŸ ืคึผืจืขืคื™ืงืก (ื“ื™ ืคึผืจื™ื™ึทื– ืคื•ืŸ ืกืึทืœืขืงื˜ื™ื ื’ ืึท ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืื™ื– ืขืกื˜ื™ืžืึทื˜ืขื“ ืฆื• ื‘ืขืขืจืขืš 50 ื˜ื•ื™ื–ื ื˜ ื“ืึธืœืœืึทืจืก). ืื™ืŸ ื“ืขืจ ื•ื•ื™ื™ึทื˜ืขืจ ืžืขืœื“ื•ื ื’, ืžื™ืจ ืคึผืœืึทืŸ ืฆื• ื“ื™ืกื™ื™ื‘ืึทืœ ื‘ื™ื™ ืคืขืœื™ืงื™ื™ึทื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ ืขืคื ื˜ืœืขืš ืฉืœื™ืกืœ ื“ื™ื’ื™ื˜ืึทืœ ื›ืกื™ืžืข ืึทืœื’ืขืจื™ื“ืึทื "ssh-rsa", ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ื“ืขืจืžืื ื˜ ืื™ืŸ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ RFC ืคึฟืึทืจ ื“ื™ SSH ืคึผืจืึธื˜ืึธืงืึธืœ ืื•ืŸ ืื™ื– ื•ื•ื™ื™ื“ืœื™ ื’ืขื ื™ืฆื˜ ืื™ืŸ ืคื™ืจ.

ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ssh-rsa ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขืžืขืŸ, ืื™ืจ ืงืขื ืขืŸ ืคึผืจื•ื‘ื™ืจืŸ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื•ืจืš ssh ืžื™ื˜ ื“ื™ "-oHostKeyAlgorithms=-ssh-rsa" ืึธืคึผืฆื™ืข. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ื“ื™ืกื™ื™ื‘ืึทืœื™ื ื’ "ืฉืฉ-ืจืกืึท" ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ื˜ื•ื˜ ื ื™ืฉื˜ ืžื™ื™ื ืขืŸ ืึท ืคื•ืœืฉื˜ืขื ื“ื™ืง ืึทื‘ืึทื ื“ืึทื ื™ื™ืฉืึทืŸ ืคื•ืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ RSA ืฉืœื™ืกืœืขืŸ, ื•ื•ื™ื™ึทืœ ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• SHA-1, ื“ื™ SSH ืคึผืจืึธื˜ืึธืงืึธืœ ืึทืœืึทื•ื– ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืื ื“ืขืจืข ื”ืึทืฉ ื›ืขื–ืฉื‘ืŸ ืึทืœื’ืขืจื™ื“ืึทืžื–. ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ืื™ืŸ ืึทื“ื™ืฉืึทืŸ ืฆื• "ืฉืฉ-ืจืกืึท", ืขืก ื•ื•ืขื˜ ื‘ืœื™ื™ื‘ืŸ ืžืขื’ืœืขืš ืฆื• ื ื•ืฆืŸ ื“ื™ "ืจืกืึท-ืฉืึท2-256" (RSA/SHA256) ืื•ืŸ "ืจืกืึท-ืฉืึท2-512" (RSA/SHA512) ืคึผืขืงืœ.

ืฆื• ื’ืœืึทื˜ ื“ื™ ื™ื‘ืขืจื’ืึทื ื’ ืฆื• ื ื™ื™ึทืข ืึทืœื’ืขืจื™ื“ืึทืžื–, OpenSSH ื‘ื™ื– ืึทื”ืขืจ ื”ืื˜ ื“ื™ UpdateHostKeys ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื•ื•ืึธืก ืึทืœืึทื•ื– ืงืœื™ื™ืึทื ืฅ ืฆื• ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ื‘ืึทืฉื˜ื™ืžืขืŸ ืฆื• ืžืขืจ ืคืึทืจืœืึธื–ืœืขืš ืึทืœื’ืขืจื™ื“ืึทืžื–. ื ื™ืฆืŸ ื“ืขื ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ, ืึท ืกืคึผืขืฆื™ืขืœ ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ืื™ื– ืขื ื™ื™ื‘ืึทืœื“ "[ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜]", ืึทืœืึทื•ื™ื ื’ ื“ื™ ืกืขืจื•ื•ืขืจ, ื ืึธืš ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืฆื• ืžื™ื˜ื˜ื™ื™ืœืŸ ื“ืขื ืงืœื™ืขื ื˜ ื•ื•ืขื’ืŸ ืึทืœืข ื‘ื ื™ืžืฆื ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ. ื“ืขืจ ืงืœื™ืขื ื˜ ืงืขื ืขืŸ ืคืึทืจื˜ืจืึทื›ื˜ื  ื–ื™ืš ื“ื™ ืฉืœื™ืกืœืขืŸ ืื™ืŸ ื–ื™ื™ืŸ ~/.ssh/known_hosts ื˜ืขืงืข, ื•ื•ืึธืก ืึทืœืึทื•ื– ื“ืขืจ ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ ืฆื• ื–ื™ื™ืŸ ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืื•ืŸ ืžืื›ื˜ ืขืก ื’ืจื™ื ื’ืขืจ ืฆื• ื˜ื•ื™ืฉืŸ ืฉืœื™ืกืœืขืŸ ืื•ื™ืฃ ื“ื™ ืกืขืจื•ื•ืขืจ.

ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ UpdateHostKeys ืื™ื– ืœื™ืžื™ื˜ืขื“ ื“ื•ืจืš ืขื˜ืœืขื›ืข ืงื™ื™ื•ื•ื™ืึทืฅ ื•ื•ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืึทื•ื•ืขืงื’ืขื ื•ืžืขืŸ ืื™ืŸ ื“ืขืจ ืฆื•ืงื•ื ืคึฟื˜: ื“ืขืจ ืฉืœื™ืกืœ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืจืขืคืขืจืขื ืกื˜ ืื™ืŸ ื“ื™ UserKnownHostsFile ืื•ืŸ ื ื™ืฉื˜ ื’ืขื ื™ืฆื˜ ืื™ืŸ ื“ื™ GlobalKnownHostsFile; ื“ืขืจ ืฉืœื™ืกืœ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืคืึธืจืฉื˜ืขืœืŸ ื‘ืœื•ื™ื– ืื•ื ื˜ืขืจ ืื™ื™ืŸ ื ืึธืžืขืŸ; ืึท ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœ ื‘ืึทื•ื•ื™ื™ึทื–ืŸ ื–ืึธืœ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜; ืื™ืŸ ื‘ืืงืื ื˜_ื”ืึธืกืฅ ืžืึทืกืงืก ื“ื•ืจืš ื‘ืึทืœืขื‘ืึธืก ื ืึธืžืขืŸ ื–ืึธืœ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜; ื“ื™ VerifyHostKeyDNS ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืคืึทืจืงืจื™ืคึผืœื˜; ื“ืขืจ UserKnownHostsFile ืคึผืึทืจืึทืžืขื˜ืขืจ ืžื•ื–ืŸ ื–ื™ื™ืŸ ืึทืงื˜ื™ื•ื•.

ืจืขืงืึทืžืขื ื“ื™ื“ ืึทืœื’ืขืจื™ื“ืึทืžื– ืคึฟืึทืจ ืžื™ื™ื’ืจื™ื™ืฉืึทืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ rsa-sha2-256/512 ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RFC8332 RSA SHA-2 (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 7.2 ืื•ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜), ssh-ed25519 (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 6.5) ืื•ืŸ ecdsa-sha2-nistp256/384 ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RFC521 ECDSA (ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 5656).

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’