veganism.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Veganism Social is a welcoming space on the internet for vegans to connect and engage with the broader decentralized social media community.

Administered by:

Server stats:

275
active users

#openssh

2 posts2 participants0 posts today
Dendrobatus Azureus<p>An unimportant remnant of the past has been removed from open SSH;<br>DSA.</p><p>Read about it in this article the next article linked will show you that it has been removed finally</p><p><a href="https://mastodon.bsd.cafe/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> <a href="https://mastodon.bsd.cafe/tags/openSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openSSH</span></a> <a href="https://mastodon.bsd.cafe/tags/DSA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DSA</span></a> <a href="https://mastodon.bsd.cafe/tags/programming" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>programming</span></a> <a href="https://mastodon.bsd.cafe/tags/coding" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>coding</span></a> <a href="https://mastodon.bsd.cafe/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://mastodon.bsd.cafe/tags/openBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openBSD</span></a> <a href="https://mastodon.bsd.cafe/tags/BSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSD</span></a> <a href="https://mastodon.bsd.cafe/tags/secureShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>secureShell</span></a> <a href="https://mastodon.bsd.cafe/tags/Infosec" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Infosec</span></a> </p><p><a href="https://undeadly.org/cgi?action=article;sid=20240111105900" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20240111105900</span></a></p>
Peter N. M. Hansteen<p>DSA signature support removed from OpenSSH <a href="https://www.undeadly.org/cgi?action=article;sid=20250507010932" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20250507010932</span></a> <a href="https://mastodon.social/tags/openbsd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openbsd</span></a> <a href="https://mastodon.social/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> <a href="https://mastodon.social/tags/ssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ssh</span></a> <a href="https://mastodon.social/tags/dsa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dsa</span></a> <a href="https://mastodon.social/tags/dsaremoval" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dsaremoval</span></a> <a href="https://mastodon.social/tags/deadkeys" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>deadkeys</span></a> <a href="https://mastodon.social/tags/signature" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>signature</span></a> <a href="https://mastodon.social/tags/deadciphers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>deadciphers</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/networking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>networking</span></a> <a href="https://mastodon.social/tags/cryptography" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptography</span></a> <a href="https://mastodon.social/tags/crypto" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crypto</span></a></p>
Peter N. M. Hansteen<p>Call for testing: Last bits of DSA to be removed from OpenSSH <a href="https://www.undeadly.org/cgi?action=article;sid=20250506054255" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20250506054255</span></a> <a href="https://mastodon.social/tags/openbsd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openbsd</span></a> <a href="https://mastodon.social/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> <a href="https://mastodon.social/tags/ssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ssh</span></a> <a href="https://mastodon.social/tags/dsa" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dsa</span></a> <a href="https://mastodon.social/tags/dsaremoval" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dsaremoval</span></a> <a href="https://mastodon.social/tags/crypto" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>crypto</span></a> <a href="https://mastodon.social/tags/cryptography" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cryptography</span></a> <a href="https://mastodon.social/tags/ciphers" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ciphers</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/networking" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>networking</span></a> <a href="https://mastodon.social/tags/development" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>development</span></a> <a href="https://mastodon.social/tags/freesoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freesoftware</span></a> <a href="https://mastodon.social/tags/libresoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>libresoftware</span></a></p>
Peter N. M. Hansteen<p>ssh: listener sockets relocated from /tmp to ~/.ssh/agent <a href="https://www.undeadly.org/cgi?action=article;sid=20250506044643" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20250506044643</span></a> <a href="https://mastodon.social/tags/openbsd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openbsd</span></a> <a href="https://mastodon.social/tags/ssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ssh</span></a> <a href="https://mastodon.social/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.social/tags/unveil" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>unveil</span></a> <a href="https://mastodon.social/tags/sshagent" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>sshagent</span></a> <a href="https://mastodon.social/tags/snoopresistant" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>snoopresistant</span></a> <a href="https://mastodon.social/tags/freesoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>freesoftware</span></a> <a href="https://mastodon.social/tags/libresoftware" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>libresoftware</span></a></p>
Vitex<p><a href="https://f.cz/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> 10.0p1 includes a number of changes that may affect existing configurations:</p><p> * This release removes support for the weak DSA signature algorithm,<br> completing the deprecation process that began in 2015 (when <a href="https://f.cz/tags/DSA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DSA</span></a> was<br> disabled by default) and repeatedly warned over the last 12 months.</p><p><a href="https://f.cz/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> <a href="https://f.cz/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
