顯示具有 sshd 標籤的文章。 顯示所有文章
顯示具有 sshd 標籤的文章。 顯示所有文章

2020年10月2日 星期五

[openssh-unix-announce] Announce: OpenSSH 8.4 released

 ---------- Forwarded message ---------

From: Damien Miller <djm@openbsd.org>

Date: Sep 27, 2020 6:59PM

Future deprecation notice

=========================

It is now possible[1] to perform chosen-prefix attacks against the

SHA-1 algorithm for less than USD$50K. For this reason, we will be

disabling the "ssh-rsa" public key signature algorithm by default in a

near-future release.

This algorithm is unfortunately still used widely despite the

existence of better alternatives, being the only remaining public key

signature algorithm specified by the original SSH RFCs.

The better alternatives include:

 * The RFC8332 RSA SHA-2 signature algorithms rsa-sha2-256/512. These

   algorithms have the advantage of using the same key type as

   "ssh-rsa" but use the safe SHA-2 hash algorithms. These have been

   supported since OpenSSH 7.2 and are already used by default if the

   client and server support them.

 * The ssh-ed25519 signature algorithm. It has been supported in

   OpenSSH since release 6.5.

 * The RFC5656 ECDSA algorithms: ecdsa-sha2-nistp256/384/521. These

   have been supported by OpenSSH since release 5.7.

To check whether a server is using the weak ssh-rsa public key

algorithm, for host authentication, try to connect to it after

removing the ssh-rsa algorithm from ssh(1)'s allowed list:

    ssh -oHostKeyAlgorithms=-ssh-rsa user@host

If the host key verification fails and no other supported host key

types are available, the server software on that host should be

upgraded.

We intend to enable UpdateHostKeys by default in the next OpenSSH

release. This will assist the client by automatically migrating to

better algorithms. Users may consider enabling this option manually.

[1] "SHA-1 is a Shambles: First Chosen-Prefix Collision on SHA-1 and

    Application to the PGP Web of Trust" Leurent, G and Peyrin, T

    (2020) https://eprint.iacr.org/2020/014.pdf

2020年6月27日 星期六

[openssh-unix-announce] Announce: OpenSSH 8.3 released

---------- Forwarded message ---------
From: Damien Miller <djm@openbsd.org>
Date: May 27, 2020 3:33PM

OpenSSH 8.3 has just been released. It will be available from the
mirrors listed at https://www.openssh.com/ shortly.

Changes since OpenSSH 8.2
=========================

The focus of this release is bug fixing.

Reporting Bugs:
===============

- Please read https://www.openssh.com/report.html
  Security bugs should be reported directly to openssh@openssh.com

2020年2月17日 星期一

[openssh-unix-announce] Announce: OpenSSH 8.2 released

---------- Forwarded message ---------
From: Damien Miller
Date: Feb 14, 2020 12:53PM

OpenSSH 8.2 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol 2.0 implementation and
includes sftp client and server support.

Once again, we would like to thank the OpenSSH community for their
continued support of the project, especially those who contributed
code or patches, reported bugs, tested snapshots or donated to the
project. More information on donations may be found at:
http://www.openssh.com/donations.html

2019年10月31日 星期四

[openssh-unix-announce] Announce: OpenSSH 8.1 released

---------- Forwarded message ---------
From: Damien Miller
Date: Oct 9, 2019 11:44AM

Security
========

 * ssh(1), sshd(8), ssh-add(1), ssh-keygen(1): an exploitable integer
   overflow bug was found in the private key parsing code for the XMSS
   key type. This key type is still experimental and support for it is
   not compiled by default. No user-facing autoconf option exists in
   portable OpenSSH to enable it. This bug was found by Adam Zabrocki
   and reported via SecuriTeam's SSD program.

 * ssh(1), sshd(8), ssh-agent(1): add protection for private keys at
   rest in RAM against speculation and memory side-channel attacks like
   Spectre, Meltdown and Rambleed. This release encrypts private keys
   when they are not in use with a symmetric key that is derived from a
   relatively large "prekey" consisting of random data (currently 16KB).

