ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.8 ืžื™ื˜ ื“ื™ืกื™ื™ื‘ืึทืœ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืจืกืึท-ืฉืึท ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื–

ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH 8.8 ืื™ื– ืืจื•ื™ืก, ืึทืŸ ืึธืคึฟืŸ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ืึท ืงืœื™ืขื ื˜ ืื•ืŸ ืกืขืจื•ื•ืขืจ ืคึฟืึทืจ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื“ื™ SSH 2.0 ืื•ืŸ SFTP ืคึผืจืึธื˜ืึธืงืึธืœืก. ื“ื™ ืžืขืœื“ื•ื ื’ ืื™ื– ื ืึธื•ื˜ืึทื‘ืึทืœ ืคึฟืึทืจ ื“ื™ืกื™ื™ื‘ืึทืœื™ื ื’ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ื“ื™ื’ื™ื˜ืึทืœ ืกื™ื’ื ืึทื˜ืฉืขืจื– ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ RSA ืฉืœื™ืกืœืขืŸ ืžื™ื˜ ืึท SHA-1 ื”ืึทืฉ ("ืกืฉ-ืจืกืึท").

ื“ื™ ื•ืคื”ืขืจ ืคื•ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ "ืฉืฉ-ืจืกืึท" ืกื™ื’ื ืึทื˜ืฉืขืจื– ืื™ื– ืจืขื›ื˜ ืฆื• ื“ืขืจ ื’ืขื•ื•ืืงืกืŸ ืขืคืขืงื˜ื™ื•ื•ืงื™ื™ึทื˜ ืคื•ืŸ ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืึทื˜ืึทืงืก ืžื™ื˜ ืึท ื’ืขื’ืขื‘ืŸ ืคึผืจืขืคื™ืงืก (ื“ื™ ืคึผืจื™ื™ึทื– ืคื•ืŸ ืกืึทืœืขืงื˜ื™ื ื’ ืึท ืฆื•ื ื•ื™ืคืฉื˜ื•ื™ืก ืื™ื– ืขืกื˜ื™ืžืึทื˜ืขื“ ื‘ื™ื™ึท ื‘ืขืขืจืขืš $ 50 ื˜ื•ื™ื–ื ื˜). ืฆื• ืคึผืจื•ื‘ื™ืจืŸ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ssh-rsa ืื•ื™ืฃ ื“ื™ื™ืŸ ืกื™ืกื˜ืขืžืขืŸ, ืื™ืจ ืงืขื ืขืŸ ืคึผืจื•ื‘ื™ืจืŸ ืงืึทื ืขืงื˜ื™ื ื’ ื“ื•ืจืš ssh ืžื™ื˜ ื“ื™ "-oHostKeyAlgorithms=-ssh-rsa" ืึธืคึผืฆื™ืข. ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ RSA ืกื™ื’ื ืึทื˜ืฉืขืจื– ืžื™ื˜ SHA-256 ืื•ืŸ SHA-512 ื”ืึทืฉืขืก (rsa-sha2-256/512), ื•ื•ืึธืก ื–ืขื ืขืŸ ื’ืขืฉื˜ื™ืฆื˜ ื–ื™ื ื˜ OpenSSH 7.2, ื‘ืœื™ื™ื‘ื˜ ืึทื ื˜ืฉื™ื™ื ื“ื–ืฉื“.

