Tux Machines

Do you waddle the waddle?

Other Sites

9to5Linux

IPFire Linux Firewall Gets Post-Quantum Cryptography Support for IPsec Tunnels

Coming after IPFire 2.29 Core Update 192, the IPFire 2.29 Core Update 193 release introduces support for post-quantum cryptography using the Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) in IPsec tunnels.

Fwupd 2.0.8 Adds New Plugins to Update the UEFI Signature Database and KEK

Coming two weeks after fwupd 2.0.7, this release introduces two new plugins for updating the UEFI Signature Database and KEK, an updated UEFI database as a new HSI attribute, /sys/firmware/efi/efivars to ReadWritePaths, support for segment value 0 in the ccgx-dmc image parser, and detection the Firehose protocol features if they aren’t automatically sent.

Linux Mint Debian Edition Is Getting Support for OEM Installations with LMDE 7

One of the big changes that Clement Lefebvre talks about in the March newsletter is support for OEM (Original Equipment Manufacturer) installations for the next major version of LMDE (Linux Mint Debian Edition), which will be based on the upcoming Debian GNU/Linux 13 “Trixie” operating system series.

OpenSSL 3.5 Released with Support for PQC Algorithms, Server-Side QUIC

Coming more than six months after OpenSSL 3.4, the OpenSSL 3.5 release introduces new features like support for server-side QUIC (RFC 9000), support for third-party QUIC stacks (including 0-RTT support), support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA), and support for central key generation in CMP.

LinuxGizmos.com

Topaz Tz170 J484 Development Kit with 256 Mbit x32 LPDDR4 at 1.6 Gbps & MIPI D-PHY

The Topaz Tz170 J484 Development Kit is a compact platform for evaluating and prototyping with the Efinix Tz170 FPGA. It integrates onboard memory, configurable I/O, and a preloaded reference design, providing a practical setup for testing and demonstration across a range of FPGA applications.

HydraNFC Shield v2 and Sniffer Decoder Expand Capabilities for NFC Development & Analysis

The HydraNFC Shield v2 is a high-performance NFC development platform built around the STMicroelectronics ST25R3916 NFC frontend. Designed for NFC research, development, debugging, and security analysis, it is intended to be used with the HydraBus v1.0, a versatile open-source baseboard that acts as the host interface for HydraNFC and other shield extensions.

Tor Project blog

New Alpha Release: Tor Browser 14.5a6

This version includes important security updates to Firefox.

Internet Society

Article 19 of the Marco Civil – Guarantee or Threat to the Future of the Brazilian Internet?

Editor’s note: This post was originally published on 6 April 2025 in JOTA Jornalismo. It has been translated from Portuguese below.

OpenSSH 9.1 released (UPDATED)

posted by Roy Schestowitz on Oct 04, 2022,
updated Oct 05, 2022

OpenSSH 9.1 has just been released. It will be available from the
mirrors listed at https://www.openssh.com/ shortly.

OpenSSH is a 100% complete SSH protocol 2.0 implementation and includes sftp client and server support.
Once again, we would like to thank the OpenSSH community for their continued support of the project, especially those who contributed code or patches, reported bugs, tested snapshots or donated to the project. More information on donations may be found at: https://www.openssh.com/donations.html
Changes since OpenSSH 9.0 =========================
This release is focused on bug fixing.
Security ========
This release contains fixes for three minor memory safety problems. None are believed to be exploitable, but we report most memory safety problems as potential security vulnerabilities out of caution.
* ssh-keyscan(1): fix a one-byte overflow in SSH- banner processing. Reported by Qualys
* ssh-keygen(1): double free() in error path of file hashing step in signing/verify code; GHPR333
* ssh-keysign(8): double-free in error path introduced in openssh-8.9
Potentially-incompatible changes --------------------------------
* The portable OpenSSH project now signs commits and release tags using git's recent SSH signature support. The list of developer signing keys is included in the repository as .git_allowed_signers and is cross-signed using the PGP key that is still used to sign release artifacts: https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc
* ssh(1), sshd(8): SetEnv directives in ssh_config and sshd_config are now first-match-wins to match other directives. Previously if an environment variable was multiply specified the last set value would have been used. bz3438
* ssh-keygen(8): ssh-keygen -A (generate all default host key types) will no longer generate DSA keys, as these are insecure and have not been used by default for some years.
New features ------------
* ssh(1), sshd(8): add a RequiredRSASize directive to set a minimum RSA key length. Keys below this length will be ignored for user authentication and for host authentication in sshd(8).
ssh(1) will terminate a connection if the server offers an RSA key that falls below this limit, as the SSH protocol does not include the ability to retry a failed key exchange.
* sftp-server(8): add a "users-groups-by-id@openssh.com" extension request that allows the client to obtain user/group names that correspond to a set of uids/gids.
* sftp(1): use "users-groups-by-id@openssh.com" sftp-server extension (when available) to fill in user/group names for directory listings.
* sftp-server(8): support the "home-directory" extension request defined in draft-ietf-secsh-filexfer-extensions-00. This overlaps a bit with the existing "expand-path@openssh.com", but some other clients support it.
* ssh-keygen(1), sshd(8): allow certificate validity intervals, sshsig verification times and authorized_keys expiry-time options to accept dates in the UTC time zone in addition to the default of interpreting them in the system time zone. YYYYMMDD and YYMMDDHHMM[SS] dates/times will be interpreted as UTC if suffixed with a 'Z' character.
Also allow certificate validity intervals to be specified in raw seconds-since-epoch as hex value, e.g. -V 0x1234:0x4567890. This is intended for use by regress tests and other tools that call ssh-keygen as part of a CA workflow. bz3468
* sftp(1): allow arguments to the sftp -D option, e.g. sftp -D "/usr/libexec/sftp-server -el debug3"
* ssh-keygen(1): allow the existing -U (use agent) flag to work with "-Y sign" operations, where it will be interpreted to require that the private keys is hosted in an agent; bz3429
Bugfixes --------
* ssh-keygen(1): implement the "verify-required" certificate option. This was already documented when support for user-verified FIDO keys was added, but the ssh-keygen(1) code was missing.
* ssh-agent(1): hook up the restrict_websafe command-line flag; previously the flag was accepted but never actually used.
* sftp(1): improve filename tab completions: never try to complete names to non-existent commands, and better match the completion type (local or remote filename) against the argument position being completed.
* ssh-keygen(1), ssh(1), ssh-agent(1): several fixes to FIDO key handling, especially relating to keys that request user-verification. These should reduce the number of unnecessary PIN prompts for keys that support intrinsic user verification. GHPR302, GHPR329
* ssh-keygen(1): when enrolling a FIDO resident key, check if a credential with matching application and user ID strings already exists and, if so, prompt the user for confirmation before overwriting the credential. GHPR329
* sshd(8): improve logging of errors when opening authorized_keys files. bz2042
* ssh(1): avoid multiplexing operations that could cause SIGPIPE from causing the client to exit early. bz3454
