]> andersk Git - openssh.git/blame - ChangeLog
- itojun@cvs.openbsd.org 2001/06/26 06:33:07
[openssh.git] / ChangeLog
CommitLineData
a96070d4 120010704
2 - OpenBSD CVS Sync
3 - markus@cvs.openbsd.org 2001/06/25 08:25:41
4 [channels.c channels.h cipher.c clientloop.c compat.c compat.h
5 hostfile.c kex.c kex.h key.c key.h nchan.c packet.c serverloop.c
6 session.c session.h sftp-server.c ssh-add.c ssh-agent.c uuencode.h]
7 update copyright for 2001
8a497b11 8 - markus@cvs.openbsd.org 2001/06/25 17:18:27
9 [ssh-keygen.1]
10 sshd(8) will never read the private keys, but ssh(1) does;
11 hugh@mimosa.com
6978866a 12 - provos@cvs.openbsd.org 2001/06/25 17:54:47
13 [auth.c auth.h auth-rsa.c]
14 terminate secure_filename checking after checking homedir. that way
ffb215be 15 it works on AFS. okay markus@
16 - stevesk@cvs.openbsd.org 2001/06/25 20:26:37
17 [auth2.c sshconnect2.c]
18 prototype cleanup; ok markus@
2b30154a 19 - markus@cvs.openbsd.org 2001/06/26 02:47:07
20 [ssh-keygen.c]
21 allow loading a private RSA key to a cyberflex card.
ffdb5d70 22 - markus@cvs.openbsd.org 2001/06/26 04:07:06
23 [ssh-agent.1 ssh-agent.c]
24 add debug flag
983def13 25 - markus@cvs.openbsd.org 2001/06/26 04:59:59
26 [authfd.c authfd.h ssh-add.c]
27 initial support for smartcards in the agent
f7e5ac7b 28 - markus@cvs.openbsd.org 2001/06/26 05:07:43
29 [ssh-agent.c]
30 update usage
2b5fe3b8 31 - markus@cvs.openbsd.org 2001/06/26 05:33:34
32 [ssh-agent.c]
33 more smartcard support.
543baeea 34 - mpech@cvs.openbsd.org 2001/06/26 05:48:07
35 [sshd.8]
36 remove unnecessary .Pp between .It;
37 millert@ ok
0c9664c2 38 - markus@cvs.openbsd.org 2001/06/26 05:50:11
39 [auth2.c]
40 new interface for secure_filename()
2a1e4639 41 - itojun@cvs.openbsd.org 2001/06/26 06:32:58
42 [atomicio.h authfd.h authfile.h auth.h auth-options.h bufaux.h
43 buffer.h canohost.h channels.h cipher.h clientloop.h compat.h
44 compress.h crc32.h deattack.h dh.h dispatch.h groupaccess.h
45 hostfile.h kex.h key.h log.h mac.h match.h misc.h mpaux.h packet.h
46 radix.h readconf.h readpass.h rsa.h]
47 prototype pedant. not very creative...
48 - () -> (void)
49 - no variable names
1c06a9ca 50 - itojun@cvs.openbsd.org 2001/06/26 06:33:07
51 [servconf.h serverloop.h session.h sftp-client.h sftp-common.h
52 sftp-glob.h sftp-int.h sshconnect.h ssh-dss.h sshlogin.h sshpty.h
53 ssh-rsa.h tildexpand.h uidswap.h uuencode.h xmalloc.h]
54 prototype pedant. not very creative...
55 - () -> (void)
56 - no variable names
a96070d4 57
aa8d09da 5820010629
59 - (bal) Removed net_aton() since we don't use it any more
64c4b8d7 60 - (bal) Fixed _DISABLE_VPOSIX in readpassphrase.c.
7af3215a 61 - (bal) Updated zlib's home. Thanks to David Howe <DaveHowe@gmx.co.uk>.
16adf618 62 - (stevesk) remove _REENTRANT #define
16995a2c 63 - (stevesk) session.c: use u_int for envsize
6a26f353 64 - (stevesk) remove cli.[ch]
aa8d09da 65
f11065cb 6620010628
67 - (djm) Sync openbsd-compat with -current libc
050df9db 68 - (djm) Fix from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE> for my
69 broken makefile
07608451 70 - (bal) Removed strtok_r() and inet_ntop() since they are no longer used.
71 - (bal) Remove getusershell() since it's no longer used.
f11065cb 72
78220944 7320010627
74 - (djm) Reintroduce pam_session call for non-pty sessions.
763dfdf0 75 - (djm) Remove redundant and incorrect test for max auth attempts in
76 PAM kbdint code. Based on fix from Matthew Melvin
77 <matthewm@webcentral.com.au>
f0194608 78 - (djm) Rename sysconfdir/primes => sysconfdir/moduli
ff4955c9 79 - (djm) Oops, forgot make logic for primes=>moduli. Also try to rename
80 existing primes->moduli if it exists.
0eb1a22d 81 - (djm) Sync with -current openbsd-compat/readpassphrase.c:
82 - djm@cvs.openbsd.org 2001/06/27 13:23:30
83 typo, spotted by Tom Holroyd <tomh@po.crl.go.jp>; ok deraadt@
5ed2bb5b 84 - (djm) Turn up warnings if gcc or egcs detected
b8fea62d 85 - (stevesk) for HP-UX 11.X use X/Open socket interface;
86 pulls in modern socket prototypes and eliminates a number of compiler
87 warnings. see xopen_networking(7).
fef01705 88 - (stevesk) fix x11 forwarding from _PATH_XAUTH change
28564873 89 - (stevesk) use X/Open socket interface for HP-UX 10.X also
78220944 90
e16f4ac8 9120010625
0cd000dd 92 - OpenBSD CVS Sync
bc233fdf 93 - markus@cvs.openbsd.org 2001/06/21 21:08:25
94 [session.c]
95 don't reset forced_command (we allow multiple login shells in
96 ssh2); dwd@bell-labs.com
a5a2da3b 97 - mpech@cvs.openbsd.org 2001/06/22 10:17:51
98 [ssh.1 sshd.8 ssh-keyscan.1]
99 o) .Sh AUTHOR -> .Sh AUTHORS;
100 o) remove unnecessary .Pp;
101 o) better -mdoc style;
102 o) typo;
103 o) sort SEE ALSO;
a5a2da3b 104 aaron@ ok
e2854364 105 - provos@cvs.openbsd.org 2001/06/22 21:27:08
106 [dh.c pathnames.h]
107 use /etc/moduli instead of /etc/primes, okay markus@
e2432638 108 - provos@cvs.openbsd.org 2001/06/22 21:28:53
109 [sshd.8]
110 document /etc/moduli
96a7b0cc 111 - markus@cvs.openbsd.org 2001/06/22 21:55:49
112 [auth2.c auth-rsa.c pathnames.h ssh.1 sshd.8 sshd_config
113 ssh-keygen.1]
114 merge authorized_keys2 into authorized_keys.
115 authorized_keys2 is used for backward compat.
116 (just append authorized_keys2 to authorized_keys).
826676b3 117 - provos@cvs.openbsd.org 2001/06/22 21:57:59
118 [dh.c]
119 increase linebuffer to deal with larger moduli; use rewind instead of
120 close/open
bc233fdf 121 - markus@cvs.openbsd.org 2001/06/22 22:21:20
122 [sftp-server.c]
123 allow long usernames/groups in readdir
a599bd06 124 - markus@cvs.openbsd.org 2001/06/22 23:35:21
2e000c58 125 [ssh.c]
126 don't overwrite argv (fixes ssh user@host in 'ps'), report by ericj@
cb220a93 127 - deraadt@cvs.openbsd.org 2001/06/23 00:16:16
128 [scp.c]
129 slightly better care
d0c8ca5c 130 - markus@cvs.openbsd.org 2001/06/23 00:20:57
131 [auth2.c auth.c auth.h auth-rh-rsa.c]
132 *known_hosts2 is obsolete for hostbased authentication and
133 only used for backward compat. merge ssh1/2 hostkey check
134 and move it to auth.c
e16f4ac8 135 - deraadt@cvs.openbsd.org 2001/06/23 02:33:05
136 [sftp.1 sftp-server.8 ssh-keygen.1]
137 join .%A entries; most by bk@rt.fm
f49bc4f7 138 - markus@cvs.openbsd.org 2001/06/23 02:34:33
139 [kexdh.c kexgex.c kex.h pathnames.h readconf.c servconf.h ssh.1
140 sshconnect1.c sshconnect2.c sshconnect.c sshconnect.h sshd.8]
141 get rid of known_hosts2, use it for hostkey lookup, but do not
142 modify.
7d747e89 143 - markus@cvs.openbsd.org 2001/06/23 03:03:59
144 [sshd.8]
145 draft-ietf-secsh-dh-group-exchange-01.txt
73473230 146 - markus@cvs.openbsd.org 2001/06/23 03:04:42
147 [auth2.c auth-rh-rsa.c]
148 restore correct ignore_user_known_hosts logic.
c10d042a 149 - markus@cvs.openbsd.org 2001/06/23 05:26:02
150 [key.c]
151 handle sigature of size 0 (some broken clients send this).
7b518233 152 - deraadt@cvs.openbsd.org 2001/06/23 05:57:09
153 [sftp.1 sftp-server.8 ssh-keygen.1]
154 ok, tmac is now fixed
2e0becb6 155 - markus@cvs.openbsd.org 2001/06/23 06:41:10
156 [ssh-keygen.c]
157 try to decode ssh-3.0.0 private rsa keys
158 (allow migration to openssh, not vice versa), #910
396c147e 159 - itojun@cvs.openbsd.org 2001/06/23 15:12:20
160 [auth1.c auth2.c auth2-chall.c authfd.c authfile.c auth-rhosts.c
161 canohost.c channels.c cipher.c clientloop.c deattack.c dh.c
162 hostfile.c kex.c kexdh.c kexgex.c key.c nchan.c packet.c radix.c
163 readpass.c scp.c servconf.c serverloop.c session.c sftp.c
164 sftp-client.c sftp-glob.c sftp-int.c sftp-server.c ssh-add.c
165 ssh-agent.c ssh.c sshconnect1.c sshconnect2.c sshconnect.c sshd.c
166 ssh-keygen.c ssh-keyscan.c]
167 more strict prototypes. raise warning level in Makefile.inc.
168 markus ok'ed
169 TODO; cleanup headers
a599bd06 170 - markus@cvs.openbsd.org 2001/06/23 17:05:22
171 [ssh-keygen.c]
172 fix import for (broken?) ssh.com/f-secure private keys
173 (i tested > 1000 RSA keys)
3730bb22 174 - itojun@cvs.openbsd.org 2001/06/23 17:48:18
175 [sftp.1 ssh.1 sshd.8 ssh-keyscan.1]
176 kill whitespace at EOL.
3aca00a3 177 - markus@cvs.openbsd.org 2001/06/23 19:12:43
178 [sshd.c]
179 pidfile/sigterm race; bbraun@synack.net
ce404659 180 - markus@cvs.openbsd.org 2001/06/23 22:37:46
181 [sshconnect1.c]
182 consistent with ssh2: skip key if empty passphrase is entered,
183 retry num_of_passwd_prompt times if passphrase is wrong. ok fgsch@
2cee8a25 184 - markus@cvs.openbsd.org 2001/06/24 05:25:10
185 [auth-options.c match.c match.h]
186 move ip+hostname check to match.c
1843a425 187 - markus@cvs.openbsd.org 2001/06/24 05:35:33
188 [readpass.c readpass.h ssh-add.c sshconnect2.c ssh-keygen.c]
189 switch to readpassphrase(3)
190 2.7/8-stable needs readpassphrase.[ch] from libc
80097c54 191 - markus@cvs.openbsd.org 2001/06/24 05:47:13
192 [sshconnect2.c]
193 oops, missing format string
b4e7177c 194 - markus@cvs.openbsd.org 2001/06/24 17:18:31
195 [ttymodes.c]
196 passing modes works fine: debug2->3
ab88181c 197 - (djm) -Wall fix for session.c
3159d49a 198 - (djm) Bring in readpassphrase() from OpenBSD libc. Compiles OK on Linux and
199 Solaris
0cd000dd 200
7751d4eb 20120010622
202 - (stevesk) handle systems without pw_expire and pw_change.
203
e04e7a19 20420010621
205 - OpenBSD CVS Sync
206 - markus@cvs.openbsd.org 2001/06/16 08:49:38
207 [misc.c]
208 typo; dunlap@apl.washington.edu
c03175c6 209 - markus@cvs.openbsd.org 2001/06/16 08:50:39
210 [channels.h]
211 bad //-style comment; thx to stevev@darkwing.uoregon.edu
08c260ea 212 - markus@cvs.openbsd.org 2001/06/16 08:57:35
213 [scp.c]
214 no stdio or exit() in signal handlers.
c4d49b85 215 - markus@cvs.openbsd.org 2001/06/16 08:58:34
216 [misc.c]
217 copy pw_expire and pw_change, too.
dac6753b 218 - markus@cvs.openbsd.org 2001/06/19 12:34:09
219 [session.c]
220 cleanup forced command handling, from dwd@bell-labs.com
ff027d84 221 - markus@cvs.openbsd.org 2001/06/19 14:09:45
222 [session.c sshd.8]
223 disable x11-fwd if use_login is enabled; from lukem@wasabisystems.com
c95add71 224 - markus@cvs.openbsd.org 2001/06/19 15:40:45
225 [session.c]
226 allocate and free at the same level.
d6746a0b 227 - markus@cvs.openbsd.org 2001/06/20 13:56:39
228 [channels.c channels.h clientloop.c packet.c serverloop.c]
229 move from channel_stop_listening to channel_free_all,
230 call channel_free_all before calling waitpid() in serverloop.
231 fixes the utmp handling; report from Lutz.Jaenicke@aet.TU-Cottbus.DE
e04e7a19 232
5ad9f968 23320010615
234 - (stevesk) don't set SA_RESTART and set SIGCHLD to SIG_DFL
235 around grantpt().
f7940aa9 236 - (stevesk) update TODO: STREAMS pty systems don't call vhangup() now
5ad9f968 237
eb26141e 23820010614
239 - OpenBSD CVS Sync
240 - markus@cvs.openbsd.org 2001/06/13 09:10:31
241 [session.c]
242 typo, use pid not s->pid, mstone@cs.loyola.edu
243
86066315 24420010613
eb26141e 245 - OpenBSD CVS Sync
86066315 246 - markus@cvs.openbsd.org 2001/06/12 10:58:29
247 [session.c]
248 merge session_free into session_close()
249 merge pty_cleanup_proc into session_pty_cleanup()
653d5f86 250 - markus@cvs.openbsd.org 2001/06/12 16:10:38
251 [session.c]
252 merge ssh1/ssh2 tty msg parse and alloc code
76735fe3 253 - markus@cvs.openbsd.org 2001/06/12 16:11:26
254 [packet.c]
255 do not log() packet_set_maxsize
b44de2b1 256 - markus@cvs.openbsd.org 2001/06/12 21:21:29
257 [session.c]
258 remove xauth-cookie-in-tmp handling. use default $XAUTHORITY, since
259 we do already trust $HOME/.ssh
260 you can use .ssh/sshrc and .ssh/environment if you want to customize
261 the location of the xauth cookies
7a313633 262 - markus@cvs.openbsd.org 2001/06/12 21:30:57
263 [session.c]
264 unused
86066315 265
2c9d881a 26620010612
38296b32 267 - scp.c ID update (upstream synced vfsprintf() from us)
268 - OpenBSD CVS Sync
2c9d881a 269 - markus@cvs.openbsd.org 2001/06/10 11:29:20
270 [dispatch.c]
271 we support rekeying
272 protocol errors are fatal.
1500bcdd 273 - markus@cvs.openbsd.org 2001/06/11 10:18:24
274 [session.c]
275 reset pointer to NULL after xfree(); report from solar@openwall.com
f740438e 276 - markus@cvs.openbsd.org 2001/06/11 16:04:38
277 [sshd.8]
278 typo; bdubreuil@crrel.usace.army.mil
2c9d881a 279
b4d02860 28020010611
281 - (bal) NeXT/MacOS X lack libgen.h and dirname(). Patch by Mark Miller
282 <markm@swoon.net>
224cbdcc 283 - (bal) Handle broken krb4 issues on Solaris with multiple defined u_*_t
284 types. Patch by Jan IVEN <Jan.Iven@cern.ch>
0bb724ce 285 - (bal) Fixed Makefile.in so that 'configure; make install' works.
b4d02860 286
bf093080 28720010610
288 - (bal) Missed two files in major resync. auth-bsdauth.c and auth-skey.c
289
e697bda7 29020010609
291 - OpenBSD CVS Sync
292 - markus@cvs.openbsd.org 2001/05/30 12:55:13
293 [auth-options.c auth2.c channels.c channels.h clientloop.c nchan.c
294 packet.c serverloop.c session.c ssh.c ssh1.h]
295 channel layer cleanup: merge header files and split .c files
36e1f6a1 296 - markus@cvs.openbsd.org 2001/05/30 15:20:10
297 [ssh.c]
298 merge functions, simplify.
a5efa1bb 299 - markus@cvs.openbsd.org 2001/05/31 10:30:17
300 [auth-options.c auth2.c channels.c channels.h clientloop.c nchan.c
301 packet.c serverloop.c session.c ssh.c]
302 undo the .c file split, just merge the header and keep the cvs
303 history
8e7895b8 304 - (bal) Channels.c and Channels.h -- "Merge Functions, simplify" (draged
305 out of ssh Attic)
a98da4aa 306 - (bal) Ooops.. nchan.c (and remove nchan.h) resync from OpenBSD ssh
307 Attic.
308 - OpenBSD CVS Sync
309 - markus@cvs.openbsd.org 2001/05/31 13:08:04
310 [sshd_config]
311 group options and add some more comments
e4f7282d 312 - markus@cvs.openbsd.org 2001/06/03 14:55:39
313 [channels.c channels.h session.c]
314 use fatal_register_cleanup instead of atexit, sync with x11 authdir
315 handling
e5b71e99 316 - markus@cvs.openbsd.org 2001/06/03 19:36:44
317 [ssh-keygen.1]
318 1-2 bits of entrophy per character (not per word), ok stevesk@
4fc334a2 319 - markus@cvs.openbsd.org 2001/06/03 19:38:42
320 [scp.c]
321 pass -v to ssh; from slade@shore.net
f5e69c65 322 - markus@cvs.openbsd.org 2001/06/03 20:06:11
323 [auth2-chall.c]
324 the challenge response device decides how to handle non-existing
325 users.
326 -> fake challenges for skey and cryptocard
f0f32b8e 327 - markus@cvs.openbsd.org 2001/06/04 21:59:43
328 [channels.c channels.h session.c]
329 switch uid when cleaning up tmp files and sockets; reported by
330 zen-parse@gmx.net on bugtraq
c9130033 331 - markus@cvs.openbsd.org 2001/06/04 23:07:21
332 [clientloop.c serverloop.c sshd.c]
333 set flags in the signal handlers, do real work in the main loop,
334 ok provos@
8dcd9d5c 335 - markus@cvs.openbsd.org 2001/06/04 23:16:16
336 [session.c]
337 merge ssh1/2 x11-fwd setup, create listener after tmp-dir
aa144206 338 - pvalchev@cvs.openbsd.org 2001/06/05 05:05:39
339 [ssh-keyscan.1 ssh-keyscan.c]
340 License clarification from David Mazieres, ok deraadt@
750c256a 341 - markus@cvs.openbsd.org 2001/06/05 10:24:32
342 [channels.c]
343 don't delete the auth socket in channel_stop_listening()
344 auth_sock_cleanup_proc() will take care of this.
fc2a1d28 345 - markus@cvs.openbsd.org 2001/06/05 16:46:19
346 [session.c]
347 let session_close() delete the pty. deny x11fwd if xauthfile is set.
d87596b0 348 - markus@cvs.openbsd.org 2001/06/06 23:13:54
349 [ssh-dss.c ssh-rsa.c]
350 cleanup, remove old code
edf9ae81 351 - markus@cvs.openbsd.org 2001/06/06 23:19:35
352 [ssh-add.c]
353 remove debug message; Darren.Moffat@eng.sun.com
2a6a054e 354 - markus@cvs.openbsd.org 2001/06/07 19:57:53
355 [auth2.c]
356 style is used for bsdauth.
357 disconnect on user/service change (ietf-drafts)
449c5ba5 358 - markus@cvs.openbsd.org 2001/06/07 20:23:05
359 [authfd.c authfile.c channels.c kexdh.c kexgex.c packet.c ssh.c
360 sshconnect.c sshconnect1.c]
361 use xxx_put_cstring()
e6abba31 362 - markus@cvs.openbsd.org 2001/06/07 22:25:02
363 [session.c]
364 don't overwrite errno
365 delay deletion of the xauth cookie
fd9ede94 366 - markus@cvs.openbsd.org 2001/06/08 15:25:40
367 [includes.h pathnames.h readconf.c servconf.c]
368 move the path for xauth to pathnames.h
0abe778b 369 - (bal) configure.in fix for Tru64 (forgeting to reset $LIB)
83c17f20 370 - (bal) ANSIify strmode()
fdf6b7aa 371 - (bal) --with-catman should be --with-mantype patch by Dave
372 Dykstra <dwd@bell-labs.com>
fd9ede94 373
4869a96f 37420010606
e697bda7 375 - OpenBSD CVS Sync
376 - markus@cvs.openbsd.org 2001/05/17 21:34:15
377 [ssh.1]
4869a96f 378 no spaces in PreferredAuthentications;
5ba55ada 379 meixner@rbg.informatik.tu-darmstadt.de
380 - markus@cvs.openbsd.org 2001/05/18 14:13:29
381 [auth-chall.c auth.h auth1.c auth2-chall.c auth2.c readconf.c
382 readconf.h servconf.c servconf.h sshconnect1.c sshconnect2.c sshd.c]
383 improved kbd-interactive support. work by per@appgate.com and me
bc03d5aa 384 - djm@cvs.openbsd.org 2001/05/19 00:36:40
385 [session.c]
386 Disable X11 forwarding if xauth binary is not found. Patch from Nalin
387 Dahyabhai <nalin@redhat.com>; ok markus@
3e4fc5f9 388 - markus@cvs.openbsd.org 2001/05/19 16:05:41
389 [scp.c]
390 ftruncate() instead of open()+O_TRUNC like rcp.c does
391 allows scp /path/to/file localhost:/path/to/file
a18395da 392 - markus@cvs.openbsd.org 2001/05/19 16:08:43
393 [sshd.8]
394 sort options; Matthew.Stier@fnc.fujitsu.com
3398dda9 395 - markus@cvs.openbsd.org 2001/05/19 16:32:16
396 [ssh.1 sshconnect2.c]
397 change preferredauthentication order to
398 publickey,hostbased,password,keyboard-interactive
399 document that hostbased defaults to no, document order
47bf6266 400 - markus@cvs.openbsd.org 2001/05/19 16:46:19
401 [ssh.1 sshd.8]
402 document MACs defaults with .Dq
e2b1fb42 403 - stevesk@cvs.openbsd.org 2001/05/19 19:43:57
404 [misc.c misc.h servconf.c sshd.8 sshd.c]
405 sshd command-line arguments and configuration file options that
406 specify time may be expressed using a sequence of the form:
407 time[qualifier], where time is a positive integer value and qualifier
408 is one of the following:
409 <none>,s,m,h,d,w
410 Examples:
411 600 600 seconds (10 minutes)
412 10m 10 minutes
413 1h30m 1 hour 30 minutes (90 minutes)
414 ok markus@
7e8c18e9 415 - stevesk@cvs.openbsd.org 2001/05/19 19:57:09
416 [channels.c]
417 typo in error message
e697bda7 418 - markus@cvs.openbsd.org 2001/05/20 17:20:36
c8445989 419 [auth-rsa.c auth.c auth.h auth2.c servconf.c servconf.h sshd.8
420 sshd_config]
421 configurable authorized_keys{,2} location; originally from peter@;
422 ok djm@
1ddf764b 423 - markus@cvs.openbsd.org 2001/05/24 11:12:42
424 [auth.c]
425 fix comment; from jakob@
4bf9c10e 426 - stevesk@cvs.openbsd.org 2001/05/24 18:57:53
427 [clientloop.c readconf.c ssh.c ssh.h]
428 don't perform escape processing when ``EscapeChar none''; ok markus@
abe0fb9f 429 - markus@cvs.openbsd.org 2001/05/25 14:37:32
430 [ssh-keygen.c]
431 use -P for -e and -y, too.
63cd7dd0 432 - markus@cvs.openbsd.org 2001/05/28 08:04:39
433 [ssh.c]
434 fix usage()
eb2e1595 435 - markus@cvs.openbsd.org 2001/05/28 10:08:55
436 [authfile.c]
437 key_load_private: set comment to filename for PEM keys
2cf27bc4 438 - markus@cvs.openbsd.org 2001/05/28 22:51:11
439 [cipher.c cipher.h]
440 simpler 3des for ssh1
6fd8622b 441 - markus@cvs.openbsd.org 2001/05/28 23:14:49
442 [channels.c channels.h nchan.c]
443 undo broken channel fix and try a different one. there
444 should be still some select errors...
eeae19d8 445 - markus@cvs.openbsd.org 2001/05/28 23:25:24
446 [channels.c]
447 cleanup, typo
08dcb5d7 448 - markus@cvs.openbsd.org 2001/05/28 23:58:35
449 [packet.c packet.h sshconnect.c sshd.c]
450 remove some lines, simplify.
a10bdd7c 451 - markus@cvs.openbsd.org 2001/05/29 12:31:27
452 [authfile.c]
453 typo
5ba55ada 454
5cde8062 45520010528
456 - (tim) [conifgure.in] add setvbuf test needed for sftp-int.c
457 Patch by Corinna Vinschen <vinschen@redhat.com>
458
362df52e 45920010517
460 - OpenBSD CVS Sync
461 - markus@cvs.openbsd.org 2001/05/12 19:53:13
462 [sftp-server.c]
463 readlink does not NULL-terminate; mhe@home.se
6efa3d14 464 - deraadt@cvs.openbsd.org 2001/05/15 22:04:01
465 [ssh.1]
466 X11 forwarding details improved
70ea8327 467 - markus@cvs.openbsd.org 2001/05/16 20:51:57
468 [authfile.c]
469 return comments for private pem files, too; report from nolan@naic.edu
24b6b45f 470 - markus@cvs.openbsd.org 2001/05/16 21:53:53
471 [clientloop.c]
472 check for open sessions before we call select(); fixes the x11 client
473 bug reported by bowman@math.ualberta.ca
7231bd47 474 - markus@cvs.openbsd.org 2001/05/16 22:09:21
475 [channels.c nchan.c]
476 more select() error fixes (don't set rfd/wfd to -1).
7043a38d 477 - (bal) Enabled USE_PIPES for Cygwin on Corinna Vinschen <vinschen@redhat.com>
b1e4dd32 478 - (bal) Corrected on_exit() emulation via atexit().
362df52e 479
89aa792b 48020010512
481 - OpenBSD CVS Sync
482 - markus@cvs.openbsd.org 2001/05/11 14:59:56
483 [clientloop.c misc.c misc.h]
484 add unset_nonblock for stdout/err flushing in client_loop().
286e38f7 485 - (bal) Patch to partial sync up contrib/solaris/ packaging software.
486 Patch by pete <ninjaz@webexpress.com>
89aa792b 487
97430469 48820010511
489 - OpenBSD CVS Sync
490 - markus@cvs.openbsd.org 2001/05/09 22:51:57
491 [channels.c]
492 fix -R for protocol 2, noticed by greg@nest.cx.
493 bug was introduced with experimental dynamic forwarding.
a16092bb 494 - markus@cvs.openbsd.org 2001/05/09 23:01:31
495 [rijndael.h]
496 fix prototype; J.S.Peatfield@damtp.cam.ac.uk
97430469 497
588f4ed0 49820010509
499 - OpenBSD CVS Sync
500 - markus@cvs.openbsd.org 2001/05/06 21:23:31
501 [cli.c]
502 cli_read() fails to catch SIGINT + overflow; from obdb@zzlevo.net
d18e0850 503 - markus@cvs.openbsd.org 2001/05/08 19:17:31
a01a10dd 504 [channels.c serverloop.c clientloop.c]
d18e0850 505 adds correct error reporting to async connect()s
506 fixes the server-discards-data-before-connected-bug found by
507 onoe@sm.sony.co.jp
8a624ebf 508 - mouring@cvs.openbsd.org 2001/05/08 19:45:25
509 [misc.c misc.h scp.c sftp.c]
510 Use addargs() in sftp plus some clean up of addargs(). OK Markus
1b02d786 511 - markus@cvs.openbsd.org 2001/05/06 21:45:14
512 [clientloop.c]
513 use atomicio for flushing stdout/stderr bufs. thanks to
514 jbw@izanami.cee.hw.ac.uk
010980f6 515 - markus@cvs.openbsd.org 2001/05/08 22:48:07
516 [atomicio.c]
517 no need for xmalloc.h, thanks to espie@
7e2d5fa4 518 - (bal) UseLogin patch for Solaris/UNICOS. Patch by Wayne Davison
519 <wayne@blorf.net>
99c8ddac 520 - (bal) ./configure support to disable SIA on OSF1. Patch by
521 Chris Adams <cmadams@hiwaay.net>
b81c369b 522 - (bal) Updates from the Sony NEWS-OS platform by NAKAJI Hiroyuki
523 <nakaji@tutrp.tut.ac.jp>
588f4ed0 524
7b22534a 52520010508
526 - (bal) Fixed configure test for USE_SIA.
527
94539b2a 52820010506
529 - (djm) Update config.guess and config.sub with latest versions (from
530 ftp://ftp.gnu.org/gnu/config/) to allow configure on ia64-hpux.
531 Suggested by Jason Mader <jason@ncac.gwu.edu>
96c63318 532 - (bal) White Space and #ifdef sync with OpenBSD
044b0662 533 - (bal) Add 'seed_rng()' to ssh-add.c
9e9bd8c0 534 - (bal) CVS ID updates for readpass.c, readpass.h, cli.c, and cli.h
cf7ff074 535 - OpenBSD CVS Sync
536 - stevesk@cvs.openbsd.org 2001/05/05 13:42:52
537 [sftp.1 ssh-add.1 ssh-keygen.1]
538 typos, grammar
94539b2a 539
98143cfc 54020010505
541 - OpenBSD CVS Sync
542 - stevesk@cvs.openbsd.org 2001/05/04 14:21:56
543 [ssh.1 sshd.8]
544 typos
5b9601c8 545 - markus@cvs.openbsd.org 2001/05/04 14:34:34
546 [channels.c]
94539b2a 547 channel_new() reallocs channels[], we cannot use Channel *c after
548 calling channel_new(), XXX fix this in the future...
719fc62f 549 - markus@cvs.openbsd.org 2001/05/04 23:47:34
550 [channels.c channels.h clientloop.c nchan.c nchan.h serverloop.c ssh.c]
551 move to Channel **channels (instead of Channel *channels), fixes realloc
552 problems. channel_new now returns a Channel *, favour Channel * over
553 channel id. remove old channel_allocate interface.
98143cfc 554
f92fee1f 55520010504
556 - OpenBSD CVS Sync
557 - stevesk@cvs.openbsd.org 2001/05/03 15:07:39
558 [channels.c]
559 typo in debug() string
503e7e5b 560 - markus@cvs.openbsd.org 2001/05/03 15:45:15
561 [session.c]
562 exec shell -c /bin/sh .ssh/sshrc, from abartlet@pcug.org.au
c98cab9b 563 - stevesk@cvs.openbsd.org 2001/05/03 21:43:01
564 [servconf.c]
565 remove "\n" from fatal()
1fcde3fe 566 - mouring@cvs.openbsd.org 2001/05/03 23:09:53
567 [misc.c misc.h scp.c sftp.c]
568 Move colon() and cleanhost() to misc.c where I should I have put it in
569 the first place
044aa419 570 - (bal) Updated Cygwin README by Corinna Vinschen <vinschen@redhat.com>
c7ccfd39 571 - (bal) Avoid socket file security issues in ssh-agent for Cygwin.
572 Patch by Egor Duda <deo@logos-m.ru>
f92fee1f 573
065604bb 57420010503
575 - OpenBSD CVS Sync
576 - markus@cvs.openbsd.org 2001/05/02 16:41:20
577 [ssh-add.c]
578 fix prompt for ssh-add.
579
742ee8f2 58020010502
581 - OpenBSD CVS Sync
582 - mouring@cvs.openbsd.org 2001/05/02 01:25:39
583 [readpass.c]
584 Put the 'const' back into ssh_askpass() function. Pointed out
585 by Mark Miller <markm@swoon.net>. OK Markus
586
3435f5a6 58720010501
588 - OpenBSD CVS Sync
589 - markus@cvs.openbsd.org 2001/04/30 11:18:52
590 [readconf.c readconf.h ssh.1 ssh.c sshconnect.c]
591 implement 'ssh -b bind_address' like 'telnet -b'
eef7adcb 592 - markus@cvs.openbsd.org 2001/04/30 15:50:46
593 [compat.c compat.h kex.c]
594 allow interop with weaker key generation used by ssh-2.0.x, x < 10
ec430473 595 - markus@cvs.openbsd.org 2001/04/30 16:02:49
596 [compat.c]
597 ssh-2.0.10 has the weak-key-bug, too.
3ca6cc45 598 - (tim) [contrib/caldera/openssh.spec] add Requires line for Caldera 3.1
3435f5a6 599
e8171bff 60020010430
39aefe7b 601 - OpenBSD CVS Sync
602 - markus@cvs.openbsd.org 2001/04/29 18:32:52
603 [serverloop.c]
604 fix whitespace
fbe90f7b 605 - markus@cvs.openbsd.org 2001/04/29 19:16:52
606 [channels.c clientloop.c compat.c compat.h serverloop.c]
607 more ssh.com-2.0.x bug-compat; from per@appgate.com
e8171bff 608 - (tim) New version of mdoc2man.pl from Mark D. Roth <roth+openssh@feep.net>
0b47e48f 609 - (djm) Add .cvsignore files, suggested by Wayne Davison <wayne@blorf.net>
39aefe7b 610
baf8c81a 61120010429
612 - (bal) Updated INSTALL. PCRE moved to a new place.
e878ffe1 613 - (djm) Release OpenSSH-2.9p1
baf8c81a 614
0096ac62 61520010427
616 - (bal) Fixed uidswap.c so it should work on non-posix complient systems.
617 patch based on 2.5.2 version by djm.
95595a77 618 - (bal) Build manpages and config files once unless changed. Patch by
619 Carson Gaspar <carson@taltos.org>
4a2df58f 620 - (bal) arpa/nameser.h does not exist on Cygwin. Patch by Corinna
621 Vinschen <vinschen@redhat.com>
5ef815d7 622 - (bal) Add /etc/sysconfig/sshd support to redhat's sshd.init. Patch by
623 Pekka Savola <pekkas@netcore.fi>
229be2df 624 - (bal) Cygwin lacks setgroups() API. Patch by Corinna Vinschen
625 <vinschen@redhat.com>
cc3ccfdc 626 - (bal) version.h synced, RPM specs updated for 2.9
b1e2a48c 627 - (tim) update contrib/caldera files with what Caldera is using.
628 <sps@caldera.de>
0096ac62 629
b587c165 63020010425
631 - OpenBSD CVS Sync
632 - markus@cvs.openbsd.org 2001/04/23 21:57:07
633 [ssh-keygen.1 ssh-keygen.c]
634 allow public key for -e, too
012bc0e1 635 - markus@cvs.openbsd.org 2001/04/23 22:14:13
636 [ssh-keygen.c]
637 remove debug
f8252c48 638 - (bal) Whitespace resync w/ OpenBSD for uidswap.c
10f72868 639 - (djm) Add new server configuration directive 'PAMAuthenticationViaKbdInt'
640 (default: off), implies KbdInteractiveAuthentication. Suggestion from
641 markus@
c2d059b5 642 - (djm) Include crypt.h if available in auth-passwd.c
533875af 643 - tim@mindrot.org 2001/04/25 21:38:01 [configure.in]
644 man page detection fixes for SCO
b587c165 645
da89cf4d 64620010424
647 - OpenBSD CVS Sync
648 - markus@cvs.openbsd.org 2001/04/22 23:58:36
649 [ssh-keygen.1 ssh.1 sshd.8]
650 document hostbased and other cleanup
5e29aeaf 651 - (stevesk) start_pam() doesn't use DNS now for sshd -u0.
3cc990d7 652 - (stevesk) auth-pam.c: use PERMIT_NO_PASSWD
d8e76a0a 653 - (bal) sys/queue.h is bogus for NCR platform. Patch by Daniel Carroll
654 <dan@mesastate.edu>
3644dc25 655 - (bal) Fixed contrib/postinstall.in. Patch by wsanders@wsanders.net
da89cf4d 656
a3626e12 65720010422
658 - OpenBSD CVS Sync
659 - markus@cvs.openbsd.org 2001/04/20 16:32:22
660 [uidswap.c]
661 set non-privileged gid before uid; tholo@ and deraadt@
1a726b04 662 - mouring@cvs.openbsd.org 2001/04/21 00:55:57
663 [sftp.1]
664 Spelling
67b964a1 665 - djm@cvs.openbsd.org 2001/04/22 08:13:30
666 [ssh.1]
667 typos spotted by stevesk@; ok deraadt@
ba917921 668 - markus@cvs.openbsd.org 2001/04/22 12:34:05
669 [scp.c]
670 scp > 2GB; niles@scyld.com; ok deraadt@, djm@
5deceabb 671 - markus@cvs.openbsd.org 2001/04/22 13:25:37
672 [ssh-keygen.1 ssh-keygen.c]
673 rename arguments -x -> -e (export key), -X -> -i (import key)
674 xref draft-ietf-secsh-publickeyfile-01.txt
2cad6cef 675 - markus@cvs.openbsd.org 2001/04/22 13:32:27
676 [sftp-server.8 sftp.1 ssh.1 sshd.8]
677 xref draft-ietf-secsh-*
bcaa828e 678 - markus@cvs.openbsd.org 2001/04/22 13:41:02
679 [ssh-keygen.1 ssh-keygen.c]
680 style, noted by stevesk; sort flags in usage
a3626e12 681
df841692 68220010421
683 - OpenBSD CVS Sync
684 - djm@cvs.openbsd.org 2001/04/20 07:17:51
685 [clientloop.c ssh.1]
686 Split out and improve escape character documentation, mention ~R in
687 ~? help text; ok markus@
0e7e0abe 688 - Update RPM spec files for CVS version.h
1ddee76b 689 - (stevesk) set the default PAM service name to __progname instead
690 of the hard-coded value "sshd"; from Mark D. Roth <roth@feep.net>
4b28be2c 691 - (stevesk) document PAM service name change in INSTALL
13dd877b 692 - tim@mindrot.org 2001/04/21 14:25:57 [Makefile.in configure.in]
693 fix perl test, fix nroff test, fix Makefile to build outside source tree
df841692 694
05cc0c99 69520010420
696 - OpenBSD CVS Sync
697 - ian@cvs.openbsd.org 2001/04/18 16:21:05
698 [ssh-keyscan.1]
699 Fix typo reported in PR/1779
561e5254 700 - markus@cvs.openbsd.org 2001/04/18 21:57:42
701 [readpass.c ssh-add.c]
702 call askpass from ssh, too, based on work by roth@feep.net, ok deraadt
f98c3421 703 - markus@cvs.openbsd.org 2001/04/18 22:03:45
704 [auth2.c sshconnect2.c]
705 use FDQN with trailing dot in the hostbased auth packets, ok deraadt@
57a5edd8 706 - markus@cvs.openbsd.org 2001/04/18 22:48:26
707 [auth2.c]
708 no longer const
8dddf799 709 - markus@cvs.openbsd.org 2001/04/18 23:43:26
710 [auth2.c compat.c sshconnect2.c]
711 more ssh v2 hostbased-auth interop: ssh.com >= 2.1.0 works now
712 (however the 2.1.0 server seems to work only if debug is enabled...)
ae88ea7e 713 - markus@cvs.openbsd.org 2001/04/18 23:44:51
714 [authfile.c]
715 error->debug; noted by fries@
5cf13595 716 - markus@cvs.openbsd.org 2001/04/19 00:05:11
717 [auth2.c]
718 use local variable, no function call needed.
719 (btw, hostbased works now with ssh.com >= 2.0.13)
431a2493 720 - (bal) Put scp-common.h back into scp.c (it exists in the upstream
721 tree) pointed out by Tom Holroyd <tomh@po.crl.go.jp>
05cc0c99 722
e78e738a 72320010418
ce2af031 724 - OpenBSD CVS Sync
e78e738a 725 - markus@cvs.openbsd.org 2001/04/17 19:34:25
3a83b819 726 [session.c]
727 move auth_approval to do_authenticated().
728 do_child(): nuke hostkeys from memory
729 don't source .ssh/rc for subsystems.
730 - markus@cvs.openbsd.org 2001/04/18 14:15:00
731 [canohost.c]
732 debug->debug3
ce2af031 733 - (bal) renabled 'catman-do:' and fixed it. So now catman pages should
734 be working again.
e0c4d3ac 735 - (bal) Makfile day... Cleaned up multiple mantype support (Patch by
736 Mark D. Roth <roth+openssh@feep.net>), and fixed PIDDIR support.
3a83b819 737
8c6b78e4 73820010417
739 - (bal) Add perl5 check for HP/UX, Removed GNUness from Makefile.in
6d165a89 740 and temporary commented out 'catman-do:' since it is broken. Patches
8c6b78e4 741 for the first two by Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
a88b7b57 742 - OpenBSD CVS Sync
53b8fe68 743 - deraadt@cvs.openbsd.org 2001/04/16 08:26:04
744 [key.c]
745 better safe than sorry in later mods; yongari@kt-is.co.kr
746 - markus@cvs.openbsd.org 2001/04/17 08:14:01
747 [sshconnect1.c]
748 check for key!=NULL, thanks to costa
749 - markus@cvs.openbsd.org 2001/04/17 09:52:48
750 [clientloop.c]
cf6bc93c 751 handle EINTR/EAGAIN on read; ok deraadt@
53b8fe68 752 - markus@cvs.openbsd.org 2001/04/17 10:53:26
753 [key.c key.h readconf.c readconf.h ssh.1 sshconnect2.c]
e961a8f9 754 add HostKeyAlgorithms; based on patch from res@shore.net; ok provos@
53b8fe68 755 - markus@cvs.openbsd.org 2001/04/17 12:55:04
756 [channels.c ssh.c]
757 undo socks5 and https support since they are not really used and
758 only bloat ssh. remove -D from usage(), since '-D' is experimental.
759
e4664c3e 76020010416
761 - OpenBSD CVS Sync
762 - stevesk@cvs.openbsd.org 2001/04/15 01:35:22
763 [ttymodes.c]
764 fix comments
ec1f12d3 765 - markus@cvs.openbsd.org 2001/04/15 08:43:47
766 [dh.c sftp-glob.c sftp-glob.h sftp-int.c sshconnect2.c sshd.c]
767 some unused variable and typos; from tomh@po.crl.go.jp
58cfa257 768 - markus@cvs.openbsd.org 2001/04/15 16:58:03
769 [authfile.c ssh-keygen.c sshd.c]
770 don't use errno for key_{load,save}_private; discussion w/ solar@openwall
e968270c 771 - markus@cvs.openbsd.org 2001/04/15 17:16:00
772 [clientloop.c]
773 set stdin/out/err to nonblocking in SSH proto 1, too. suggested by ho@
774 should fix some of the blocking problems for rsync over SSH-1
84fc17bf 775 - stevesk@cvs.openbsd.org 2001/04/15 19:41:21
776 [sshd.8]
777 some ClientAlive cleanup; ok markus@
b7c70970 778 - stevesk@cvs.openbsd.org 2001/04/15 21:28:35
779 [readconf.c servconf.c]
780 use fatal() or error() vs. fprintf(); ok markus@
5d97cfbf 781 - (djm) Convert mandoc manpages to man automatically. Patch from Mark D.
782 Roth <roth+openssh@feep.net>
6023325e 783 - (bal) CVS ID fix up and slight manpage fix from OpenBSD tree.
47b53518 784 - (djm) OpenBSD CVS Sync
785 - mouring@cvs.openbsd.org 2001/04/16 02:31:44
786 [scp.c sftp.c]
787 IPv6 support for sftp (which I bungled in my last patch) which is
788 borrowed from scp.c. Thanks to Markus@ for pointing it out.
764291b3 789 - deraadt@cvs.openbsd.org 2001/04/16 08:05:34
790 [xmalloc.c]
791 xrealloc dealing with ptr == nULL; mouring
f2c2fd71 792 - djm@cvs.openbsd.org 2001/04/16 08:19:31
793 [session.c]
794 Split motd and hushlogin checks into seperate functions, helps for
795 portable. From Chris Adams <cmadams@hiwaay.net>; ok markus@
c96a4aaf 796 - Fix OSF SIA support displaying too much information for quiet
797 logins and logins where access was denied by SIA. Patch from Chris Adams
798 <cmadams@hiwaay.net>
e4664c3e 799
f03228b1 80020010415
801 - OpenBSD CVS Sync
802 - deraadt@cvs.openbsd.org 2001/04/14 04:31:01
803 [ssh-add.c]
804 do not double free
9cf972fa 805 - markus@cvs.openbsd.org 2001/04/14 16:17:14
806 [channels.c]
807 remove some channels that are not appropriate for keepalive.
eae942e2 808 - markus@cvs.openbsd.org 2001/04/14 16:27:57
809 [ssh-add.c]
810 use clear_pass instead of xfree()
30dcc918 811 - stevesk@cvs.openbsd.org 2001/04/14 16:33:20
812 [clientloop.c packet.h session.c ssh.c ttymodes.c ttymodes.h]
813 protocol 2 tty modes support; ok markus@
36967a16 814 - stevesk@cvs.openbsd.org 2001/04/14 17:04:42
815 [scp.c]
816 'T' handling rcp/scp sync; ok markus@
e4664c3e 817 - Missed sshtty.[ch] in Sync.
f03228b1 818
e400a640 81920010414
820 - Sync with OpenBSD glob.c, strlcat.c and vis.c changes
fe56c12b 821 - Cygwin sftp/sftp-server binary mode patch from Corinna Vinschen
822 <vinschen@redhat.com>
3ffc6336 823 - OpenBSD CVS Sync
824 - beck@cvs.openbsd.org 2001/04/13 22:46:54
825 [channels.c channels.h servconf.c servconf.h serverloop.c sshd.8]
826 Add options ClientAliveInterval and ClientAliveCountMax to sshd.
827 This gives the ability to do a "keepalive" via the encrypted channel
828 which can't be spoofed (unlike TCP keepalives). Useful for when you want
829 to use ssh connections to authenticate people for something, and know
830 relatively quickly when they are no longer authenticated. Disabled
831 by default (of course). ok markus@
e400a640 832
cc44f691 83320010413
834 - OpenBSD CVS Sync
835 - markus@cvs.openbsd.org 2001/04/12 14:29:09
836 [ssh.c]
837 show debug output during option processing, report from
838 pekkas@netcore.fi
8002af61 839 - markus@cvs.openbsd.org 2001/04/12 19:15:26
840 [auth-rhosts.c auth.h auth2.c buffer.c canohost.c canohost.h
841 compat.c compat.h hostfile.c pathnames.h readconf.c readconf.h
842 servconf.c servconf.h ssh.c sshconnect.c sshconnect.h sshconnect1.c
843 sshconnect2.c sshd_config]
844 implement HostbasedAuthentication (= RhostRSAAuthentication for ssh v2)
845 similar to RhostRSAAuthentication unless you enable (the experimental)
846 HostbasedUsesNameFromPacketOnly option. please test. :)
0140e66a 847 - markus@cvs.openbsd.org 2001/04/12 19:39:27
848 [readconf.c]
849 typo
2d2a2c65 850 - stevesk@cvs.openbsd.org 2001/04/12 20:09:38
851 [misc.c misc.h readconf.c servconf.c ssh.c sshd.c]
852 robust port validation; ok markus@ jakob@
edeeab1e 853 - mouring@cvs.openbsd.org 2001/04/12 23:17:54
854 [sftp-int.c sftp-int.h sftp.1 sftp.c]
855 Add support for:
856 sftp [user@]host[:file [file]] - Fetch remote file(s)
857 sftp [user@]host[:dir[/]] - Start in remote dir/
858 OK deraadt@
57aa8961 859 - stevesk@cvs.openbsd.org 2001/04/13 01:26:17
860 [ssh.c]
861 missing \n in error message
96f8b59f 862 - (bal) Added openbsd-compat/inet_ntop.[ch] since HP/UX (and others)
863 lack it.
cc44f691 864
28b9cb4d 86520010412
866 - OpenBSD CVS Sync
867 - markus@cvs.openbsd.org 2001/04/10 07:46:58
868 [channels.c]
869 cleanup socks4 handling
c0ecc314 870 - itojun@cvs.openbsd.org 2001/04/10 09:13:22
871 [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
872 document id_rsa{.pub,}. markus ok
070adba2 873 - markus@cvs.openbsd.org 2001/04/10 12:15:23
874 [channels.c]
875 debug cleanup
45a2e669 876 - djm@cvs.openbsd.org 2001/04/11 07:06:22
877 [sftp-int.c]
878 'mget' and 'mput' aliases; ok markus@
6031af8d 879 - markus@cvs.openbsd.org 2001/04/11 10:59:01
880 [ssh.c]
881 use strtol() for ports, thanks jakob@
6683b40f 882 - markus@cvs.openbsd.org 2001/04/11 13:56:13
883 [channels.c ssh.c]
884 https-connect and socks5 support. i feel so bad.
ff14faf1 885 - lebel@cvs.openbsd.org 2001/04/11 16:25:30
886 [sshd.8 sshd.c]
887 implement the -e option into sshd:
888 -e When this option is specified, sshd will send the output to the
889 standard error instead of the system log.
890 markus@ OK.
28b9cb4d 891
0a85ab61 89220010410
893 - OpenBSD CVS Sync
894 - deraadt@cvs.openbsd.org 2001/04/08 20:52:55
895 [sftp.c]
896 do not modify an actual argv[] entry
b2ae83b8 897 - stevesk@cvs.openbsd.org 2001/04/08 23:28:27
898 [sshd.8]
899 spelling
317611b5 900 - stevesk@cvs.openbsd.org 2001/04/09 00:42:05
901 [sftp.1]
902 spelling
a8666d84 903 - markus@cvs.openbsd.org 2001/04/09 15:12:23
904 [ssh-add.c]
905 passphrase caching: ssh-add tries last passphrase, clears passphrase if
906 not successful and after last try.
907 based on discussions with espie@, jakob@, ... and code from jakob@ and
908 wolfgang@wsrcc.com
49ae4185 909 - markus@cvs.openbsd.org 2001/04/09 15:19:49
910 [ssh-add.1]
911 ssh-add retries the last passphrase...
b8a297f1 912 - stevesk@cvs.openbsd.org 2001/04/09 18:00:15
913 [sshd.8]
914 ListenAddress mandoc from aaron@
0a85ab61 915
6e9944b8 91620010409
febd3f8e 917 - (stevesk) use setresgid() for setegid() if needed
26de7942 918 - (stevesk) configure.in: typo
6e9944b8 919 - OpenBSD CVS Sync
920 - stevesk@cvs.openbsd.org 2001/04/08 16:01:36
921 [sshd.8]
922 document ListenAddress addr:port
d64050ef 923 - markus@cvs.openbsd.org 2001/04/08 13:03:00
924 [ssh-add.c]
925 init pointers with NULL, thanks to danimal@danimal.org
d0a4c20b 926 - markus@cvs.openbsd.org 2001/04/08 11:27:33
927 [clientloop.c]
928 leave_raw_mode if ssh2 "session" is closed
63bd8c36 929 - markus@cvs.openbsd.org 2001/04/06 21:00:17
930 [auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth2.c channels.c session.c
931 ssh.c sshconnect.c sshconnect.h uidswap.c uidswap.h]
932 do gid/groups-swap in addition to uid-swap, should help if /home/group
933 is chmod 750 + chgrp grp /home/group/, work be deraadt and me, thanks
934 to olar@openwall.com is comments. we had many requests for this.
0490e609 935 - markus@cvs.openbsd.org 2001/04/07 08:55:18
936 [buffer.c channels.c channels.h readconf.c ssh.c]
937 allow the ssh client act as a SOCKS4 proxy (dynamic local
938 portforwarding). work by Dan Kaminsky <dankamin@cisco.com> and me.
939 thanks to Dan for this great patch: use 'ssh -D 1080 host' and make
940 netscape use localhost:1080 as a socks proxy.
d98d029a 941 - markus@cvs.openbsd.org 2001/04/08 11:24:33
942 [uidswap.c]
943 KNF
6e9944b8 944
d9d49fdb 94520010408
946 - OpenBSD CVS Sync
947 - stevesk@cvs.openbsd.org 2001/04/06 22:12:47
948 [hostfile.c]
949 unused; typo in comment
d11c1288 950 - stevesk@cvs.openbsd.org 2001/04/06 22:25:25
951 [servconf.c]
952 in addition to:
953 ListenAddress host|ipv4_addr|ipv6_addr
954 permit:
955 ListenAddress [host|ipv4_addr|ipv6_addr]:port
956 ListenAddress host|ipv4_addr:port
957 sshd.8 updates coming. ok markus@
d9d49fdb 958
613fc910 95920010407
960 - (bal) CVS ID Resync of version.h
cc94bd38 961 - OpenBSD CVS Sync
962 - markus@cvs.openbsd.org 2001/04/05 23:39:20
963 [serverloop.c]
964 keep the ssh session even if there is no active channel.
965 this is more in line with the protocol spec and makes
966 ssh -N -L 1234:server:110 host
967 more useful.
968 based on discussion with <mats@mindbright.se> long time ago
969 and recent mail from <res@shore.net>
0fc791ba 970 - deraadt@cvs.openbsd.org 2001/04/06 16:46:59
971 [scp.c]
972 remove trailing / from source paths; fixes pr#1756
613fc910 973
63f7e231 97420010406
975 - (stevesk) logintest.c: fix for systems without __progname
72170131 976 - (stevesk) Makefile.in: log.o is in libssh.a
d8a2f554 977 - OpenBSD CVS Sync
978 - markus@cvs.openbsd.org 2001/04/05 10:00:06
979 [compat.c]
980 2.3.x does old GEX, too; report jakob@
6ba22c93 981 - markus@cvs.openbsd.org 2001/04/05 10:39:03
982 [compress.c compress.h packet.c]
983 reset compress state per direction when rekeying.
3667ba79 984 - markus@cvs.openbsd.org 2001/04/05 10:39:48
985 [version.h]
986 temporary version 2.5.4 (supports rekeying).
987 this is not an official release.
cd332296 988 - markus@cvs.openbsd.org 2001/04/05 10:42:57
989 [auth-chall.c authfd.c channels.c clientloop.c kex.c kexgex.c key.c
990 mac.c packet.c serverloop.c sftp-client.c sftp-client.h sftp-glob.c
991 sftp-glob.h sftp-int.c sftp-server.c sftp.c ssh-keygen.c sshconnect.c
992 sshconnect2.c sshd.c]
993 fix whitespace: unexpand + trailing spaces.
255cfda1 994 - markus@cvs.openbsd.org 2001/04/05 11:09:17
995 [clientloop.c compat.c compat.h]
996 add SSH_BUG_NOREKEY and detect broken (=all old) openssh versions.
b4a19d21 997 - markus@cvs.openbsd.org 2001/04/05 15:45:43
998 [ssh.1]
999 ssh defaults to protocol v2; from quisar@quisar.ambre.net
46e3af7f 1000 - stevesk@cvs.openbsd.org 2001/04/05 15:48:18
1001 [canohost.c canohost.h session.c]
1002 move get_remote_name_or_ip() to canohost.[ch]; for portable. ok markus@
54506d2e 1003 - markus@cvs.openbsd.org 2001/04/05 20:01:10
1004 [clientloop.c]
1005 for ~R print message if server does not support rekeying. (and fix ~R).
b37caf1a 1006 - markus@cvs.openbsd.org 2001/04/05 21:02:46
1007 [buffer.c]
1008 better error message
eb0dd41f 1009 - markus@cvs.openbsd.org 2001/04/05 21:05:24
1010 [clientloop.c ssh.c]
1011 don't request a session for 'ssh -N', pointed out slade@shore.net
63f7e231 1012
d8ee838b 101320010405
1014 - OpenBSD CVS Sync
1015 - markus@cvs.openbsd.org 2001/04/04 09:48:35
1016 [kex.c kex.h kexdh.c kexgex.c packet.c sshconnect2.c sshd.c]
1017 don't sent multiple kexinit-requests.
1018 send newkeys, block while waiting for newkeys.
1019 fix comments.
7a37c112 1020 - markus@cvs.openbsd.org 2001/04/04 14:34:58
1021 [clientloop.c kex.c kex.h serverloop.c sshconnect2.c sshd.c]
1022 enable server side rekeying + some rekey related clientup.
1023 todo: we should not send any non-KEX messages after we send KEXINIT
5adb303f 1024 - markus@cvs.openbsd.org 2001/04/04 15:50:55
1025 [compat.c]
1026 f-secure 1.3.2 does not handle IGNORE; from milliondl@ornl.gov
c422989b 1027 - markus@cvs.openbsd.org 2001/04/04 20:25:38
1028 [channels.c channels.h clientloop.c kex.c kex.h serverloop.c
1029 sshconnect2.c sshd.c]
1030 more robust rekeying
1031 don't send channel data after rekeying is started.
0715ec6c 1032 - markus@cvs.openbsd.org 2001/04/04 20:32:56
1033 [auth2.c]
1034 we don't care about missing bannerfiles; from tsoome@ut.ee, ok deraadt@
bbb4cc1b 1035 - markus@cvs.openbsd.org 2001/04/04 22:04:35
1036 [kex.c kexgex.c serverloop.c]
1037 parse full kexinit packet.
1038 make server-side more robust, too.
a7ca6275 1039 - markus@cvs.openbsd.org 2001/04/04 23:09:18
1040 [dh.c kex.c packet.c]
1041 clear+free keys,iv for rekeying.
