# OpenSSH

Published articles for OpenSSH.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Security updates for Wednesday

DevFeed: [Security updates for Wednesday](<https://devfeed.tech/articles/security-updates-for-wednesday-31515.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094720/>)

Author: corbet

Published: 2026-09-16T13:40:53Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Security updates were issued by AlmaLinux, Debian, Fedora, Oracle, Red Hat, SUSE, and Ubuntu for packages including kernels, nginx, OpenSSL, Python, Perl, Git, Docker, OpenSSH, and other software.

### Source excerpt

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).

## How to Run Codex in an Ubuntu Virtual Machine on Proxmox

DevFeed: [How to Run Codex in an Ubuntu Virtual Machine on Proxmox](<https://devfeed.tech/articles/your-coding-agent-should-be-in-jail-here-s-why-and-how-32185.md>)

Original publisher: [Read original article](<https://spin.atomicobject.com/coding-agent-in-jail/>)

Author: Travis Henderson

Published: 2026-09-15T12:00:11Z

Content type: tutorial

Language: en

Sources: [Atomic Object](<https://devfeed.tech/sources/atomic-object.md>)

Topics: [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [codex](<https://devfeed.tech/topics/codex.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>), [Proxmox](<https://devfeed.tech/topics/proxmox.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Authorization](<https://devfeed.tech/topics/authorization.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-for-developers](<https://devfeed.tech/tags/ai-for-developers.md>), [codex](<https://devfeed.tech/tags/codex.md>), [coding-agents](<https://devfeed.tech/tags/coding-agents.md>), [development](<https://devfeed.tech/tags/development.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [permissions](<https://devfeed.tech/tags/permissions.md>), [proxmox](<https://devfeed.tech/tags/proxmox.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [ubuntu](<https://devfeed.tech/tags/ubuntu.md>)

### AI overview

This guide explains how to isolate Codex in a headless Ubuntu virtual machine running on Proxmox, using a separate Linux account and OpenSSH. The setup limits the files, dependencies, and network access available to the agent while keeping administrator tasks separate, but it does not eliminate risks from credentials, network access, or mistakes pushed to GitHub.

### Source excerpt

The more useful coding agents become, the more access they tend to need. Installing dependencies, running commands, changing files, and generally more autonomy are part of the appeal. They're also the point where I start thinking about what else the coding agent can reach, especially while these tools are changing so quickly. My answer is [...] The post Your Coding Agent Should be in Jail. Here's Why and How. appeared first on Atomic Spin.

## Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

DevFeed: [Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)](<https://devfeed.tech/articles/microsoft-s-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880-8267.md>)

Original publisher: [Read original article](<https://www.tenable.com/blog/microsofts-september-2026-patch-tuesday-addresses-964-cves-cve-2026-81963-cve-2026-85880>)

Author: Research Special Operations

Published: 2026-09-08T18:07:55Z

Content type: news

Language: en

Sources: [Tenable Blog](<https://devfeed.tech/sources/tenable-blog.md>)

Topics: [Microsoft](<https://devfeed.tech/topics/microsoft.md>), [cve-2026-85880](<https://devfeed.tech/topics/cve-2026-85880.md>), [.NET](<https://devfeed.tech/topics/net.md>), [ASP.NET](<https://devfeed.tech/topics/aspnet.md>), [GitHub Copilot](<https://devfeed.tech/topics/github-copilot.md>), [Visual Studio Code](<https://devfeed.tech/topics/visual-studio-code.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [asp-net-core](<https://devfeed.tech/tags/asp-net-core.md>), [cve-2026-81963](<https://devfeed.tech/tags/cve-2026-81963.md>), [cve-2026-85880](<https://devfeed.tech/tags/cve-2026-85880.md>), [github-copilot](<https://devfeed.tech/tags/github-copilot.md>), [microsoft](<https://devfeed.tech/tags/microsoft.md>), [net](<https://devfeed.tech/tags/net.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [patch-tuesday](<https://devfeed.tech/tags/patch-tuesday.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [visual-studio](<https://devfeed.tech/tags/visual-studio.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Microsoft's September 2026 Patch Tuesday release addresses 964 CVEs, including two zero-days exploited in the wild. The release rates 104 vulnerabilities as critical and 860 as important.

### Source excerpt

104Critical 860Important 0Moderate 0Low Microsoft addresses 964 CVEs, smashing July's release as the largest Patch Tuesday release. This month's updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important. This month's update includes patches for: .NET .NET and Visual Studio ASP.NET Core Active Directory Certificate Services (AD CS) Active Directory Domain Services Active Directory Federation Services (AD FS) Audio Video Control Transport Protocol Azure Arc Azure CycleCloud Azure HDInsights BranchCache Connected Devices Platform Service (Cdpsvc) Data Sharing Service Client GitHub Copilot and Visual Studio Code Graphic Fonts HID class driver IP Helper Internet Storage Name Service Kernel Streaming WOW Thunk Service Driver Microsoft Account Microsoft Authenticator Microsoft Azure Attestation service and Device Health Attestation Service Microsoft Azure CLI Microsoft COM for Windows Microsoft Dynamics 365 Microsoft Exchange Server Microsoft Graphics Component Microsoft Install Service Microsoft JScript Microsoft Local Security Authority Server (lsasrv) Microsoft Office Microsoft Office Access Microsoft Office Excel Microsoft Office Outlook Microsoft Office PowerPoint Microsoft Office Publisher Microsoft Office SharePoint Microsoft Office Word Microsoft Standard XPS Microsoft Teams for Android Microsoft Trace Data Helper Microsoft UxTheme Library (uxtheme.dll) Microsoft WDAC OLE DB provider for SQL Microsoft WebP Image Extension Microsoft Windows Codecs Library Microsoft Windows Media Foundation Microsoft Windows PDF Microsoft Windows SCSI Class System File Microsoft Windows Search Component Microsoft Windows Speech OpenSSH for Windows Power Automate Push Message Routing Service RPC Runtime Reliable Multicast Transport Driver (RMCAST) Remote Desktop Client Remote Desktop Gateway Service Role: DNS Server Role: Windows Fax Serv

## Configuring Guix services by translating Scheme fields to YAML

DevFeed: [Configuring Guix services by translating Scheme fields to YAML](<https://devfeed.tech/articles/demystifying-complex-configurations-34146.md>)

Original publisher: [Read original article](<https://guix.gnu.org/blog/2026/demystifying-complex-configurations//>)

Author: Sergio Pastor Pérez

Published: 2026-09-07T08:30:00Z

Content type: tutorial

Language: en

Sources: [GNU Guix -- Blog](<https://devfeed.tech/sources/gnu-guix-blog.md>)

Topics: [configuration](<https://devfeed.tech/topics/configuration.md>), [YAML](<https://devfeed.tech/topics/yaml.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [configuration](<https://devfeed.tech/tags/configuration.md>), [development](<https://devfeed.tech/tags/development.md>), [functional-package-management](<https://devfeed.tech/tags/functional-package-management.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [programming-interfaces](<https://devfeed.tech/tags/programming-interfaces.md>), [scheme-api](<https://devfeed.tech/tags/scheme-api.md>), [yaml](<https://devfeed.tech/tags/yaml.md>)

### AI overview

This tutorial explains how Guix services represent configuration through Scheme bindings and how to define a complex Goimapnotify service configuration by translating Guile Scheme fields into YAML.

### Source excerpt

Guix system and Guix home introduce the concept of services. These provide users with a way to control background processes, commonly refereed as daemons , as well as ways of controlling the setup of files. For example, openssh-service-type is a service which controls a SSH daemon. In contrast, etc-service-type is a service that populates the contents of the /etc directory. One peculiarity of Guix services is that it's customary to provide Scheme bindings for the different fields. By that I mean that the different fields of the configuration of most services will be a...

## August 2026 Updates #1 for XCP-ng 8.3 LTS

DevFeed: [August 2026 Updates #1 for XCP-ng 8.3 LTS](<https://devfeed.tech/articles/august-2026-updates-1-for-xcp-ng-8-3-lts-12824.md>)

Original publisher: [Read original article](<https://xcp-ng.org/blog/2026/08/18/august-2026-updates-1-for-xcp-ng-8-3-lts/>)

Author: Samuel Verschelde

Published: 2026-08-18T16:22:04Z

Content type: article

Language: en

Sources: [XCP-ng Blog](<https://devfeed.tech/sources/xcp-ng-blog.md>)

Topics: [Disk image](<https://devfeed.tech/topics/disk-image.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Software](<https://devfeed.tech/topics/software.md>)

Tags: [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [lts](<https://devfeed.tech/tags/lts.md>), [maintenance](<https://devfeed.tech/tags/maintenance.md>), [maintenance-updates](<https://devfeed.tech/tags/maintenance-updates.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [performance](<https://devfeed.tech/tags/performance.md>), [storage](<https://devfeed.tech/tags/storage.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

This article announces maintenance updates for XCP-ng 8.3 LTS. It explains the required rolling update process and highlights storage improvements, including live leaf coalescing for QCOW2, faster QCOW2 storage repository scans, and improved responsiveness for LINSTOR storage repositories.