ืื™ืŸ ืจื•ื‘ึฟ ืคืืœืŸ, ืึธืคึผืฉื˜ืขืœืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ "ssh-rsa" ื•ื•ืขื˜ ื ื™ืฉื˜ ื“ืึทืจืคืŸ ืงื™ื™ืŸ ืžืึทื ื•ืึทืœ ืึทืงืฉืึทื ื– ืคื•ืŸ ื™ื•ื–ืขืจื–, ื–ื™ื ื˜ OpenSSH ื‘ื™ื– ืึทื”ืขืจ ื”ืื˜ ื“ื™ UpdateHostKeys ื‘ืึทืฉื˜ืขื˜ื™ืงืŸ ืขื ื™ื™ื‘ืึทืœื“ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜, ื•ื•ืึธืก ืื•ื™ื˜ืึธืžืึทื˜ื™ืฉ ืžื™ื™ื’ืจื™ื™ื˜ ืงืœื™ื™ืึทื ืฅ ืฆื• ืžืขืจ ืคืึทืจืœืึธื–ืœืขืš ืึทืœื’ืขืจื™ื“ืึทืžื–. ืคึฟืึทืจ ืžื™ื™ื’ืจื™ื™ืฉืึทืŸ, ื“ื™ ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจืœืขื ื’ืขืจื•ื ื’ "[ืื™ืžืขื™ืœ ื‘ืืฉื™ืฆื˜]", ืึทืœืึทื•ื™ื ื’ ื“ื™ ืกืขืจื•ื•ืขืจ, ื ืึธืš ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ, ืฆื• ืžื™ื˜ื˜ื™ื™ืœืŸ ื“ืขื ืงืœื™ืขื ื˜ ื•ื•ืขื’ืŸ ืึทืœืข ื‘ื ื™ืžืฆื ื‘ืึทืœืขื‘ืึธืก ืฉืœื™ืกืœืขืŸ. ืื™ืŸ ืคืึทืœ ืคื•ืŸ ืงืึทื ืขืงื˜ื™ื ื’ ืฆื• ื”ืึธืกืฅ ืžื™ื˜ ื–ื™ื™ืขืจ ืึทืœื˜ ื•ื•ืขืจืกื™ืขืก ืคื•ืŸ OpenSSH ืื•ื™ืฃ ื“ื™ ืงืœื™ืขื ื˜ ื–ื™ื™ึทื˜, ืื™ืจ ืงืขื ืขืŸ ืกืึทืœืขืงื˜ื™ื•ื•ืœื™ ืฆื•ืจื™ืงืงื•ืžืขืŸ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ "ssh-rsa" ืกื™ื’ื ืึทื˜ืฉืขืจื– ื“ื•ืจืš ืึทื“ื™ื ื’ ืฆื• ~/.ssh/config: ื”ืึธืกื˜ ืึทืœื˜_ื”ืึธืกื˜ื ืึทืžืข HostkeyAlgorithms +ssh-rsa PubkeyAcceptedAlgorithms + ssh-rsa

ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข ืื•ื™ืš ืกืึทืœื•ื•ื– ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึทืจื•ื™ืกื’ืขื‘ืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš sshd, ืกื˜ืึทืจื˜ื™ื ื’ ืžื™ื˜ OpenSSH 6.2, ื ื™ื˜ ืจืขื›ื˜ ื™ื ื™ื˜ื™ืึทืœื™ื™ื–ื™ื ื’ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ื’ืจื•ืคึผืข ื•ื•ืขืŸ ืขืงืกืึทืงื™ื•ื˜ื™ื ื’ ืงืึทืžืึทื ื“ื– ืกืคึผืขืกื™ืคื™ืขื“ ืื™ืŸ ื“ื™ AuthorizedKeysCommand ืื•ืŸ AuthorizedPrincipalsCommand ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื–. ื“ื™ ื“ื™ื™ืจืขืงื˜ื™ื•ื•ื– ื–ืขื ืขืŸ ื’ืขืžื™ื™ื ื˜ ืฆื• ืœืึธื–ืŸ ืงืึทืžืึทื ื“ื– ืœื•ื™ืคืŸ ืื•ื ื˜ืขืจ ืึท ืึทื ื“ืขืจืฉ ื‘ืึทื ื™ืฆืขืจ, ืึธื‘ืขืจ ืื™ืŸ ืคืึทืงื˜ ื–ื™ื™ ื™ื ื›ืขืจืึทื˜ื™ื“ ื“ื™ ืจืฉื™ืžื” ืคื•ืŸ ื’ืจื•ืคึผืขืก ื’ืขื ื™ืฆื˜ ื•ื•ืขืŸ ืคืœื™ืกื ื“ื™ืง sshd. ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™, ื“ืขื ื ืึทื˜ื•ืจ, ืื™ืŸ ื“ืขื ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ื–ื™ื›ืขืจ ืกื™ืกื˜ืขื ืกืขื˜ื˜ื™ื ื’ืก, ืขืจืœื•ื™ื‘ื˜ ื“ื™ ืœืึธื ื˜ืฉื˜ ื”ืึทื ื“ืœืขืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื ืึธืš ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื– ืื•ื™ืฃ ื“ื™ ืกื™ืกื˜ืขื.

