OpenSSH

共 8 篇文章。

作弊条:SSH 的 ProxyJump 跳板服务

• Cheatsheets

问题

有些环境中,SSH 服务器可能无法从 Internet 直接访问(例如,SSH 服务器可能使用的是一个私有 IP地址,或是 Internet 服务提供商没有提供 IPv6 服务,而 SSH 服务器只提供 IPv6 服务)。

考虑到 SSH 已经进行了相互认证(连接时客户端会验证服务器的公钥是否与已知公钥,例如 ~/.ssh/known_hosts,或是通过 DNSsec 发布的 SSHFP RR 匹配;服务器端则会验证用户是否能证明自己拥有与授权公钥对应的私钥),因此比较常见的解决方法便是使用 VPN、在防火墙上穿孔,或是使用代理服务器。

由于 SSH 自身也提供了许多转发功能,因此如果中间的跳板服务器也提供 SSH 服务,便可以使用这些跳转服务器直接作为代理服务器来用。与前面那些传统方法相比,这样做的优点是避免了安装额外的软件,也不需要特别指定端口。

阅读全文… ( 本文约 1419 字,阅读大致需要 3 分钟 )

用 FIDO key 来做 SSH key

• Security

OpenSSH 8.2 中新增了 FIDO/U2F 支持。它支持两种密钥对类型: ecdsa-sk 和 ed25519-sk。需要注意的是并非所有的 FIDO Security Key都实现了 ed25519-sk 的硬件支持:例如,截至2022年,Titan Security Key 就不支持 ed25519-sk。

使用 FIDO key 的 SSH key 在使用上和之前的 SSH key 类似,主要的区别在于在登录时系统会确认用户是否在机器旁边(通常是碰一下 FIDO key),这可以显著地改善安全性:与之前的 SSH key 不同的是,即使机器上的 U2F/FIDO SSH key 私钥文件被攻击者获得,在没有硬件 FIDO key 的情况下也无法使用这个私钥。对于对方同时能获得私钥文件和物理访问的情况,参见 xkcd/538,就不要跟扳手过不去了。

阅读全文… ( 本文约 718 字,阅读大致需要 2 分钟 )

号召:捐款或买CD,救OpenBSD!

• Others

由于购买 OpenBSD CD 的人数日益减少,导致 OpenBSD 最近几年财务困难,最近两年亏损达四万美元。如果再找不到资金来源,恐怕 2007 年的 OpenBSD hackathon 将无法如期举办,因为其花费在1-3万美元之间,还不包括将提供给贫困和在校开发者的旅行补助。

阅读全文… ( 本文约 180 字,阅读大致需要 1 分钟 )

严重安全问题公告 FreeBSD SA-06:09.sshd

• Security

我们今天发布了 FreeBSD SA-06:09.sshd,这是一个针对 sshd 的 DoS 攻击。如果您使用的是 FreeBSD 5.3、5.4或5.5-PRERELEASE(到昨天之前的版本),请立即升级到最新的安全分支。

阅读全文… ( 本文约 207 字,阅读大致需要 1 分钟 )

ssh.com的sshd2:疑似有問題

• Security

今天有人跟我說他裝的sshd2莫名其妙地起了100多進程,登上去一看果然如此,十分吊詭。用OpenSSH就一點事都沒有,於是開始建議所有人改回OpenSSH(過去OpenSSH確實有過一些安全上的不良記錄,不過在OpenBSD一群人的努力之下已經兩年沒有出過安全問題了,所以我認爲可以重新開始信任這一軟体)

参与评论

Keeping your ssh connection alive

• Security

Sometimes, when you are in a NAT’ed environment, ssh connection may be dropped when the gateway is busy.

OpenSSH has provided a solution against this.

The option is called “ClientAliveInterval”. With this setting in your sshd_config, sshd(8) would send a ping message through the encrypted channel periodically, thus prevent the early drop.

The default setting is 15, meaning the ping period is 15 seconds.

阅读全文… ( 本文约 79 字,阅读大致需要 1 分钟 )

Using ssh-agent(1) to ease usage of SSH key authentication

• Security

Many SSH clients supports “key agent” or “authentication agent”, which holds private key for you, and ease the authentication process.

By default, OpenSSH does not enable this. You can easily use ssh-agent(1) to accomplish the mission.

ssh-agent startx

The above command will start X session with ssh-agent. This means that you can add private key to the agent.

ssh-add ~/.ssh/id_dsa

Add your own ssh key.

Then ssh authentications will be accomplished automatically. Note that you may need to use ssh -A in certain configurations.

参与评论