Potentially-incompatible changes
================================

This release includes a number of changes that may affect existing
configurations:

 * ssh-keygen(1): when acting as a CA and signing certificates with
   an RSA key, default to using the rsa-sha2-512 signature algorithm.
   Certificates signed by RSA keys will therefore be incompatible
   with OpenSSH versions prior to 7.2 unless the default is
   overridden (using "ssh-keygen -t ssh-rsa -s ...").

Changes since OpenSSH 8.0
=========================

This release is focused on bug-fixing.

2019年4月25日 星期四

[openssh-unix-announce] Announce: OpenSSH 8.0 released

---------- Forwarded message ---------
From: Damien Miller
Date: Apr 18, 2019 9:36AM

OpenSSH 8.0 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.
...
This release contains mitigation for a weakness in the scp(1) tool
and protocol (CVE-2019-6111): when copying files from a remote system
to a local directory, scp(1) did not verify that the filenames that
the server sent matched those requested by the client. This could
allow a hostile server to create or clobber unexpected local files
with attacker-controlled content.

This release adds client-side checking that the filenames sent from
the server match the command-line request,

The scp protocol is outdated, inflexible and not readily fixed. We
recommend the use of more modern protocols like sftp and rsync for
file transfer instead.

2018年10月23日 星期二

[openssh-unix-announce] Announce: OpenSSH 7.9 released

---------- Forwarded message ---------
From: Damien Miller
Date: 2018年10月19日 週五 上午11:51

OpenSSH 7.9 has just been released. It will be available from the
mirrors listed at http://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol 2.0 implementation and
includes sftp client and server support.

Once again, we would like to thank the OpenSSH community for their
continued support of the project, especially those who contributed
code or patches, reported bugs, tested snapshots or donated to the
project. More information on donations may be found at:
http://www.openssh.com/donations.html

Potentially-incompatible changes
================================

This release includes a number of changes that may affect existing
configurations:

 * ssh(1), sshd(8): the setting of the new CASignatureAlgorithms
   option (see below) bans the use of DSA keys as certificate
   authorities.

 * sshd(8): the authentication success/failure log message has
   changed format slightly. It now includes the certificate
   fingerprint (previously it included only key ID and CA key
   fingerprint).

Changes since OpenSSH 7.8
=========================

This is primarily a bugfix release.
...

Reporting Bugs:
===============

- Please read http://www.openssh.com/report.html
  Security bugs should be reported directly to openssh@openssh.com

2018年8月27日 星期一

OpenSSH 7.8 released

---------- Forwarded message ---------
From: Damien Miller
Date: 2018年8月24日 週五 下午3:40

Potentially-incompatible changes
================================
This release includes a number of changes that may affect existing
configurations:

Changes since OpenSSH 7.7
=========================
This is primarily a bugfix release.

Reporting Bugs:
===============
- Please read http://www.openssh.com/report.html

2017年10月4日 星期三

OpenSSH 7.6 released

This is primarily a bugfix release. It also contains substantial
internal refactoring.

Security
--------

 * sftp-server(8): in read-only mode, sftp-server was incorrectly
   permitting creation of zero-length files. Reported by Michal
   Zalewski.

New Features
------------
REF: http://www.openssh.com/

2017年1月26日 星期四

secure data transfer

FTP may be the most popular protocol for transferring data over Internet. However, it is unencrypted by default. Here're some remedies for this issue.

  • FTP over SSL. it may be affected by SSL mismatch of versions between clients and server due to SSL upgrade.
  • SFTP from OpenSSH. shell access or chroot may be required.
  • VPN. using VPN as secure tunnel would be easier between sites.

2016年8月15日 星期一

rsync ssh to alternative port

rsync over ssh is convenient, and remember to install rsync package on both sides. alternative port is supported.

$ rsync -e "ssh -p 8496" -avz digen@myserver.com:/home/digen/Learning Learning

Ref: http://www.linuxquestions.org/questions/linux-server-73/rsync-ssh-server-on-a-different-port-535870/

2012年1月28日 星期六

port 6010 listening...


FreeBSD-Security: RE: sshd listening on port 6010

www.derkeiler.com › ... › 2001-03 - 頁庫存檔 - 翻譯這個網頁
5 Mar 2001 – Just disable X11 forwarding if you dont want it. ...