1042 + fix DH mem leaks. ok niels@
86c9e193 1043 - (stevesk) don't use vhangup() if defined(HAVE_DEV_PTMX); also removes
1044 BROKEN_VHANGUP
d8ee838b 1045
9d451c5a 104620010404
1047 - OpenBSD CVS Sync
1048 - deraadt@cvs.openbsd.org 2001/04/02 17:32:23
1049 [ssh-agent.1]
1050 grammar; slade@shore.net
894c5fa6 1051 - stevesk@cvs.openbsd.org 2001/04/03 13:56:11
1052 [sftp-glob.c ssh-agent.c ssh-keygen.c]
1053 free() -> xfree()
a5c9ffdb 1054 - markus@cvs.openbsd.org 2001/04/03 19:53:29
1055 [dh.c dh.h kex.c kex.h sshconnect2.c sshd.c]
1056 move kex to kex*.c, used dispatch_set() callbacks for kex. should
1057 make rekeying easier.
3463ff28 1058 - todd@cvs.openbsd.org 2001/04/03 21:19:38
1059 [ssh_config]
1060 id_rsa1/2 -> id_rsa; ok markus@
d1ac6175 1061 - markus@cvs.openbsd.org 2001/04/03 23:32:12
1062 [kex.c kex.h packet.c sshconnect2.c sshd.c]
1063 undo parts of recent my changes: main part of keyexchange does not
1064 need dispatch-callbacks, since application data is delayed until
1065 the keyexchange completes (if i understand the drafts correctly).
1066 add some infrastructure for re-keying.
e092ce67 1067 - markus@cvs.openbsd.org 2001/04/04 00:06:54
1068 [clientloop.c sshconnect2.c]
1069 enable client rekeying
1070 (1) force rekeying with ~R, or
1071 (2) if the server requests rekeying.
1072 works against ssh-2.0.12/2.0.13/2.1.0/2.2.0/2.3.0/2.3.1/2.4.0
0bc35151 1073 - (bal) Oops.. Missed including kexdh.c and kexgex.c in OpenBSD sync.
9d451c5a 1074
672f212f 107520010403
1076 - OpenBSD CVS Sync
1077 - stevesk@cvs.openbsd.org 2001/04/02 14:15:31
1078 [sshd.8]
1079 typo; ok markus@
6be9a5e8 1080 - stevesk@cvs.openbsd.org 2001/04/02 14:20:23
1081 [readconf.c servconf.c]
1082 correct comment; ok markus@
fe39c3df 1083 - (stevesk) nchan.c: remove ostate checks and add EINVAL to
1084 shutdown(SHUT_RD) error() bypass for HP-UX.
672f212f 1085
0be033ea 108620010402
1087 - (stevesk) log.c openbsd sync; missing newlines
5d9e4c8d 1088 - (stevesk) sshpty.h openbsd sync; PTY_H -> SSHPTY_H
0be033ea 1089
b7a2a476 109020010330
1091 - (djm) Another openbsd-compat/glob.c sync
4047d868 1092 - (djm) OpenBSD CVS Sync
1093 - provos@cvs.openbsd.org 2001/03/28 21:59:41
1094 [kex.c kex.h sshconnect2.c sshd.c]
1095 forgot to include min and max params in hash, okay markus@
c8682232 1096 - provos@cvs.openbsd.org 2001/03/28 22:04:57
1097 [dh.c]
1098 more sanity checking on primes file
d9cd3575 1099 - markus@cvs.openbsd.org 2001/03/28 22:43:31
1100 [auth.h auth2.c auth2-chall.c]
1101 check auth_root_allowed for kbd-int auth, too.
86b878d5 1102 - provos@cvs.openbsd.org 2001/03/29 14:24:59
1103 [sshconnect2.c]
1104 use recommended defaults
1ad64a93 1105 - stevesk@cvs.openbsd.org 2001/03/29 21:06:21
1106 [sshconnect2.c sshd.c]
1107 need to set both STOC and CTOS for SSH_BUG_BIGENDIANAES; ok markus@
03b8f8be 1108 - markus@cvs.openbsd.org 2001/03/29 21:17:40
1109 [dh.c dh.h kex.c kex.h]
1110 prepare for rekeying: move DH code to dh.c
76ca7b01 1111 - djm@cvs.openbsd.org 2001/03/29 23:42:01
1112 [sshd.c]
1113 Protocol 1 key regeneration log => verbose, some KNF; ok markus@
b7a2a476 1114
01ce749f 111520010329
1116 - OpenBSD CVS Sync
1117 - stevesk@cvs.openbsd.org 2001/03/26 15:47:59
1118 [ssh.1]
1119 document more defaults; misc. cleanup. ok markus@
569807fb 1120 - markus@cvs.openbsd.org 2001/03/26 23:12:42
1121 [authfile.c]
1122 KNF
457fc0c6 1123 - markus@cvs.openbsd.org 2001/03/26 23:23:24
1124 [rsa.c rsa.h ssh-agent.c ssh-keygen.c]
1125 try to read private f-secure ssh v2 rsa keys.
1a92bd7e 1126 - markus@cvs.openbsd.org 2001/03/27 10:34:08
1127 [ssh-rsa.c sshd.c]
1128 use EVP_get_digestbynid, reorder some calls and fix missing free.
a4da628b 1129 - markus@cvs.openbsd.org 2001/03/27 10:57:00
1130 [compat.c compat.h ssh-rsa.c]
1131 some older systems use NID_md5 instead of NID_sha1 for RSASSA-PKCS1-v1_5
1132 signatures in SSH protocol 2, ok djm@
db1cd2f3 1133 - provos@cvs.openbsd.org 2001/03/27 17:46:50
1134 [compat.c compat.h dh.c dh.h ssh2.h sshconnect2.c sshd.c version.h]
1135 make dh group exchange more flexible, allow min and max group size,
1136 okay markus@, deraadt@
e5ff6ecf 1137 - stevesk@cvs.openbsd.org 2001/03/28 19:56:23
1138 [scp.c]
1139 start to sync scp closer to rcp; ok markus@
03cb2621 1140 - stevesk@cvs.openbsd.org 2001/03/28 20:04:38
1141 [scp.c]
1142 usage more like rcp and add missing -B to usage; ok markus@
563834bb 1143 - markus@cvs.openbsd.org 2001/03/28 20:50:45
1144 [sshd.c]
1145 call refuse() before close(); from olemx@ans.pl
01ce749f 1146
b5b68128 114720010328
1148 - (djm) Reorder tests and library inclusion for Krb4/AFS to try to
1149 resolve linking conflicts with libcrypto. Report and suggested fix
1150 from Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
edbe6722 1151 - (djm) Work around Solaris' broken struct dirent. Diagnosis and suggested
1152 fix from Philippe Levan <levan@epix.net>
cccfea16 1153 - (djm) Rework krbIV tests to get us closer to building on Redhat. Still
1154 doesn't work because of conflicts between krbIV's and OpenSSL's des.h
8d0cc79b 1155 - (djm) Sync openbsd-compat/glob.c
b5b68128 1156
0c90b590 115720010327
1158 - Attempt sync with sshlogin.c w/ OpenBSD (mainly CVS ID)
60a8683f 1159 - Fix pointer issues in waitpid() and wait() replaces. Patch by Lutz
1160 Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
690d0d7f 1161 - OpenBSD CVS Sync
1162 - djm@cvs.openbsd.org 2001/03/25 00:01:34
1163 [session.c]
1164 shorten; ok markus@
4f4648f9 1165 - stevesk@cvs.openbsd.org 2001/03/25 13:16:11
1166 [servconf.c servconf.h session.c sshd.8 sshd_config]
1167 PrintLastLog option; from chip@valinux.com with some minor
1168 changes by me. ok markus@
9afbfcfa 1169 - markus@cvs.openbsd.org 2001/03/26 08:07:09
1170 [authfile.c authfile.h ssh-add.c ssh-keygen.c ssh.c sshconnect.c
1171 sshconnect.h sshconnect1.c sshconnect2.c sshd.c]
1172 simpler key load/save interface, see authfile.h
1173 - (djm) Reestablish PAM credentials (which can be supplemental group
1174 memberships) after initgroups() blows them away. Report and suggested
1175 fix from Nalin Dahyabhai <nalin@redhat.com>
0c90b590 1176
b567a40c 117720010324
1178 - Fixed permissions ssh-keyscan. Thanks to Christopher Linn <celinn@mtu.edu>.
80cd07ae 1179 - OpenBSD CVS Sync
1180 - djm@cvs.openbsd.org 2001/03/23 11:04:07
1181 [compat.c compat.h sshconnect2.c sshd.c]
1182 Compat for OpenSSH with broken Rijndael/AES. ok markus@
7af9f7f8 1183 - markus@cvs.openbsd.org 2001/03/23 12:02:49
1184 [auth1.c]
1185 authctxt is now passed to do_authenticated
e285053e 1186 - markus@cvs.openbsd.org 2001/03/23 13:10:57
1187 [sftp-int.c]
1188 fix put, upload to _absolute_ path, ok djm@
1d3c30db 1189 - markus@cvs.openbsd.org 2001/03/23 14:28:32
1190 [session.c sshd.c]
1191 ignore SIGPIPE, restore in child, fixes x11-fwd crashes; with djm@
8ca3f6dc 1192 - (djm) Pull out our own SIGPIPE hacks
b567a40c 1193
8a169574 119420010323
1195 - OpenBSD CVS Sync
1196 - deraadt@cvs.openbsd.org 2001/03/22 20:22:55
1197 [sshd.c]
1198 do not place linefeeds in buffer
1199
ee110bfb 120020010322
1201 - (djm) Better AIX no tty fix, spotted by Gert Doering <gert@greenie.muc.de>
289ba62e 1202 - (bal) version.c CVS ID resync
a5b09902 1203 - (bal) auth-chall.c auth-passwd.c auth.h auth1.c auth2.c session.c CVS ID
1204 resync
ae7242ef 1205 - (bal) scp.c CVS ID resync
3e587cc3 1206 - OpenBSD CVS Sync
1207 - markus@cvs.openbsd.org 2001/03/20 19:10:16
1208 [readconf.c]
1209 default to SSH protocol version 2
e5d7a405 1210 - markus@cvs.openbsd.org 2001/03/20 19:21:21
1211 [session.c]
1212 remove unused arg
39f7530f 1213 - markus@cvs.openbsd.org 2001/03/20 19:21:21
1214 [session.c]
1215 remove unused arg
bb5639fe 1216 - markus@cvs.openbsd.org 2001/03/21 11:43:45
1217 [auth1.c auth2.c session.c session.h]
1218 merge common ssh v1/2 code
5e7cb456 1219 - jakob@cvs.openbsd.org 2001/03/21 14:20:45
1220 [ssh-keygen.c]
1221 add -B flag to usage
ca4df544 1222 - markus@cvs.openbsd.org 2001/03/21 21:06:30
1223 [session.c]
1224 missing init; from mib@unimelb.edu.au
ee110bfb 1225
f5f6020e 122620010321
1227 - (djm) Fix ttyname breakage for AIX and Tru64. Patch from Steve
1228 VanDevender <stevev@darkwing.uoregon.edu>
37eadb90 1229 - (djm) Make sure pam_retval is initialised on call to pam_end. Patch
1230 from Solar Designer <solar@openwall.com>
0a3700ee 1231 - (djm) Don't loop forever when changing password via PAM. Patch
1232 from Solar Designer <solar@openwall.com>
0c13ffa2 1233 - (djm) Generate config files before build
7a7101ec 1234 - (djm) Correctly handle SIA and AIX when no tty present. Spotted and
1235 suggested fix from Mike Battersby <mib@unimelb.edu.au>
f5f6020e 1236
8d539493 123720010320
01022caf 1238 - (bal) glob.c update to added GLOB_LIMITS (OpenBSD CVS).
1239 - (bal) glob.c update to set gl_pathv to NULL (OpenBSD CVS).
1620233b 1240 - (bal) Oops. Missed globc.h change (OpenBSD CVS).
614dee3a 1241 - (djm) OpenBSD CVS Sync
1242 - markus@cvs.openbsd.org 2001/03/19 17:07:23
1243 [auth.c readconf.c]
1244 undo /etc/shell and proto 2,1 change for openssh-2.5.2
3dd16786 1245 - markus@cvs.openbsd.org 2001/03/19 17:12:10
1246 [version.h]
1247 version 2.5.2
ea44783f 1248 - (djm) Update RPM spec version
1249 - (djm) Release 2.5.2p1
3743cc2f 1250- tim@mindrot.org 2001/03/19 18:33:47 [defines.h]
1251 change S_ISLNK macro to work for UnixWare 2.03
9887f269 1252- tim@mindrot.org 2001/03/19 20:45:11 [openbsd-compat/glob.c]
1253 add get_arg_max(). Use sysconf() if ARG_MAX is not defined
8d539493 1254
e339aa53 125520010319
1256 - (djm) Seed PRNG at startup, rather than waiting for arc4random calls to
1257 do it implicitly.
7cdb79d4 1258 - (djm) Add getusershell() functions from OpenBSD CVS
b1ed8313 1259 - OpenBSD CVS Sync
1260 - markus@cvs.openbsd.org 2001/03/18 12:07:52
1261 [auth-options.c]
1262 ignore permitopen="host:port" if AllowTcpForwarding==no
f8f230bf 1263 - (djm) Make scp work on systems without 64-bit ints
2538ecf1 1264 - tim@mindrot.org 2001/03/18 18:28:39 [defines.h]
1265 move HAVE_LONG_LONG_INT where it works
d1581d5f 1266 - (bal) Use 'NGROUPS' for NeXT Since 'MAX_NGROUPS' is wrapped up in -lposix
107628c0 1267 stuff. Change suggested by Mark Miller <markm@swoon.net>
d1581d5f 1268 - (bal) Small fix to scp. %lu vs %ld
610e8ff5 1269 - (bal) NeXTStep lacks S_ISLNK. Plus split up S_IS*
bb6da70f 1270 - (djm) OpenBSD CVS Sync
1271 - djm@cvs.openbsd.org 2001/03/19 03:52:51
1272 [sftp-client.c]
1273 Report ssh connection closing correctly; ok deraadt@
3a1c54d4 1274 - deraadt@cvs.openbsd.org 2001/03/18 23:30:55
1275 [compat.c compat.h sshd.c]
1276 specifically version match on ssh scanners. do not log scan
1277 information to the console
dc504afd 1278 - djm@cvs.openbsd.org 2001/03/19 12:10:17
db4d3098 1279 [sshd.8]
dc504afd 1280 Document permitopen authorized_keys option; ok markus@
babd91d4 1281 - djm@cvs.openbsd.org 2001/03/19 05:49:52
1282 [ssh.1]
1283 document PreferredAuthentications option; ok markus@
05c64611 1284 - (bal) Minor NeXT fixed. Forgot to #undef NGROUPS_MAX
e339aa53 1285
ec0ad9c2 128620010318
1287 - (bal) Fixed scp type casing issue which causes "scp: protocol error:
1288 size not delimited" fatal errors when tranfering.
5cc8d4ad 1289 - OpenBSD CVS Sync
1290 - markus@cvs.openbsd.org 2001/03/17 17:27:59
1291 [auth.c]
1292 check /etc/shells, too
7411201c 1293 - tim@mindrot.org 2001/03/17 18:45:25 [compat.c]
1294 openbsd-compat/fake-regex.h
ec0ad9c2 1295
8a968c25 129620010317
1297 - Support usrinfo() on AIX. Based on patch from Gert Doering
1298 <gert@greenie.muc.de>
bf1d27bd 1299 - OpenBSD CVS Sync
1300 - markus@cvs.openbsd.org 2001/03/15 15:05:59
1301 [scp.c]
1302 use %lld in printf, ok millert@/deraadt@; report from ssh@client.fi
56b3e9ce 1303 - markus@cvs.openbsd.org 2001/03/15 22:07:08
1304 [session.c]
1305 pass Session to do_child + KNF
d50d9b63 1306 - djm@cvs.openbsd.org 2001/03/16 08:16:18
1307 [sftp-client.c sftp-client.h sftp-glob.c sftp-int.c]
1308 Revise globbing for get/put to be more shell-like. In particular,
1309 "get/put file* directory/" now works. ok markus@
f55d1b5f 1310 - markus@cvs.openbsd.org 2001/03/16 09:55:53
1311 [sftp-int.c]
1312 fix memset and whitespace
6a8496e4 1313 - markus@cvs.openbsd.org 2001/03/16 13:44:24
1314 [sftp-int.c]
1315 discourage strcat/strcpy
01794848 1316 - markus@cvs.openbsd.org 2001/03/16 19:06:30
1317 [auth-options.c channels.c channels.h serverloop.c session.c]
1318 implement "permitopen" key option, restricts -L style forwarding to
1319 to specified host:port pairs. based on work by harlan@genua.de
40849fdb 1320 - Check for gl_matchc support in glob_t and fall back to the
1321 openbsd-compat/glob.[ch] support if it does not exist.
8a968c25 1322
4cb5d598 132320010315
1324 - OpenBSD CVS Sync
1325 - markus@cvs.openbsd.org 2001/03/14 08:57:14
1326 [sftp-client.c]
1327 Wall
85cf5827 1328 - markus@cvs.openbsd.org 2001/03/14 15:15:58
1329 [sftp-int.c]
1330 add version command
61b3a2bc 1331 - deraadt@cvs.openbsd.org 2001/03/14 22:50:25
1332 [sftp-server.c]
1333 note no getopt()
51e2fc8f 1334 - (stevesk) ssh-keyscan.c: specify "openbsd-compat/fake-queue.h"
9a00bfce 1335 - (bal) Cygwin README change by Corinna Vinschen <vinschen@redhat.com>
4cb5d598 1336
acc9d6d7 133720010314
1338 - OpenBSD CVS Sync
85cf5827 1339 - markus@cvs.openbsd.org 2001/03/13 17:34:42
1340 [auth-options.c]
1341 missing xfree, deny key on parse error; ok stevesk@
1342 - djm@cvs.openbsd.org 2001/03/13 22:42:54
1343 [sftp-client.c sftp-client.h sftp-glob.c sftp-glob.h sftp-int.c]
1344 sftp client filename globbing for get, put, ch{mod,grp,own}. ok markus@
84ceda19 1345 - (bal) Fix strerror() in bsd-misc.c
1346 - (djm) Add replacement glob() from OpenBSD libc if the system glob is
1347 missing or lacks the GLOB_ALTDIRFUNC extension
1348 - (djm) Remove -I$(srcdir)/openbsd-compat from CFLAGS, refer to headers
1349 relatively. Avoids conflict between glob.h and /usr/include/glob.h
acc9d6d7 1350
22138a36 135120010313
1352 - OpenBSD CVS Sync
1353 - markus@cvs.openbsd.org 2001/03/12 22:02:02
1354 [key.c key.h ssh-add.c ssh-keygen.c sshconnect.c sshconnect2.c]
1355 remove old key_fingerprint interface, s/_ex//
1356
539af7f5 135720010312
1358 - OpenBSD CVS Sync
1359 - markus@cvs.openbsd.org 2001/03/11 13:25:36
1360 [auth2.c key.c]
1361 debug
301e8e5b 1362 - jakob@cvs.openbsd.org 2001/03/11 15:03:16
1363 [key.c key.h]
1364 add improved fingerprint functions. based on work by Carsten
1365 Raskgaard <cara@int.tele.dk> and modified by me. ok markus@.
954f0550 1366 - jakob@cvs.openbsd.org 2001/03/11 15:04:16
1367 [ssh-keygen.1 ssh-keygen.c]
1368 print both md5, sha1 and bubblebabble fingerprints when using
1369 ssh-keygen -l -v. ok markus@.
08345971 1370 - jakob@cvs.openbsd.org 2001/03/11 15:13:09
1371 [key.c]
1372 cleanup & shorten some var names key_fingerprint_bubblebabble.
64b1aa3b 1373 - deraadt@cvs.openbsd.org 2001/03/11 16:39:03
1374 [ssh-keygen.c]
1375 KNF, and SHA1 binary output is just creeping featurism
733cf7f4 1376 - tim@mindrot.org 2001/03/11 17:29:32 [configure.in]
1377 test if snprintf() supports %ll
1378 add /dev to search path for PRNGD/EGD socket
1379 fix my mistake in USER_PATH test program
79c9ac1b 1380 - OpenBSD CVS Sync
1381 - markus@cvs.openbsd.org 2001/03/11 18:29:51
1382 [key.c]
1383 style+cleanup
aaf45d87 1384 - markus@cvs.openbsd.org 2001/03/11 22:33:24
1385 [ssh-keygen.1 ssh-keygen.c]
1386 remove -v again. use -B instead for bubblebabble. make -B consistent
1387 with -l and make -B work with /path/to/known_hosts. ok deraadt@
a0322342 1388 - (djm) Bump portable version number for generating test RPMs
94dd09e3 1389 - (djm) Add "static_openssl" RPM build option, remove rsh build dependency
5e8611f1 1390 - (bal) Reorder includes in Makefile.
539af7f5 1391
d156519a 139220010311
1393 - OpenBSD CVS Sync
1394 - markus@cvs.openbsd.org 2001/03/10 12:48:27
1395 [sshconnect2.c]
1396 ignore nonexisting private keys; report rjmooney@mediaone.net
5e36d59c 1397 - deraadt@cvs.openbsd.org 2001/03/10 12:53:51
1398 [readconf.c ssh_config]
1399 default to SSH2, now that m68k runs fast
2f778758 1400 - stevesk@cvs.openbsd.org 2001/03/10 15:02:05
1401 [ttymodes.c ttymodes.h]
1402 remove unused sgtty macros; ok markus@
99c415db 1403 - deraadt@cvs.openbsd.org 2001/03/10 15:31:00
1404 [compat.c compat.h sshconnect.c]
1405 all known netscreen ssh versions, and older versions of OSU ssh cannot
1406 handle password padding (newer OSU is fixed)
456fce50 1407 - tim@mindrot.org 2001/03/10 16:33:42 [configure.in Makefile.in sshd_config]
1408 make sure $bindir is in USER_PATH so scp will work
cab80f75 1409 - OpenBSD CVS Sync
1410 - markus@cvs.openbsd.org 2001/03/10 17:51:04
1411 [kex.c match.c match.h readconf.c readconf.h sshconnect2.c]
1412 add PreferredAuthentications
d156519a 1413
1c9a907f 141420010310
1415 - OpenBSD CVS Sync
1416 - deraadt@cvs.openbsd.org 2001/03/09 03:14:39
1417 [ssh-keygen.c]
1418 create *.pub files with umask 0644, so that you can mv them to
1419 authorized_keys
cb7bd922 1420 - deraadt@cvs.openbsd.org 2001/03/09 12:30:29
1421 [sshd.c]
1422 typo; slade@shore.net
61cf0e38 1423 - Removed log.o from sftp client. Not needed.
1c9a907f 1424
385590e4 142520010309
1426 - OpenBSD CVS Sync
1427 - stevesk@cvs.openbsd.org 2001/03/08 18:47:12
1428 [auth1.c]
1429 unused; ok markus@
acf06a60 1430 - stevesk@cvs.openbsd.org 2001/03/08 20:44:48
1431 [sftp.1]
1432 spelling, cleanup; ok deraadt@
fee56204 1433 - markus@cvs.openbsd.org 2001/03/08 21:42:33
1434 [compat.c compat.h readconf.h ssh.c sshconnect1.c sshconnect2.c]
1435 implement client side of SSH2_MSG_USERAUTH_PK_OK (test public key ->
1436 no need to do enter passphrase or do expensive sign operations if the
1437 server does not accept key).
385590e4 1438
3a7fe5ba 143920010308
1440 - OpenBSD CVS Sync
d5ebca2b 1441 - djm@cvs.openbsd.org 2001/03/07 10:11:23
1442 [sftp-client.c sftp-client.h sftp-int.c sftp-server.c sftp.1 sftp.c sftp.h]
1443 Support for new draft (draft-ietf-secsh-filexfer-01). New symlink handling
1444 functions and small protocol change.
1445 - markus@cvs.openbsd.org 2001/03/08 00:15:48
1446 [readconf.c ssh.1]
1447 turn off useprivilegedports by default. only rhost-auth needs
1448 this. older sshd's may need this, too.
097ca118 1449 - (stevesk) Reliant Unix (SNI) needs HAVE_BOGUS_SYS_QUEUE_H;
1450 Dirk Markwardt <D.Markwardt@tu-bs.de>
3a7fe5ba 1451
3251b439 145220010307
1453 - (bal) OpenBSD CVS Sync
1454 - deraadt@cvs.openbsd.org 2001/03/06 06:11:18
1455 [ssh-keyscan.c]
1456 appease gcc
a5ec8a3d 1457 - deraadt@cvs.openbsd.org 2001/03/06 06:11:44
1458 [sftp-int.c sftp.1 sftp.c]
1459 sftp -b batchfile; mouring@etoh.eviladmin.org
17910dce 1460 - deraadt@cvs.openbsd.org 2001/03/06 15:10:42
1461 [sftp.1]
1462 order things
2c86906e 1463 - deraadt@cvs.openbsd.org 2001/03/07 01:19:06
1464 [ssh.1 sshd.8]
1465 the name "secure shell" is boring, noone ever uses it
7daf8515 1466 - deraadt@cvs.openbsd.org 2001/03/07 04:05:58
1467 [ssh.1]
1468 removed dated comment
f52798a4 1469 - Cygwin contrib improvements from Corinna Vinschen <vinschen@redhat.com>
3251b439 1470
657297ff 147120010306
1472 - (bal) OpenBSD CVS Sync
1473 - deraadt@cvs.openbsd.org 2001/03/05 14:28:47
1474 [sshd.8]
1475 alpha order; jcs@rt.fm
7c8f2a26 1476 - stevesk@cvs.openbsd.org 2001/03/05 15:44:51
1477 [servconf.c]
1478 sync error message; ok markus@
f2ba0775 1479 - deraadt@cvs.openbsd.org 2001/03/05 15:56:16
1480 [myproposal.h ssh.1]
1481 switch to aes128-cbc/hmac-md5 by default in SSH2 -- faster;
1482 provos & markus ok
7a6c39a3 1483 - deraadt@cvs.openbsd.org 2001/03/05 16:07:15
1484 [sshd.8]
1485 detail default hmac setup too
7de5b06b 1486 - markus@cvs.openbsd.org 2001/03/05 17:17:21
1487 [kex.c kex.h sshconnect2.c sshd.c]
1488 generate a 2*need size (~300 instead of 1024/2048) random private
1489 exponent during the DH key agreement. according to Niels (the great
1490 german advisor) this is safe since /etc/primes contains strong
1491 primes only.
1492
1493 References:
1494 P. C. van Oorschot and M. J. Wiener, On Diffie-Hellman key
1495 agreement with short exponents, In Advances in Cryptology
1496 - EUROCRYPT'96, LNCS 1070, Springer-Verlag, 1996, pp.332-343.
a5df12e9 1497 - stevesk@cvs.openbsd.org 2001/03/05 17:40:48
1498 [ssh.1]
1499 more ssh_known_hosts2 documentation; ok markus@
0b2190ee 1500 - stevesk@cvs.openbsd.org 2001/03/05 17:58:22
1501 [dh.c]
1502 spelling
bbc62e59 1503 - deraadt@cvs.openbsd.org 2001/03/06 00:33:04
1504 [authfd.c cli.c ssh-agent.c]
1505 EINTR/EAGAIN handling is required in more cases
c16c7f20 1506 - millert@cvs.openbsd.org 2001/03/06 01:06:03
1507 [ssh-keyscan.c]
1508 Don't assume we wil get the version string all in one read().
1509 deraadt@ OK'd
09cb311c 1510 - millert@cvs.openbsd.org 2001/03/06 01:08:27
1511 [clientloop.c]
1512 If read() fails with EINTR deal with it the same way we treat EAGAIN
657297ff 1513
1a2936c4 151420010305
1515 - (bal) CVS ID touch up on sshpty.[ch] and sshlogin.[ch]
2552505b 1516 - (bal) CVS ID touch up on sftp-int.c
e77df335 1517 - (bal) CVS ID touch up on uuencode.c
6cca9fde 1518 - (bal) CVS ID touch up on auth2.c, serverloop.c, session.c & sshd.c
778f6940 1519 - (bal) OpenBSD CVS Sync
dcb971e1 1520 - deraadt@cvs.openbsd.org 2001/02/17 23:48:48
1521 [sshd.8]
1522 it's the OpenSSH one
778f6940 1523 - deraadt@cvs.openbsd.org 2001/02/21 07:37:04
1524 [ssh-keyscan.c]
1525 inline -> __inline__, and some indent
81333640 1526 - deraadt@cvs.openbsd.org 2001/02/21 09:05:54
1527 [authfile.c]
1528 improve fd handling
79ddf6db 1529 - deraadt@cvs.openbsd.org 2001/02/21 09:12:56
1530 [sftp-server.c]
1531 careful with & and &&; markus ok
96ee8386 1532 - stevesk@cvs.openbsd.org 2001/02/21 21:14:04
1533 [ssh.c]
1534 -i supports DSA identities now; ok markus@
0c126dc9 1535 - deraadt@cvs.openbsd.org 2001/02/22 04:29:37
1536 [servconf.c]
1537 grammar; slade@shore.net
ed2166d8 1538 - deraadt@cvs.openbsd.org 2001/02/22 06:43:55
1539 [ssh-keygen.1 ssh-keygen.c]
1540 document -d, and -t defaults to rsa1
b07ae1e9 1541 - deraadt@cvs.openbsd.org 2001/02/22 08:03:51
1542 [ssh-keygen.1 ssh-keygen.c]
1543 bye bye -d
e2fccec3 1544 - deraadt@cvs.openbsd.org 2001/02/22 18:09:06
1545 [sshd_config]
1546 activate RSA 2 key
e91c60f2 1547 - markus@cvs.openbsd.org 2001/02/22 21:57:27
1548 [ssh.1 sshd.8]
1549 typos/grammar from matt@anzen.com
3b1a83df 1550 - markus@cvs.openbsd.org 2001/02/22 21:59:44
1551 [auth.c auth.h auth1.c auth2.c misc.c misc.h ssh.c]
1552 use pwcopy in ssh.c, too
19d57054 1553 - markus@cvs.openbsd.org 2001/02/23 15:34:53
1554 [serverloop.c]
1555 debug2->3
00be5382 1556 - markus@cvs.openbsd.org 2001/02/23 18:15:13
1557 [sshd.c]
1558 the random session key depends now on the session_key_int
1559 sent by the 'attacker'
1560 dig1 = md5(cookie|session_key_int);
1561 dig2 = md5(dig1|cookie|session_key_int);
1562 fake_session_key = dig1|dig2;
1563 this change is caused by a mail from anakin@pobox.com
1564 patch based on discussions with my german advisor niels@openbsd.org
ec63b02d 1565 - deraadt@cvs.openbsd.org 2001/02/24 10:37:55
1566 [readconf.c]
1567 look for id_rsa by default, before id_dsa
582038fb 1568 - deraadt@cvs.openbsd.org 2001/02/24 10:37:26
1569 [sshd_config]
1570 ssh2 rsa key before dsa key
6e18cb71 1571 - markus@cvs.openbsd.org 2001/02/27 10:35:27
1572 [packet.c]
1573 fix random padding
1b5dfeb2 1574 - markus@cvs.openbsd.org 2001/02/27 11:00:11
1575 [compat.c]
1576 support SSH-2.0-2.1 ; from Christophe_Moret@hp.com
4ab21f86 1577 - deraadt@cvs.openbsd.org 2001/02/28 05:34:28
1578 [misc.c]
1579 pull in protos
167b3512 1580 - deraadt@cvs.openbsd.org 2001/02/28 05:36:28
1581 [sftp.c]
1582 do not kill the subprocess on termination (we will see if this helps
1583 things or hurts things)
7e8911cd 1584 - markus@cvs.openbsd.org 2001/02/28 08:45:39
1585 [clientloop.c]
1586 fix byte counts for ssh protocol v1
ee55dacf 1587 - markus@cvs.openbsd.org 2001/02/28 08:54:55
1588 [channels.c nchan.c nchan.h]
1589 make sure remote stderr does not get truncated.