ื“ื™ ื ื™ื™ึทืข ืžืขืœื“ื•ื ื’ ื˜ืึธืŸ ืื•ื™ืš ื›ื•ืœืœ ืึท ื•ื•ืืจืขื ื•ื ื’ ืึทื– ืกืงืคึผ ื•ื•ืขื˜ ืคืขืœื™ืงื™ื™ึทื˜ ืฆื• SFTP ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื“ื™ ืœืขื’ืึทื˜ SCP / RCP ืคึผืจืึธื˜ืึธืงืึธืœ. SFTP ื ื™ืฆื˜ ืžืขืจ ืคึผืจื™ื“ื™ืงื˜ืึทื‘ืึทืœ ื ืึธืžืขืŸ ื”ืึทื ื“ืœื™ื ื’ ืžืขื˜ื”ืึธื“ืก ืื•ืŸ ื˜ื•ื˜ ื ื™ืฉื˜ ื ื•ืฆืŸ ืฉืึธืœ ืคึผืจืึทืกืขืกื™ื ื’ ืคื•ืŸ ื’ืœืึธื‘ ืคึผืึทื˜ืขืจื ื– ืื™ืŸ ื˜ืขืงืข ื ืขืžืขืŸ ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื‘ืึทืœืขื‘ืึธืก ื–ื™ื™ึทื˜, ื•ื•ืึธืก ืงืจื™ื™ื™ืฅ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืคึผืจืึธื‘ืœืขืžืก. ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ, ื•ื•ืขืŸ ื ื™ืฆืŸ SCP ืื•ืŸ RCP, ื“ืขืจ ืกืขืจื•ื•ืขืจ ื“ื™ืกื™ื™ื“ื– ื•ื•ืึธืก ื˜ืขืงืขืก ืื•ืŸ ื“ื™ืจืขืงื˜ืขืจื™ื– ืฆื• ืฉื™ืงืŸ ืฆื• ื“ืขื ืงืœื™ืขื ื˜, ืื•ืŸ ื“ืขืจ ืงืœื™ืขื ื˜ ื ืึธืจ ื˜ืฉืขืงืก ื“ื™ ืงืขืจืขืงื˜ื ืึทืก ืคื•ืŸ ื“ื™ ืื•ืžื’ืขืงืขืจื˜ ืึทื‘ื“ื–ืฉืขืงืฅ ื ืขืžืขืŸ, ื•ื•ืึธืก, ืื™ืŸ ื“ืขืจ ืึทื•ื•ืขืง ืคื•ืŸ ื’ืขื”ืขืจื™ืง ื˜ืฉืขืงืก ืื•ื™ืฃ ื“ื™ ืงืœื™ืขื ื˜ ื–ื™ื™ึทื˜, ืึทืœืึทื•ื– ื“ื™ ื‘ืึทื ื™ืฆืขืจ. ืกืขืจื•ื•ืขืจ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ืื ื“ืขืจืข ื˜ืขืงืข ื ืขืžืขืŸ ื•ื•ืึธืก ื–ืขื ืขืŸ ืึทื ื“ืขืจืฉ ืคื•ืŸ ื“ื™ ื’ืขื‘ืขื˜ืŸ. ื“ื™ SFTP ืคึผืจืึธื˜ืึธืงืึธืœ ื˜ื•ื˜ ื ื™ืฉื˜ ื”ืึธื‘ืŸ ื“ื™ ืคึผืจืึธื‘ืœืขืžืก, ืึธื‘ืขืจ ื˜ื•ื˜ ื ื™ืฉื˜ ืฉื˜ื™ืฆืŸ ื“ื™ ื™ืงืกืคึผืึทื ืฉืึทืŸ ืคื•ืŸ ืกืคึผืขืฆื™ืขืœ ืคึผืึทื˜ืก ืึทื–ืึท ื•ื•ื™ "~/". ืฆื• ืึทื“ืจืขืก ื“ืขื ื—ื™ืœื•ืง, ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ืžืขืœื“ื•ื ื’ ืคื•ืŸ OpenSSH ื™ื ื˜ืจืึธื•ื“ื•ืกื˜ ืึท ื ื™ื™ึทืข SFTP ืคึผืจืึธื˜ืึธืงืึธืœ ืคืึทืจืœืขื ื’ืขืจื•ื ื’ ืฆื• ื“ื™ ~/ ืื•ืŸ ~ ื‘ืึทื ื™ืฆืขืจ/ ืคึผืึทื˜ืก ืื™ืŸ ื“ื™ SFTP ืกืขืจื•ื•ืขืจ ื™ืžืคึผืœืึทืžืขื ื˜ื™ื™ืฉืึทืŸ.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’