### Source excerpt

Maintenance updates for XCP-ng: storage performance and fixes, configurable OpenSSH, and much more.

## Linux ssh-keygen: Set Up SSH Key Authentication the Right Way

DevFeed: [Linux ssh-keygen: Set Up SSH Key Authentication the Right Way](<https://devfeed.tech/articles/linux-ssh-keygen-set-up-ssh-key-authentication-the-right-way-20873.md>)

Original publisher: [Read original article](<https://linuxblog.io/linux-ssh-keygen-set-up-ssh-key-authentication-the-right-way/>)

Author: Hayden James

Published: 2026-08-03T10:53:19Z

Content type: tutorial

Language: en

Sources: [Hayden James](<https://devfeed.tech/sources/hayden-james.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [Security](<https://devfeed.tech/topics/security.md>), [passwords](<https://devfeed.tech/topics/passwords.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [blog](<https://devfeed.tech/tags/blog.md>), [guide](<https://devfeed.tech/tags/guide.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [password](<https://devfeed.tech/tags/password.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [sysadmins](<https://devfeed.tech/tags/sysadmins.md>)

### AI overview

A practical guide to setting up SSH key authentication on Linux with ssh-keygen. It covers generating key pairs, copying public keys to servers, disabling password login safely, configuring multiple identities, and using passphrases or FIDO2 security keys.

### Source excerpt

Password-based SSH login is a liability. This guide walks through generating SSH key pairs with ssh-keygen, deploying public keys, disabling password authentication, and managing multiple keys cleanly with ~/.ssh/config. Continue reading...

## June 2026 Updates #1 for XCP-ng 8.3 LTS

DevFeed: [June 2026 Updates #1 for XCP-ng 8.3 LTS](<https://devfeed.tech/articles/june-2026-updates-1-for-xcp-ng-8-3-lts-12819.md>)

Original publisher: [Read original article](<https://xcp-ng.org/blog/2026/06/02/june-2026-updates-1-for-xcp-ng-8-3-lts/>)

Author: Philippe Coval

Published: 2026-06-02T16:17:58Z

Content type: release

Language: en

Sources: [XCP-ng Blog](<https://devfeed.tech/sources/xcp-ng-blog.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [UEFI](<https://devfeed.tech/topics/uefi.md>), [USB](<https://devfeed.tech/topics/usb.md>), [io\_uring](<https://devfeed.tech/topics/io-uring.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [lts](<https://devfeed.tech/tags/lts.md>), [maintenance-updates](<https://devfeed.tech/tags/maintenance-updates.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [uefi](<https://devfeed.tech/tags/uefi.md>), [update](<https://devfeed.tech/tags/update.md>), [updates](<https://devfeed.tech/tags/updates.md>), [usb](<https://devfeed.tech/tags/usb.md>)

### AI overview

XCP-ng 8.3 LTS receives security and maintenance updates. The release fixes Linux kernel vulnerabilities in the control domain, including issues that could allow an unprivileged local user to gain root privileges, and rejects obsolete insecure OpenSSH clients. It also includes improvements for USB smartcard passthrough, QEMU memory mapping, UEFI booting and CPU limits, PXE booting, and dmidecode.

### Source excerpt

Security vulnerabilities have been identified and fixed in the Linux kernel used by XCP-ng's control domain (dom0). Additional lower-priority maintenance updates are included in this release alongside these security fixes.

## PowerShell, OpenSSH, and DSC team investments for 2026

DevFeed: [PowerShell, OpenSSH, and DSC team investments for 2026](<https://devfeed.tech/articles/powershell-openssh-and-dsc-team-investments-for-2026-2990.md>)

Original publisher: [Read original article](<https://devblogs.microsoft.com/powershell/powershell-openssh-and-dsc-team-investments-for-2026/>)

Author: Steve Lee

Published: 2026-02-17T19:21:34Z

Content type: article

Language: en

Sources: [PowerShell Team](<https://devfeed.tech/sources/powershell-team.md>)

