Component: ssh
139 changelog entries across 73 version(s)
Releases by channel (stacked)
- added support for ED25519-SK keys;
- improved logging of failed login attempts;
- refactored SSH service internal processes;
- renamed User SSH keys "key-owner" field to "info";
- replaced "always-allow-password-login" with "password-authentication" in SSH settings;
- fixed non-interactive command execution (introduced in v7.20);
- improved stability on busy server;
- show user public key fingerprint under /user/ssh-keys;
- fixed authorization with SSH key when multiple user SSH public keys are imported;
- improved channel resumption after rekey and eof handling;
- added option to configure SSH ciphers (replaced allow-none-crypto parameter);
- do not regenerate host key after update from RouterOS version older than 7.9;
- improved logging;
- improved speed;
- prefer GCM ciphers for arm64 and x86 devices when ciphers=auto;
- fixed unsupported user SSH public key import (introduced in v7.15);
- fixed SSH cryptographic accelerator selection (introduced in v7.14);
- added support for user Ed25519 private keys;
- export host Ed25519 public key;
- fixed bogus output;
- fixed permissions to run ".auto.rsc" scripts;
- require "policy" user policy when adding public key;
- require "policy" user policy when adding public key;
- improved SSH performance on ARM, MIPS, MMIPS, SMIPS and TILE devices;
- refactored SSH service internal processes;
- added cipher and hash function acceleration for ARM64 and x86 architectures;
- fix error that caused large chunks of text not being pasted in their entirety into console;
- added support for user ed25519 public keys;
- allow to specify key owner on import;
- fixed SSH tunnel performance (introduced in v7.10);
- improved connection stability when pasting large chunks of text into console;
- added inline key "passphrase" property;
- fixed RouterOS SSH client login when using a key (introduced in v7.9);
- added Ed25519 host key support;
- added support for Ed25519 key export and import in PKCS8 format;
- do not allow SHA1 usage with strong crypto enabled;
- improved service responsiveness when changing SSH service settings;
- improved SSH key import process;
- hard-coded "localhost" address for forwarding requests;
- improved system stability when processing none-crypto SSH connection;
- added support for Ed25519 key exchange;
- do not allow SHA1 usage with strong crypto enabled;
- fixed handling of non standard size RSA keys;
- increased key generation timeout;
- added AES support for PEM decryption;
- fixed importing of public keys;
- fixed minor typo issue when importing public key;
- disable ssh-rsa when strong-crypto=yes and use rsa-sha2-sha256;
- fixed host key generation (introduced in v7.3);
- implemented "server-sig-algs" extension in order to improve rsa-sha2-sha256 support;
- added AES-GCM cipher support;
- fail non-interactive client after first invalid password;
- fixed corrupt host key automatic regeneration;
- fixed private key usage after downgrade;
- removed DSA public key authentication support;
- fixed forwarding with IPv6 link-local addresses;
- fixed "undo" functionality;