Recommended update for openssh8.4

Announcement ID: SUSE-RU-2024:0918-1
Rating: moderate
References:
Affected Products:
  • SUSE Linux Enterprise High Performance Computing 12 SP5
  • SUSE Linux Enterprise Server 12 SP5
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
  • SUSE Linux Enterprise Software Development Kit 12 SP5

An update that contains two features and has one fix can now be installed.

Description:

This update for libcbor, libfido2, openssh8.4 fixes the following issues:

This update brings a parallel installable version of openssh 8.4 (same as SUSE Linux Enterprise 15 version).

This release contains:

  • added cryptographic ciphers required by various compliance standards
  • FIDO key support
  • more

The default openssh is kept as there might be incompatibilities between configurations.

A transition to openssh 8.4 needs to be triggered manually by doing:

    zypper in openssh8.4-server
    zypper in openssh8.4-clients

When zypper prompts you, select deinstallation of the regular openssh and installation of the new openssh8.4 packages.

After doing this review if the service starts or if it needs configuration adjustments.

If sshd.service was default enabled before, you will need to also enable it again doing these once:

systemctl enable sshd.service
systemctl start sshd.service

This update also shops libfido2 supporting the FIDO keys.

openssh was also enhanced to:

  • Add conflicts with openssh8.4-(server|clients|common) packages to make the downgrading from openssh 8.4 back to 7.2 easier (SLE-24929, bsc#1201750)

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE Linux Enterprise Software Development Kit 12 SP5
    zypper in -t patch SUSE-SLE-SDK-12-SP5-2024-918=1
  • SUSE Linux Enterprise High Performance Computing 12 SP5
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-918=1
  • SUSE Linux Enterprise Server 12 SP5
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-918=1
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5
    zypper in -t patch SUSE-SLE-SERVER-12-SP5-2024-918=1

Package List:

  • SUSE Linux Enterprise Software Development Kit 12 SP5 (aarch64 ppc64le s390x x86_64)
    • libfido2-devel-1.5.0-8.3.22
    • libcbor-devel-0.5.0-8.3.20
  • SUSE Linux Enterprise High Performance Computing 12 SP5 (aarch64 x86_64)
    • openssh8.4-askpass-gnome-debuginfo-8.4p1-8.10.1
    • openssh8.4-clients-8.4p1-8.10.1
    • openssh8.4-common-debuginfo-8.4p1-8.10.1
    • openssh8.4-common-8.4p1-8.10.1
    • openssh8.4-fips-8.4p1-8.10.1
    • libcbor0-debuginfo-0.5.0-8.3.20
    • libfido2-utils-debuginfo-1.5.0-8.3.22
    • libfido2-debugsource-1.5.0-8.3.22
    • libfido2-1-debuginfo-1.5.0-8.3.22
    • openssh8.4-helpers-8.4p1-8.10.1
    • openssh8.4-debugsource-8.4p1-8.10.1
    • libcbor0-0.5.0-8.3.20
    • openssh8.4-helpers-debuginfo-8.4p1-8.10.1
    • libfido2-utils-1.5.0-8.3.22
    • openssh8.4-8.4p1-8.10.1
    • openssh8.4-server-debuginfo-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-debugsource-8.4p1-8.10.1
    • libfido2-1-1.5.0-8.3.22
    • openssh8.4-server-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-8.4p1-8.10.1
    • openssh8.4-clients-debuginfo-8.4p1-8.10.1
  • SUSE Linux Enterprise High Performance Computing 12 SP5 (noarch)
    • libfido2-udev-1.5.0-8.3.22
  • SUSE Linux Enterprise Server 12 SP5 (aarch64 ppc64le s390x x86_64)
    • openssh8.4-askpass-gnome-debuginfo-8.4p1-8.10.1
    • openssh8.4-clients-8.4p1-8.10.1
    • openssh8.4-common-debuginfo-8.4p1-8.10.1
    • openssh8.4-common-8.4p1-8.10.1
    • openssh8.4-fips-8.4p1-8.10.1
    • libcbor0-debuginfo-0.5.0-8.3.20
    • libfido2-utils-debuginfo-1.5.0-8.3.22
    • libfido2-debugsource-1.5.0-8.3.22
    • libfido2-1-debuginfo-1.5.0-8.3.22
    • openssh8.4-helpers-8.4p1-8.10.1
    • openssh8.4-debugsource-8.4p1-8.10.1
    • libcbor0-0.5.0-8.3.20
    • openssh8.4-helpers-debuginfo-8.4p1-8.10.1
    • libfido2-utils-1.5.0-8.3.22
    • openssh8.4-8.4p1-8.10.1
    • openssh8.4-server-debuginfo-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-debugsource-8.4p1-8.10.1
    • libfido2-1-1.5.0-8.3.22
    • openssh8.4-server-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-8.4p1-8.10.1
    • openssh8.4-clients-debuginfo-8.4p1-8.10.1
  • SUSE Linux Enterprise Server 12 SP5 (noarch)
    • libfido2-udev-1.5.0-8.3.22
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 (ppc64le x86_64)
    • openssh8.4-askpass-gnome-debuginfo-8.4p1-8.10.1
    • openssh8.4-clients-8.4p1-8.10.1
    • openssh8.4-common-debuginfo-8.4p1-8.10.1
    • openssh8.4-common-8.4p1-8.10.1
    • openssh8.4-fips-8.4p1-8.10.1
    • libcbor0-debuginfo-0.5.0-8.3.20
    • libfido2-utils-debuginfo-1.5.0-8.3.22
    • libfido2-debugsource-1.5.0-8.3.22
    • libfido2-1-debuginfo-1.5.0-8.3.22
    • openssh8.4-helpers-8.4p1-8.10.1
    • openssh8.4-debugsource-8.4p1-8.10.1
    • libcbor0-0.5.0-8.3.20
    • openssh8.4-helpers-debuginfo-8.4p1-8.10.1
    • libfido2-utils-1.5.0-8.3.22
    • openssh8.4-8.4p1-8.10.1
    • openssh8.4-server-debuginfo-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-debugsource-8.4p1-8.10.1
    • libfido2-1-1.5.0-8.3.22
    • openssh8.4-server-8.4p1-8.10.1
    • openssh8.4-askpass-gnome-8.4p1-8.10.1
    • openssh8.4-clients-debuginfo-8.4p1-8.10.1
  • SUSE Linux Enterprise Server for SAP Applications 12 SP5 (noarch)
    • libfido2-udev-1.5.0-8.3.22

References: