{"id":134834,"date":"2015-08-12T09:28:46","date_gmt":"2015-08-12T07:28:46","guid":{"rendered":"http:\/\/mybroadband.co.za\/news\/?p=134834"},"modified":"2015-08-12T09:30:01","modified_gmt":"2015-08-12T07:30:01","slug":"openssh-7-0-released","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/134834-openssh-7-0-released.html","title":{"rendered":"OpenSSH 7.0 released"},"content":{"rendered":"<p>OpenSSH has launched version 7.0 of the software, aimed at combating\u00a0weak and unsafe cryptography.<\/p>\n<p>Specifically, support for SSH version 1 is now disabled by default at compile time, 1,024-bit diffie-hellman-group1-sha1 key exchange is disabled by default at run-time, and the legacy v00 certificate format has been removed.<\/p>\n<p>There have also been changes to the way OpenSSH treats the setting which allows logins without a password.<\/p>\n<p>The default for the <em>PermitRootLogin<\/em> option has changed from \u201cyes\u201d to \u201cprohibit-password\u201d.<\/p>\n<p>Setting <em>PermitRootLogin<\/em> to without-password or prohibit-password now bans all interactive authentication methods, allowing only public-key, host-based, and Generic Security Services Application Program Interface authentication.<\/p>\n<p>Previously, it allowed users to type in a password in addition to the password-less authentication options.<\/p>\n<p>There is also a\u00a0plan to retire more legacy cryptography in the next release:<\/p>\n<ul>\n<li>All RSA keys smaller than 1,024 bits will be refused (the current minimum is 768 bits).<\/li>\n<li>Several ciphers will be disabled by default: blowfish-cbc,\u00a0cast128-cbc, all arcfour variants and the rijndael-cbc aliases\u00a0for AES.<\/li>\n<li>MD5-based HMAC algorithms will be disabled by default.<\/li>\n<\/ul>\n<p>OpenSSH is an SSH protocol 2.0 implementation and\u00a0includes SFTP\u00a0client and server support. OpenSSH also includes\u00a0transitional support for the legacy SSH 1.3 and 1.5 protocols\u00a0that may be enabled at compile-time.<\/p>\n<h3 id=\"related\">More security news<\/h3>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134824-windows-pcs-infected-through-big-usb-security-flaw.html\"><strong>Windows PCs infected through big USB security flaw<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134820-cognition-holdings-responds-to-security-concerns.html\"><strong>Cognition Holdings responds to security concerns<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134684-security-flaw-in-fax-to-email-service.html\"><strong>Security flaw exposes faxes of some FaxEmail clients<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134584-super-cellphone-spying-machine-in-sa-used-to-rig-government-tenders.html\"><strong>Super cellphone spying machine in SA used to rig government tenders<\/strong><\/a><\/p>\n<p><a href=\"http:\/\/mybroadband.co.za\/news\/security\/134564-massive-android-vulnerability-means-hackers-can-take-over-your-phone.html\"><strong>Massive Android vulnerability means hackers can take over your phone<\/strong><\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The latest version of OpenSSH has been released.<\/p>\n","protected":false},"author":23,"featured_media":84713,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[36,32072,32074],"class_list":["post-134834","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-active","tag-openssh","tag-openssh-7-0"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134834"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/23"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=134834"}],"version-history":[{"count":1,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134834\/revisions"}],"predecessor-version":[{"id":134838,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/134834\/revisions\/134838"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/84713"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=134834"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=134834"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=134834"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}