1590 remove closed fd's from the select mask.
a6215e53 1591 - markus@cvs.openbsd.org 2001/02/28 09:57:07
1592 [packet.c packet.h sshconnect2.c]
1593 in ssh protocol v2 use ignore messages for padding (instead of
1594 trailing \0).
94dfb550 1595 - markus@cvs.openbsd.org 2001/02/28 12:55:07
1596 [channels.c]
1597 unify debug messages
5649fbbe 1598 - deraadt@cvs.openbsd.org 2001/02/28 17:52:54
1599 [misc.c]
1600 for completeness, copy pw_gecos too
0572fe75 1601 - markus@cvs.openbsd.org 2001/02/28 21:21:41
1602 [sshd.c]
1603 generate a fake session id, too
95ce5599 1604 - markus@cvs.openbsd.org 2001/02/28 21:27:48
1605 [channels.c packet.c packet.h serverloop.c]
1606 use ignore message to simulate a SSH2_MSG_CHANNEL_DATA message
1607 use random content in ignore messages.
355724fc 1608 - markus@cvs.openbsd.org 2001/02/28 21:31:32
1609 [channels.c]
1610 typo
c3f7d267 1611 - deraadt@cvs.openbsd.org 2001/03/01 02:11:25
1612 [authfd.c]
1613 split line so that p will have an easier time next time around
a01a5f30 1614 - deraadt@cvs.openbsd.org 2001/03/01 02:29:04
1615 [ssh.c]
1616 shorten usage by a line
12bf85ed 1617 - deraadt@cvs.openbsd.org 2001/03/01 02:45:10
1618 [auth-rsa.c auth2.c deattack.c packet.c]
1619 KNF
4371658c 1620 - deraadt@cvs.openbsd.org 2001/03/01 03:38:33
1621 [cli.c cli.h rijndael.h ssh-keyscan.1]
1622 copyright notices on all source files
ce91d6f8 1623 - markus@cvs.openbsd.org 2001/03/01 22:46:37
1624 [ssh.c]
1625 don't truncate remote ssh-2 commands; from mkubita@securities.cz
1626 use min, not max for logging, fixes overflow.
409edaba 1627 - deraadt@cvs.openbsd.org 2001/03/02 06:21:01
1628 [sshd.8]
1629 explain SIGHUP better
b8dc87d3 1630 - deraadt@cvs.openbsd.org 2001/03/02 09:42:49
1631 [sshd.8]
1632 doc the dsa/rsa key pair files
f3c7c613 1633 - deraadt@cvs.openbsd.org 2001/03/02 18:54:31
1634 [atomicio.c atomicio.h auth-chall.c auth.c auth2-chall.c crc32.h
1635 scp.c serverloop.c session.c sftp-server.8 sftp.1 ssh-add.1 ssh-add.c
1636 ssh-agent.1 ssh-agent.c ssh-keygen.1 ssh.1 sshd.8]
1637 make copyright lines the same format
2671b47f 1638 - deraadt@cvs.openbsd.org 2001/03/03 06:53:12
1639 [ssh-keyscan.c]
1640 standard theo sweep
ff7fee59 1641 - millert@cvs.openbsd.org 2001/03/03 21:19:41
1642 [ssh-keyscan.c]
1643 Dynamically allocate read_wait and its copies. Since maxfd is
1644 based on resource limits it is often (usually?) larger than FD_SETSIZE.
c8d75031 1645 - millert@cvs.openbsd.org 2001/03/03 21:40:30
1646 [sftp-server.c]
1647 Dynamically allocate fd_set; deraadt@ OK
20e04e90 1648 - millert@cvs.openbsd.org 2001/03/03 21:41:07
1649 [packet.c]
1650 Dynamically allocate fd_set; deraadt@ OK
dce9bac5 1651 - deraadt@cvs.openbsd.org 2001/03/03 22:07:50
1652 [sftp-server.c]
1653 KNF
c630ce76 1654 - markus@cvs.openbsd.org 2001/03/03 23:52:22
1655 [sftp.c]
1656 clean up arg processing. based on work by Christophe_Moret@hp.com
20244695 1657 - markus@cvs.openbsd.org 2001/03/03 23:59:34
1658 [log.c ssh.c]
1659 log*.c -> log.c
61f8a1d1 1660 - markus@cvs.openbsd.org 2001/03/04 00:03:59
1661 [channels.c]
1662 debug1->2
38967add 1663 - stevesk@cvs.openbsd.org 2001/03/04 10:57:53
1664 [ssh.c]
1665 add -m to usage; ok markus@
46f23b8d 1666 - stevesk@cvs.openbsd.org 2001/03/04 11:04:41
1667 [sshd.8]
1668 small cleanup and clarify for PermitRootLogin; ok markus@
9c81df4c 1669 - stevesk@cvs.openbsd.org 2001/03/04 11:16:06
1670 [servconf.c sshd.8]
1671 kill obsolete RandomSeed; ok markus@ deraadt@
f5429434 1672 - stevesk@cvs.openbsd.org 2001/03/04 12:54:04
1673 [sshd.8]
1674 spelling
54b974dc 1675 - millert@cvs.openbsd.org 2001/03/04 17:42:28
1676 [authfd.c channels.c dh.c log.c readconf.c servconf.c sftp-int.c
1677 ssh.c sshconnect.c sshd.c]
1678 log functions should not be passed strings that end in newline as they
1679 get passed on to syslog() and when logging to stderr, do_log() appends
1680 its own newline.
51c251f0 1681 - deraadt@cvs.openbsd.org 2001/03/04 18:21:28
1682 [sshd.8]
1683 list SSH2 ciphers
2605addd 1684 - (bal) Put HAVE_PW_CLASS_IN_PASSWD back into pwcopy()
164c80dc 1685 - (bal) Fix up logging since it changed. removed log-*.c
cc3067d6 1686 - (djm) Fix up LOG_AUTHPRIV for systems that have it
70a052c7 1687 - (stevesk) OpenBSD sync:
1688 - deraadt@cvs.openbsd.org 2001/03/05 08:37:27
1689 [ssh-keyscan.c]
1690 skip inlining, why bother
5152d46f 1691 - (stevesk) sftp.c: handle __progname
1a2936c4 1692
40edd7ef 169320010304
1694 - (bal) Remove make-ssh-known-hosts.1 since it's no longer valid.
889fbcd3 1695 - (bal) Updated contrib/README to remove 'make-ssh-known-hosts' and
1696 give Mark Roth credit for mdoc2man.pl
40edd7ef 1697
9817de5f 169820010303
40edd7ef 1699 - (djm) Remove make-ssh-known-hosts.pl, ssh-keyscan is better.
1700 - (djm) Document PAM ChallengeResponseAuthentication in sshd.8
1701 - (djm) Disable and comment ChallengeResponseAuthentication in sshd_config
1702 - (djm) Allow PRNGd entropy collection from localhost TCP socket. Replace
9bdd5929 1703 "--with-egd-pool" configure option with "--with-prngd-socket" and
1704 "--with-prngd-port" options. Debugged and improved by Lutz Jaenicke
1705 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
9817de5f 1706
20cad736 170720010301
1708 - (djm) Properly add -lcrypt if needed.
5f404be3 1709 - (djm) Force standard PAM conversation function in a few more places.
1710 Patch from Redhat 2.5.1p1-2 RPM, probably Nalin Dahyabhai
1711 <nalin@redhat.com>
480eb294 1712 - (djm) Cygwin needs pw->pw_gecos copied too. Patch from Corinna Vinschen
1713 <vinschen@redhat.com>
ad1f4a20 1714 - (djm) Released 2.5.1p2
20cad736 1715
cf0c5df5 171620010228
1717 - (djm) Detect endianness in configure and use it in rijndael.c. Fixes
1718 "Bad packet length" bugs.
403f5a8e 1719 - (djm) Fully revert PAM session patch (again). All PAM session init is
1720 now done before the final fork().
065ef9b1 1721 - (djm) EGD detection patch from Tim Rice <tim@multitalents.net>
d9b1f19a 1722 - (djm) Remove /tmp from EGD socket search list
cf0c5df5 1723
86b416a7 172420010227
51fb577a 1725 - (bal) Applied shutdown() patch for sftp.c by Corinna Vinschen
1726 <vinschen@redhat.com>
2af09193 1727 - (bal) OpenBSD Sync
1728 - markus@cvs.openbsd.org 2001/02/23 15:37:45
1729 [session.c]
1730 handle SSH_PROTOFLAG_SCREEN_NUMBER for buggy clients
a892c46e 1731 - (bal) sshd.init support for all Redhat release. Patch by Jim Knoble
1732 <jmknoble@jmknoble.cx>
f4e9a0e1 1733 - (djm) Fix up POSIX saved uid support. Report from Mark Miller
1734 <markm@swoon.net>
1735 - (djm) Search for -lcrypt on FreeBSD too
c7c72446 1736 - (djm) fatal() on OpenSSL version mismatch
27cf96de 1737 - (djm) Move PAM init to after fork for non-Solaris derived PAMs
d5c4c52e 1738 - (djm) Warning fix on entropy.c saved uid stuff. Patch from Mark Miller
1739 <markm@swoon.net>
4bc6dd70 1740 - (djm) Fix PAM fix
4236bde4 1741 - (djm) Remove 'noreplace' flag from sshd_config in RPM spec files. This
1742 change is being made as 2.5.x configfiles are not back-compatible with
64e0e67e 1743 2.3.x.
1744 - (djm) Avoid warnings for missing broken IP_TOS. Patch from Mark Miller
1745 <markm@swoon.net>
a29d3f1c 1746 - (djm) Open Server 5 doesn't need BROKEN_SAVED_UIDS. Patch from Tim Rice
1747 <tim@multitalents.net>
1748 - (djm) Avoid multiple definition of _PATH_LS. Patch from Tim Rice
1749 <tim@multitalents.net>
51fb577a 1750
4925395f 175120010226
1752 - (bal) Fixed bsd-snprinf.c so it now honors 'BROKEN_SNPRINTF' again.
e9a13ac1 1753 - (djm) Some systems (SCO3, NeXT) have weird saved uid semantics.
1754 Based on patch from Tim Rice <tim@multitalents.net>
4925395f 1755
1eb4ec64 175620010225
1757 - (djm) Use %{_libexecdir} rather than hardcoded path in RPM specfile
1758 Patch from Adrian Ho <lexfiend@usa.net>
490cad94 1759 - (bal) Replace 'unsigned long long' to 'u_int64_t' since not every
1760 platform defines u_int64_t as being that.
1eb4ec64 1761
a738c3b0 176220010224
1763 - (bal) Missed part of the UNIX sockets patch. Patch by Corinna
1764 Vinschen <vinschen@redhat.com>
1765 - (bal) Reorder where 'strftime' is detected to resolve linking
1766 issues on SCO. Patch by Tim Rice <tim@multitalents.net>
1767
8fd97cc4 176820010224
1769 - (bal) pam_stack fix to correctly detect between RH7 and older RHs.
1770 Patch by Pekka Savola <pekkas@netcore.fi>
8f0b3553 1771 - (bal) Renamed sigaction.[ch] to sigact.[ch]. Causes problems with
1772 some platforms.
3d114925 1773 - (bal) Generalize lack of UNIX sockets since this also effects Cray
1774 not just Cygwin. Based on patch by Wendy Palm <wendyp@cray.com>
8fd97cc4 1775
14a49e44 177620010223
1777 - (bal) Fix --define rh7 in openssh.spec file. Patch by Steve Tell
1778 <tell@telltronics.org>
cb291102 1779 - (bal) Patch to force OpenSSH rpm to require the same version of OpenSSL
1780 that it was compiled against. Patch by Pekka Savola <pekkas@netcore.fi>
5a67331c 1781 - (bal) Double -I for OpenSSL on SCO. Patch by Tim Rice
1782 <tim@multitalents.net>
14a49e44 1783
73d6d7fa 178420010222
1785 - (bal) Corrected SCO luid patch by svaughan <svaughan@asterion.com>
ca742b3b 1786 - (bal) Added mdoc2man.pl from Mark Roth <roth@feep.net>
1787 - (bal) Removed reference to liblogin from contrib/README. It was
1788 integrated into OpenSSH a long while ago.
2a81eb9f 1789 - (stevesk) remove erroneous #ifdef sgi code.
1790 Michael Stone <mstone@cs.loyola.edu>
73d6d7fa 1791
fbf305f1 179220010221
1793 - (bal) Removed -L/usr/ucblib -R/usr/ucblib for Solaris platform.
9dd3bc84 1794 - (bal) Fixed OpenSSL rework to use $saved_*. Patch by Tim Rice
1795 <tim@multitalents.net>
1fe61b2e 1796 - (bal) Reverted out of 2001/02/15 patch by djm below because it
1797 breaks Solaris.
1798 - (djm) Move PAM session setup back to before setuid to user.
1799 fixes problems on Solaris-drived PAMs.
266140a8 1800 - (stevesk) session.c: back out to where we were before:
1801 - (djm) Move PAM session initialisation until after fork in sshd. Patch
1802 from Nalin Dahyabhai <nalin@redhat.com>
9dd3bc84 1803
8b3319f4 180420010220
1805 - (bal) Fix mixed up params to memmove() from Jan 5th in setenv.c and
1806 getcwd.c.
c2b544a5 1807 - (bal) OpenBSD CVS Sync:
1808 - deraadt@cvs.openbsd.org 2001/02/19 23:09:05
1809 [sshd.c]
1810 clarify message to make it not mention "ident"
8b3319f4 1811
1729c161 181220010219
1813 - (bal) Markus' blessing to rename login.[ch] -> sshlogin.[ch] and
1814 pty.[ch] -> sshpty.[ch]
d6f13fbb 1815 - (djm) Rework search for OpenSSL location. Skip directories which don't
1816 exist, don't add -L$ssldir/lib if it doesn't exist. Should help SCO
1817 with its limit of 6 -L options.
0476625f 1818 - OpenBSD CVS Sync:
1819 - reinhard@cvs.openbsd.org 2001/02/17 08:24:40
1820 [sftp.1]
1821 typo
1822 - deraadt@cvs.openbsd.org 2001/02/17 16:28:58
1823 [ssh.c]
1824 cleanup -V output; noted by millert
1825 - deraadt@cvs.openbsd.org 2001/02/17 16:48:48
1826 [sshd.8]
1827 it's the OpenSSH one
1828 - markus@cvs.openbsd.org 2001/02/18 11:33:54
1829 [dispatch.c]
1830 typo, SSH2_MSG_KEXINIT, from aspa@kronodoc.fi
1831 - markus@cvs.openbsd.org 2001/02/19 02:53:32
1832 [compat.c compat.h serverloop.c]
1833 ssh-1.2.{18-22} has broken handling of ignore messages; report from
1834 itojun@
1835 - markus@cvs.openbsd.org 2001/02/19 03:35:23
1836 [version.h]
1837 OpenSSH_2.5.1 adds bug compat with 1.2.{18-22}
1838 - deraadt@cvs.openbsd.org 2001/02/19 03:36:25
1839 [scp.c]
1840 np is changed by recursion; vinschen@redhat.com
1841 - Update versions in RPM spec files
1842 - Release 2.5.1p1
1729c161 1843
663fd560 184420010218
1845 - (bal) Patch for fix FCHMOD reference in ftp-client.c by Tim Rice
1846 <tim@multitalents.net>
25cd3375 1847 - (Bal) Patch for lack of RA_RESTART in misc.c for mysignal by
1848 stevesk
58e7f038 1849 - (djm) Fix my breaking of cygwin builds, Patch from Corinna Vinschen
1850 <vinschen@redhat.com> and myself.
32ced054 1851 - (djm) Close listen_sock on bind() failures. Patch from Arkadiusz
1852 Miskiewicz <misiek@pld.ORG.PL>
6a951840 1853 - (djm) Robustify EGD/PRNGd code in face of socket closures. Patch from
1854 Todd C. Miller <Todd.Miller@courtesan.com>
b82f1310 1855 - (djm) Use ttyname() to determine name of tty returned by openpty()
1856 rather then risking overflow. Patch from Marek Michalkiewicz
1857 <marekm@amelek.gda.pl>
bdf80b2c 1858 - (djm) Swapped tests for no_libsocket and no_libnsl in configure.in.
1859 Patch from Marek Michalkiewicz <marekm@amelek.gda.pl>
af8fda37 1860 - (djm) Doc fixes from Pekka Savola <pekkas@netcore.fi>
df538d55 1861 - (djm) Use SA_INTERRUPT along SA_RESTART if present (equivalent for
1862 SunOS)
f61d6b17 1863 - (djm) SCO needs librpc for libwrap. Patch from Tim Rice
1864 <tim@multitalents.net>
dfef7e7e 1865 - (stevesk) misc.c: cpp rework of SA_(INTERRUPT|RESTART) handling.
36a358ca 1866 - (stevesk) scp.c: use mysignal() for updateprogressmeter() handler.
d54d99a3 1867 - (djm) SA_INTERRUPT is the converse of SA_RESTART, apply it only for
1868 SIGALRM.
e1a023df 1869 - (djm) Move entropy.c over to mysignal()
667beaa9 1870 - (djm) SunOS 4.x also needs to define HAVE_BOGUS_SYS_QUEUE_H as it has
1871 a <sys/queue.h> that lacks the TAILQ_* macros. Patch from Todd C.
1872 Miller <Todd.Miller@courtesan.com>
ecdde3d8 1873 - (djm) Update RPM spec files for 2.5.0p1
51ee9048 1874 - (djm) Merge BSD_AUTH support from Markus Friedl and David J. MacKenzie
1875 enable with --with-bsd-auth.
2adddc78 1876 - (stevesk) entropy.c: typo; should be SIGPIPE
663fd560 1877
0b1728c5 187820010217
1879 - (bal) OpenBSD Sync:
1880 - markus@cvs.openbsd.org 2001/02/16 13:38:18
1881 [channel.c]
1882 remove debug
c8b058b4 1883 - markus@cvs.openbsd.org 2001/02/16 14:03:43
1884 [session.c]
1885 proper payload-length check for x11 w/o screen-number
0b1728c5 1886
b41d8d4d 188720010216
1888 - (bal) added '--with-prce' to allow overriding of system regex when
1889 required (tested by David Dulek <ddulek@fastenal.com>)
d6fdb079 1890 - (bal) Added DG/UX case and set that they have a broken IPTOS.
278588d8 1891 - (djm) Mini-configure reorder patch from Tim Rice <tim@multitalents.net>
1892 Fixes linking on SCO.
0ceb21d6 1893 - (djm) Make gnome-ssh-askpass handle multi-line prompts. Patch from
1894 Nalin Dahyabhai <nalin@redhat.com>
1895 - (djm) BSD license for gnome-ssh-askpass (was X11)
1896 - (djm) KNF on gnome-ssh-askpass
ed6553e2 1897 - (djm) USE_PIPES for a few more sysv platforms
1898 - (djm) Cleanup configure.in a little
1899 - (djm) Ask users to check config.log when we can't find necessary libs
aca75d94 1900 - (djm) Set "login ID" on systems with setluid. Only enabled for SCO
1901 OpenServer for now. Based on patch from svaughan <svaughan@asterion.com>
0ae4fe1d 1902 - (djm) OpenBSD CVS:
1903 - markus@cvs.openbsd.org 2001/02/15 16:19:59
1904 [channels.c channels.h serverloop.c sshconnect.c sshconnect.h]
1905 [sshconnect1.c sshconnect2.c]
1906 genericize password padding function for SSH1 and SSH2.
1907 add stylized echo to 2, too.
1908 - (djm) Add roundup() macro to defines.h
9535dddf 1909 - (stevesk) set SA_RESTART flag in mysignal() for SIGCHLD;
1910 needed on Unixware 2.x.
b41d8d4d 1911
0086bfaf 191220010215
1913 - (djm) Move PAM session setup back to before setuid to user. Fixes
1914 problems on Solaris-derived PAMs.
e11aab29 1915 - (djm) Clean up PAM namespace. Suggested by Darren Moffat
1916 <Darren.Moffat@eng.sun.com>
9e3c31f7 1917 - (bal) Sync w/ OpenSSH for new release
1918 - markus@cvs.openbsd.org 2001/02/12 12:45:06
1919 [sshconnect1.c]
1920 fix xmalloc(0), ok dugsong@
b2552997 1921 - markus@cvs.openbsd.org 2001/02/11 12:59:25
1922 [Makefile.in sshd.8 sshconnect2.c readconf.h readconf.c packet.c
1923 sshd.c ssh.c ssh.1 servconf.h servconf.c myproposal.h kex.h kex.c]
1924 1) clean up the MAC support for SSH-2
1925 2) allow you to specify the MAC with 'ssh -m'
1926 3) or the 'MACs' keyword in ssh(d)_config
1927 4) add hmac-{md5,sha1}-96
1928 ok stevesk@, provos@
15853e93 1929 - markus@cvs.openbsd.org 2001/02/12 16:16:23
1930 [auth-passwd.c auth.c auth.h auth1.c auth2.c servconf.c servconf.h
1931 ssh-keygen.c sshd.8]
1932 PermitRootLogin={yes,without-password,forced-commands-only,no}
1933 (before this change, root could login even if PermitRootLogin==no)
7cc4cf0a 1934 - deraadt@cvs.openbsd.org 2001/02/12 22:56:09
fd193ca4 1935 [clientloop.c packet.c ssh-keyscan.c]
1936 deal with EAGAIN/EINTR selects which were skipped
7cc4cf0a 1937 - markus@cvs.openssh.org 2001/02/13 22:49:40
1938 [auth1.c auth2.c]
1939 setproctitle(user) only if getpwnam succeeds
1940 - markus@cvs.openbsd.org 2001/02/12 23:26:20
1941 [sshd.c]
1942 missing memset; from solar@openwall.com
1943 - stevesk@cvs.openbsd.org 2001/02/12 20:53:33
1944 [sftp-int.c]
1945 lumask now works with 1 numeric arg; ok markus@, djm@
1946 - djm@cvs.openbsd.org 2001/02/14 9:46:03
1947 [sftp-client.c sftp-int.c sftp.1]
1948 Fix and document 'preserve modes & times' option ('-p' flag in sftp);
1949 ok markus@
0b16bb01 1950 - (bal) replaced PATH_MAX in sftp-int.c w/ MAXPATHLEN.
1951 - (djm) Move to Jim's 1.2.0 X11 askpass program
62da27dd 1952 - (stevesk) OpenBSD sync:
1953 - deraadt@cvs.openbsd.org 2001/02/15 01:38:04
1954 [serverloop.c]
1955 indent
0b16bb01 1956
1c2d0a13 195720010214
1958 - (djm) Don't try to close PAM session or delete credentials if the
1959 session has not been open or credentials not set. Based on patch from
1960 Andrew Bartlett <abartlet@pcug.org.au>
0ab1bcba 1961 - (djm) Move PAM session initialisation until after fork in sshd. Patch
1962 from Nalin Dahyabhai <nalin@redhat.com>
958e5ae4 1963 - (bal) Missing function prototype in bsd-snprintf.c patch by
1964 Mark Miller <markm@swoon.net>
b7ccb051 1965 - (djm) Split out and improve OSF SIA auth code. Patch from Chris Adams
1966 <cmadams@hiwaay.net> with a little modification and KNF.
815800e1 1967 - (stevesk) fix for SIA patch, misplaced session_setup_sia()
1c2d0a13 1968
0610439b 196920010213
84eb157c 1970 - (djm) Only test -S potential EGD sockets if they exist and are readable.
f1312c76 1971 - (bal) Cleaned out bsd-snprintf.c. VARARGS have been banished and
1972 I did a base KNF over the whe whole file to make it more acceptable.
1973 (backed out of original patch and removed it from ChangeLog)
01f13020 1974 - (bal) Use chown() if fchown() does not exist in ftp-server.c patch by
1975 Tim Rice <tim@multitalents.net>
8d60e965 1976 - (stevesk) auth1.c: fix PAM passwordless check.
0610439b 1977
894a4851 197820010212
1979 - (djm) Update Redhat specfile to allow --define "skip_x11_askpass 1",
1980 --define "skip_gnome_askpass 1", --define "rh7 1" and make the
1981 implicit rpm-3.0.5 dependancy explicit. Patch and suggestions from
1982 Pekka Savola <pekkas@netcore.fi>
782d6a0d 1983 - (djm) Clean up PCRE text in INSTALL
77db6c3f 1984 - (djm) Fix OSF SIA auth NULL pointer deref. Report from Mike Battersby
1985 <mib@unimelb.edu.au>
6f68f28a 1986 - (bal) NCR SVR4 compatiblity provide by Don Bragg <thewizarddon@yahoo.com>
01a7bc9a 1987 - (stevesk) session.c: remove debugging code.
894a4851 1988
abf1f107 198920010211
1990 - (bal) OpenBSD Sync
1991 - markus@cvs.openbsd.org 2001/02/07 22:35:46
1992 [auth1.c auth2.c sshd.c]
1993 move k_setpag() to a central place; ok dugsong@
c845316f 1994 - markus@cvs.openbsd.org 2001/02/10 12:52:02
1995 [auth2.c]
1996 offer passwd before s/key
e6fa162e 1997 - markus@cvs.openbsd.org 2001/02/8 22:37:10
1998 [canohost.c]
1999 remove last call to sprintf; ok deraadt@
0ab4b0f0 2000 - markus@cvs.openbsd.org 2001/02/10 1:33:32
2001 [canohost.c]
2002 add debug message, since sshd blocks here if DNS is not available
7f8ea238 2003 - markus@cvs.openbsd.org 2001/02/10 12:44:02
2004 [cli.c]
2005 don't call vis() for \r
5c470997 2006 - danh@cvs.openbsd.org 2001/02/10 0:12:43
2007 [scp.c]
2008 revert a small change to allow -r option to work again; ok deraadt@
2009 - danh@cvs.openbsd.org 2001/02/10 15:14:11
2010 [scp.c]
2011 fix memory leak; ok markus@
a0e6fead 2012 - djm@cvs.openbsd.org 2001/02/10 0:45:52
2013 [scp.1]
2014 Mention that you can quote pathnames with spaces in them
b3106440 2015 - markus@cvs.openbsd.org 2001/02/10 1:46:28
2016 [ssh.c]
2017 remove mapping of argv[0] -> hostname
f72e01a5 2018 - markus@cvs.openbsd.org 2001/02/06 22:26:17
2019 [sshconnect2.c]
2020 do not ask for passphrase in batch mode; report from ejb@ql.org
2021 - itojun@cvs.opebsd.org 2001/02/08 10:47:05
5d1d11d1 2022 [sshconnect.c sshconnect1.c sshconnect2.c]
f72e01a5 2023 %.30s is too short for IPv6 numeric address. use %.128s for now.
2024 markus ok
2025 - markus@cvs.openbsd.org 2001/02/09 12:28:35
2026 [sshconnect2.c]
2027 do not free twice, thanks to /etc/malloc.conf
2028 - markus@cvs.openbsd.org 2001/02/09 17:10:53
2029 [sshconnect2.c]
2030 partial success: debug->log; "Permission denied" if no more auth methods
2031 - markus@cvs.openbsd.org 2001/02/10 12:09:21
2032 [sshconnect2.c]
2033 remove some lines
e0b2cf6b 2034 - markus@cvs.openbsd.org 2001/02/09 13:38:07
2035 [auth-options.c]
2036 reset options if no option is given; from han.holl@prismant.nl
ca910e13 2037 - markus@cvs.openbsd.org 2001/02/08 21:58:28
2038 [channels.c]
2039 nuke sprintf, ok deraadt@
2040 - markus@cvs.openbsd.org 2001/02/08 21:58:28
2041 [channels.c]
2042 nuke sprintf, ok deraadt@
affa8be4 2043 - markus@cvs.openbsd.org 2001/02/06 22:43:02
2044 [clientloop.h]
2045 remove confusing callback code
d2c46e77 2046 - deraadt@cvs.openbsd.org 2001/02/08 14:39:36
2047 [readconf.c]
2048 snprintf
cc8aca8a 2049 - itojun@cvs.openbsd.org 2001/02/08 19:30:52
2050 sync with netbsd tree changes.
2051 - more strict prototypes, include necessary headers
2052 - use paths.h/pathnames.h decls
2053 - size_t typecase to int -> u_long
5be2ec5e 2054 - itojun@cvs.openbsd.org 2001/02/07 18:04:50
2055 [ssh-keyscan.c]
2056 fix size_t -> int cast (use u_long). markus ok
2057 - markus@cvs.openbsd.org 2001/02/07 22:43:16
2058 [ssh-keyscan.c]
2059 s/getline/Linebuf_getline/; from roumen.petrov@skalasoft.com
2060 - itojun@cvs.openbsd.org 2001/02/09 9:04:59
2061 [ssh-keyscan.c]
2062 do not assume malloc() returns zero-filled region. found by
2063 malloc.conf=AJ.
f21032a6 2064 - markus@cvs.openbsd.org 2001/02/08 22:35:30
2065 [sshconnect.c]
2066 don't connect if batch_mode is true and stricthostkeychecking set to
2067 'ask'
7bbcc167 2068 - djm@cvs.openbsd.org 2001/02/04 21:26:07
2069 [sshd_config]
2070 type: ok markus@
2071 - deraadt@cvs.openbsd.org 2001/02/06 22:07:50
2072 [sshd_config]
2073 enable sftp-server by default
a2e6d17d 2074 - deraadt 2001/02/07 8:57:26
2075 [xmalloc.c]
2076 deal with new ANSI malloc stuff
2077 - markus@cvs.openbsd.org 2001/02/07 16:46:08
2078 [xmalloc.c]
2079 typo in fatal()
2080 - itojun@cvs.openbsd.org 2001/02/07 18:04:50
2081 [xmalloc.c]
2082 fix size_t -> int cast (use u_long). markus ok
4ef922e3 2083 - 1.47 Thu Feb 8 23:11:42 GMT 2001 by dugsong
2084 [serverloop.c sshconnect1.c]
2085 mitigate SSH1 traffic analysis - from Solar Designer
2086 <solar@openwall.com>, ok provos@
ca910e13 2087 - (bal) fixed sftp-client.c. Return 'status' instead of '0'
2088 (from the OpenBSD tree)
6b442913 2089 - (bal) Synced ssh.1, ssh-add.1 and sshd.8 w/ OpenBSD
27df9d4a 2090 - (bal) sftp-sever.c '%8lld' to '%8llu' (OpenBSD Sync)
17321afe 2091 - (bal) uuencode.c resync w/ OpenBSD tree, plus whitespace.
f98d56f0 2092 - (bal) A bit more whitespace cleanup
e275684f 2093 - (djm) Set PAM_RHOST earlier, patch from Andrew Bartlett
2094 <abartlet@pcug.org.au>
b27e97b1 2095 - (stevesk) misc.c: ssh.h not needed.
38a316c0 2096 - (stevesk) compat.c: more friendly cpp error
94f38e16 2097 - (stevesk) OpenBSD sync:
2098 - stevesk@cvs.openbsd.org 2001/02/11 06:15:57
2099 [LICENSE]
2100 typos and small cleanup; ok deraadt@
abf1f107 2101
0426a3b4 210220010210
2103 - (djm) Sync sftp and scp stuff from OpenBSD:
2104 - djm@cvs.openbsd.org 2001/02/07 03:55:13
2105 [sftp-client.c]
2106 Don't free handles before we are done with them. Based on work from
2107 Corinna Vinschen <vinschen@redhat.com>. ok markus@
2108 - djm@cvs.openbsd.org 2001/02/06 22:32:53
2109 [sftp.1]
2110 Punctuation fix from Pekka Savola <pekkas@netcore.fi>
2111 - deraadt@cvs.openbsd.org 2001/02/07 04:07:29
2112 [sftp.1]
2113 pretty up significantly
2114 - itojun@cvs.openbsd.org 2001/02/07 06:49:42
2115 [sftp.1]
2116 .Bl-.El mismatch. markus ok
2117 - djm@cvs.openbsd.org 2001/02/07 06:12:30
2118 [sftp-int.c]
2119 Check that target is a directory before doing ls; ok markus@
2120 - itojun@cvs.openbsd.org 2001/02/07 11:01:18
2121 [scp.c sftp-client.c sftp-server.c]
2122 unsigned long long -> %llu, not %qu. markus ok
2123 - stevesk@cvs.openbsd.org 2001/02/07 11:10:39
2124 [sftp.1 sftp-int.c]
2125 more man page cleanup and sync of help text with man page; ok markus@
2126 - markus@cvs.openbsd.org 2001/02/07 14:58:34
2127 [sftp-client.c]
2128 older servers reply with SSH2_FXP_NAME + count==0 instead of EOF
2129 - djm@cvs.openbsd.org 2001/02/07 15:27:19
2130 [sftp.c]
2131 Don't forward agent and X11 in sftp. Suggestion from Roumen Petrov
2132 <roumen.petrov@skalasoft.com>
2133 - stevesk@cvs.openbsd.org 2001/02/07 15:36:04
2134 [sftp-int.c]
2135 portable; ok markus@
2136 - stevesk@cvs.openbsd.org 2001/02/07 15:55:47
2137 [sftp-int.c]
2138 lowercase cmds[].c also; ok markus@
2139 - markus@cvs.openbsd.org 2001/02/07 17:04:52
2140 [pathnames.h sftp.c]
2141 allow sftp over ssh protocol 1; ok djm@
2142 - deraadt@cvs.openbsd.org 2001/02/08 07:38:55
2143 [scp.c]
2144 memory leak fix, and snprintf throughout
2145 - deraadt@cvs.openbsd.org 2001/02/08 08:02:02
2146 [sftp-int.c]
2147 plug a memory leak
2148 - stevesk@cvs.openbsd.org 2001/02/08 10:11:23
2149 [session.c sftp-client.c]
2150 %i -> %d
2151 - stevesk@cvs.openbsd.org 2001/02/08 10:57:59
2152 [sftp-int.c]
2153 typo
2154 - stevesk@cvs.openbsd.org 2001/02/08 15:28:07
2155 [sftp-int.c pathnames.h]
2156 _PATH_LS; ok markus@
2157 - djm@cvs.openbsd.org 2001/02/09 04:46:25
2158 [sftp-int.c]
2159 Check for NULL attribs for chown, chmod & chgrp operations, only send
2160 relevant attribs back to server; ok markus@
96b64eb0 2161 - djm@cvs.openbsd.org 2001/02/06 15:05:25
2162 [sftp.c]
2163 Use getopt to process commandline arguments
2164 - djm@cvs.openbsd.org 2001/02/06 15:06:21
2165 [sftp.c ]
2166 Wait for ssh subprocess at exit
2167 - djm@cvs.openbsd.org 2001/02/06 15:18:16
2168 [sftp-int.c]
2169 stat target for remote chdir before doing chdir
2170 - djm@cvs.openbsd.org 2001/02/06 15:32:54
2171 [sftp.1]
2172 Punctuation fix from Pekka Savola <pekkas@netcore.fi>
2173 - provos@cvs.openbsd.org 2001/02/05 22:22:02
2174 [sftp-int.c]
2175 cleanup get_pathname, fix pwd after failed cd. okay djm@
0426a3b4 2176 - (djm) Update makefile.in for _PATH_SFTP_SERVER
c9f5e42e 2177 - (bal) sftp-client.c replace NULL w/ 0 in do_ls() (pending in OpenBSD tree)
0426a3b4 2178
6d1e1d2b 217920010209
2180 - (bal) patch to vis.c to deal with HAVE_VIS right by Robert Mooney
2181 <rjmooney@mediaone.net>
bb0c1991 2182 - (bal) .c.o rule in openbsd-compat/Makefile.in did not make it to the
2183 main tree while porting forward. Pointed out by Lutz Jaenicke
2184 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
f902d909 2185 - (bal) double entry in configure.in. Pointed out by Lutz Jaenicke
2186 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
25f4c264 2187 - (stevesk) OpenBSD sync:
2188 - markus@cvs.openbsd.org 2001/02/08 11:20:01
2189 [auth2.c]
2190 strict checking
2191 - markus@cvs.openbsd.org 2001/02/08 11:15:22
2192 [version.h]
2193 update to 2.3.2
2194 - markus@cvs.openbsd.org 2001/02/08 11:12:30
2195 [auth2.c]
2196 fix typo
72b3f75d 2197 - (djm) Update spec files
0ed28836 2198 - (bal) OpenBSD sync:
2199 - deraadt@cvs.openbsd.org 2001/02/08 14:38:54
2200 [scp.c]
2201 memory leak fix, and snprintf throughout
1fc8ccdf 2202 - markus@cvs.openbsd.org 2001/02/06 22:43:02
2203 [clientloop.c]
2204 remove confusing callback code
0b202697 2205 - (djm) Add CVS Id's to files that we have missed
5ca51e19 2206 - (bal) OpenBSD Sync (more):
2207 - itojun@cvs.openbsd.org 2001/02/08 19:30:52
2208 sync with netbsd tree changes.
2209 - more strict prototypes, include necessary headers
2210 - use paths.h/pathnames.h decls
2211 - size_t typecase to int -> u_long
1f3bf5aa 2212 - markus@cvs.openbsd.org 2001/02/06 22:07:42
2213 [ssh.c]
2214 fatal() if subsystem fails
2215 - markus@cvs.openbsd.org 2001/02/06 22:43:02
2216 [ssh.c]
2217 remove confusing callback code
2218 - jakob@cvs.openbsd.org 2001/02/06 23:03:24
2219 [ssh.c]
2220 add -1 option (force protocol version 1). ok markus@
2221 - jakob@cvs.openbsd.org 2001/02/06 23:06:21
2222 [ssh.c]
2223 reorder -{1,2,4,6} options. ok markus@
e6aa01b4 2224 - (bal) Missing 'const' in readpass.h
9c5a8165 2225 - (bal) OpenBSD Sync (so at least the thing compiles for 2.3.2 =)
2226 - djm@cvs.openbsd.org 2001/02/06 23:30:28
2227 [sftp-client.c]
2228 replace arc4random with counter for request ids; ok markus@
bc79ed5c 2229 - (djm) Define _PATH_TTY for systems that don't. Report from Lutz
2230 Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
6d1e1d2b 2231
6a25c04c 223220010208
2233 - (djm) Don't delete external askpass program in make uninstall target.
2234 Report and fix from Roumen Petrov <roumen.petrov@skalasoft.com>
6958bd37 2235 - (djm) Fix linking of sftp, don't need arc4random any more.
2236 - (djm) Try to use shell that supports "test -S" for EGD socket search.
2237 Based on patch from Tim Rice <tim@multitalents.net>
6a25c04c 2238
547519f0 223920010207
bee0a37e 2240 - (bal) Save the whole path to AR in configure. Some Solaris 2.7 installs
2241 seem lose track of it while in openbsd-compat/ (two confirmed reports)
5c377b3b 2242 - (djm) Much KNF on PAM code
547519f0 2243 - (djm) Revise auth-pam.c conversation function to be a little more
2244 readable.
5c377b3b 2245 - (djm) Revise kbd-int PAM conversation function to fold all text messages
2246 to before first prompt. Fixes hangs if last pam_message did not require
2247 a reply.
2248 - (djm) Fix password changing when using PAM kbd-int authentication
bee0a37e 2249
547519f0 225020010205
2b87da3b 2251 - (bal) Disable groupaccess by setting NGROUPS_MAX to 0 for platforms
99286dc8 2252 that don't have NGROUPS_MAX.
57559587 2253 - (bal) AIX patch for auth1.c by William L. Jones <jones@hpc.utexas.edu>
2b87da3b 2254 - (stevesk) OpenBSD sync:
2255 - stevesk@cvs.openbsd.org 2001/02/04 08:32:27
2256 [many files; did this manually to our top-level source dir]
2257 unexpand and remove end-of-line whitespace; ok markus@
408ba72f 2258 - stevesk@cvs.openbsd.org 2001/02/04 15:21:19
2259 [sftp-server.c]
2260 SSH2_FILEXFER_ATTR_UIDGID support; ok markus@
ec2a033a 2261 - deraadt@cvs.openbsd.org 2001/02/04 17:02:32
2262 [sftp-int.c]
2263 ? == help
2264 - deraadt@cvs.openbsd.org 2001/02/04 16:47:46
2265 [sftp-int.c]
2266 sort commands, so that abbreviations work as expected
2267 - stevesk@cvs.openbsd.org 2001/02/04 15:17:52
2268 [sftp-int.c]
2269 debugging sftp: precedence and missing break. chmod, chown, chgrp
2270 seem to be working now.
2271 - markus@cvs.openbsd.org 2001/02/04 14:41:21
2272 [sftp-int.c]
2273 use base 8 for umask/chmod
2274 - markus@cvs.openbsd.org 2001/02/04 11:11:54
2275 [sftp-int.c]
2276 fix LCD
c44559d2 2277 - markus@cvs.openbsd.org 2001/02/04 08:10:44
2278 [ssh.1]
2279 typo; dpo@club-internet.fr
a5930351 2280 - stevesk@cvs.openbsd.org 2001/02/04 06:30:12
2281 [auth2.c authfd.c packet.c]
2282 remove duplicate #include's; ok markus@
6a416424 2283 - deraadt@cvs.openbsd.org 2001/02/04 16:56:23
2284 [scp.c sshd.c]
2285 alpha happiness
2286 - stevesk@cvs.openbsd.org 2001/02/04 15:12:17
2287 [sshd.c]
2288 precedence; ok markus@
02a024dd 2289 - deraadt@cvs.openbsd.org 2001/02/04 08:14:15
6a416424 2290 [ssh.c sshd.c]
2291 make the alpha happy
02a024dd 2292 - markus@cvs.openbsd.org 2001/01/31 13:37:24
2293 [channels.c channels.h serverloop.c ssh.c]
547519f0 2294 do not disconnect if local port forwarding fails, e.g. if port is
2295 already in use
02a024dd 2296 - markus@cvs.openbsd.org 2001/02/01 14:58:09
2297 [channels.c]
2298 use ipaddr in channel messages, ietf-secsh wants this
2299 - markus@cvs.openbsd.org 2001/01/31 12:26:20
2300 [channels.c]
547519f0 2301 ssh.com-2.0.1x does not send additional info in CHANNEL_OPEN_FAILURE
2302 messages; bug report from edmundo@rano.org
a741554f 2303 - markus@cvs.openbsd.org 2001/01/31 13:48:09
2304 [sshconnect2.c]
2305 unused
9378f292 2306 - deraadt@cvs.openbsd.org 2001/02/04 08:23:08
2307 [sftp-client.c sftp-server.c]
2308 make gcc on the alpha even happier
1fc243d1 2309
547519f0 231020010204
781a0585 2311 - (bal) I think this is the last of the bsd-*.h that don't belong.
634e0b53 2312 - (bal) Minor Makefile fix
f0f14bea 2313 - (bal) openbsd-compat/Makefile minor fix. Ensure dependancies are done
61e96248 2314 right.
78987b57 2315 - (bal) Changed order of LIB="" in -with-skey due to library resolving.
166e4f2a 2316 - (bal) next-posix.h changed to bsd-nextstep.h
61e96248 2317 - (djm) OpenBSD CVS sync:
2318 - markus@cvs.openbsd.org 2001/02/03 03:08:38
2319 [auth-options.c auth-rh-rsa.c auth-rhosts.c auth.c canohost.c]
2320 [canohost.h servconf.c servconf.h session.c sshconnect1.c sshd.8]
2321 [sshd_config]
2322 make ReverseMappingCheck optional in sshd_config; ok djm@,dugsong@
2323 - markus@cvs.openbsd.org 2001/02/03 03:19:51
2324 [ssh.1 sshd.8 sshd_config]
2325 Skey is now called ChallengeResponse
2326 - markus@cvs.openbsd.org 2001/02/03 03:43:09
2327 [sshd.8]
2328 use no-pty option in .ssh/authorized_keys* if you need a 8-bit clean
2329 channel. note from Erik.Anggard@cygate.se (pr/1659)
2330 - stevesk@cvs.openbsd.org 2001/02/03 10:03:06
2331 [ssh.1]
2332 typos; ok markus@
2333 - djm@cvs.openbsd.org 2001/02/04 04:11:56
2334 [scp.1 sftp-server.c ssh.1 sshd.8 sftp-client.c sftp-client.h]
2335 [sftp-common.c sftp-common.h sftp-int.c sftp-int.h sftp.1 sftp.c]
2336 Basic interactive sftp client; ok theo@
2337 - (djm) Update RPM specs for new sftp binary
2338 - (djm) Update several bits for new optional reverse lookup stuff. I
2339 think I got them all.
8b061486 2340 - (djm) Makefile.in fixes
1aa00dcb 2341 - (stevesk) add mysignal() wrapper and use it for the protocol 2
2342 SIGCHLD handler.
408ba72f 2343 - (djm) Use setvbuf() instead of setlinebuf(). Suggest from stevesk@
781a0585 2344
547519f0 234520010203
63fe0529 2346 - (bal) Cygwin clean up by Corinna Vinschen <vinschen@redhat.com>
bf3db92d 2347 - (bal) renamed queue.h to fake-queue.h (even if it's an OpenBSD
2348 based file) to ensure #include space does not get confused.
f78888c7 2349 - (bal) Minor Makefile.in tweak. dirname may not exist on some
2350 platforms so builds fail. (NeXT being a well known one)
63fe0529 2351
547519f0 235220010202
61e96248 2353 - (bal) Makefile fix where sourcedir != builddir by Corinna Vinschen
c85a87f2 2354 <vinschen@redhat.com>
71301416 2355 - (bal) Makefile fix to use $(MAKE) instead of 'make' for platforms
2356 that use 'gmake'. Patch by Tim Rice <tim@multitalents.net>
c85a87f2 2357
547519f0 235820010201
ad5075bd 2359 - (bal) Minor fix to Makefile to stop rebuilding executables if no
2360 changes have occured to any of the supporting code. Patch by
2361 Roumen Petrov <roumen.petrov@skalasoft.com>
2362
9c8dbb1b 236320010131
37845585 2364 - (djm) OpenBSD CVS Sync:
2365 - djm@cvs.openbsd.org 2001/01/30 15:48:53
2366 [sshconnect.c]
2367 Make warning message a little more consistent. ok markus@
8c89dd2b 2368 - (djm) Fix autoconf logic for --with-lastlog=no Report and diagnosis from
2369 Philipp Buehler <lists@fips.de> and Kevin Steves <stevesk@sweden.hp.com>
2370 respectively.
c59dc6bd 2371 - (djm) Don't log SSH2 PAM KbdInt responses to debug, they may contain
2372 passwords.
9c8dbb1b 2373 - (bal) Reorder. Move all bsd-*, fake-*, next-*, and cygwin* stuff to
2374 openbsd-compat/. And resolve all ./configure and Makefile.in issues
2375 assocated.
37845585 2376
9c8dbb1b 237720010130
39929cdb 2378 - (djm) OpenBSD CVS Sync:
2379 - markus@cvs.openbsd.org 2001/01/29 09:55:37
2380 [channels.c channels.h clientloop.c serverloop.c]
2381 fix select overflow; ok deraadt@ and stevesk@
865ac82e 2382 - markus@cvs.openbsd.org 2001/01/29 12:42:35
2383 [canohost.c canohost.h channels.c clientloop.c]
2384 add get_peer_ipaddr(socket), x11-fwd in ssh2 requires ipaddr, not DNS
46aa2d1f 2385 - markus@cvs.openbsd.org 2001/01/29 12:47:32
2386 [rsa.c rsa.h ssh-agent.c sshconnect1.c sshd.c]
2387 handle rsa_private_decrypt failures; helps against the Bleichenbacher
2388 pkcs#1 attack
ae810de7 2389 - djm@cvs.openbsd.org 2001/01/29 05:36:11
2390 [ssh.1 ssh.c]
2391 Allow invocation of sybsystem by commandline (-s); ok markus@
83bc57f9 2392 - (stevesk) configure.in: remove duplicate PROG_LS
39929cdb 2393
9c8dbb1b 239420010129
f29ef605 2395 - (stevesk) sftp-server.c: use %lld vs. %qd
2396
cb9da0fc 239720010128
2398 - (bal) Put USE_PIPES back into sco3.2v5
23c2a7a5 2399 - (bal) OpenBSD Sync
9bd5b720 2400 - markus@cvs.openbsd.org 2001/01/28 10:15:34
2401 [dispatch.c]
2402 re-keying is not supported; ok deraadt@
5fb622e4 2403 - markus@cvs.openbsd.org 2001/01/28 10:24:04
7f5c4295 2404 [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
5fb622e4 2405 cleanup AUTHORS sections
9bd5b720 2406 - markus@cvs.openbsd.org 2001/01/28 10:37:26
ab60252b 2407 [sshd.c sshd.8]
9bd5b720 2408 remove -Q, no longer needed
2409 - stevesk@cvs.openbsd.org 2001/01/28 20:36:16
a877488a 2410 [readconf.c ssh.1]
9bd5b720 2411 ``StrictHostKeyChecking ask'' documentation and small cleanup.
2412 ok markus@
6f37606e 2413 - stevesk@cvs.openbsd.org 2001/01/28 20:43:25
61e96248 2414 [sshd.8]
6f37606e 2415 spelling. ok markus@
95f4ccfb 2416 - stevesk@cvs.openbsd.org 2001/01/28 20:53:21
2417 [xmalloc.c]
2418 use size_t for strlen() return. ok markus@
6f37606e 2419 - stevesk@cvs.openbsd.org 2001/01/28 22:27:05
2420 [authfile.c]
2421 spelling. use sizeof vs. strlen(). ok markus@
9bd5b720 2422 - niklas@cvs.openbsd.org 2001/01/29 1:59:14
23c2a7a5 2423 [atomicio.h canohost.h clientloop.h deattack.h dh.h dispatch.h
2424 groupaccess.c groupaccess.h hmac.h hostfile.h includes.h kex.h
2425 key.h log.h login.h match.h misc.h myproposal.h nchan.ms pathnames.h
2426 radix.h readpass.h rijndael.h serverloop.h session.h sftp.h ssh-add.1
2427 ssh-dss.h ssh-keygen.1 ssh-keyscan.1 ssh-rsa.h ssh1.h ssh_config
2428 sshconnect.h sshd_config tildexpand.h uidswap.h uuencode.h]
2429 $OpenBSD$
b0e305c9 2430 - (bal) Minor auth2.c resync. Whitespace and moving of an #include.
cb9da0fc 2431
c9606e03 243220010126
61e96248 2433 - (bal) SSH_PROGRAM vs _PATH_SSH_PROGRAM fix pointed out by Roumen
c9606e03 2434 Petrov <roumen.petrov@skalasoft.com>
2f4b2e38 2435 - (bal) OpenBSD Sync
2436 - deraadt@cvs.openbsd.org 2001/01/25 8:06:33
2437 [ssh-agent.c]
2438 call _exit() in signal handler
c9606e03 2439
d7d5f0b2 244020010125
2441 - (djm) Sync bsd-* support files:
2442 - deraadt@cvs.openbsd.org 2000/01/26 03:43:20
2443 [rresvport.c bindresvport.c]
61e96248 2444 new bindresvport() semantics that itojun, shin, jean-luc and i have
d7d5f0b2 2445 agreed on, which will be happy for the future. bindresvport_sa() for
2446 sockaddr *, too. docs later..
2447 - deraadt@cvs.openbsd.org 2000/01/24 02:24:21
2448 [bindresvport.c]
61e96248 2449 in bindresvport(), if sin is non-NULL, example sin->sin_family for
d7d5f0b2 2450 the actual family being processed
e1dd3a7a 2451 - (djm) Mention PRNGd in documentation, it is nicer than EGD
2452 - (djm) Automatically search for "well-known" EGD/PRNGd sockets in autoconf
8080699b 2453 - (bal) AC_FUNC_STRFTIME added to autoconf
4ccb01d6 2454 - (bal) OpenBSD Resync
2455 - stevesk@cvs.openbsd.org 2001/01/24 21:03:50
2456 [channels.c]
2457 missing freeaddrinfo(); ok markus@
d7d5f0b2 2458
556eb464 245920010124
2460 - (bal) OpenBSD Resync
2461 - markus@cvs.openbsd.org 2001/01/23 10:45:10
2462 [ssh.h]
61e96248 2463 nuke comment
1aecda34 2464 - (bal) no 64bit support patch from Tim Rice <tim@multitalents.net>
2465 - (bal) #ifdef around S_IFSOCK if platform does not support it.
2466 patch by Tim Rice <tim@multitalents.net>
2467 - (bal) fake-regex.h cleanup based on Tim Rice's patch.
c33f0b36 2468 - (stevesk) sftp-server.c: fix chmod() mode mask
556eb464 2469
effa6591 247020010123
2471 - (bal) regexp.h typo in configure.in. Should have been regex.h
2472 - (bal) SSH_USER_DIR to _PATH_SSH_USER_DIR patch by stevesk@
61e96248 2473 - (bal) SSH_ASKPASS_DEFAULT to _PATH_SSH_ASKPASS_DEFAULT
53a24016 2474 - (bal) OpenBSD Resync
2475 - markus@cvs.openbsd.org 2001/01/22 8:15:00
2476 [auth-krb4.c sshconnect1.c]
2477 only AFS needs radix.[ch]
2478 - markus@cvs.openbsd.org 2001/01/22 8:32:53
2479 [auth2.c]
2480 no need to include; from mouring@etoh.eviladmin.org
2481 - stevesk@cvs.openbsd.org 2001/01/22 16:55:21
2482 [key.c]
2483 free() -> xfree(); ok markus@
2484 - stevesk@cvs.openbsd.org 2001/01/22 17:22:28
2485 [sshconnect2.c sshd.c]
2486 fix memory leaks in SSH2 key exchange; ok markus@
d464095c 2487 - markus@cvs.openbsd.org 2001/01/22 23:06:39
2488 [auth1.c auth2.c readconf.c readconf.h servconf.c servconf.h
2489 sshconnect1.c sshconnect2.c sshd.c]
2490 rename skey -> challenge response.
2491 auto-enable kbd-interactive for ssh2 if challenge-reponse is enabled.
53a24016 2492
effa6591 2493
42f11eb2 249420010122
2495 - (bal) OpenBSD Resync
2496 - markus@cvs.openbsd.org 2001/01/19 12:45:26 GMT 2001 by markus
2497 [servconf.c ssh.h sshd.c]
2498 only auth-chall.c needs #ifdef SKEY
2499 - markus@cvs.openbsd.org 2001/01/19 15:55:10 GMT 2001 by markus
2500 [auth-krb4.c auth-options.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c
2501 auth1.c auth2.c channels.c clientloop.c dh.c dispatch.c nchan.c
2502 packet.c pathname.h readconf.c scp.c servconf.c serverloop.c
2503 session.c ssh-add.c ssh-keygen.c ssh-keyscan.c ssh.c ssh.h
2504 ssh1.h sshconnect1.c sshd.c ttymodes.c]
2505 move ssh1 definitions to ssh1.h, pathnames to pathnames.h
2506 - markus@cvs.openbsd.org 2001/01/19 16:48:14
2507 [sshd.8]
2508 fix typo; from stevesk@
2509 - markus@cvs.openbsd.org 2001/01/19 16:50:58
2510 [ssh-dss.c]
61e96248 2511 clear and free digest, make consistent with other code (use dlen); from
42f11eb2 2512 stevesk@
2513 - markus@cvs.openbsd.org 2001/01/20 15:55:20 GMT 2001 by markus
2514 [auth-options.c auth-options.h auth-rsa.c auth2.c]
2515 pass the filename to auth_parse_options()
61e96248 2516 - markus@cvs.openbsd.org 2001/01/20 17:59:40 GMT 2001
42f11eb2 2517 [readconf.c]
2518 fix SIGSEGV from -o ""; problem noted by jehsom@togetherweb.com
2519 - stevesk@cvs.openbsd.org 2001/01/20 18:20:29
2520 [sshconnect2.c]
2521 dh_new_group() does not return NULL. ok markus@
2522 - markus@cvs.openbsd.org 2001/01/20 21:33:42
2523 [ssh-add.c]
61e96248 2524 do not loop forever if askpass does not exist; from
42f11eb2 2525 andrew@pimlott.ne.mediaone.net
2526 - djm@cvs.openbsd.org 2001/01/20 23:00:56
2527 [servconf.c]
2528 Check for NULL return from strdelim; ok markus
2529 - djm@cvs.openbsd.org 2001/01/20 23:02:07
2530 [readconf.c]
2531 KNF; ok markus
2532 - jakob@cvs.openbsd.org 2001/01/21 9:00:33
2533 [ssh-keygen.1]
2534 remove -R flag; ok markus@
2535 - markus@cvs.openbsd.org 2001/01/21 19:05:40
2536 [atomicio.c automicio.h auth-chall.c auth-krb4.c auth-options.c
2537 auth-options.h auth-passwd.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c
2538 auth.c auth.h auth1.c auth2-chall.c auth2.c authfd.c authfile.c
2539 bufaux.c bufaux.h buffer.c canahost.c canahost.h channels.c
2540 cipher.c cli.c clientloop.c clientloop.h compat.c compress.c
2541 deattack.c dh.c dispatch.c groupaccess.c hmac.c hostfile.c kex.c
2542 key.c key.h log-client.c log-server.c log.c log.h login.c login.h
2543 match.c misc.c misc.h nchan.c packet.c pty.c radix.h readconf.c
2544 readpass.c readpass.h rsa.c scp.c servconf.c serverloop.c serverloop.h
2545 session.c sftp-server.c ssh-add.c ssh-agent.c ssh-dss.c ssh-keygen.c
61e96248 2546 ssh-keyscan.c ssh-rsa.c ssh.c ssh.h sshconnect.c sshconnect.h
42f11eb2 2547 sshconnect1.c sshconnect2.c sshd.c tildexpand.c tildexpand.h
2548 ttysmodes.c uidswap.c xmalloc.c]
61e96248 2549 split ssh.h and try to cleanup the #include mess. remove unnecessary
42f11eb2 2550 #includes. rename util.[ch] -> misc.[ch]
2551 - (bal) renamed 'PIDDIR' to '_PATH_SSH_PIDDIR' to match OpenBSD tree
61e96248 2552 - (bal) Moved #ifdef KRB4 in auth-krb4.c above the #include to resolve
42f11eb2 2553 conflict when compiling for non-kerb install
2554 - (bal) removed the #ifdef SKEY in auth1.c to match Markus' changes
2555 on 1/19.
2556
6005a40c 255720010120
2558 - (bal) OpenBSD Resync
2559 - markus@cvs.openbsd.org 2001/01/19 12:45:26
2560 [ssh-chall.c servconf.c servconf.h ssh.h sshd.c]
2561 only auth-chall.c needs #ifdef SKEY
47af6577 2562 - (bal) Slight auth2-pam.c clean up.
2563 - (bal) Includes a fake-regexp.h to be only used if regcomp() is found,
2564 but no 'regexp.h' found (SCO OpenServer 3 lacks the header).
6005a40c 2565
922e6493 256620010119
2567 - (djm) Update versions in RPM specfiles
59c97189 2568 - (bal) OpenBSD Resync
2569 - markus@cvs.openbsd.org 2001/01/18 16:20:21
2570 [log-client.c log-server.c log.c readconf.c servconf.c ssh.1 ssh.h
2571 sshd.8 sshd.c]
61e96248 2572 log() is at pri=LOG_INFO, since LOG_NOTICE goes to /dev/console on many
59c97189 2573 systems
2574 - markus@cvs.openbsd.org 2001/01/18 16:59:59
2575 [auth-passwd.c auth.c auth.h auth1.c auth2.c serverloop.c session.c
2576 session.h sshconnect1.c]
2577 1) removes fake skey from sshd, since this will be much
2578 harder with /usr/libexec/auth/login_XXX
2579 2) share/unify code used in ssh-1 and ssh-2 authentication (server side)
2580 3) make addition of BSD_AUTH and other challenge reponse methods
2581 easier.
2582 - markus@cvs.openbsd.org 2001/01/18 17:12:43
2583 [auth-chall.c auth2-chall.c]
2584 rename *-skey.c *-chall.c since the files are not skey specific
04fc7a67 2585 - (djm) Merge patch from Tim Waugh (via Nalin Dahyabhai <nalin@redhat.com>)
2586 to fix NULL pointer deref and fake authloop breakage in PAM code.
f4ebf0e8 2587 - (bal) Updated contrib/cygwin/ by Corinna Vinschen <vinschen@redhat.com>
3c418020 2588 - (bal) Minor cygwin patch to auth1.c. Suggested by djm.
61e96248 2589
b5c334cc 259020010118
2591 - (bal) Super Sized OpenBSD Resync
2592 - markus@cvs.openbsd.org 2001/01/11 22:14:20 GMT 2001 by markus
2593 [sshd.c]
2594 maxfd+1
2595 - markus@cvs.openbsd.org 2001/01/13 17:59:18
2596 [ssh-keygen.1]
2597 small ssh-keygen manpage cleanup; stevesk@pobox.com
2598 - markus@cvs.openbsd.org 2001/01/13 18:03:07
2599 [scp.c ssh-keygen.c sshd.c]
2600 getopt() returns -1 not EOF; stevesk@pobox.com
2601 - markus@cvs.openbsd.org 2001/01/13 18:06:54
2602 [ssh-keyscan.c]
2603 use SSH_DEFAULT_PORT; from stevesk@pobox.com
2604 - markus@cvs.openbsd.org 2001/01/13 18:12:47
2605 [ssh-keyscan.c]
2606 free() -> xfree(); fix memory leak; from stevesk@pobox.com
2607 - markus@cvs.openbsd.org 2001/01/13 18:14:13
2608 [ssh-add.c]
2609 typo, from stevesk@sweden.hp.com
2610 - markus@cvs.openbsd.org 2001/01/13 18:32:50
61e96248 2611 [packet.c session.c ssh.c sshconnect.c sshd.c]
b5c334cc 2612 split out keepalive from packet_interactive (from dale@accentre.com)
2613 set IPTOS_LOWDELAY TCP_NODELAY IPTOS_THROUGHPUT for ssh2, too.
2614 - markus@cvs.openbsd.org 2001/01/13 18:36:45
2615 [packet.c packet.h]
2616 reorder, typo
2617 - markus@cvs.openbsd.org 2001/01/13 18:38:00
2618 [auth-options.c]
2619 fix comment
2620 - markus@cvs.openbsd.org 2001/01/13 18:43:31
2621 [session.c]
2622 Wall
61e96248 2623 - markus@cvs.openbsd.org 2001/01/13 19:14:08
b5c334cc 2624 [clientloop.h clientloop.c ssh.c]
2625 move callback to headerfile
2626 - markus@cvs.openbsd.org 2001/01/15 21:40:10
2627 [ssh.c]
2628 use log() instead of stderr
2629 - markus@cvs.openbsd.org 2001/01/15 21:43:51
2630 [dh.c]
2631 use error() not stderr!
2632 - markus@cvs.openbsd.org 2001/01/15 21:45:29
2633 [sftp-server.c]
2634 rename must fail if newpath exists, debug off by default
2635 - markus@cvs.openbsd.org 2001/01/15 21:46:38
2636 [sftp-server.c]
2637 readable long listing for sftp-server, ok deraadt@
2638 - markus@cvs.openbsd.org 2001/01/16 19:20:06
2639 [key.c ssh-rsa.c]
61e96248 2640 make "ssh-rsa" key format for ssh2 confirm to the ietf-drafts; from
2641 galb@vandyke.com. note that you have to delete older ssh2-rsa keys,
2642 since they are in the wrong format, too. they must be removed from
b5c334cc 2643 .ssh/authorized_keys2 and .ssh/known_hosts2, etc.
61e96248 2644 (cd; grep -v ssh-rsa .ssh/authorized_keys2 > TMP && mv TMP
2645 .ssh/authorized_keys2) additionally, we now check that
b5c334cc 2646 BN_num_bits(rsa->n) >= 768.
2647 - markus@cvs.openbsd.org 2001/01/16 20:54:27
2648 [sftp-server.c]
2649 remove some statics. simpler handles; idea from nisse@lysator.liu.se
2650 - deraadt@cvs.openbsd.org 2001/01/16 23:58:08
2651 [bufaux.c radix.c sshconnect.h sshconnect1.c]
2652 indent
2653 - (bal) Added bsd-strmode.[ch] since some non-OpenBSD platforms may
2654 be missing such feature.
2655
61e96248 2656
52ce34a2 265720010117
2658 - (djm) Only write random seed file at exit
717057b6 2659 - (djm) Make PAM support optional, enable with --with-pam
61e96248 2660 - (djm) Try to use libcrypt on Linux, but link it after OpenSSL (which
717057b6 2661 provides a crypt() of its own)
2662 - (djm) Avoid a warning in bsd-bindresvport.c
2663 - (djm) Try to avoid adding -I/usr/include to CPPFLAGS during SSL tests. This
61e96248 2664 can cause weird segfaults errors on Solaris
8694a1ce 2665 - (djm) Avoid warning in PAM code by making read_passphrase arguments const
d748039d 2666 - (djm) Add --with-pam to RPM spec files
52ce34a2 2667
2fd3c144 266820010115
2669 - (bal) sftp-server.c change to use chmod() if fchmod() does not exist.
89c7e31c 2670 - (bal) utimes() support via utime() interface on machine that lack utimes().
2fd3c144 2671
63b68889 267220010114
2673 - (stevesk) initial work for OpenBSD "support supplementary group in
2674 {Allow,Deny}Groups" patch:
2675 - import getgrouplist.c from OpenBSD (bsd-getgrouplist.c)
2676 - add bsd-getgrouplist.h
2677 - new files groupaccess.[ch]
2678 - build but don't use yet (need to merge auth.c changes)
c6a69271 2679 - (stevesk) complete:
2680 - markus@cvs.openbsd.org 2001/01/13 11:56:48
2681 [auth.c sshd.8]
2682 support supplementary group in {Allow,Deny}Groups
2683 from stevesk@pobox.com
61e96248 2684
f546c780 268520010112
2686 - (bal) OpenBSD Sync
2687 - markus@cvs.openbsd.org 2001/01/10 22:56:22
2688 [bufaux.h bufaux.c sftp-server.c sftp.h getput.h]
2689 cleanup sftp-server implementation:
547519f0 2690 add buffer_get_int64, buffer_put_int64, GET_64BIT, PUT_64BIT
2691 parse SSH2_FILEXFER_ATTR_EXTENDED
2692 send SSH2_FX_EOF if readdir returns no more entries
2693 reply to SSH2_FXP_EXTENDED message
2694 use #defines from the draft
2695 move #definations to sftp.h
f546c780 2696 more info:
61e96248 2697 http://www.ietf.org/internet-drafts/draft-ietf-secsh-filexfer-00.txt
f546c780 2698 - markus@cvs.openbsd.org 2001/01/10 19:43:20
2699 [sshd.c]
2700 XXX - generate_empheral_server_key() is not safe against races,
61e96248 2701 because it calls log()
f546c780 2702 - markus@cvs.openbsd.org 2001/01/09 21:19:50
2703 [packet.c]
2704 allow TCP_NDELAY for ipv6; from netbsd via itojun@
2705
9548d6c8 270620010110
2707 - (djm) SNI/Reliant Unix needs USE_PIPES and $DISPLAY hack. Report from
2708 Bladt Norbert <Norbert.Bladt@adi.ch>
2709
af972861 271020010109
2711 - (bal) Resync CVS ID of cli.c
4b80e97b 2712 - (stevesk) auth1.c: free should be after WITH_AIXAUTHENTICATE
2713 code.
eea39c02 2714 - (bal) OpenBSD Sync
2715 - markus@cvs.openbsd.org 2001/01/08 22:29:05
2716 [auth2.c compat.c compat.h servconf.c servconf.h sshd.8
2717 sshd_config version.h]
2718 implement option 'Banner /etc/issue.net' for ssh2, move version to
2719 2.3.1 (needed for bugcompat detection, 2.3.0 would fail if Banner
2720 is enabled).
2721 - markus@cvs.openbsd.org 2001/01/08 22:03:23
2722 [channels.c ssh-keyscan.c]
2723 O_NDELAY -> O_NONBLOCK; thanks stevesk@pobox.com
2724 - markus@cvs.openbsd.org 2001/01/08 21:55:41
2725 [sshconnect1.c]
2726 more cleanups and fixes from stevesk@pobox.com:
2727 1) try_agent_authentication() for loop will overwrite key just
2728 allocated with key_new(); don't alloc
2729 2) call ssh_close_authentication_connection() before exit
2730 try_agent_authentication()
2731 3) free mem on bad passphrase in try_rsa_authentication()
2732 - markus@cvs.openbsd.org 2001/01/08 21:48:17
2733 [kex.c]
2734 missing free; thanks stevesk@pobox.com
f1c4659d 2735 - (bal) Detect if clock_t structure exists, if not define it.
2736 - (bal) Detect if O_NONBLOCK exists, if not define it.
2737 - (bal) removed news4-posix.h (now empty)
2738 - (bal) changed bsd-bindresvport.c and bsd-rresvport.c to use 'socklen_t'
2739 instead of 'int'
adc83ebf 2740 - (stevesk) sshd_config: sync
4f771a33 2741 - (stevesk) defines.h: remove spurious ``;''
af972861 2742
bbcf899f 274320010108
2744 - (bal) Fixed another typo in cli.c
2745 - (bal) OpenBSD Sync
2746 - markus@cvs.openbsd.org 2001/01/07 21:26:55
2747 [cli.c]
2748 typo
2749 - markus@cvs.openbsd.org 2001/01/07 21:26:55
2750 [cli.c]
2751 missing free, stevesk@pobox.com
2752 - markus@cvs.openbsd.org 2001/01/07 19:06:25
2753 [auth1.c]
2754 missing free, stevesk@pobox.com
2755 - markus@cvs.openbsd.org 2001/01/07 11:28:04
2756 [log-client.c log-server.c log.c readconf.c servconf.c ssh.1
2757 ssh.h sshd.8 sshd.c]
2758 rename SYSLOG_LEVEL_INFO->SYSLOG_LEVEL_NOTICE
2759 syslog priority changes:
2760 fatal() LOG_ERR -> LOG_CRIT
2761 log() LOG_INFO -> LOG_NOTICE
b8c37305 2762 - Updated TODO
bbcf899f 2763
9616313f 276420010107
2765 - (bal) OpenBSD Sync
2766 - markus@cvs.openbsd.org 2001/01/06 11:23:27
2767 [ssh-rsa.c]
2768 remove unused
2769 - itojun@cvs.openbsd.org 2001/01/05 08:23:29
2770 [ssh-keyscan.1]
2771 missing .El
2772 - markus@cvs.openbsd.org 2001/01/04 22:41:03
2773 [session.c sshconnect.c]
2774 consistent use of _PATH_BSHELL; from stevesk@pobox.com
2775 - djm@cvs.openbsd.org 2001/01/04 22:35:32
2776 [ssh.1 sshd.8]
2777 Mention AES as available SSH2 Cipher; ok markus
2778 - markus@cvs.openbsd.org 2001/01/04 22:25:58
2779 [sshd.c]
2780 sync usage()/man with defaults; from stevesk@pobox.com
2781 - markus@cvs.openbsd.org 2001/01/04 22:21:26
2782 [sshconnect2.c]
2783 handle SSH2_MSG_USERAUTH_BANNER; fixes bug when connecting to a server
2784 that prints a banner (e.g. /etc/issue.net)
61e96248 2785
1877dc0c 278620010105
2787 - (bal) contrib/caldera/ provided by Tim Rice <tim@multitalents.net>
5a64a938 2788 - (bal) bsd-getcwd.c and bsd-setenv.c changed from bcopy() to memmove()
1877dc0c 2789
488c06c8 279020010104
2791 - (djm) Fix memory leak on systems with BROKEN_GETADDRINFO. Based on
2792 work by Chris Vaughan <vaughan99@yahoo.com>
2793
7c49df64 279420010103
2795 - (bal) fixed up sshconnect.c so it was closer inline with the OpenBSD
2796 tree (mainly positioning)
2797 - (bal) OpenSSH CVS Update
2798 - markus@cvs.openbsd.org 2001/01/02 20:41:02
2799 [packet.c]
2800 log remote ip on disconnect; PR 1600 from jcs@rt.fm
2801 - markus@cvs.openbsd.org 2001/01/02 20:50:56
2802 [sshconnect.c]
61e96248 2803 strict_host_key_checking for host_status != HOST_CHANGED &&
7c49df64 2804 ip_status == HOST_CHANGED
61e96248 2805 - (bal) authfile.c: Synced CVS ID tag
2c523de9 2806 - (bal) UnixWare 2.0 fixes by Tim Rice <tim@multitalents.net>
2807 - (bal) Disable sftp-server if no 64bit int support exists. Based on
2808 patch by Tim Rice <tim@multitalents.net>
2809 - (bal) Makefile.in changes to uninstall: target to remove sftp-server
2810 and sftp-server.8 manpage.
7c49df64 2811
a421e945 281220010102
2813 - (bal) OpenBSD CVS Update
2814 - markus@cvs.openbsd.org 2001/01/01 14:52:49
2815 [scp.c]
2816 use shared fatal(); from stevesk@pobox.com
2817
0efc80a7 281820001231
2819 - (bal) Reverted out of MAXHOSTNAMELEN. This should be set per OS.
2820 for multiple reasons.
b1335fdf 2821 - (bal) Reverted out of a partial NeXT patch.
0efc80a7 2822
efcae5b1 282320001230
2824 - (bal) OpenBSD CVS Update
2825 - markus@cvs.openbsd.org 2000/12/28 18:58:30
2826 [ssh-keygen.c]
2827 enable 'ssh-keygen -l -f ~/.ssh/{authorized_keys,known_hosts}{,2}
b148018f 2828 - markus@cvs.openbsd.org 2000/12/29 22:19:13
2829 [channels.c]
2830 missing xfree; from vaughan99@yahoo.com
efcae5b1 2831 - (bal) Resynced CVS ID with OpenBSD for channel.c and uidswap.c
03a14cc9 2832 - (bal) if no MAXHOSTNAMELEN is defined. Default to 64 character defination.
34665bf7 2833 Suggested by Christian Kurz <shorty@debian.org>
cb6dabf4 2834 - (bal) Add in '.c.o' section to Makefile.in to address make programs that
61e96248 2835 don't honor CPPFLAGS by default. Suggested by Lutz Jaenicke
cb6dabf4 2836 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
0dd78cd8 2837
283820001229
61e96248 2839 - (bal) Fixed spelling of 'authorized_keys' in ssh-copy-id.1 by Christian
34665bf7 2840 Kurz <shorty@debian.org>
8abcdba4 2841 - (bal) OpenBSD CVS Update
2842 - markus@cvs.openbsd.org 2000/12/28 14:25:51
2843 [auth.h auth2.c]
2844 count authentication failures only
2845 - markus@cvs.openbsd.org 2000/12/28 14:25:03
2846 [sshconnect.c]
2847 fingerprint for MITM attacks, too.
2848 - markus@cvs.openbsd.org 2000/12/28 12:03:57
2849 [sshd.8 sshd.c]
2850 document -D
2851 - markus@cvs.openbsd.org 2000/12/27 14:19:21
2852 [serverloop.c]
2853 less chatty
2854 - markus@cvs.openbsd.org 2000/12/27 12:34
2855 [auth1.c sshconnect2.c sshd.c]
2856 typo
2857 - markus@cvs.openbsd.org 2000/12/27 12:30:19
2858 [readconf.c readconf.h ssh.1 sshconnect.c]
2859 new option: HostKeyAlias: allow the user to record the host key
2860 under a different name. This is useful for ssh tunneling over
2861 forwarded connections or if you run multiple sshd's on different
2862 ports on the same machine.
2863 - markus@cvs.openbsd.org 2000/12/27 11:51:53
2864 [ssh.1 ssh.c]
2865 multiple -t force pty allocation, document ORIGINAL_COMMAND
2866 - markus@cvs.openbsd.org 2000/12/27 11:41:31
2867 [sshd.8]
2868 update for ssh-2
c52c7082 2869 - (stevesk) compress.[ch] sync with openbsd; missed in prototype
2870 fix merge.
0dd78cd8 2871
8f523d67 287220001228
2873 - (bal) Patch to add libutil.h to loginrec.c only if the platform has
2874 libutil.h. Suggested by Pekka Savola <pekka@netcore.fi>
9fb76616 2875 - (djm) Update to new x11-askpass in RPM spec
0dd78cd8 2876 - (bal) SCO patch to not include <sys/queue.h> since it's unrelated
2877 header. Patch by Tim Rice <tim@multitalents.net>
2878 - Updated TODO w/ known HP/UX issue
2879 - (bal) removed extra <netdb.h> noticed by Kevin Steves and removed the
2880 bad reference to 'NeXT including it else were' on the #ifdef version.
8f523d67 2881
b03bd394 288220001227
61e96248 2883 - (bal) Typo in configure.in: entut?ent should be endut?ent. Suggested by
b03bd394 2884 Takumi Yamane <yamtak@b-session.com>
2885 - (bal) Checks for getrlimit(), sysconf(), and setdtablesize(). Patch
8f523d67 2886 by Corinna Vinschen <vinschen@redhat.com>
2887 - (djm) Fix catman-do target for non-bash
61e96248 2888 - (bal) Typo in configure.in: entut?ent should be endut?ent. Suggested by
8f523d67 2889 Takumi Yamane <yamtak@b-session.com>
2890 - (bal) Checks for getrlimit(), sysconf(), and setdtablesize(). Patch
b03bd394 2891 by Corinna Vinschen <vinschen@redhat.com>
13991f8e 2892 - (djm) Fix catman-do target for non-bash
61e96248 2893 - (bal) Fixed NeXT's lack of CPPFLAGS honoring.
2894 - (bal) ssh-keyscan.c: NeXT (and older BSDs) don't support getrlimit() w/
f318b98b 2895 'RLIMIT_NOFILE'
61e96248 2896 - (djm) Remove *.Ylonen files. They are no longer in the OpenBSD tree,
2897 the info in COPYING.Ylonen has been moved to the start of each
3bdf55b1 2898 SSH1-derived file and README.Ylonen is well out of date.
b03bd394 2899
8d88011e 290020001223
2901 - (bal) Fixed Makefile.in to support recompile of all ssh and sshd objects
2902 if a change to config.h has occurred. Suggested by Gert Doering
2903 <gert@greenie.muc.de>
2904 - (bal) OpenBSD CVS Update:
2905 - markus@cvs.openbsd.org 2000/12/22 16:49:40
2906 [ssh-keygen.c]
2907 fix ssh-keygen -x -t type > file; from Roumen.Petrov@skalasoft.com
2908
1e3b8b07 290920001222
2910 - Updated RCSID for pty.c
2911 - (bal) OpenBSD CVS Updates:
2912 - markus@cvs.openbsd.org 2000/12/21 15:10:16
2913 [auth-rh-rsa.c hostfile.c hostfile.h sshconnect.c]
2914 print keyfile:line for changed hostkeys, for deraadt@, ok deraadt@
2915 - markus@cvs.openbsd.org 2000/12/20 19:26:56
2916 [authfile.c]
2917 allow ssh -i userkey for root
2918 - markus@cvs.openbsd.org 2000/12/20 19:37:21
2919 [authfd.c authfd.h kex.c sshconnect2.c sshd.c uidswap.c uidswap.h]
2920 fix prototypes; from stevesk@pobox.com
2921 - markus@cvs.openbsd.org 2000/12/20 19:32:08
2922 [sshd.c]
2923 init pointer to NULL; report from Jan.Ivan@cern.ch
2924 - markus@cvs.openbsd.org 2000/12/19 23:17:54
2925 [auth-krb4.c auth-options.c auth-options.h auth-rhosts.c auth-rsa.c
2926 auth1.c auth2-skey.c auth2.c authfd.c authfd.h authfile.c bufaux.c
2927 bufaux.h buffer.c canohost.c channels.c clientloop.c compress.c
2928 crc32.c deattack.c getput.h hmac.c hmac.h hostfile.c kex.c kex.h
2929 key.c key.h log.c login.c match.c match.h mpaux.c mpaux.h packet.c
2930 packet.h radix.c readconf.c rsa.c scp.c servconf.c servconf.h
2931 serverloop.c session.c sftp-server.c ssh-agent.c ssh-dss.c ssh-dss.h
2932 ssh-keygen.c ssh-keyscan.c ssh-rsa.c ssh-rsa.h ssh.c ssh.h uuencode.c
2933 uuencode.h sshconnect1.c sshconnect2.c sshd.c tildexpand.c]
2934 replace 'unsigned bla' with 'u_bla' everywhere. also replace 'char
2935 unsigned' with u_char.
2936
67b0facb 293720001221
2938 - (stevesk) OpenBSD CVS updates:
2939 - markus@cvs.openbsd.org 2000/12/19 15:43:45
2940 [authfile.c channels.c sftp-server.c ssh-agent.c]
2941 remove() -> unlink() for consistency
2942 - markus@cvs.openbsd.org 2000/12/19 15:48:09
2943 [ssh-keyscan.c]
2944 replace <ssl/x.h> with <openssl/x.h>
2945 - markus@cvs.openbsd.org 2000/12/17 02:33:40
2946 [uidswap.c]
2947 typo; from wsanchez@apple.com
61e96248 2948
adeebd37 294920001220
61e96248 2950 - (djm) Workaround PAM inconsistencies between Solaris derived PAM code
adeebd37 2951 and Linux-PAM. Based on report and fix from Andrew Morgan
2952 <morgan@transmeta.com>
2953
f072c47a 295420001218
2955 - (stevesk) rsa.c: entropy.h not needed.
0c2fb82f 2956 - (bal) split CFLAGS into CFLAGS and CPPFLAGS in configure.in and Makefile.
2957 Suggested by Wilfredo Sanchez <wsanchez@apple.com>
f072c47a 2958
731c1541 295920001216
2960 - (stevesk) OpenBSD CVS updates:
2961 - markus@cvs.openbsd.org 2000/12/16 02:53:57
2962 [scp.c]
2963 allow + in usernames; request from Florian.Weimer@RUS.Uni-Stuttgart.DE
2964 - markus@cvs.openbsd.org 2000/12/16 02:39:57
2965 [scp.c]
2966 unused; from stevesk@pobox.com
2967
227e8e86 296820001215
9853409f 2969 - (stevesk) Old OpenBSD patch wasn't completely applied:
2970 - markus@cvs.openbsd.org 2000/01/24 22:11:20
2971 [scp.c]
2972 allow '.' in usernames; from jedgar@fxp.org
227e8e86 2973 - (stevesk) OpenBSD CVS updates:
2974 - markus@cvs.openbsd.org 2000/12/13 16:26:53
2975 [ssh-keyscan.c]
2976 fatal already adds \n; from stevesk@pobox.com
2977 - markus@cvs.openbsd.org 2000/12/13 16:25:44
2978 [ssh-agent.c]
2979 remove redundant spaces; from stevesk@pobox.com
2980 - ho@cvs.openbsd.org 2000/12/12 15:50:21
2981 [pty.c]
2982 When failing to set tty owner and mode on a read-only filesystem, don't
2983 abort if the tty already has correct owner and reasonably sane modes.
2984 Example; permit 'root' to login to a firewall with read-only root fs.
2985 (markus@ ok)
2986 - deraadt@cvs.openbsd.org 2000/12/13 06:36:05
2987 [pty.c]
2988 KNF
6ffc9c88 2989 - markus@cvs.openbsd.org 2000/12/12 14:45:21
2990 [sshd.c]
2991 source port < 1024 is no longer required for rhosts-rsa since it
2992 adds no additional security.
2993 - markus@cvs.openbsd.org 2000/12/12 16:11:49
2994 [ssh.1 ssh.c]
2995 rhosts-rsa is no longer automagically disabled if ssh is not privileged.
2996 UsePrivilegedPort=no disables rhosts-rsa _only_ for old servers.
2997 these changes should not change the visible default behaviour of the ssh client.