Bryan Steele :flan_beard:<p>A very welcome change in <a href="https://bsd.network/tags/OpenBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenBSD</span></a> -current that impacts software which restrict filesystem access with unveil(2), but permit access to /tmp (like web browsers). :flan_thumbs:​</p><p>ssh-agent(1) listener sockets and forwarded sockets in sshd(8) will now be under ~/.ssh/agent instead.</p><blockquote><p>djm@ modified src/usr.bin/ssh/*: Move agent listener sockets from /tmp to under ~/.ssh/agent for both ssh-agent(1) and forwarded sockets in sshd(8).</p><p>This ensures processes (such as Firefox) that have restricted filesystem access that includes /tmp (via unveil(3)) do not have the ability to use keys in an agent.</p><p>Moving the default directory has the consequence that the OS will no longer clean up stale agent sockets, so ssh-agent now gains this<br>ability.</p><p>To support $HOME on NFS, the socket path includes a truncated hash of the hostname. ssh-agent will by default only clean up sockets from the same hostname.</p><p>ssh-agent gains some new flags: -U suppresses the automatic cleanup of stale sockets when it starts. -u forces a cleanup without keeping a running agent, -uu forces a cleanup that ignores the hostname. -T makes ssh-agent put the socket back in /tmp.</p><p>feedback deraadt@ naddy@<br>doitdoitdoit deraadt@</p></blockquote><p><a href="https://bsd.network/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/OpenBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenBSD</span></a> 7.7 has been released (<a href="https://mastodon.social/tags/BSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>BSD</span></a> / <a href="https://mastodon.social/tags/NetBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>NetBSD</span></a> / <a href="https://mastodon.social/tags/386BSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>386BSD</span></a> / <a href="https://mastodon.social/tags/Unix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Unix</span></a> / <a href="https://mastodon.social/tags/LibreSSL" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>LibreSSL</span></a> / <a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> / <a href="https://mastodon.social/tags/OpenBGPD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenBGPD</span></a> / <a href="https://mastodon.social/tags/OpenSMTPD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSMTPD</span></a> / <a href="https://mastodon.social/tags/OpenNTPD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenNTPD</span></a> / <a href="https://mastodon.social/tags/OpenIKED" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenIKED</span></a> / <a href="https://mastodon.social/tags/rpkiClient" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>rpkiClient</span></a> / <a href="https://mastodon.social/tags/mandoc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mandoc</span></a>) <a href="https://openbsd.org/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">openbsd.org/</span><span class="invisible"></span></a></p>
Marcus Adams<p>This version will come down the pipe in <a href="https://mastodon.social/tags/Debian" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Debian</span></a> Trixie later this year. Other distributions may already have it, or should in the near future.</p><p>Headline: <a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> 10.0 Introduces Default Post-Quantum Key Exchange Algorithm - Quantum Computing Report</p><p>Source: <a href="https://quantumcomputingreport.com/openssh-10-0-introduces-default-post-quantum-key-exchange-algorithm/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">quantumcomputingreport.com/ope</span><span class="invisible">nssh-10-0-introduces-default-post-quantum-key-exchange-algorithm/</span></a></p><p><a href="https://mastodon.social/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://mastodon.social/tags/CyberSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>CyberSecurity</span></a> <a href="https://mastodon.social/tags/Quantum" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Quantum</span></a></p>
A.J. Armstrong<p>Fixing OpenSSH.exe Issues After October 2024 Windows Server Update&nbsp;|&nbsp;<a href="https://techygeekshome.info/fixing-openssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19516&nbsp;|&nbsp;#Guide" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techygeekshome.info/fixing-ope</span><span class="invisible">nssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19516&nbsp;|&nbsp;#Guide</span></a> <a href="https://techhub.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://techhub.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> <a href="https://techhub.social/tags/refresh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>refresh</span></a> <a href="https://techhub.social/tags/Server" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Server</span></a> <a href="https://techhub.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://techhub.social/tags/WindowsUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsUpdate</span></a>&nbsp;<br><a href="https://techygeekshome.info/fixing-openssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19516" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techygeekshome.info/fixing-ope</span><span class="invisible">nssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19516</span></a></p>
Anthony Powell<p>Fixing OpenSSH.exe Issues After October 2024 Windows Server Update&nbsp;|&nbsp;<a href="https://techygeekshome.info/fixing-openssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19515&nbsp;|&nbsp;#Guide" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techygeekshome.info/fixing-ope</span><span class="invisible">nssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19515&nbsp;|&nbsp;#Guide</span></a> <a href="https://mastodon.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> <a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> <a href="https://mastodon.social/tags/refresh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>refresh</span></a> <a href="https://mastodon.social/tags/Server" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Server</span></a> <a href="https://mastodon.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mastodon.social/tags/WindowsUpdate" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>WindowsUpdate</span></a>&nbsp;<br><a href="https://techygeekshome.info/fixing-openssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19515" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">techygeekshome.info/fixing-ope</span><span class="invisible">nssh-exe-issues-after-october-2024-windows-server-update/?fsp_sid=19515</span></a></p>