Topics: [PowerShell](<https://devfeed.tech/topics/powershell.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Security](<https://devfeed.tech/topics/security.md>), [Tooling](<https://devfeed.tech/topics/tooling.md>), [pull-requests](<https://devfeed.tech/topics/pull-requests.md>)

Tags: [community](<https://devfeed.tech/tags/community.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [post](<https://devfeed.tech/tags/post.md>), [powershell](<https://devfeed.tech/tags/powershell.md>), [pull-requests](<https://devfeed.tech/tags/pull-requests.md>), [security](<https://devfeed.tech/tags/security.md>), [tooling](<https://devfeed.tech/tags/tooling.md>)

### AI overview

The PowerShell, OpenSSH, and DSC teams outline planned investments for 2026, emphasizing security and compliance, critical bug fixes, community pull requests, and upcoming PowerShell improvements. Proposed work includes relocating PSUserContentPath, enabling module features without profile scripts, and improving update notifications.

### Source excerpt

Planned team investments for 2026 for PowerShell, OpenSSH, DSC, and related tooling. The post PowerShell, OpenSSH, and DSC team investments for 2026 appeared first on PowerShell Team.

## Cómo configurar un servidor SSH seguro en Linux

DevFeed: [Cómo configurar un servidor SSH seguro en Linux](<https://devfeed.tech/articles/como-configurar-un-servidor-ssh-seguro-en-linux-34052.md>)

Original publisher: [Read original article](<https://tengoping.com/blog/configurar-servidor-ssh-seguro-linux/>)

Author: Antonio Pérez

Published: 2026-01-01T00:00:00Z

Content type: tutorial

Language: es

Sources: [tengoping.com](<https://devfeed.tech/sources/tengoping-com.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Fail2ban](<https://devfeed.tech/topics/fail2ban.md>)

Tags: [fail2ban](<https://devfeed.tech/tags/fail2ban.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [hardening](<https://devfeed.tech/tags/hardening.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>)

### AI overview

A step-by-step guide to securing an OpenSSH server on Linux. It covers layered protections including non-standard ports, public-key authentication, hardened ciphers, two-factor authentication, and fail2ban, along with configuration and verification guidance.

### Source excerpt

Guía paso a paso para configurar y securizar un servidor SSH en cualquier servidor Linux, incluyendo autenticación por clave, fail2ban y mejores prácticas.

## Recovering/undeleting short deleted files in 50 SLOC of pure C, any filesystem supported.

DevFeed: [Recovering/undeleting short deleted files in 50 SLOC of pure C, any filesystem supported.](<https://devfeed.tech/articles/recovering-undeleting-short-deleted-files-in-50-sloc-of-pure-c-any-filesystem-supported-20584.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/undelete/>)

Published: 2025-10-13T22:00:00Z

Content type: tutorial

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [C](<https://devfeed.tech/topics/c.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [SQLite](<https://devfeed.tech/topics/sqlite.md>), [Bitcoin](<https://devfeed.tech/topics/bitcoin.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [bitcoin](<https://devfeed.tech/tags/bitcoin.md>), [bug](<https://devfeed.tech/tags/bug.md>), [c](<https://devfeed.tech/tags/c.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [files](<https://devfeed.tech/tags/files.md>), [filesystem](<https://devfeed.tech/tags/filesystem.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [sqlite](<https://devfeed.tech/tags/sqlite.md>)

### AI overview

This article presents a small pure-C utility for recovering short deleted files by scanning storage for known file headers or boundary strings. It describes recovering data from Linux ext4 SSDs, virtual-machine images, and RAM save files, and notes that deleted OpenSSH keys and Bitcoin wallets may be identifiable. It recommends secure deletion and filesystem encryption to reduce recovery risk.

### Source excerpt

Recovering/undeleting short deleted files in 50 SLOC of pure C, any filesystem supported.

## Mobian Trixie Released as the New Stable Version with Rotating Signing Keys

DevFeed: [Mobian Trixie Released as the New Stable Version with Rotating Signing Keys](<https://devfeed.tech/articles/a-new-stable-and-rotating-keys-34242.md>)

Original publisher: [Read original article](<https://blog.mobian.org/posts/2025/10/new-stable-rotating-keys/>)

Author: Mobian team

Published: 2025-10-13T12:00:00Z

Content type: release

Language: en

Sources: [Mobian's Blog](<https://devfeed.tech/sources/mobian-s-blog.md>)

Topics: [Debian](<https://devfeed.tech/topics/debian.md>), [Mobile](<https://devfeed.tech/topics/mobile.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [kernel](<https://devfeed.tech/tags/kernel.md>), [mobile](<https://devfeed.tech/tags/mobile.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [release](<https://devfeed.tech/tags/release.md>), [stable](<https://devfeed.tech/tags/stable.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>)

### AI overview

Mobian has released Trixie as its new stable version and is beginning to rotate the PGP/GPG keys used to sign its images and package archive. The release includes mobile images based on Phosh 46.0 and Plasma Mobile 6.3, with a 6.12 kernel for most supported devices.