* ssh_config(5), sshd_config(5): clarify that the RekeyLimit directive applies to both transmitted and received data. GHPR328
* ssh-keygen(1): avoid double fclose() in error path.
* sshd(8): log an error if pipe() fails while accepting a connection. bz3447
* ssh(1), ssh-keygen(1): fix possible NULL deref when built without FIDO support. bz3443
* ssh-keyscan(1): add missing *-sk types to ssh-keyscan manpage. GHPR294.
* sshd(8): ensure that authentication passwords are cleared from memory in error paths. GHPR286
* ssh(1), ssh-agent(1): avoid possibility of notifier code executing kill(-1). GHPR286
* ssh_config(5): note that the ProxyJump directive also accepts the same tokens as ProxyCommand. GHPR305.
* scp(1): do not not ftruncate(3) files early when in sftp mode. The previous behaviour of unconditionally truncating the destination file would cause "scp ~/foo localhost:foo" and the reverse "scp localhost:foo ~/foo" to delete all the contents of their destination. bz3431
* ssh-keygen(1): improve error message when 'ssh-keygen -Y sign' is unable to load a private key; bz3429
* sftp(1), scp(1): when performing operations that glob(3) a remote path, ensure that the implicit working directory used to construct that path escapes glob(3) characters. This prevents glob characters from being processed in places they shouldn't, e.g. "cd /tmp/a*/", "get *.txt" should have the get operation treat the path "/tmp/a*" literally and not attempt to expand it.
* ssh(1), sshd(8): be stricter in which characters will be accepted in specifying a mask length; allow only 0-9. GHPR278
* ssh-keygen(1): avoid printing hash algorithm twice when dumping a KRL
* ssh(1), sshd(8): continue running local I/O for open channels during SSH transport rekeying. This should make ~-escapes work in the client (e.g. to exit) if the connection happened to have stalled during a rekey event.
* ssh(1), sshd(8): avoid potential poll() spin during rekeying
* Further hardening for sshbuf internals: disallow "reparenting" a hierarchical sshbuf and zero the entire buffer if reallocation fails. GHPR287
Portability -----------
* ssh(1), ssh-keygen(1), sshd(8): automatically enable the built-in FIDO security key support if libfido2 is found and usable, unless --without-security-key-builtin was requested.
* ssh(1), ssh-keygen(1), sshd(8): many fixes to make the WinHello FIDO device usable on Cygwin. The windows://hello FIDO device will be automatically used by default on this platform unless requested otherwise, or when probing resident FIDO credentials (an operation not currently supported by WinHello).
* Portable OpenSSH: remove workarounds for obsolete and unsupported versions of OpenSSL libcrypto. In particular, this release removes fallback support for OpenSSL that lacks AES-CTR or AES-GCM.
Those AES cipher modes were added to OpenSSL prior to the minimum version currently supported by OpenSSH, so this is not expected to impact any currently supported configurations.
* sshd(8): fix SANDBOX_SECCOMP_FILTER_DEBUG on current Linux/glibc
* All: resync and clean up internal CSPRNG code.
* scp(1), sftp(1), sftp-server(8): avoid linking these programs with unnecessary libraries. They are no longer linked against libz and libcrypto. This may be of benefit to space constrained systems using any of those components in isolation.
* sshd(8): add AUDIT_ARCH_PPC to supported seccomp sandbox architectures.
* configure: remove special casing of crypt(). configure will no longer search for crypt() in libcrypto, as it was removed from there years ago. configure will now only search libc and libcrypt.
* configure: refuse to use OpenSSL 3.0.4 due to potential RCE in its RSA implementation (CVE-2022-2274) on x86_64.
* All: request 1.1x API compatibility for OpenSSL >=3.x; GHPR#322
* ssh(1), ssh-keygen(1), sshd(8): fix a number of missing includes required by the XMSS code on some platforms.
* sshd(8): cache timezone data in capsicum sandbox.
Checksums: ==========
- SHA1 (openssh-9.1.tar.gz) = 3ae2d6a3a695d92778c4c4567dcd6ad481092f6c - SHA256 (openssh-9.1.tar.gz) = QKfVArlcItV+e8V1Th85TL5//5d/AvOUhYOeHMDEGuE=
- SHA1 (openssh-9.1p1.tar.gz) = 15545440268967511d3194ebf20bcd0c7ff3fcc9 - SHA256 (openssh-9.1p1.tar.gz) = GfhQCcfj4jeH8CNvuxV4OSq01L+fjsX+a8HNfov90og=
Please note that the SHA256 signatures are base64 encoded and not hexadecimal (which is the default for most checksum tools). The PGP key used to sign the releases is available from the mirror sites: https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc
Reporting Bugs: ===============
- Please read https://www.openssh.com/report.html Security bugs should be reported directly to openssh@openssh.com

