IArch Linux itshintsha i-algorithm ye-hashing yegama lokugqitha

Arch Linux

IArch Linux yinjongo ngokubanzi yokusasazwa kweLinux ejolise kubasebenzisi abaphambili.

Kwiintsuku ezimbalwa ezidlulileyo yabhengezwa ngokupapashwa kwiwebhusayithi yeArch Linux esemthethweni, apho i Abaphuhlisi babhengeze utshintsho kwiskimu se-hashing Igama lokugqitha elingagqibekanga, kunye notshintsho lwenziwe kuqwalaselo lwe umask.

Isithuba sikhankanya ukuba iArch Linu yakha ngokux bayakusuka ekusebenziseni i-SHA512 HASH basebenzise yescrypt.

yescrypt ludweliso olutsha loguqulelo oluntsonkothileyo amagama agqithisiweyo kwaye uvelise izitshixo ze-cryptographic ukusuka kwiiphasiwedi okanye amagama okugqithisa. Yescrypt Isekwe kwi-scrypt kwaye ibandakanya inkxaso ye-scrypt yakudala, uguqulelo olugcinayo lokufihla (okubizwa ngokuba yi-YESCRYPT_WORM) kwaye ekugqibeleni uguqulelo olunzulu lokufihla (okubizwa ngokuba yi-YESCRYPT_RW), olunikezwa njengelona liphambili (kwaye lichazwa ngu-yescrypt ukususela ngoku ukuya phambili).

Phakathi kweengenelo ukusuka Yescrypt, kukhankanyiwe ukuba oku yandisa izakhono ze-scrypt yakudala ngokuxhasa ukusetyenziswa kwezicwangciso ezinzulu kwimemori kunye nokunciphisa ukusebenza kohlaselo kusetyenziswa iiGPU, iiFPGA, kunye neechips ezikhethekileyo. Ezokhuseleko ngu Yescrypt iqinisekiswa ngu ukusetyenziswa kwe-cryptographic primitives I-SHA-256, i-HMAC kunye ne-PBKDF2 sele ivavanyiwe.

I-Yescrypt sesona skim se-hashing se-password esinokuhlaselwa kakhulu, sibonelela ngokhuseleko olusondele kakhulu ngokuchasene nohlaselo olungasebenziyo kuluhlu olubanzi lweememori ezisebenzisekayo, ukusuka kwiikhilobhayithi ukuya kwiiterabytes nangaphaya. Ngakolunye uhlangothi, iindleko zolu bunzima be-yescrypt, kwaye ubunzima buyinto engafanelekanga kuyo nayiphi na isofthiwe.

Ngenxa yesi sizathu, yescrypt okwangoku yenzelwe ukusasazwa okukhulu (izigidi zeephasiwedi) apho ubunzima be-yescrypt buncinci xa kuthelekiswa nobunzima benkonzo yoqinisekiso. Ukusasazwa okuncinci kunye nokudityaniswa kwenkqubo, i-bcrypt ihlala iyinketho yexesha elifutshane elifanelekileyo okwangoku.

Ngelixa kwicala lokungalungi yenkqubo yehashing esetyenzisiweyo ngaphambili esekelwe kwi-algorithm I-SHA512 ibandakanya: limfuneko yokuseta amaxabiso etyuwa amakhulu ngokwaneleyo (ubuncinci amasuntswana angama-128), ukuba sengozini kuhlaselo lwe-DoS ngokwenza umthwalo parasitic kwi CPU xa hashing amagama ayimfihlo elide, sukuba buthathaka kuhlaselo lwesayizi yegama lokugqitha ngokusekwe kucazululo lokwenziwa kwexesha lokwenziwa kwehash, sebenza ngaphandle kokusebenzisa i-cryptographic key derivation function (KDF).

Ukongeza, usebenzisa yescrypt ngoku igcina uqwalaselo lwe umask kwifayile yoqwalaselo /etc/login.defs endaweni yokuba /etc/profile.

Malunga notshintsho lwehashi, Kukwakhankanywa ukuba iArgon2 algorithm, ephumelele ukhuphiswano lwe-password hashing ngo-2015, nayo yathathwa njengokhetho ye-password hashing, kodwa ayisetyenziswanga kwiArch Linux kuba ayixhaswa lithala leencwadi libxcrypt isetyenziswa kwi PAM.

Yongeza kule nto, uthetha ngokuphuculwa kweArch Linux, Kwakhona kubalulekile ukuba uqaphele luhlaziyo lwe-archinstall 2.6.1. Archinstall ingasetyenziswa endaweni yonikezelo lwemowudi yofako lwemanyuwali olungagqibekanga, inikezela ngemowudi yofakelo ekhokelwayo nezenzekelayo

Kuhlelo olutsha umsebenzisi ngoku unakho ukumisela inani elingenasizathu lokukhutshelwa okunxuseneyo, ukhetho longezwe ukusetyenziswa ly ​​njengomphathi obonisa ikhonsoli kwaye usebenzise i-slick-greeter endaweni ye-gtk-greeter kwi-lightdm. I-kitty, i-Dolphin kunye nezicelo ze-wofi zongezwe kwiprofayili eyenza indawo engqongileyo esekelwe kwi-server ye-Hyprland composite.

Zabanye utshintsho olubonakalayo de Archinstall 2.6.1:

  • Ingozi elungisiweyo ebangelwe ngezahlulo ezingaxhaswanga
  • Ukulayisha okulungisiweyo kweeprofayile zedesktop ukusuka kwimimiselo esele iqwalaselwe
  • Kulungiswe umba wofakelo lwe-GRUB kwizixhobo ze-MBR ngenxa yesixhobo ekujoliswe kuso esingalunganga
  • Kulungiswe ezinye iibugs kwisahlulelo sesandla
  • Umba wemiyalelo yesiko elungisiweyo
  • Vumela ukwabiwa kweendawo zokunyuka kwizahlulo ezikhoyo
  • Lungisa ukufunyanwa kwe-UUID
  • Hlela iiprofayile zokungahoyi imeko

ekugqibeleni ukuba ukhona unomdla wokwazi ngakumbi ngayo, ungazijonga iinkcukacha kwi ukulandela ikhonkco.


Shiya uluvo lwakho

Idilesi yakho ye email aziyi kupapashwa. ezidingekayo ziphawulwe *

*

*

  1. Inoxanduva lwedatha: I-AB Internet Networks 2008 SL
  2. Injongo yedatha: Ulawulo lwe-SPAM, ulawulo lwezimvo.
  3. Umthetho: Imvume yakho
  4. Unxibelelwano lwedatha: Idatha ayizukuhanjiswa kubantu besithathu ngaphandle koxanduva lomthetho.
  5. Ukugcinwa kweenkcukacha
  6. Amalungelo: Ngalo naliphi na ixesha unganciphisa, uphinde uphinde ucime ulwazi lwakho.