### Source excerpt

A little more than 2 months after Debian, we're finally releasing Mobian Trixie as our new stable release! We're also taking this opportunity to start rotating the PGP/GPG keys we're using for signing both our images and package archive. Trixie has landed! Over 2 years in the making, and with a small delay following the Debian release, we're proud to finally announce Mobian Trixie has just been released and is therefore our new stable! This release offers images based on Phosh 46.0 and Plasma Mobile 6.3, running a 6.12 kernel for almost all supported devices (the Librem 5 is still using a 6.6 kernel), the list of which is growing as we now provide stable images for the following phones and tablets: PINE64 PinePhone, PinePhone Pro and PineTab Purism Librem 5 Google Pixel 3a and 3a XL OnePlus 6 and 6T Xiaomi Pocophone F1 Trixie images are also available for the following devices, although important hardware features (such as e.g. WiFi or audio) are not working: Fairphone 4 and 5 PINE64 PineTab 2 SHIFT6mq Please check our installation instructions and download the image for your device. Upgrade procedure Although we do our best to provide a smooth upgrade path for each Mobian release, as a downstream Debian derivative, and the mobile software stack being a quickly moving target, major Mobian upgrades are usually trickier than we'd hoped for. This time is no exception, and therefore we highly recommend that you backup all your personal data, flash your device with a fresh Trixie image, then restore your files. If you feel brave enough to go the "manual upgrade" route, here are a few tricks you should know: keep your device plugged to a power source: such an upgrade can be a rather long process, you don't want to run out of battery half-way there! backup all your personal data really, we mean it: backup all your personal data! install openssh-server and execute the entire upgrade process over SSH (and preferrably using screen or a similar tool, so the upgrade can carry o

## Response: NAT Traversal Mess

DevFeed: [Response: NAT Traversal Mess](<https://devfeed.tech/articles/response-nat-traversal-mess-11172.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2025/04/response-nat-traversal/>)

Published: 2025-04-10T06:00:00Z

Content type: opinion

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [networking](<https://devfeed.tech/topics/networking.md>), [firewalls](<https://devfeed.tech/topics/firewalls.md>), [client](<https://devfeed.tech/topics/client.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>)

Tags: [connectivity](<https://devfeed.tech/tags/connectivity.md>), [firewalls](<https://devfeed.tech/tags/firewalls.md>), [github](<https://devfeed.tech/tags/github.md>), [internet](<https://devfeed.tech/tags/internet.md>), [libraries](<https://devfeed.tech/tags/libraries.md>), [nat](<https://devfeed.tech/tags/nat.md>), [networking](<https://devfeed.tech/tags/networking.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [pypi](<https://devfeed.tech/tags/pypi.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [video-conferencing](<https://devfeed.tech/tags/video-conferencing.md>)

### AI overview

The article examines NAT traversal for client-to-client connectivity, explaining the roles and limitations of STUN, TURN, and ICE, and contrasting them with protocols that request public ports from NAT devices. It argues that NAT remains difficult to avoid and notes the availability of libraries that simplify implementation.

### Source excerpt

Let's look at another part of the lengthy comment Bob left after listening to the Rise of NAT podcast. This one is focused on the NAT traversal mess: You mentioned that only video-conferencing and BitTorrent use client-to-client connectivity (and they are indeed the main use cases), but hell, do they need to engineer complex systems to circumvent these NATs and firewalls: STUN, TURN, ICE, DHT... Cleaning up the acronym list first: DHT is unlike the others and has nothing to do with NAT. Read more ...

## Nix Weekly Recap: 2024-07-07

DevFeed: [Nix Weekly Recap: 2024-07-07](<https://devfeed.tech/articles/nix-weekly-recap-2024-07-07-34725.md>)

Original publisher: [Read original article](<https://nixpkgs.news/archive/2024-07-07/>)

Published: 2024-07-07T00:00:00Z

Content type: news

Language: en

Sources: [nixpkgs.news](<https://devfeed.tech/sources/nixpkgs-news.md>)

Topics: [Nix](<https://devfeed.tech/topics/nix.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Development](<https://devfeed.tech/topics/development.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [FIRST](<https://devfeed.tech/topics/first.md>), [Shell](<https://devfeed.tech/topics/shell.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [GitHub](<https://devfeed.tech/topics/github.md>)

Tags: [github](<https://devfeed.tech/tags/github.md>), [modular](<https://devfeed.tech/tags/modular.md>), [module](<https://devfeed.tech/tags/module.md>), [news](<https://devfeed.tech/tags/news.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [recap](<https://devfeed.tech/tags/recap.md>), [report](<https://devfeed.tech/tags/report.md>), [security](<https://devfeed.tech/tags/security.md>), [security-advisory](<https://devfeed.tech/tags/security-advisory.md>), [weekly](<https://devfeed.tech/tags/weekly.md>)

### AI overview

This weekly Nix ecosystem recap announces that nixpkgs.news will stop issuing new releases and focus primarily on news about Lix and Aux. It also covers an OpenSSH CVE-2024-6387 security advisory, the modular make-shell project, the faster nix-search utility, and updates to Nixpkgs governance.

### Source excerpt

Critical SSH vulnerability, improved DX for dev shells, faster search, and Nix Constitutional Assembly updates.

## Chainguard's response to CVE-2024-3094, aka the backdoor in xz library

DevFeed: [Chainguard's response to CVE-2024-3094, aka the backdoor in xz library](<https://devfeed.tech/articles/chainguard-s-response-to-cve-2024-3094-aka-the-backdoor-in-xz-library-12995.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguards-response-to-cve-2024-3094-aka-the-backdoor-in-xz-library>)

Published: 2024-03-29T00:00:00Z

Content type: opinion

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [backdoor](<https://devfeed.tech/topics/backdoor.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Compression](<https://devfeed.tech/topics/compression.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [backdoor](<https://devfeed.tech/tags/backdoor.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [compression](<https://devfeed.tech/tags/compression.md>), [customer-trust](<https://devfeed.tech/tags/customer-trust.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cve-2024-3094](<https://devfeed.tech/tags/cve-2024-3094.md>), [liblzma](<https://devfeed.tech/tags/liblzma.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [secure-images](<https://devfeed.tech/tags/secure-images.md>), [security](<https://devfeed.tech/tags/security.md>), [xz](<https://devfeed.tech/tags/xz.md>), [xz-library](<https://devfeed.tech/tags/xz-library.md>)

### AI overview

Chainguard describes its response to CVE-2024-3094, a backdoor introduced into the upstream xz/liblzma project. It says its Images were not affected, while impacted packages were withdrawn, revoked, and rebuilt with unaffected liblzma versions.

### Source excerpt

Chainguard effectively addresses CVE-2024-3094 in xz library, showcasing quick action to secure images and uphold customer trust.

## Application and AI roundup - August

DevFeed: [Application and AI roundup - August](<https://devfeed.tech/articles/application-and-ai-roundup-august-36676.md>)

Original publisher: [Read original article](<https://shostack.org/blog/appsec-roundup-aug/>)

Author: Adam

Published: 2023-08-30T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [LLMs](<https://devfeed.tech/topics/llms.md>), [Application Security](<https://devfeed.tech/topics/application-security.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [amazon](<https://devfeed.tech/tags/amazon.md>), [application-security](<https://devfeed.tech/tags/application-security.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [llms](<https://devfeed.tech/tags/llms.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

An August roundup of articles and developments covering large language models, AI product development, AI threats, application security, threat modeling, OpenSSH sandboxing, regulatory requirements, and Amazon's Threat Composer tool.

### Source excerpt

Lots of interesting work in LLMs (again)

## How to Choose an SSH Client for Windows

DevFeed: [How to Choose an SSH Client for Windows](<https://devfeed.tech/articles/how-to-choose-a-ssh-client-for-windows-29603.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/choosing-ssh-client-windows/>)

Author: info@goteleport.com (Ruort Zest, Grzegorz Zdunek)

Published: 2023-08-20T00:00:00Z

Content type: comparison

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [ssh](<https://devfeed.tech/topics/ssh.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [client](<https://devfeed.tech/topics/client.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Software](<https://devfeed.tech/topics/software.md>), [Terminal](<https://devfeed.tech/topics/terminal.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [compare](<https://devfeed.tech/tags/compare.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

This comparison reviews Windows-friendly SSH clients for connecting securely to Linux-based servers, Kubernetes containers, and microservices. It discusses cost, setup and usability, protocol support, and features, including PuTTY and SecureCRT.

### Source excerpt

There are several Windows-friendly SSH clients to keep connections secure. We explore the most common ones and compare their core characteristics.

## Teleport Files with SCP

DevFeed: [Teleport Files with SCP](<https://devfeed.tech/articles/teleport-files-with-scp-29921.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-files/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2023-06-30T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [credentials](<https://devfeed.tech/tags/credentials.md>), [files](<https://devfeed.tech/tags/files.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [remote](<https://devfeed.tech/tags/remote.md>), [server](<https://devfeed.tech/tags/server.md>), [sftp](<https://devfeed.tech/tags/sftp.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

A tutorial on transferring files between local and remote systems with SCP, including copying files in both directions and between two remote hosts. It covers OpenSSH SCP and Teleport's secure file copy options, including the Teleport UI and Teleport Connect.

### Source excerpt

In this blog post, we'll cover how to transfer files from one server to another.

## Teleport 13 Newsletter

DevFeed: [Teleport 13 Newsletter](<https://devfeed.tech/articles/teleport-13-newsletter-29892.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/teleport-13-newsletter/>)

Author: ben@goteleport.com (Ben Arent)

Published: 2023-04-15T00:00:00Z

Content type: release

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [releases](<https://devfeed.tech/topics/releases.md>), [Release notes](<https://devfeed.tech/topics/release-notes.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [OpenID connect (OIDC)](<https://devfeed.tech/topics/oidc.md>), [opensearch](<https://devfeed.tech/topics/opensearch.md>), [terraform provider](<https://devfeed.tech/topics/terraform-provider.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [newsletter](<https://devfeed.tech/tags/newsletter.md>), [oidc](<https://devfeed.tech/tags/oidc.md>), [opensearch](<https://devfeed.tech/tags/opensearch.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [terraform-provider](<https://devfeed.tech/tags/terraform-provider.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

The May 2023 Teleport newsletter summarizes the Teleport 13 release, including automatic agent upgrades, no-code AWS onboarding, TLS routing through an ALB, universal binaries, improved OpenSSH support, Kubernetes tracing, Okta application protection, AWS OpenSearch support, and Windows session recording export.

### Source excerpt

Teleport 13 Newsletter - May 2023 Edition

## SFTP: a More Secure Successor to SCP

DevFeed: [SFTP: a More Secure Successor to SCP](<https://devfeed.tech/articles/sftp-a-more-secure-successor-to-scp-29844.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/sftp/>)

Author: andrew.lefevre@goteleport.com (Andrew LeFevre)

Published: 2022-12-30T00:00:00Z

Content type: article

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [integrity](<https://devfeed.tech/topics/integrity.md>)

Tags: [cryptography](<https://devfeed.tech/tags/cryptography.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [secure-software](<https://devfeed.tech/tags/secure-software.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article explains how SCP and SFTP transfer files over SSH, describes SCP's operation, and argues that SFTP is the more secure successor and should generally be preferred. It also discusses security properties and vulnerabilities associated with SCP.

### Source excerpt

SCP is a simple protocol, but it's not secure. SFTP is a more secure successor to SCP, and should be used wherever possible.

## Why OpenSSH private key files differ after restoration

DevFeed: [Why OpenSSH private key files differ after restoration](<https://devfeed.tech/articles/marshaling-ssh-private-keys-why-there-s-always-a-different-block-37851.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/ssh-marshal-private-key/>)

Author: Carlos Alexandro Becker

Published: 2022-12-20T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [private key](<https://devfeed.tech/topics/private-key.md>), [Go](<https://devfeed.tech/topics/go.md>), [Code](<https://devfeed.tech/topics/code.md>), [C](<https://devfeed.tech/topics/c.md>)

Tags: [code](<https://devfeed.tech/tags/code.md>), [go](<https://devfeed.tech/tags/go.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This article investigates why restoring an SSH private key and marshaling it back to OpenSSH private-key format produces a different block. It explains that duplicated random values in the encrypted format allow successful decryption to be checked, while the restored keys can still represent the same key.

### Source excerpt

Not long ago, when I was building melt, I learned something interesting.