UPDATE

A couple of reference pages:

Other Recent Tux Machines' Posts

Linux Mint Debian Edition Is Getting Support for OEM Installations with LMDE 7
Linux Mint Debian Edition is getting OEM support with the LMDE 7 release based on the Debian GNU/Linux 13 “Trixie” operating system.
Techrights Focus [original]
some thoughts
OpenSSL 3.5 Released with Support for PQC Algorithms, Server-Side QUIC
OpenSSL 3.5 has been released today as a major update to this open-source, cross-platform, and free software library that provides secure communications over computer networks for applications and websites.
Linus Torvalds Announces First Linux Kernel 6.15 Release Candidate
Today, Linus Torvalds announced the general availability of the first Release Candidate development milestone of the upcoming Linux 6.15 kernel series for public testing.
Benchmark Stuff: Linux Better Than Windows and Facebook is Misleading With Its Proprietary LLMs (Openwashing and Other Deceit)
testing speeds
FreeDOS 1.4 is Out
new FreeDOS release
today's howtos
many from idroot
 
Linkwarden 2.10 Brings AI Tagging, Advanced Search, and More
Linkwarden 2.10 self-hosted bookmark manager introduces powerful new tools—highlighting, advanced search
Android Leftovers
This Android OEM could let you easily overclock or underclock your phone
FreeDOS 1.4 Now Available — A Major Update for the Beloved DOS Revival
FreeDOS 1.4 open-source MS DOS-compatible OS released with updated core utilities, better reliability
Best Free and Open Source Software
We recommend the best free and open source alternatives
Proxmox Virtual Environment 8.4 Released
Proxmox VE 8.4 is out now, featuring live VM migration with NVIDIA vGPU, API for backups, virtiofs, and updated open-source tech
openSUSE’s Agama Installer Lands with Enhanced Web UI
openSUSE's new Agama installer v13 is here, bringing hostname configuration
EasyNAS – Linux distribution designed for storage management
EasyNAS is a storage management system for home or small office
CAINE – live Linux distribution for digital forensics
CAINE (Computer Aided INvestigative Environment) is an Italian Linux live distribution created as a Digital Forensics project
Wesley Gardner presents: Draw and Paint Better with Krita
Some time ago we reached out to Wesley Gardner because, a bit belatedly, we saw he has published a great book on Krita, titled Draw and Paint Better with Krita
The easiest way to try out Ubuntu Linux
Don't have a spare computer? Afraid the installation will be too difficult
We’re in Kenya. Fedora at Murang’a University
On March 28, 2025, we brought Fedora to Murang’a University of Technology in Kenya
today's leftovers
misc. picks for today
Security Leftovers
Security news and such
LWN on 6.15 merge window and the 2025 Linux Storage, Filesystem, Memory-Management, and BPF Summit
outside the paywall now
Making the OpenWrt One
GPL-enforcement activities
Catching up with calibre
Calibre development started in 2006, when creator Kovid Goyal bought a Sony E Ink reader
Today in Techrights
Some of the latest articles
OpenSUSE and Ubuntu Leftovers
only 3 more links
Free, Libre, and Open Source Software Events, More
today's leftovers
Programming Leftovers
Development of programs and games
BSD Leftovers
OpenBSD and ramble
Fedora and Red Bait (IBM) Leftovers
3 stories for now
Audiocasts/Shows: Destination Linux, MiSTer FPGA, "Non-Woke Software List", Microsoft Moles
new videos or episodes
IPFire Linux Firewall Gets Post-Quantum Cryptography Support for IPsec Tunnels
IPFire 2.29 Core Update 193 has been released today for this powerful, open-source, and secure Linux-based firewall distribution designed to protect networks against evolving cyber threats introducing post-quantum cryptography.
Fwupd 2.0.8 Adds New Plugins to Update the UEFI Signature Database and KEK
Fwupd 2.0.8 is out today as the eighth maintenance update to the latest fwupd 2.0 release of this open-source Linux firmware update utility with support for more devices, new features, and bug fixes.
