OpenSSH 9.3 inosvika neyakasiyana siyana kugadzirisa uye nezvimwe

kuvhura

OpenSSH seti yezvishandiso inobvumira kuvharirwa kutaurirana pamusoro petiweki, uchishandisa iyo SSH protocol.

Rakabudiswa OpenSSH 9.3 kuburitswa, mutengi akavhurika uye kusevha server kushanda neSSH 2.0 uye SFTP protocol. Iyo itsva vhezheni yeOpenSSH 9.3 inokwanisa kugadzirisa mamwe matambudziko ekuchengetedza, mukuwedzera nekuwedzera zvimwe zvitsva

Kune avo vasingazive nezve OpenSSH (Vhura Yakachengeteka Shell) vanofanirwa kuziva izvo iyi seti yezvishandiso inobvumidza yakavharidzirwa kutaurirana pamusoro penetiweki, uchishandisa SSH protocol. Yakagadzirwa senge yemahara uye yakavhurika imwe nzira kune Yakachengeteka Shell chirongwa, inova yepfuma software.

Main nyowani maficha eOpenSSH 9.3

Muiyi vhezheni itsva inobuda muOpenSSH 9.3 chimwe chezvinyowani ndechekuti sshd inowedzera `sshd -G` sarudzo inodhinda nekudhinda iyo chaiyo yekumisikidza pasina kuedza kurodha makiyi epachivande uye kuita mamwe macheki. Izvi zvinobvumira sarudzo kuti ishandiswe makiyi asati agadzirwa uye kuongororwa kwekugadzirisa uye kuongororwa nevasina rombo vashandisi.

Kune chikamu chekugadzirisa bug, mhosho ine musoro yakawanikwa mune ssh-add utility, saka kana uchiwedzera smart card kiyi kune ssh-agent, zvirambidzo zvakatsanangurwa ne "ssh-add -h" sarudzo hazvina kupfuudzwa kumumiririri. Nekuda kweizvozvo, kiyi yakawedzerwa kune mumiriri, saka pakanga pasina zvirambidzo zvaibvumira kubatana chete kubva kune mamwe mauto.

Imwe yezvigadziriso iyo yakaitwa, ndiyo kusagadzikana mune ssh utility izvo zvinogona kukonzera data kuti iverengwe kubva munzvimbo ye stack kunze kwebhafa yakagoverwa paunenge uchigadzira dzakanyatsogadzirwa DNS mhinduro kana VerifyHostKeyDNS kuseta kwakabatanidzwa mufaira rekugadzirisa.

Dambudziko riripo mukumisikidzwa kweiyo getrrsetbyname () basa, rinoshandiswa pamashanduro anotakurika eOpenSSH akavakwa pasina kushandisa raibhurari yekunze ldns (-with-ldns) uye pamasisitimu ane maraibhurari akajairwa asingatsigire getrrsetbyname() kufona. Iko mukana wekushandisa kusazvibata, kunze kwekutanga kurambwa kwesevhisi kune ssh mutengi, inoonekwa sezvisingaite.

Pakati pemashanduro matsva anobuda pachena:

  • Mu scp uye sftp inogadzirisa kufambira mberi kwemamita uori pamasikirini makuru;
  • ssh-add uye ssh-keygen shandisa RSA/SHA256 paunenge uchiyedza yakavanzika kiyi usability, sezvo mamwe masisitimu ari kutanga kudzima RSA/SHA1 mu libcrypto.
  • Mu sftp-server yakaita gadziriso yekudonha kwendangariro.
  • Mu ssh, sshd uye ssh-kiyi scan kodhi yekuenderana yakabviswa uye yakarerutsa zvakasara zve "vestigal" protocol.
  • Yakagadzirisa kune yakaderera maitiro Coverity static ongororo yemhedzisiro.
    Izvi zvinosanganisira akati wandei akashumwa:
    * ssh_config(5), sshd_config(5): taura kuti dzimwe sarudzo hadzisi
    mutambo wekutanga wakahwina
    * Rework log yekudzokorora bvunzo. Regression test ikozvino
    tora matanda akasiyana ega ega ssh uye sshd invocation muyedzo.
    * ssh(1): ita `ssh -Q CasignatureAlgorithms` kushanda sepeji remunhu
    anoti zvinofanira; bz3532.

Pakupedzisira, zvinofanira kucherechedzwa kuti kusagadzikana kunogona kucherechedzwa muraibhurari ye libskey inosanganisirwa neOpenBSD, iyo inoshandiswa neOpenSSH. Dambudziko ravepo kubva 1997 uye rinogona kukonzera stack buffer kufashukira kana uchigadzira akagadzirwa akagadzirwa mazita ekutambira.

Finalmente kana iwe uchifarira kuziva zvakawanda nezvazvo nezve iyi vhezheni nyowani, iwe unogona kutarisa iyo ruzivo nekuenda kunotevera chinongedzo.

Maitiro ekuisa OpenSSH 9.3 paLinux?

Kune avo vanofarira kugona kuisa iyi nyowani vhezheni yeOpenSSH pane avo masisitimu, nekuti izvozvi vanogona kuzviita kurodha pasi kodhi kodhi yeiyi uye vachiita muunganidzwa pamakomputa avo.

Izvi zvinodaro nekuti iyo vhezheni nyowani haisati yaverengerwa mumachengeterwo ezvekutanga zvekuparadzirwa kweLinux. Kuti uwane iyo kodhi kodhi, iwe unogona kuita kubva ku next link.

Waita kurodha pasi, ikozvino tava kuzobvisa pasuru yacho nemirairo inotevera

tar -xvf openssh-9.3.tar.gz

Isu tinopinda dhairekitori rakagadzirwa:

cd openssh-9.3

Y tinogona kuumbiridza ne inotevera mirairo:

./configure --prefix=/opt --sysconfdir=/etc/ssh
make
make install

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira data: AB Internet Networks 2008 SL
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako