SSH.NET Fails to Strictly Adhere to SSH Protocol Standards
还没有人认领这个 Issue。
评估
- 难度
- 4/5
- 预计耗时
- 3-5 天
- 新手友好度
- 42/100
- Issue 类型
- 缺陷
- 描述清晰度
- 基本清楚
- 活跃度
- 停滞
- 技术栈
- csharp
调研方向
从 RFC 4253 和 RFC 5656 开始,然后复现所描述的两种情况:大小写混合的椭圆曲线名称,以及使用八位字节字符串表示 r 和 s 的 ECDSA 签名。检查涉及的 SSH.NET 验证路径,并为协议边界情况添加全面的测试。当格式错误的名称和签名能够根据标准一致地被拒绝时,即表示完成。
由索引模型根据 Issue 内容生成。
描述
Issue Summary: SSH.NET Fails to Strictly Adhere to SSH Protocol Standards
1. Elliptic Curve Name Case Sensitivity
According to [RFC 5656], the elliptic curve name must strictly match the defined format, which is case-sensitive. For example, nistp256 (all lowercase) is the correct identifier for the NIST P-256 curve. However, SSH.NET incorrectly accepts nistP256 (mixed case) without raising an error.
Observed Behavior:
- SSH.NET tolerates curve names with incorrect case (e.g.,
nistP256), while strict implementations like OpenSSH reject these values, leading to compatibility issues.
Impact:
- This behavior violates the SSH protocol standard, potentially causing interoperability problems with compliant clients/servers.
- It may obscure configuration errors, leading to production issues that are difficult to debug.
Suggested Fix:
- Ensure that SSH.NET strictly enforces case-sensitive validation of elliptic curve names as defined in the standard.
2. Improper Handling of ECDSA Signature Format
The ECDSA signature in SSH must follow the format specified in RFC 4253:
- The signature is an
ecdsa_signature_blobcontaining twompintvalues:rands.
However, SSH.NET does not validate the format of the signature and accepts invalid representations, such as encoding r and s as octet strings instead of mpint.
Observed Behavior:
- When the server sends an invalid ECDSA signature (e.g.,
randsencoded as octet strings), SSH.NET does not report an error. - Strict clients, like OpenSSH, correctly reject such signatures with errors such as "Signature from server's host key is invalid."
Impact:
- Interoperability Risk: Inconsistent behavior when communicating with standards-compliant clients.
- Security Risk: Weak or incorrect signature validation could expose users to potential attacks (e.g., replay attacks or signature forgery).
Suggested Fix:
- Implement strict validation of the
ecdsa_signature_blobto ensurerandsare properly formatted asmpintvalues.
3. Steps to Reproduce
Case Sensitivity Issue:
- Configure SSH.NET to use the
nistP256curve name. - Attempt to connect to a strict client/server, such as OpenSSH.
- Observe that SSH.NET establishes the connection, while OpenSSH rejects the curve name if it’s mismatched.
Invalid ECDSA Signature Issue:
- Set up an SSH server to send an ECDSA signature with
randsencoded as octet strings. - Use SSH.NET to connect to the server.
- Observe that SSH.NET accepts the connection, while OpenSSH fails with a signature validation error.
4. Proposed Actions
- Validation Enforcement: Add strict checks for curve names and signature format in SSH.NET.
- Comprehensive Testing: Introduce test cases to cover protocol edge cases and ensure compliance with RFC standards.
- Community Discussion: Gather feedback on the potential impacts of enforcing stricter validation and provide configuration options if needed.
5. References
- 主要语言
- C#
- 星标
- 4.4k
- 派生
- 990
- PR 合并指标
- 30 天内没有已合并 PR
环境准备
- 没有 Dockerfile 或 Docker Compose 文件
- 没有 Pull Request 模板
- 阅读贡献指南
从这里开始
- 先读完整个 Issue,再读项目的贡献指南。
- 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
- Fork 仓库,在一个分支上完成修改。
- 提交 Pull Request,并在描述里引用这个 Issue 编号。
sshnet/SSH.NET 的其他 Issue
-
难度 2/5 1-3 小时 新手友好度 62/100
-
难度 5/5 一周以上 新手友好度 45/100
-
ShellStream.Expect over-discards on undecodable bytes, driving ArrayBuffer.ActiveLength negative未关闭
难度 4/5 3-5 天 新手友好度 52/100
-
难度 3/5 1-2 天 新手友好度 68/100
-
难度 4/5 3-5 天 新手友好度 48/100
相似的 Issue
-
[Doc Gap] Document new --enable-public-network-access breaking change for azurebackup vault create未关闭copilot documentation
难度 2/5 1-3 小时 新手友好度 86/100
维护者通常 1 天内回复
-
area-dashboard
难度 2/5 1-3 小时 新手友好度 68/100
维护者通常 1 天内回复
-
0 - Backlog Bug
难度 2/5 1-3 小时 新手友好度 72/100
BrighterCommand/Brighter#4539 ·
维护者通常 1 天内回复
-
area-networking
难度 2/5 1-3 小时 新手友好度 68/100
dotnet/aspnetcore#69671 · 1 条评论 ·
维护者通常 1 天内回复
-
test
难度 2/5 1-3 小时 新手友好度 72/100
NethermindEth/nethermind#14274 ·
维护者通常 1 天内回复