3 Remove C99ism, where new_ccname was being declared in the middle of a
8 Make default for GSSAPIStrictAcceptorCheck be Yes, to match previous, and
9 documented, behaviour. Reported by Dan Watson.
12 - [ gss-genr.c kexgssc.c kexgsss.c kex.h monitor.c sshconnect2.c sshd.c
14 add support for gss-group14-sha1 key exchange mechanisms
15 - [ gss-serv.c servconf.c servconf.h sshd_config sshd_config.5 ]
16 Add GSSAPIStrictAcceptorCheck option to allow the disabling of
17 acceptor principal checking on multi-homed machines.
19 - [ sshd_config ssh_config ]
20 Add settings for GSSAPIKeyExchange and GSSAPITrustDNS to the sample
22 - [ kexgss.c kegsss.c sshconnect2.c sshd.c ]
23 Code cleanup. Replace strlen/xmalloc/snprintf sequences with xasprintf()
24 Limit length of error messages displayed by client
27 - [ gss-genr.c gss-serv.c ]
28 move ssh_gssapi_acquire_cred() and ssh_gssapi_server_ctx to be server
29 only, where they belong
34 Fix CCAPI credentials cache name when creating KRB5CCNAME environment
39 Avoid Heimdal context freeing problem
40 <Fixed upstream 20060829>
43 - [ gss-genr.c ssh-gss.h sshconnect2.c ]
44 Make sure that SPENGO is disabled
45 <Bugzilla #1218 - Fixed upstream 20060818>
48 - [ gssgenr.c, sshconnect2.c ]
49 a few type changes (signed versus unsigned, int versus size_t) to
50 fix compiler errors/warnings
51 (from jbasney AT ncsa.uiuc.edu)
52 - [ kexgssc.c, sshconnect2.c ]
53 fix uninitialized variable warnings
54 (from jbasney AT ncsa.uiuc.edu)
56 pass oid to gss_display_status (helpful when using GSSAPI mechglue)
57 (from jbasney AT ncsa.uiuc.edu)
60 #ifdef HAVE_GSSAPI_KRB5 should be #ifdef HAVE_GSSAPI_KRB5_H
61 (from jbasney AT ncsa.uiuc.edu)
62 <Fixed upstream 20060304>
63 - [ readconf.c, readconf.h, ssh_config.5, sshconnect2.c
64 add client-side GssapiKeyExchange option
65 (from jbasney AT ncsa.uiuc.edu)
67 add support for GssapiTrustDns option for gssapi-with-mic
68 (from jbasney AT ncsa.uiuc.edu)
69 <gssapi-with-mic support is Bugzilla #1008>