## Issuing and using SSH Certificates

DevFeed: [Issuing and using SSH Certificates](<https://devfeed.tech/articles/issuing-and-using-ssh-certificates-37850.md>)

Original publisher: [Read original article](<https://carlosbecker.com/posts/ssh-certificates/>)

Author: Carlos Alexandro Becker

Published: 2022-11-09T00:00:00Z

Content type: tutorial

Language: en

Sources: [Carlos Becker](<https://devfeed.tech/sources/carlos-becker.md>)

Topics: [certificates](<https://devfeed.tech/topics/certificates.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Docker](<https://devfeed.tech/topics/docker.md>), [configuration-management](<https://devfeed.tech/topics/configuration-management.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [configuration-management](<https://devfeed.tech/tags/configuration-management.md>), [docker](<https://devfeed.tech/tags/docker.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [ssh](<https://devfeed.tech/tags/ssh.md>)

### AI overview

This tutorial explains how SSH certificates let administrators control access to servers without managing authorized keys. It covers creating a Certificate Authority key pair, issuing short-lived user certificates, using certificates with private keys, and testing the setup with OpenSSH in Docker.

### Source excerpt

SSH certificates allow system administrators to SSH into machines without having to manage authorized keys in the servers.

## SSH Certificates: How Do OpenSSH Certificates Compare to X.509?

DevFeed: [SSH Certificates: How Do OpenSSH Certificates Compare to X.509?](<https://devfeed.tech/articles/ssh-certificates-how-do-openssh-certificates-compare-to-x-509-29978.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/x509-vs-openssh-certificates/>)

Author: sakshyam.shah@goteleport.com (Sakshyam Shah)

Published: 2022-06-23T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [public key](<https://devfeed.tech/topics/public-key.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This article explains how OpenSSH certificates differ from X.509 certificates. It describes OpenSSH's custom certificate format and certificate-based authentication flow, including CA signing, certificate validation, expiration checks, and security constraints.

### Source excerpt

Learn how OpenSSH certificates differ from X.509.

## SSH configuration | ssh\_config

DevFeed: [SSH configuration | ssh\_config](<https://devfeed.tech/articles/ssh-configuration-ssh-config-29868.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/ssh-config/>)

Author: info@goteleport.com (Virag Mody)

Published: 2022-05-02T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [ssh](<https://devfeed.tech/topics/ssh.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Unix](<https://devfeed.tech/topics/unix.md>), [macOS](<https://devfeed.tech/topics/macos.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [command-line](<https://devfeed.tech/tags/command-line.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [ed25519](<https://devfeed.tech/tags/ed25519.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [remote](<https://devfeed.tech/tags/remote.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tips](<https://devfeed.tech/tags/tips.md>), [tips-and-tricks](<https://devfeed.tech/tags/tips-and-tricks.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

A tutorial on configuring the SSH client through ssh_config. It explains configuration precedence, host-specific settings, readable stanzas, and ways to improve security, reduce failures, and simplify connections to remote machines.

### Source excerpt

What is ssh_config? How do you configure an SSH client with it? This blog post offers some of our favorite tips and tricks!

## How to Configure SSH Certificate-Based Authentication

DevFeed: [How to Configure SSH Certificate-Based Authentication](<https://devfeed.tech/articles/how-to-configure-ssh-certificate-based-authentication-29683.md>)

Original publisher: [Read original article](<https://goteleport.com/blog/how-to-configure-ssh-certificate-based-authentication/>)

Author: info@goteleport.com (Honda McLaren)

Published: 2022-04-26T00:00:00Z

Content type: tutorial

Language: en

Sources: [Teleport](<https://devfeed.tech/sources/teleport.md>)

Topics: [Authentication](<https://devfeed.tech/topics/authentication.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [Security](<https://devfeed.tech/topics/security.md>), [public key](<https://devfeed.tech/topics/public-key.md>), [private key](<https://devfeed.tech/topics/private-key.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [tutorial](<https://devfeed.tech/tags/tutorial.md>)

### AI overview

This tutorial explains how to configure SSH certificate-based authentication for an OpenSSH server. It contrasts static SSH keys with short-lived, CA-signed certificates that include identity, expiration, and policy controls, and outlines how servers validate certificates.

### Source excerpt

Learn how to configure SSH certificate-based authentication in OpenSSH using short-lived, CA-signed certificates to replace static SSH keys and improve security.

[Next page](<https://devfeed.tech/tags/openssh.md?cursor=WyIyMDIyLTA0LTI2VDAwOjAwOjAwKzAwOjAwIiwgImZhYTczMGY5LTdiODktNDA3OS04YjFiLThlYTZmZDI3M2EzMSJd>)