Michael Dexter<p><span class="h-card"><a href="https://floss.social/@bkuhn" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>bkuhn</span></a></span> So you’re saying <a href="https://bsd.network/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> isn’t popular and isn’t supporting software freedom?</p>
Kevin Lyda<p>OK, this is a thing I didn't know. In <a href="https://mastodon.ie/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> config files, the first mention wins, not the last.</p><p>The overrides in the .d directories are included *first* (normally this happens last - see nginx, sudo, etc) which is how they override things.</p><p><a href="https://utcc.utoronto.ca/~cks/space/blog/sysadmin/OpenSSHConfigOrderMatters" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">utcc.utoronto.ca/~cks/space/bl</span><span class="invisible">og/sysadmin/OpenSSHConfigOrderMatters</span></a></p>
Neustradamus :xmpp: :linux:<p><a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> 10.0 has been released (<a href="https://mastodon.social/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> / <a href="https://mastodon.social/tags/SecureShell" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SecureShell</span></a> / <a href="https://mastodon.social/tags/OpenBSD" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenBSD</span></a>) <a href="https://openssh.com/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">openssh.com/</span><span class="invisible"></span></a></p>
Rihards Olups<p>Neat, OpenSSH client adds variable expansion in "User".<br>This will allow for much simpler PAM (the privileged access management one) related configuration - for example, expanding user into user%original_hostname etc.</p><p><a href="https://github.com/openssh/openssh-portable/commit/bd30cf784d6e825ef71592fb723c41d4f2fd407b" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">github.com/openssh/openssh-por</span><span class="invisible">table/commit/bd30cf784d6e825ef71592fb723c41d4f2fd407b</span></a></p><p><a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> <a href="https://mastodon.social/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a> <a href="https://mastodon.social/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a></p>
unixbhaskar<p>Heads up! Kiddos...measure...</p><p><a href="https://mastodon.social/tags/linuxadmin" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linuxadmin</span></a> <a href="https://mastodon.social/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a> <a href="https://mastodon.social/tags/tool" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>tool</span></a> <a href="https://mastodon.social/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> </p><p><a href="https://www.openssh.com/releasenotes.html#10.0p1" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">openssh.com/releasenotes.html#</span><span class="invisible">10.0p1</span></a></p>
Maquinari.cat<p>OpenSSH arriba a la versió 10.0. Entre d'altres, inclou l'algoritme mlkem768x25519-sha256, que diuen és a prova d'ordinadors quàntics.</p><p><a href="https://www.phoronix.com/news/OpenSSH-10.0-Released" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">phoronix.com/news/OpenSSH-10.0</span><span class="invisible">-Released</span></a></p><p><a href="https://mastodon.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> <a href="https://mastodon.social/tags/Qu%C3%A0ntic" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Quàntic</span></a> <a href="https://mastodon.social/tags/mlkem768x25519" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mlkem768x25519</span></a>-sha256</p>
Jeff Forcier<p>I see <a href="https://social.coop/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> got to fully removing DSA key support, so that means my “probably do that in <a href="https://social.coop/tags/Paramiko" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Paramiko</span></a>” todo list item has no more excuses 🤔</p><p>Well, ok, it still has a few excuses (will be years before the average sshd is OpenSSH 10.0+) but still. Needs happenin' sometime and it ain't like old releases go away, so.</p>
nixCraft 🐧<p>OpenSSH 10.0/10.0p2 released <a href="https://www.openssh.com/releasenotes.html#10.0p1" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">openssh.com/releasenotes.html#</span><span class="invisible">10.0p1</span></a></p><p><a href="https://mastodon.social/tags/unix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>unix</span></a> <a href="https://mastodon.social/tags/openssh" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>openssh</span></a> <a href="https://mastodon.social/tags/linux" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>linux</span></a> <a href="https://mastodon.social/tags/opensource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>opensource</span></a></p>
KielKontrovers Blog<p><a href="https://norden.social/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> 10.0 Released</p><p><a href="https://undeadly.org/cgi?action=article;sid=20250410053152" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20250410053152</span></a></p><p><a href="https://norden.social/tags/Openbsd" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Openbsd</span></a> <a href="https://norden.social/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a></p>
Senioradmin<p><a href="https://social.tchncs.de/tags/OpenSSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSSH</span></a> 9.8 und höher kommt allmählich auf die Server. Da wird die Option PerSourcePenalties interessant (siehe <a href="https://undeadly.org/cgi?action=article;sid=20240607042157" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">undeadly.org/cgi?action=articl</span><span class="invisible">e;sid=20240607042157</span></a> ) die fail2ban u.ä. überflüssig machen könnte.</p><p>Konfig-Beispiele sind aber noch rar gesät. Nach der manpage zu urteilen, sollte aber </p><p>PerSourcePenalties authfail:3600s</p><p>dafür sorgen dass IPs, die Brute-Force Attacken fahren für 1 Stunde geblockt werden, korrekt? </p><p><a href="https://social.tchncs.de/tags/SSH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSH</span></a></p>