Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Package Request] - update OpenSSH / sshd: current version 8 to major version 9 - at least to 9.8 #894

Open
rgoltz opened this issue Jan 27, 2025 · 1 comment
Labels
enhancement New feature or request packages Package request

Comments

@rgoltz
Copy link

rgoltz commented Jan 27, 2025

What package is missing from Amazon Linux 2023? Please describe and include package name.
openssh / sshd

Is this an update to existing package or new package request?
Update/Upgrade to an existing package.

What is the version of this package right now?
Today, it's version: OpenSSH_8.7p1, OpenSSL 3.0.8 7 Feb 2023

Any additional information you'd like to include. (use-cases, etc)
I guess, it's just one example/use-case: We like to benefit from the PerSourcePenalties feature in OpenSSH 9.8 ff. This new option is exciting because for the first time it lets us block only rapidly repeating SSH sources that fail to authenticate. You can check via the following links for PerSourcePenalties configuration setting and its defaults, and also see PerSourcePenaltyExemptList and PerSourceNetBlockSize. With OpenSSH 8.7 we are not able to use this feature yet - We still need to maintain local rules based on ip-tables to implement an 'authfail' penalty duration.

@stewartsmith stewartsmith added the enhancement New feature or request label Jan 28, 2025
@stewartsmith
Copy link
Member

To set expectations here, we are very unlikely to bump OpenSSH due to the requirement of getting it FIPS validated.

@stewartsmith stewartsmith added the packages Package request label Jan 28, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request packages Package request
Projects
None yet
Development

No branches or pull requests

2 participants