IPFire 2.29 - Core Update 193 released
We are happy to announce the release of IPFire 2.29 - Core Update 193
FOSS, Education, Sharing, and Standards
today's leftovers
Programming Leftovers
Git, Prolog, and more
Windows TCO Leftovers
Microsoft's cost
IBM and Latest in redhat.com
Mostly redhat.com articles/fluff
Open Hardware: SBCs, Arduino, OrangePi, and More
Hardware picks
Android Leftovers
Google fixes two Android zero-day bugs actively exploited by hackers
Git Distributed Version Control System Turned 20
Git, Linus Torvalds's brainchild that revolutionized software development, just turned 20
Microchip SAMA7D65 Cortex-A7 MPU comes in SoC and SiP packages with up to 2Gbit integrated DDR3L memory
The company mentions that the device supports various tools and software, including the Linux4SAM platform for embedded Linux development
Free and Open Source Software, howtos and Installations
This is free and open source software
PBXware is a Linux telephony platform distribution
PBXware is a Gentoo-based single-purpose distribution that serves as a telephony platform
Plasma 6.3.4 Now Available
Although not a major release, Plasma 6.3.4 does fix some bugs and offer a subtle change for the Plasma sidebar
Games: Croc Legend of the Gobbos, The Fortress of Dr. Radiaki, and More
latest from GamingOnLinux
Today in Techrights
Some of the latest articles
Asahi Linux hits an M4 support roadblock
The Asahi Linux project is having trouble bringing the operating system to M4 Macs
Operating Systems and Standards
today's leftovers
Free, Libre, and Open Source Software Leftovers
FOSS picks for today
Native NPU support for openSUSE Linux and Logo Call openSUSE.Asia Summit
Some opensuse news
Fedora / Red Hat / IBM Leftovers
4 more stories
Open Hardware/Modding: Retro, ESP32, and More
hardware leftovers
Mozilla: Shafting Developers, Pushing LLM Slop, Firefox Nightly
Mozilla news
Programming Leftovers
Development picks for today
KDE and Qt Leftovers
mostly the latter
Audiocasts/Shows: Linux User Space and Late Night Linux
2 new episodes
FreeBSD: On FreeBSD Jails and a Journey to FreeBSD
Some BSD picks
GNOME Desktop/GTK: Foundry.DocumentationManager and Keypunch 6.0
Some GNOME news
Security Leftovers
Security-related leftovers
Applications: Istio 1.23.6, GNU gperf 3.2, SageMath, Resources 1.8, and More
Software news
today's howtos
Instructionals/Technical picks
Kernel Space: Microsoft- and Microsoft LF-Sponsored Rust-in-Linux Advocacy, Benchmarking Up To 8,192 Cores On Linux
kernel news
today's howtos
only a handful for now
Windows TCO Leftovers
Windows TCO examples
Open Hardware: Arduino abd Raspberry Pi Projects
Raspberry Pi and more
Games: Truckful, Fogpiercer, and Linux GPU Control Application (LACT)
9 new articles from GamingOnLinux
Android Leftovers
This Samsung Galaxy S25 variant will get eight years of Android updates
Wine 10.5 Released with Vulkan H.264 Decoding
Wine 10.5 is out with ARM64 large page support, updated Mono 10.0
DXVK 2.6.1 Improves Support for Assassin’s Creed Origins and AMD Vega GPUs
DXVK 2.6.1 Vulkan-based implementation of D3D9, D3D10, and D3D11 for Linux / Wine is now available for download with improvements for several games and various bug fixes.
I tried gaming on Linux — and it's better (and worse) than you think
Gaming on Linux has come a long way, but is it ready to replace Windows yet
Free and Open Source Software, howtos and Installations
This is free and open source software
BlueOnyx is a fully-integrated Internet hosting platform
BlueOnyx is open source software, released under a Sun modified BSD license
I'm a Linux power user, and the latest Ubuntu update put a smile on my face | ZDNET
Canonical is preparing the release of Ubuntu 25.04 (Plucky Puffin) with a new kernel, the latest desktop environment, and an improved installer.
Today in Techrights
Some of the latest articles