71c0d06a 2998 - deraadt@cvs.openbsd.org 2000/12/11 10:27:33
2999 [scp.c]
3000 when copying 0-sized files, do not re-print ETA time at completion
3e1caa83 3001 - provos@cvs.openbsd.org 2000/12/15 10:30:15
3002 [kex.c kex.h sshconnect2.c sshd.c]
3003 compute diffie-hellman in parallel between server and client. okay markus@
227e8e86 3004
6c935fbd 300520001213
3006 - (djm) Make sure we reset the SIGPIPE disposition after we fork. Report
3007 from Andreas M. Kirchwitz <amk@krell.zikzak.de>
227e8e86 3008 - (stevesk) OpenBSD CVS update:
1fe6a48f 3009 - markus@cvs.openbsd.org 2000/12/12 15:30:02
3010 [ssh-keyscan.c ssh.c sshd.c]
61e96248 3011 consistently use __progname; from stevesk@pobox.com
6c935fbd 3012
367d1840 301320001211
3014 - (bal) Applied patch to include ssh-keyscan into Redhat's package, and
3015 patch to install ssh-keyscan manpage. Patch by Pekka Savola
3016 <pekka@netcore.fi>
e3a70753 3017 - (bal) OpenbSD CVS update
3018 - markus@cvs.openbsd.org 2000/12/10 17:01:53
3019 [sshconnect1.c]
3020 always request new challenge for skey/tis-auth, fixes interop with
3021 other implementations; report from roth@feep.net
367d1840 3022
6b523bae 302320001210
3024 - (bal) OpenBSD CVS updates
61e96248 3025 - markus@cvs.openbsd.org 2000/12/09 13:41:51
6b523bae 3026 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
3027 undo rijndael changes
61e96248 3028 - markus@cvs.openbsd.org 2000/12/09 13:48:31
6b523bae 3029 [rijndael.c]
3030 fix byte order bug w/o introducing new implementation
61e96248 3031 - markus@cvs.openbsd.org 2000/12/09 14:08:27
6b523bae 3032 [sftp-server.c]
3033 "" -> "." for realpath; from vinschen@redhat.com
61e96248 3034 - markus@cvs.openbsd.org 2000/12/09 14:06:54
6b523bae 3035 [ssh-agent.c]
3036 extern int optind; from stevesk@sweden.hp.com
13af0aa2 3037 - provos@cvs.openbsd.org 2000/12/09 23:51:11
3038 [compat.c]
3039 remove unnecessary '\n'
6b523bae 3040
ce9c0b75 304120001209
6b523bae 3042 - (bal) OpenBSD CVS updates:
61e96248 3043 - djm@cvs.openbsd.org 2000/12/07 4:24:59
ce9c0b75 3044 [ssh.1]
3045 Typo fix from Wilfredo Sanchez <wsanchez@apple.com>; ok theo
3046
f72fc97f 304720001207
6b523bae 3048 - (bal) OpenBSD CVS updates:
61e96248 3049 - markus@cvs.openbsd.org 2000/12/06 22:58:14
f72fc97f 3050 [compat.c compat.h packet.c]
3051 disable debug messages for ssh.com/f-secure 2.0.1x, 2.1.0
dfe89252 3052 - markus@cvs.openbsd.org 2000/12/06 23:10:39
3053 [rijndael.c]
3054 unexpand(1)
61e96248 3055 - markus@cvs.openbsd.org 2000/12/06 23:05:43
dfe89252 3056 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
3057 new rijndael implementation. fixes endian bugs
f72fc97f 3058
97fb6912 305920001206
6b523bae 3060 - (bal) OpenBSD CVS updates:
97fb6912 3061 - markus@cvs.openbsd.org 2000/12/05 20:34:09
3062 [channels.c channels.h clientloop.c serverloop.c]
3063 async connects for -R/-L; ok deraadt@
3064 - todd@cvs.openssh.org 2000/12/05 16:47:28
3065 [sshd.c]
3066 tweak comment to reflect real location of pid file; ok provos@
bf5f69f7 3067 - (stevesk) Import <sys/queue.h> from OpenBSD for systems that don't
3068 have it (used in ssh-keyscan).
227e8e86 3069 - (stevesk) OpenBSD CVS update:
f20255cb 3070 - markus@cvs.openbsd.org 2000/12/06 19:57:48
3071 [ssh-keyscan.c]
3072 err(3) -> internal error(), from stevesk@sweden.hp.com
97fb6912 3073
f6fdbddf 307420001205
6b523bae 3075 - (bal) OpenBSD CVS updates:
f6fdbddf 3076 - markus@cvs.openbsd.org 2000/12/04 19:24:02
3077 [ssh-keyscan.c ssh-keyscan.1]
3078 David Maziere's ssh-keyscan, ok niels@
3079 - (bal) Updated Makefile.in to include ssh-keyscan that was just added
3080 to the recent OpenBSD source tree.
835d2104 3081 - (stevesk) fix typos in contrib/hpux/README
f6fdbddf 3082
cbc5abf9 308320001204
3084 - (bal) More C functions defined in NeXT that are unaccessable without
61e96248 3085 defining -POSIX.
3086 - (bal) OpenBSD CVS updates:
3087 - markus@cvs.openbsd.org 2000/12/03 11:29:04
cbc5abf9 3088 [compat.c]
3089 remove fallback to SSH_BUG_HMAC now that the drafts are updated
3090 - markus@cvs.openbsd.org 2000/12/03 11:27:55
3091 [compat.c]
61e96248 3092 correctly match "2.1.0.pl2 SSH" etc; from
97fb6912 3093 pekkas@netcore.fi/bugzilla.redhat
cbc5abf9 3094 - markus@cvs.openbsd.org 2000/12/03 11:15:03
3095 [auth2.c compat.c compat.h sshconnect2.c]
3096 support f-secure/ssh.com 2.0.12; ok niels@
3097
0b6fbf03 309820001203
cbc5abf9 3099 - (bal) OpenBSD CVS updates:
0b6fbf03 3100 - markus@cvs.openbsd.org 2000/11/30 22:54:31
3101 [channels.c]
61e96248 3102 debug->warn if tried to do -R style fwd w/o client requesting this;
0b6fbf03 3103 ok neils@
3104 - markus@cvs.openbsd.org 2000/11/29 20:39:17
3105 [cipher.c]
3106 des_cbc_encrypt -> des_ncbc_encrypt since it already updates the IV
3107 - markus@cvs.openbsd.org 2000/11/30 18:33:05
3108 [ssh-agent.c]
3109 agents must not dump core, ok niels@
61e96248 3110 - markus@cvs.openbsd.org 2000/11/30 07:04:02
0b6fbf03 3111 [ssh.1]
3112 T is for both protocols
3113 - markus@cvs.openbsd.org 2000/12/01 00:00:51
3114 [ssh.1]
3115 typo; from green@FreeBSD.org
3116 - markus@cvs.openbsd.org 2000/11/30 07:02:35
3117 [ssh.c]
3118 check -T before isatty()
3119 - provos@cvs.openbsd.org 2000/11/29 13:51:27
3120 [sshconnect.c]
61e96248 3121 show IP address and hostname when new key is encountered. okay markus@
0b6fbf03 3122 - markus@cvs.openbsd.org 2000/11/30 22:53:35
3123 [sshconnect.c]
3124 disable agent/x11/port fwding if hostkey has changed; ok niels@
3125 - marksu@cvs.openbsd.org 2000/11/29 21:11:59
3126 [sshd.c]
3127 sshd -D, startup w/o deamon(), for monitoring scripts or inittab;
3128 from handler@sub-rosa.com and eric@urbanrange.com; ok niels@
8c9fe09e 3129 - (djm) Added patch from Nalin Dahyabhai <nalin@redhat.com> to enable
3130 PAM authentication using KbdInteractive.
3131 - (djm) Added another TODO
0b6fbf03 3132
90f4078a 313320001202
3134 - (bal) Backed out of part of Alain St-Denis' loginrec.c patch.
61e96248 3135 - (bal) Irix need some sort of mansubdir, patch by Michael Stone
90f4078a 3136 <mstone@cs.loyola.edu>
3137
dcef6523 313820001129
7062c40f 3139 - (djm) Back out all the serverloop.c hacks. sshd will now hang again
3140 if there are background children with open fds.
c193d002 3141 - (djm) bsd-rresvport.c bzero -> memset
61e96248 3142 - (djm) Don't fail in defines.h on absence of 64 bit types (we will
c193d002 3143 still fail during compilation of sftp-server).
3144 - (djm) Fail if ar is not found during configure
c523303b 3145 - (djm) OpenBSD CVS updates:
3146 - provos@cvs.openbsd.org 2000/11/22 08:38:31
3147 [sshd.8]
3148 talk about /etc/primes, okay markus@
3149 - markus@cvs.openbsd.org 2000/11/23 14:03:48
3150 [ssh.c sshconnect1.c sshconnect2.c]
3151 complain about invalid ciphers for ssh1/ssh2, fall back to reasonable
3152 defaults
3153 - markus@cvs.openbsd.org 2000/11/25 09:42:53
3154 [sshconnect1.c]
3155 reorder check for illegal ciphers, bugreport from espie@
3156 - markus@cvs.openbsd.org 2000/11/25 10:19:34
3157 [ssh-keygen.c ssh.h]
3158 print keytype when generating a key.
3159 reasonable defaults for RSA1/RSA/DSA keys.
b3ec54b4 3160 - (djm) Patch from Pekka Savola <Pekka.Savola@netcore.fi> to include a few
3161 more manpage paths in fixpaths calls
3162 - (djm) Also add xauth path at Pekka's suggestion.
57ce3f00 3163 - (djm) Add Redhat RPM patch for AUTHPRIV SyslogFacility
dcef6523 3164
e879a080 316520001125
3166 - (djm) Give up privs when reading seed file
3167
d343d900 316820001123
3169 - (bal) Merge OpenBSD changes:
3170 - markus@cvs.openbsd.org 2000/11/15 22:31:36
3171 [auth-options.c]
61e96248 3172 case insensitive key options; from stevesk@sweeden.hp.com
d343d900 3173 - markus@cvs.openbsd.org 2000/11/16 17:55:43
3174 [dh.c]
3175 do not use perror() in sshd, after child is forked()
3176 - markus@cvs.openbsd.org 2000/11/14 23:42:40
3177 [auth-rsa.c]
3178 parse option only if key matches; fix some confusing seen by the client
3179 - markus@cvs.openbsd.org 2000/11/14 23:44:19
3180 [session.c]
3181 check no_agent_forward_flag for ssh-2, too
3182 - markus@cvs.openbsd.org 2000/11/15
3183 [ssh-agent.1]
3184 reorder SYNOPSIS; typo, use .It
3185 - markus@cvs.openbsd.org 2000/11/14 23:48:55
3186 [ssh-agent.c]
3187 do not reorder keys if a key is removed
3188 - markus@cvs.openbsd.org 2000/11/15 19:58:08
3189 [ssh.c]
61e96248 3190 just ignore non existing user keys
d343d900 3191 - millert@cvs.openbsd.org 200/11/15 20:24:43
3192 [ssh-keygen.c]
3193 Add missing \n at end of error message.
3194
0b49a754 319520001122
3196 - (bal) Minor patch to ensure platforms lacking IRIX job limit supports
3197 are compilable.
3198 - (bal) Updated TODO as of 11/18/2000 with known things to resolve.
3199
fab2e5d3 320020001117
3201 - (bal) Changed from 'primes' to 'primes.out' for consistancy sake. It
3202 has no affect the output. Patch by Corinna Vinschen <vinschen@redhat.com>
61e96248 3203 - (stevesk) Reworked progname support.
260d427b 3204 - (bal) Misplaced #include "includes.h" in bsd-setproctitle.c. Patch by
3205 Shinichi Maruyama <marya@st.jip.co.jp>
fab2e5d3 3206
c2207f11 320720001116
3208 - (bal) Added in MAXSYMLINK test in bsd-realpath.c. Required for some SCO
3209 releases.
3210 - (bal) Make builds work outside of source tree. Patch by Mark D. Roth
3211 <roth@feep.net>
3212
3d398e04 321320001113
61e96248 3214 - (djm) Add pointer to http://www.imasy.or.jp/~gotoh/connect.c to
3d398e04 3215 contrib/README
fa08c86b 3216 - (djm) Merge OpenBSD changes:
3217 - markus@cvs.openbsd.org 2000/11/06 16:04:56
3218 [channels.c channels.h clientloop.c nchan.c serverloop.c]
3219 [session.c ssh.c]
3220 agent forwarding and -R for ssh2, based on work from
3221 jhuuskon@messi.uku.fi
3222 - markus@cvs.openbsd.org 2000/11/06 16:13:27
3223 [ssh.c sshconnect.c sshd.c]
3224 do not disabled rhosts(rsa) if server port > 1024; from
3225 pekkas@netcore.fi
3226 - markus@cvs.openbsd.org 2000/11/06 16:16:35
3227 [sshconnect.c]
3228 downgrade client to 1.3 if server is 1.4; help from mdb@juniper.net
3229 - markus@cvs.openbsd.org 2000/11/09 18:04:40
3230 [auth1.c]
3231 typo; from mouring@pconline.com
3232 - markus@cvs.openbsd.org 2000/11/12 12:03:28
3233 [ssh-agent.c]
3234 off-by-one when removing a key from the agent
3235 - markus@cvs.openbsd.org 2000/11/12 12:50:39
3236 [auth-rh-rsa.c auth2.c authfd.c authfd.h]
3237 [authfile.c hostfile.c kex.c kex.h key.c key.h myproposal.h]
3238 [readconf.c readconf.h rsa.c rsa.h servconf.c servconf.h ssh-add.c]
3239 [ssh-agent.c ssh-keygen.1 ssh-keygen.c ssh.1 ssh.c ssh_config]
3240 [sshconnect1.c sshconnect2.c sshd.8 sshd.c sshd_config ssh-dss.c]
61e96248 3241 [ssh-dss.h ssh-rsa.c ssh-rsa.h dsa.c dsa.h]
fa08c86b 3242 add support for RSA to SSH2. please test.
3243 there are now 3 types of keys: RSA1 is used by ssh-1 only,
3244 RSA and DSA are used by SSH2.
3245 you can use 'ssh-keygen -t rsa -f ssh2_rsa_file' to generate RSA
3246 keys for SSH2 and use the RSA keys for hostkeys or for user keys.
3247 SSH2 RSA or DSA keys are added to .ssh/authorised_keys2 as before.
3248 - (djm) Fix up Makefile and Redhat init script to create RSA host keys
f001465f 3249 - (djm) Change to interim version
5733a41a 3250 - (djm) Fix RPM spec file stupidity
6fff1ac4 3251 - (djm) fixpaths to DSA and RSA keys too
3d398e04 3252
d287c664 325320001112
3254 - (bal) SCO Patch to add needed libraries for configure.in. Patch by
3255 Phillips Porch <root@theporch.com>
3d398e04 3256 - (bal) IRIX patch to adding Job Limits. Patch by Denis Parker
3257 <dcp@sgi.com>
a3bf38d0 3258 - (stevesk) pty.c: HP-UX 10 and 11 don't define TIOCSCTTY. Add error() to
3259 failed ioctl(TIOCSCTTY) call.
d287c664 3260
3c4d4fef 326120001111
3262 - (djm) Added /etc/primes for kex DH group neg, fixup Makefile.in and
3263 packaging files
35325fd4 3264 - (djm) Fix new Makefile.in warnings
61e96248 3265 - (djm) Fix vsprintf("%h") in bsd-snprintf.c, short int va_args are
3266 promoted to type int. Report and fix from Dan Astoorian
027bf205 3267 <djast@cs.toronto.edu>
61e96248 3268 - (djm) Hardwire sysconfdir in RPM spec files as some RPM versions get
e3291159 3269 it wrong. Report from Bennett Todd <bet@rahul.net>
3c4d4fef 3270
3e366738 327120001110
3272 - (bal) Fixed dropped answer from skey_keyinfo() in auth1.c
3273 - (bal) Changed from --with-skey to --with-skey=PATH in configure.in
3274 - (bal) Added in check to verify S/Key library is being detected in
3275 configure.in
61e96248 3276 - (bal) next-posix.h - added another prototype wrapped in POSIX ifdef/endif.
3e366738 3277 Patch by Mark Miller <markm@swoon.net>
3278 - (bal) Added 'util.h' header to loginrec.c only if HAVE_UTIL_H is defined
61e96248 3279 to remove warnings under MacOS X. Patch by Mark Miller <markm@swoon.net>
3e366738 3280 - (bal) Fixed LDFLAG mispelling in configure.in for --with-afs
3281
373998a4 328220001107
e506ee73 3283 - (bal) acconfig.in - removed the double "USE_PIPES" entry. Patch by
3284 Mark Miller <markm@swoon.net>
373998a4 3285 - (bal) sshd.init files corrected to assign $? to RETVAL. Patch by
3286 Jarno Huuskonen <jhuuskon@messi.uku.fi>
e506ee73 3287 - (bal) fixpaths fixed to stop it from quitely failing. Patch by
3288 Mark D. Roth <roth@feep.net>
373998a4 3289
ac89998a 329020001106
3291 - (djm) Use Jim's new 1.0.3 askpass in Redhat RPMs
6c09e23c 3292 - (djm) Manually fix up missed diff hunks (mainly RCS idents)
61e96248 3293 - (djm) Remove UPGRADING document in favour of a link to the better
d6846e6a 3294 maintained FAQ on www.openssh.com
73bd30fe 3295 - (djm) Fix multiple dependancy on gnome-libs from Pekka Savola
3296 <pekkas@netcore.fi>
3297 - (djm) Don't need X11-askpass in RPM spec file if building without it
3298 from Pekka Savola <pekkas@netcore.fi>
c215ba3b 3299 - (djm) Release 2.3.0p1
97b378bf 3300 - (bal) typo in configure.in in regards to --with-ldflags from Marko
3301 Asplund <aspa@kronodoc.fi>
3302 - (bal) fixed next-posix.h. Forgot prototype of getppid().
68f189a9 3303
b850ecd9 330420001105
3305 - (bal) Sync with OpenBSD:
3306 - markus@cvs.openbsd.org 2000/10/31 9:31:58
3307 [compat.c]
3308 handle all old openssh versions
3309 - markus@cvs.openbsd.org 2000/10/31 13:1853
3310 [deattack.c]
3311 so that large packets do not wrap "n"; from netbsd
3312 - (bal) rijndel.c - fix up RCSID to match OpenBSD tree
a30ce26d 3313 - (bal) auth2-skey.c - Checked in. Missing from portable tree.
3314 - (bal) Reworked NEWS-OS and NeXT ports to extract waitpid() and
3315 setsid() into more common files
96054e6f 3316 - (stevesk) pty.c: use __hpux to identify HP-UX.
d0127657 3317 - (bal) Missed auth-skey.o in Makefile.in and minor correction to
3318 bsd-waitpid.c
b850ecd9 3319
75b90ced 332020001029
3321 - (stevesk) Fix typo in auth.c: USE_PAM not PAM
95273555 3322 - (stevesk) Create contrib/cygwin/ directory; patch from
3323 Corinna Vinschen <vinschen@redhat.com>
e9e4a1c7 3324 - (bal) Resolved more $xno and $xyes issues in configure.in
fd5f0295 3325 - (bal) next-posix.h - spelling and forgot a prototype
75b90ced 3326
344f2b94 332720001028
61e96248 3328 - (djm) fix select hack in serverloop.c from Philippe WILLEM
344f2b94 3329 <Philippe.WILLEM@urssaf.fr>
240ae474 3330 - (djm) Fix mangled AIXAUTHENTICATE code
61e96248 3331 - (djm) authctxt->pw may be NULL. Fix from Markus Friedl
606ea390 3332 <markus.friedl@informatik.uni-erlangen.de>
a22aff1f 3333 - (djm) Sync with OpenBSD:
3334 - markus@cvs.openbsd.org 2000/10/16 15:46:32
3335 [ssh.1]
3336 fixes from pekkas@netcore.fi
3337 - markus@cvs.openbsd.org 2000/10/17 14:28:11
3338 [atomicio.c]
3339 return number of characters processed; ok deraadt@
3340 - markus@cvs.openbsd.org 2000/10/18 12:04:02
3341 [atomicio.c]
3342 undo
3343 - markus@cvs.openbsd.org 2000/10/18 12:23:02
3344 [scp.c]
3345 replace atomicio(read,...) with read(); ok deraadt@
3346 - markus@cvs.openbsd.org 2000/10/18 12:42:00
3347 [session.c]
3348 restore old record login behaviour
3349 - deraadt@cvs.openbsd.org 2000/10/19 10:41:13
3350 [auth-skey.c]
3351 fmt string problem in unused code
3352 - provos@cvs.openbsd.org 2000/10/19 10:45:16
3353 [sshconnect2.c]
3354 don't reference freed memory. okay deraadt@
3355 - markus@cvs.openbsd.org 2000/10/21 11:04:23
3356 [canohost.c]
3357 typo, eramore@era-t.ericsson.se; ok niels@
3358 - markus@cvs.openbsd.org 2000/10/23 13:31:55
3359 [cipher.c]
3360 non-alignment dependent swap_bytes(); from
3361 simonb@wasabisystems.com/netbsd
3362 - markus@cvs.openbsd.org 2000/10/26 12:38:28
3363 [compat.c]
3364 add older vandyke products
3365 - markus@cvs.openbsd.org 2000/10/27 01:32:19
3366 [channels.c channels.h clientloop.c serverloop.c session.c]
3367 [ssh.c util.c]
61e96248 3368 enable non-blocking IO on channels, and tty's (except for the
a22aff1f 3369 client ttys).
344f2b94 3370
ddc49b5c 337120001027
3372 - (djm) Increase REKEY_BYTES to 2^24 for arc4random
3373
48e7916f 337420001025
3375 - (djm) Added WARNING.RNG file and modified configure to ask users of the
3376 builtin entropy code to read it.
3377 - (djm) Prefer builtin regex to PCRE.
00937921 3378 - (bal) Added USE_PIPS defined to NeXT configure.in since scp hangs randomly.
3379 - (bal) Apply fixes to configure.in pointed out by Pavel Roskin
3380 <proski@gnu.org>
48e7916f 3381
8dcda1e3 338220001020
3383 - (djm) Don't define _REENTRANT for SNI/Reliant Unix
07bee9a7 3384 - (bal) Imported NEWS-OS waitpid() macros into NeXT. Since implementation
3385 is more correct then current version.
8dcda1e3 3386
f5af5cd5 338720001018
3388 - (stevesk) Add initial support for setproctitle(). Current
3389 support is for the HP-UX pstat(PSTAT_SETCMD, ...) method.
134fd7f6 3390 - (stevesk) Add egd startup scripts to contrib/hpux/
f5af5cd5 3391
2f31bdd6 339220001017
3393 - (djm) Add -lregex to cywin libs from Corinna Vinschen
3394 <vinschen@cygnus.com>
ba7a3f40 3395 - (djm) Don't rely on atomicio's retval to determine length of askpass
3396 supplied passphrase. Problem report from Lutz Jaenicke
3397 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
66d6c27e 3398 - (bal) Changed from GNU rx to PCRE on suggestion from djm.
61e96248 3399 - (bal) Integrated Sony NEWS-OS patches from NAKAJI Hirouyuki
66d6c27e 3400 <nakaji@tutrp.tut.ac.jp>
2f31bdd6 3401
33de75a3 340220001016
3403 - (djm) Sync with OpenBSD:
3404 - markus@cvs.openbsd.org 2000/10/14 04:01:15
3405 [cipher.c]
3406 debug3
3407 - markus@cvs.openbsd.org 2000/10/14 04:07:23
3408 [scp.c]
3409 remove spaces from arguments; from djm@mindrot.org
3410 - markus@cvs.openbsd.org 2000/10/14 06:09:46
3411 [ssh.1]
3412 Cipher is for SSH-1 only
3413 - markus@cvs.openbsd.org 2000/10/14 06:12:09
3414 [servconf.c servconf.h serverloop.c session.c sshd.8]
3415 AllowTcpForwarding; from naddy@
3416 - markus@cvs.openbsd.org 2000/10/14 06:16:56
3417 [auth2.c compat.c compat.h sshconnect2.c version.h]
61e96248 3418 OpenSSH_2.3; note that is is not complete, but the version number
33de75a3 3419 needs to be changed for interoperability reasons
3420 - markus@cvs.openbsd.org 2000/10/14 06:19:45
3421 [auth-rsa.c]
3422 do not send RSA challenge if key is not allowed by key-options; from
3423 eivind@ThinkSec.com
3424 - markus@cvs.openbsd.org 2000/10/15 08:14:01
3425 [rijndael.c session.c]
3426 typos; from stevesk@sweden.hp.com
3427 - markus@cvs.openbsd.org 2000/10/15 08:18:31
3428 [rijndael.c]
3429 typo
61e96248 3430 - (djm) Copy manpages back over from OpenBSD - too tedious to wade
30d8b039 3431 through diffs
61e96248 3432 - (djm) Added condrestart to Redhat init script. Patch from Pekka Savola
30d8b039 3433 <pekkas@netcore.fi>
aa0289fe 3434 - (djm) Update version in Redhat spec file
61e96248 3435 - (djm) Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
aa0289fe 3436 Redhat 7.0 spec file
5b2d4b75 3437 - (djm) Make inability to read/write PRNG seedfile non-fatal
3438
33de75a3 3439
4d670c24 344020001015
3441 - (djm) Fix ssh2 hang on background processes at logout.
3442
71dfaf1c 344320001014
443172c4 3444 - (bal) Add support for realpath and getcwd for platforms with broken
3445 or missing realpath implementations for sftp-server.
3446 - (bal) Corrected mistake in INSTALL in regards to GNU rx library
61e96248 3447 - (bal) Add support for GNU rx library for those lacking regexp support
71dfaf1c 3448 - (djm) Don't accept PAM_PROMPT_ECHO_ON messages during initial auth
02323c45 3449 - (djm) Revert SSH2 serverloop hack, will find a better way.
4ee81249 3450 - (djm) Add workaround for Linux 2.4's gratuitious errno change. Patch
3451 from Martin Johansson <fatbob@acc.umu.se>
94ec8c6b 3452 - (djm) Big OpenBSD sync:
3453 - markus@cvs.openbsd.org 2000/09/30 10:27:44
3454 [log.c]
3455 allow loglevel debug
3456 - markus@cvs.openbsd.org 2000/10/03 11:59:57
3457 [packet.c]
3458 hmac->mac
3459 - markus@cvs.openbsd.org 2000/10/03 12:03:03
3460 [auth-krb4.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth1.c]
3461 move fake-auth from auth1.c to individual auth methods, disables s/key in
3462 debug-msg
3463 - markus@cvs.openbsd.org 2000/10/03 12:16:48
3464 ssh.c
3465 do not resolve canonname, i have no idea why this was added oin ossh
3466 - markus@cvs.openbsd.org 2000/10/09 15:30:44
3467 ssh-keygen.1 ssh-keygen.c
3468 -X now reads private ssh.com DSA keys, too.
3469 - markus@cvs.openbsd.org 2000/10/09 15:32:34
3470 auth-options.c
3471 clear options on every call.
3472 - markus@cvs.openbsd.org 2000/10/09 15:51:00
3473 authfd.c authfd.h
3474 interop with ssh-agent2, from <res@shore.net>
3475 - markus@cvs.openbsd.org 2000/10/10 14:20:45
3476 compat.c
3477 use rexexp for version string matching
3478 - provos@cvs.openbsd.org 2000/10/10 22:02:18
3479 [kex.c kex.h myproposal.h ssh.h ssh2.h sshconnect2.c sshd.c dh.c dh.h]
3480 First rough implementation of the diffie-hellman group exchange. The
3481 client can ask the server for bigger groups to perform the diffie-hellman
3482 in, thus increasing the attack complexity when using ciphers with longer
3483 keys. University of Windsor provided network, T the company.
3484 - markus@cvs.openbsd.org 2000/10/11 13:59:52
3485 [auth-rsa.c auth2.c]
3486 clear auth options unless auth sucessfull
3487 - markus@cvs.openbsd.org 2000/10/11 14:00:27
3488 [auth-options.h]
3489 clear auth options unless auth sucessfull
3490 - markus@cvs.openbsd.org 2000/10/11 14:03:27
3491 [scp.1 scp.c]
3492 support 'scp -o' with help from mouring@pconline.com
3493 - markus@cvs.openbsd.org 2000/10/11 14:11:35
3494 [dh.c]
3495 Wall
3496 - markus@cvs.openbsd.org 2000/10/11 14:14:40
3497 [auth.h auth2.c readconf.c readconf.h readpass.c servconf.c servconf.h]
3498 [ssh.h sshconnect2.c sshd_config auth2-skey.c cli.c cli.h]
3499 add support for s/key (kbd-interactive) to ssh2, based on work by
3500 mkiernan@avantgo.com and me
3501 - markus@cvs.openbsd.org 2000/10/11 14:27:24
3502 [auth.c auth1.c auth2.c authfile.c cipher.c cipher.h kex.c kex.h]
3503 [myproposal.h packet.c readconf.c session.c ssh.c ssh.h sshconnect1.c]
3504 [sshconnect2.c sshd.c]
3505 new cipher framework
3506 - markus@cvs.openbsd.org 2000/10/11 14:45:21
3507 [cipher.c]
3508 remove DES
3509 - markus@cvs.openbsd.org 2000/10/12 03:59:20
3510 [cipher.c cipher.h sshconnect1.c sshconnect2.c sshd.c]
3511 enable DES in SSH-1 clients only
3512 - markus@cvs.openbsd.org 2000/10/12 08:21:13
3513 [kex.h packet.c]
3514 remove unused
3515 - markus@cvs.openbsd.org 2000/10/13 12:34:46
3516 [sshd.c]
3517 Kludge for F-Secure Macintosh < 1.0.2; appro@fy.chalmers.se
3518 - markus@cvs.openbsd.org 2000/10/13 12:59:15
3519 [cipher.c cipher.h myproposal.h rijndael.c rijndael.h]
3520 rijndael/aes support
3521 - markus@cvs.openbsd.org 2000/10/13 13:10:54
3522 [sshd.8]
3523 more info about -V
3524 - markus@cvs.openbsd.org 2000/10/13 13:12:02
3525 [myproposal.h]
3526 prefer no compression
3ed32516 3527 - (djm) Fix scp user@host handling
3528 - (djm) Don't clobber ssh_prng_cmds on install
6bcf7caa 3529 - (stevesk) Include config.h in rijndael.c so we define intXX_t and
3530 u_intXX_t types on all platforms.
9ea53ba5 3531 - (stevesk) rijndael.c: cleanup missing declaration warnings.
2919e060 3532 - (stevesk) ~/.hushlogin shouldn't cause required password change to
3533 be bypassed.
f5665f6f 3534 - (stevesk) Display correct path to ssh-askpass in configure output.
3535 Report from Lutz Jaenicke.
71dfaf1c 3536
ebd782f7 353720001007
3538 - (stevesk) Print PAM return value in PAM log messages to aid
3539 with debugging.
97994d32 3540 - (stevesk) Fix detection of pw_class struct member in configure;
3541 patch from KAMAHARA Junzo <kamahara@cc.kshosen.ac.jp>
3542
47a134c1 354320001002
3544 - (djm) Fix USER_PATH, report from Kevin Steves <stevesk@sweden.hp.com>
3545 - (djm) Add host system and CC to end-of-configure report. Suggested by
3546 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
3547
7322ef0e 354820000931
3549 - (djm) Cygwin fixes from Corinna Vinschen <vinschen@cygnus.com>
3550
6ac7829a 355120000930
b6490dcb 3552 - (djm) Irix ssh_prng_cmds path fix from Pekka Savola <pekkas@netcore.fi>
61e96248 3553 - (djm) Support in bsd-snprintf.c for long long conversions from
772bd898 3554 Ben Lindstrom <mouring@pconline.com>
3555 - (djm) Cleanup NeXT support from Ben Lindstrom <mouring@pconline.com>
857040fb 3556 - (djm) Ignore SIGPIPEs from serverloop to child. Fixes crashes with
61e96248 3557 very short lived X connections. Bug report from Tobias Oetiker
857040fb 3558 <oetiker@ee.ethz.ch>. Fix from Markus Friedl <markus@cvs.openbsd.org>
bd2d7f6a 3559 - (djm) Add recent InitScripts as a RPM dependancy for openssh-server
3560 patch from Pekka Savola <pekkas@netcore.fi>
58665035 3561 - (djm) Forgot to cvs add LICENSE file
dc2901a0 3562 - (djm) Add LICENSE to RPM spec files
de273eef 3563 - (djm) CVS OpenBSD sync:
3564 - markus@cvs.openbsd.org 2000/09/26 13:59:59
3565 [clientloop.c]
3566 use debug2
3567 - markus@cvs.openbsd.org 2000/09/27 15:41:34
3568 [auth2.c sshconnect2.c]
3569 use key_type()
3570 - markus@cvs.openbsd.org 2000/09/28 12:03:18
3571 [channels.c]
3572 debug -> debug2 cleanup
61e96248 3573 - (djm) Irix strips "/dev/tty" from [uw]tmp entries (other systems only
2a7d529a 3574 strip "/dev/"). Fix loginrec.c based on patch from Alain St-Denis
3575 <Alain.St-Denis@ec.gc.ca>
61e96248 3576 - (djm) Fix 9 character passphrase failure with gnome-ssh-askpass.
3577 Problem was caused by interrupted read in ssh-add. Report from Donald
2a7d529a 3578 J. Barry <don@astro.cornell.edu>
6ac7829a 3579
c5d85828 358020000929
3581 - (djm) Fix SSH2 not terminating until all background tasks done problem.
61e96248 3582 - (djm) Another off-by-one fix from Pavel Kankovsky
3583 <peak@argo.troja.mff.cuni.cz>
22d89d24 3584 - (djm) Clean up. Strip some unnecessary differences with OpenBSD's code,
3585 tidy necessary differences. Use Markus' new debugN() in entropy.c
61e96248 3586 - (djm) Merged big SCO portability patch from Tim Rice
77bb0bca 3587 <tim@multitalents.net>
c5d85828 3588
6fd7f731 358920000926
3590 - (djm) Update X11-askpass to 1.0.2 in RPM spec file
c5ae7384 3591 - (djm) Define _REENTRANT to pickup strtok_r() on HP/UX
61e96248 3592 - (djm) Security: fix off-by-one buffer overrun in fake-getnameinfo.c.
3593 Report and fix from Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
6fd7f731 3594
2f125ca1 359520000924
3596 - (djm) Merged cleanup patch from Mark Miller <markm@swoon.net>
3597 - (djm) A bit more cleanup - created cygwin_util.h
bcdaaeab 3598 - (djm) Include strtok_r() from OpenBSD libc. Fixes report from Mark Miller
3599 <markm@swoon.net>
2f125ca1 3600
764d4113 360120000923
61e96248 3602 - (djm) Fix address logging in utmp from Kevin Steves
764d4113 3603 <stevesk@sweden.hp.com>
777319db 3604 - (djm) Redhat spec and manpage fixes from Pekka Savola <pekkas@netcore.fi>
bd590612 3605 - (djm) Seperate tests for int64_t and u_int64_t types
61e96248 3606 - (djm) Tweak password expiry checking at suggestion of Kevin Steves
37c1c46d 3607 <stevesk@sweden.hp.com>
e79b44e1 3608 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
61e96248 3609 - (djm) Use printf %lld instead of %qd in sftp-server.c. Fix from
e2144f11 3610 Michael Stone <mstone@cs.loyola.edu>
188adeb2 3611 - (djm) OpenBSD CVS sync:
3612 - markus@cvs.openbsd.org 2000/09/17 09:38:59
3613 [sshconnect2.c sshd.c]
3614 fix DEBUG_KEXDH
3615 - markus@cvs.openbsd.org 2000/09/17 09:52:51
3616 [sshconnect.c]
3617 yes no; ok niels@
3618 - markus@cvs.openbsd.org 2000/09/21 04:55:11
3619 [sshd.8]
3620 typo
3621 - markus@cvs.openbsd.org 2000/09/21 05:03:54
3622 [serverloop.c]
3623 typo
3624 - markus@cvs.openbsd.org 2000/09/21 05:11:42
3625 scp.c
3626 utime() to utimes(); mouring@pconline.com
3627 - markus@cvs.openbsd.org 2000/09/21 05:25:08
3628 sshconnect2.c
3629 change login logic in ssh2, allows plugin of other auth methods
3630 - markus@cvs.openbsd.org 2000/09/21 05:25:35
3631 [auth2.c channels.c channels.h clientloop.c dispatch.c dispatch.h]
3632 [serverloop.c]
3633 add context to dispatch_run
3634 - markus@cvs.openbsd.org 2000/09/21 05:07:52
3635 authfd.c authfd.h ssh-agent.c
3636 bug compat for old ssh.com software
764d4113 3637
7f377177 363820000920
3639 - (djm) Fix bad path substitution. Report from Andrew Miner
3640 <asminer@cs.iastate.edu>
3641
bcbf86ec 364220000916
61e96248 3643 - (djm) Fix SSL search order from Lutz Jaenicke
7950bf97 3644 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
19ece6d2 3645 - (djm) New SuSE spec from Corinna Vinschen <corinna@vinschen.de>
9cd45ea4 3646 - (djm) Update CygWin support from Corinna Vinschen <vinschen@cygnus.com>
995edaac 3647 - (djm) Use a real struct sockaddr inside the fake struct sockaddr_storage.
3648 Patch from Larry Jones <larry.jones@sdrc.com>
61e96248 3649 - (djm) Add Steve VanDevender's <stevev@darkwing.uoregon.edu> PAM
ad55cd03 3650 password change patch.
3651 - (djm) Bring licenses on my stuff in line with OpenBSD's
0bbfbdeb 3652 - (djm) Cleanup auth-passwd.c and unify HP/UX authentication. Patch from
3653 Kevin Steves <stevesk@sweden.hp.com>
7f8f5e00 3654 - (djm) Shadow expiry check fix from Pavel Troller <patrol@omni.sinus.cz>
3655 - (djm) Re-enable int64_t types - we need them for sftp
3656 - (djm) Use libexecdir from configure , rather than libexecdir/ssh
3657 - (djm) Update Redhat SPEC file accordingly
3658 - (djm) Add Kevin Steves <stevesk@sweden.hp.com> HP/UX contrib files
3659 - (djm) Add Charles Levert <charles@comm.polymtl.ca> getpgrp patch
61e96248 3660 - (djm) Fix password auth on HP/UX 10.20. Patch from Dirk De Wachter
7f8f5e00 3661 <Dirk.DeWachter@rug.ac.be>
61e96248 3662 - (djm) Fixprogs and entropy list fixes from Larry Jones
7f8f5e00 3663 <larry.jones@sdrc.com>
3664 - (djm) Fix for SuSE spec file from Takashi YOSHIDA
3665 <tyoshida@gemini.rc.kyushu-u.ac.jp>
bcbf86ec 3666 - (djm) Merge OpenBSD changes:
3667 - markus@cvs.openbsd.org 2000/09/05 02:59:57
3668 [session.c]
3669 print hostname (not hushlogin)
3670 - markus@cvs.openbsd.org 2000/09/05 13:18:48
3671 [authfile.c ssh-add.c]
3672 enable ssh-add -d for DSA keys
3673 - markus@cvs.openbsd.org 2000/09/05 13:20:49
3674 [sftp-server.c]
3675 cleanup
3676 - markus@cvs.openbsd.org 2000/09/06 03:46:41
3677 [authfile.h]
3678 prototype
3679 - deraadt@cvs.openbsd.org 2000/09/07 14:27:56
3680 [ALL]
61e96248 3681 cleanup copyright notices on all files. I have attempted to be
3682 accurate with the details. everything is now under Tatu's licence
3683 (which I copied from his readme), and/or the core-sdi bsd-ish thing
3684 for deattack, or various openbsd developers under a 2-term bsd
bcbf86ec 3685 licence. We're not changing any rules, just being accurate.
3686 - markus@cvs.openbsd.org 2000/09/07 14:40:30
3687 [channels.c channels.h clientloop.c serverloop.c ssh.c]
3688 cleanup window and packet sizes for ssh2 flow control; ok niels
3689 - markus@cvs.openbsd.org 2000/09/07 14:53:00
3690 [scp.c]
3691 typo
3692 - markus@cvs.openbsd.org 2000/09/07 15:13:37
3693 [auth-options.c auth-options.h auth-rh-rsa.c auth-rsa.c auth.c]
3694 [authfile.h canohost.c channels.h compat.c hostfile.h log.c match.h]
3695 [pty.c readconf.c]
3696 some more Copyright fixes
3697 - markus@cvs.openbsd.org 2000/09/08 03:02:51
3698 [README.openssh2]
3699 bye bye
3700 - deraadt@cvs.openbsd.org 2000/09/11 18:38:33
3701 [LICENCE cipher.c]
3702 a few more comments about it being ARC4 not RC4
3703 - markus@cvs.openbsd.org 2000/09/12 14:53:11
3704 [log-client.c log-server.c log.c ssh.1 ssh.c ssh.h sshd.8 sshd.c]
3705 multiple debug levels
3706 - markus@cvs.openbsd.org 2000/09/14 14:25:15
3707 [clientloop.c]
3708 typo
3709 - deraadt@cvs.openbsd.org 2000/09/15 01:13:51
3710 [ssh-agent.c]
3711 check return value for setenv(3) for failure, and deal appropriately
3712
deb8d717 371320000913
3714 - (djm) Fix server not exiting with jobs in background.
3715
b5e300c2 371620000905
3717 - (djm) Import OpenBSD CVS changes
3718 - markus@cvs.openbsd.org 2000/08/31 15:52:24
3719 [Makefile sshd.8 sshd_config sftp-server.8 sftp-server.c]
3720 implement a SFTP server. interops with sftp2, scp2 and the windows
3721 client from ssh.com
3722 - markus@cvs.openbsd.org 2000/08/31 15:56:03
3723 [README.openssh2]
3724 sync
3725 - markus@cvs.openbsd.org 2000/08/31 16:05:42
3726 [session.c]
3727 Wall
3728 - markus@cvs.openbsd.org 2000/08/31 16:09:34
3729 [authfd.c ssh-agent.c]
3730 add a flag to SSH2_AGENTC_SIGN_REQUEST for future extensions
3731 - deraadt@cvs.openbsd.org 2000/09/01 09:25:13
3732 [scp.1 scp.c]
3733 cleanup and fix -S support; stevesk@sweden.hp.com
3734 - markus@cvs.openbsd.org 2000/09/01 16:29:32
3735 [sftp-server.c]
3736 portability fixes
3737 - markus@cvs.openbsd.org 2000/09/01 16:32:41
3738 [sftp-server.c]
3739 fix cast; mouring@pconline.com
3740 - itojun@cvs.openbsd.org 2000/09/03 09:23:28
3741 [ssh-add.1 ssh.1]
3742 add missing .El against .Bl.
3743 - markus@cvs.openbsd.org 2000/09/04 13:03:41
3744 [session.c]
3745 missing close; ok theo
3746 - markus@cvs.openbsd.org 2000/09/04 13:07:21
3747 [session.c]
3748 fix get_last_login_time order; from andre@van-veen.de
3749 - markus@cvs.openbsd.org 2000/09/04 13:10:09
3750 [sftp-server.c]
3751 more cast fixes; from mouring@pconline.com
3752 - markus@cvs.openbsd.org 2000/09/04 13:06:04
3753 [session.c]
3754 set SSH_ORIGINAL_COMMAND; from Leakin@dfw.nostrum.com, bet@rahul.net
3755 - (djm) Cleanup after import. Fix sftp-server compilation, Makefile
3c62e7eb 3756 - (djm) Merge cygwin support from Corinna Vinschen <vinschen@cygnus.com>
3757
1e61f54a 375820000903
3759 - (djm) Fix Redhat init script
3760
c80876b4 376120000901
3762 - (djm) Pick up Jim's new X11-askpass
3763 - (djm) Release 2.2.0p1
3764
8b4a0d08 376520000831
bcbf86ec 3766 - (djm) Workaround SIGPIPE problems on SCO. Fix from Aran Cox
8b4a0d08 3767 <acox@cv.telegroup.com>
b817711d 3768 - (djm) Pick up new version (2.2.0) from OpenBSD CVS
8b4a0d08 3769
0b65b628 377020000830
3771 - (djm) Compile warning fixes from Mark Miller <markm@swoon.net>
10fa00c8 3772 - (djm) Periodically rekey arc4random
3773 - (djm) Clean up diff against OpenBSD.
bcbf86ec 3774 - (djm) HPUX 11 needs USE_PIPES as well: Kevin Steves
2b10f47a 3775 <stevesk@sweden.hp.com>
b33a2e6e 3776 - (djm) Quieten the pam delete credentials error message
44839801 3777 - (djm) Fix printing of $DISPLAY hack if set by system type. Report from
3778 Kevin Steves <stevesk@sweden.hp.com>
84a770d1 3779 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
7efa2776 3780 - (djm) Fix doh in bsd-arc4random.c
0b65b628 3781
9aaf9be4 378220000829
bcbf86ec 3783 - (djm) Fix ^C ignored issue on Solaris. Diagnosis from Gert
3784 Doering <gert@greenie.muc.de>, John Horne <J.Horne@plymouth.ac.uk> and
9aaf9be4 3785 Garrick James <garrick@james.net>
b5f90139 3786 - (djm) Check for SCO pty naming style (ptyp%d/ttyp%d). Based on fix from
3787 Bastian Trompetter <btrompetter@firemail.de>
698d107e 3788 - (djm) NeXT tweaks from Ben Lindstrom <mouring@pconline.com>
14a9a859 3789 - More OpenBSD updates:
3790 - deraadt@cvs.openbsd.org 2000/08/24 15:46:59
3791 [scp.c]
3792 off_t in sink, to fix files > 2GB, i think, test is still running ;-)
3793 - deraadt@cvs.openbsd.org 2000/08/25 10:10:06
3794 [session.c]
3795 Wall
3796 - markus@cvs.openbsd.org 2000/08/26 04:33:43
3797 [compat.c]
3798 ssh.com-2.3.0
3799 - markus@cvs.openbsd.org 2000/08/27 12:18:05
3800 [compat.c]
3801 compatibility with future ssh.com versions
3802 - deraadt@cvs.openbsd.org 2000/08/27 21:50:55
3803 [auth-krb4.c session.c ssh-add.c sshconnect.c uidswap.c]
3804 print uid/gid as unsigned
3805 - markus@cvs.openbsd.org 2000/08/28 13:51:00
3806 [ssh.c]
3807 enable -n and -f for ssh2
3808 - markus@cvs.openbsd.org 2000/08/28 14:19:53
3809 [ssh.c]
3810 allow combination of -N and -f
3811 - markus@cvs.openbsd.org 2000/08/28 14:20:56
3812 [util.c]
3813 util.c
3814 - markus@cvs.openbsd.org 2000/08/28 14:22:02
3815 [util.c]
3816 undo
3817 - markus@cvs.openbsd.org 2000/08/28 14:23:38
3818 [util.c]
3819 don't complain if setting NONBLOCK fails with ENODEV
9aaf9be4 3820
137d7b6c 382120000823
3822 - (djm) Define USE_PIPES to avoid socketpair problems on HPUX 10 and SunOS 4
bcbf86ec 3823 Avoids "scp never exits" problem. Reports from Lutz Jaenicke
3824 <Lutz.Jaenicke@aet.TU-Cottbus.DE> and Tamito KAJIYAMA
137d7b6c 3825 <kajiyama@grad.sccs.chukyo-u.ac.jp>
2e73a022 3826 - (djm) Pick up LOGIN_PROGRAM from environment or PATH if not set by headers
da40ab4d 3827 - (djm) Add local version to version.h
ea788c22 3828 - (djm) Don't reseed arc4random everytime it is used
2e73a022 3829 - (djm) OpenBSD CVS updates:
3830 - deraadt@cvs.openbsd.org 2000/08/18 20:07:23
3831 [ssh.c]
3832 accept remsh as a valid name as well; roman@buildpoint.com
3833 - deraadt@cvs.openbsd.org 2000/08/18 20:17:13
3834 [deattack.c crc32.c packet.c]
3835 rename crc32() to ssh_crc32() to avoid zlib name clash. do not move to
3836 libz crc32 function yet, because it has ugly "long"'s in it;
3837 oneill@cs.sfu.ca
3838 - deraadt@cvs.openbsd.org 2000/08/18 20:26:08
3839 [scp.1 scp.c]
3840 -S prog support; tv@debian.org
3841 - deraadt@cvs.openbsd.org 2000/08/18 20:50:07
3842 [scp.c]
3843 knf
3844 - deraadt@cvs.openbsd.org 2000/08/18 20:57:33
3845 [log-client.c]
3846 shorten
3847 - markus@cvs.openbsd.org 2000/08/19 12:48:11
3848 [channels.c channels.h clientloop.c ssh.c ssh.h]
3849 support for ~. in ssh2
3850 - deraadt@cvs.openbsd.org 2000/08/19 15:29:40
3851 [crc32.h]
3852 proper prototype
3853 - markus@cvs.openbsd.org 2000/08/19 15:34:44
bcbf86ec 3854 [authfd.c authfd.h key.c key.h ssh-add.1 ssh-add.c ssh-agent.1]
3855 [ssh-agent.c ssh-keygen.c sshconnect1.c sshconnect2.c Makefile]
2e73a022 3856 [fingerprint.c fingerprint.h]
3857 add SSH2/DSA support to the agent and some other DSA related cleanups.
3858 (note that we cannot talk to ssh.com's ssh2 agents)
3859 - markus@cvs.openbsd.org 2000/08/19 15:55:52
3860 [channels.c channels.h clientloop.c]
3861 more ~ support for ssh2
3862 - markus@cvs.openbsd.org 2000/08/19 16:21:19
3863 [clientloop.c]
3864 oops
3865 - millert@cvs.openbsd.org 2000/08/20 12:25:53
3866 [session.c]
3867 We have to stash the result of get_remote_name_or_ip() before we
3868 close our socket or getpeername() will get EBADF and the process
3869 will exit. Only a problem for "UseLogin yes".
3870 - millert@cvs.openbsd.org 2000/08/20 12:30:59
3871 [session.c]
3872 Only check /etc/nologin if "UseLogin no" since login(1) may have its
3873 own policy on determining who is allowed to login when /etc/nologin
3874 is present. Also use the _PATH_NOLOGIN define.
3875 - millert@cvs.openbsd.org 2000/08/20 12:42:43
3876 [auth1.c auth2.c session.c ssh.c]
3877 Add calls to setusercontext() and login_get*(). We basically call
3878 setusercontext() in most places where previously we did a setlogin().
3879 Add default login.conf file and put root in the "daemon" login class.
3880 - millert@cvs.openbsd.org 2000/08/21 10:23:31
3881 [session.c]
3882 Fix incorrect PATH setting; noted by Markus.
137d7b6c 3883
c345cf9d 388420000818
3885 - (djm) OpenBSD CVS changes:
3886 - markus@cvs.openbsd.org 2000/07/22 03:14:37
3887 [servconf.c servconf.h sshd.8 sshd.c sshd_config]
3888 random early drop; ok theo, niels
3889 - deraadt@cvs.openbsd.org 2000/07/26 11:46:51
3890 [ssh.1]
3891 typo
3892 - deraadt@cvs.openbsd.org 2000/08/01 11:46:11
3893 [sshd.8]
3894 many fixes from pepper@mail.reppep.com
3895 - provos@cvs.openbsd.org 2000/08/01 13:01:42
3896 [Makefile.in util.c aux.c]
3897 rename aux.c to util.c to help with cygwin port
3898 - deraadt@cvs.openbsd.org 2000/08/02 00:23:31
3899 [authfd.c]
3900 correct sun_len; Alexander@Leidinger.net
3901 - provos@cvs.openbsd.org 2000/08/02 10:27:17
3902 [readconf.c sshd.8]
3903 disable kerberos authentication by default
3904 - provos@cvs.openbsd.org 2000/08/02 11:27:05
3905 [sshd.8 readconf.c auth-krb4.c]
3906 disallow kerberos authentication if we can't verify the TGT; from
3907 dugsong@
3908 kerberos authentication is on by default only if you have a srvtab.
3909 - markus@cvs.openbsd.org 2000/08/04 14:30:07
3910 [auth.c]
3911 unused
3912 - markus@cvs.openbsd.org 2000/08/04 14:30:35
3913 [sshd_config]
3914 MaxStartups
3915 - markus@cvs.openbsd.org 2000/08/15 13:20:46
3916 [authfd.c]
3917 cleanup; ok niels@
3918 - markus@cvs.openbsd.org 2000/08/17 14:05:10
3919 [session.c]
3920 cleanup login(1)-like jobs, no duplicate utmp entries
3921 - markus@cvs.openbsd.org 2000/08/17 14:06:34
3922 [session.c sshd.8 sshd.c]
3923 sshd -u len, similar to telnetd
1a022229 3924 - (djm) Lastlog was not getting closed after writing login entry
39987cc0 3925 - (djm) Add Solaris package support from Rip Loomis <loomisg@cist.saic.com>
c345cf9d 3926
416ed5a7 392720000816
3928 - (djm) Replacement for inet_ntoa for Irix (which breaks on gcc)
bcbf86ec 3929 - (djm) Fix strerror replacement for old SunOS. Based on patch from
416ed5a7 3930 Charles Levert <charles@comm.polymtl.ca>
bcbf86ec 3931 - (djm) Seperate arc4random into seperate file and use OpenSSL's RC4
416ed5a7 3932 implementation.
ba606eb2 3933 - (djm) SUN_LEN macro for systems which lack it
416ed5a7 3934
dbaa2e87 393520000815
3936 - (djm) More SunOS 4.1.x fixes from Nate Itkin <nitkin@europa.com>
cd352c82 3937 - (djm) Avoid failures on Irix when ssh is not setuid. Fix from
3938 Michael Stone <mstone@cs.loyola.edu>
d93a7e5a 3939 - (djm) Don't seek in directory based lastlogs
bcbf86ec 3940 - (djm) Fix --with-ipaddr-display configure option test. Patch from
d93a7e5a 3941 Jarno Huuskonen <jhuuskon@messi.uku.fi>
2a2cb9e7 3942 - (djm) Fix AIX limits from Alexandre Oliva <oliva@lsd.ic.unicamp.br>
dbaa2e87 3943
6c33bf70 394420000813
3945 - (djm) Add $(srcdir) to includes when compiling (for VPATH). Report from
3946 Fabrice bacchella <fabrice.bacchella@marchfirst.fr>
3947
3fcce26c 394820000809
bcbf86ec 3949 - (djm) Define AIX hard limits if headers don't. Report from
3fcce26c 3950 Bill Painter <william.t.painter@lmco.com>
bcbf86ec 3951 - (djm) utmp direct write & SunOS 4 patch from Charles Levert
32eec038 3952 <charles@comm.polymtl.ca>
3fcce26c 3953
71d43804 395420000808
3955 - (djm) Cleanup Redhat RPMs. Generate keys at runtime rather than install
3956 time, spec file cleanup.
3957
f9bcea07 395820000807
378f2232 3959 - (djm) Set 0755 on binaries during install. Report from Lutz Jaenicke
47670e77 3960 - (djm) Suppress error messages on channel close shutdown() failurs
3961 works around Linux bug. Patch from Zack Weinberg <zack@wolery.cumb.org>
378f2232 3962 - (djm) Add some more entropy collection commands from Lutz Jaenicke
f9bcea07 3963
bcf89935 396420000725
3965 - (djm) Fix autoconf typo: HAVE_BINRESVPORT_AF -> HAVE_BINDRESVPORT_AF
3966
4c8722d9 396720000721
3968 - (djm) OpenBSD CVS updates:
3969 - markus@cvs.openbsd.org 2000/07/16 02:27:22
3970 [authfd.c authfd.h channels.c clientloop.c ssh-add.c ssh-agent.c ssh.c]
3971 [sshconnect1.c sshconnect2.c]
3972 make ssh-add accept dsa keys (the agent does not)
3973 - djm@cvs.openbsd.org 2000/07/17 19:25:02
3974 [sshd.c]
3975 Another closing of stdin; ok deraadt
3976 - markus@cvs.openbsd.org 2000/07/19 18:33:12
3977 [dsa.c]
3978 missing free, reorder
3979 - markus@cvs.openbsd.org 2000/07/20 16:23:14
3980 [ssh-keygen.1]
3981 document input and output files
3982
240777b8 398320000720
4c8722d9 3984 - (djm) Spec file fix from Petr Novotny <Petr.Novotny@antek.cz>
240777b8 3985
3c7def32 398620000716
4c8722d9 3987 - (djm) Release 2.1.1p4
3c7def32 3988
819b676f 398920000715
704b1659 3990 - (djm) OpenBSD CVS updates
3991 - provos@cvs.openbsd.org 2000/07/13 16:53:22
3992 [aux.c readconf.c servconf.c ssh.h]
3993 allow multiple whitespace but only one '=' between tokens, bug report from
3994 Ralf S. Engelschall <rse@engelschall.com> but different fix. okay deraadt@
3995 - provos@cvs.openbsd.org 2000/07/13 17:14:09
3996 [clientloop.c]
3997 typo; todd@fries.net
3998 - provos@cvs.openbsd.org 2000/07/13 17:19:31
3999 [scp.c]
4000 close can fail on AFS, report error; from Greg Hudson <ghudson@mit.edu>
4001 - markus@cvs.openbsd.org 2000/07/14 16:59:46
4002 [readconf.c servconf.c]
4003 allow leading whitespace. ok niels
4004 - djm@cvs.openbsd.org 2000/07/14 22:01:38
4005 [ssh-keygen.c ssh.c]
4006 Always create ~/.ssh with mode 700; ok Markus
819b676f 4007 - Fixes for SunOS 4.1.4 from Gordon Atwood <gordon@cs.ualberta.ca>
4008 - Include floatingpoint.h for entropy.c
4009 - strerror replacement
704b1659 4010
3f7a7e4a 401120000712
c37fb3c1 4012 - (djm) Remove -lresolve for Reliant Unix
3f7a7e4a 4013 - (djm) OpenBSD CVS Updates:
4014 - deraadt@cvs.openbsd.org 2000/07/11 02:11:34
4015 [session.c sshd.c ]
4016 make MaxStartups code still work with -d; djm
4017 - deraadt@cvs.openbsd.org 2000/07/11 13:17:45
4018 [readconf.c ssh_config]
4019 disable FallBackToRsh by default
c37fb3c1 4020 - (djm) Replace in_addr_t with u_int32_t in bsd-inet_aton.c. Report from
4021 Ben Lindstrom <mouring@pconline.com>
1e970014 4022 - (djm) Make building of X11-Askpass and GNOME-Askpass optional in RPM
4023 spec file.
dcb36e5d 4024 - (djm) Released 2.1.1p3
3f7a7e4a 4025
56118702 402620000711
4027 - (djm) Fixup for AIX getuserattr() support from Tom Bertelson
4028 <tbert@abac.com>
132dd316 4029 - (djm) ReliantUNIX support from Udo Schweigert <ust@cert.siemens.de>
bcbf86ec 4030 - (djm) NeXT: dirent structures to get scp working from Ben Lindstrom
c99e5056 4031 <mouring@pconline.com>
bcbf86ec 4032 - (djm) Fix broken inet_ntoa check and ut_user/ut_name confusion, report
dc2a6d09 4033 from Jim Watt <jimw@peisj.pebio.com>
2d9a148e 4034 - (djm) Replaced bsd-snprintf.c with one from Mutt source tree, it is known
4035 to compile on more platforms (incl NeXT).
cc6f2c4c 4036 - (djm) Added bsd-inet_aton and configure support for NeXT
aae19451 4037 - (djm) Misc NeXT fixes from Ben Lindstrom <mouring@pconline.com>
089fbbd2 4038 - (djm) OpenBSD CVS updates:
4039 - markus@cvs.openbsd.org 2000/06/26 03:22:29
4040 [authfd.c]
4041 cleanup, less cut&paste
4042 - markus@cvs.openbsd.org 2000/06/26 15:59:19
4043 [servconf.c servconf.h session.c sshd.8 sshd.c]
bcbf86ec 4044 MaxStartups: limit number of unauthenticated connections, work by
089fbbd2 4045 theo and me
4046 - deraadt@cvs.openbsd.org 2000/07/05 14:18:07
4047 [session.c]
4048 use no_x11_forwarding_flag correctly; provos ok
4049 - provos@cvs.openbsd.org 2000/07/05 15:35:57
4050 [sshd.c]
4051 typo
4052 - aaron@cvs.openbsd.org 2000/07/05 22:06:58
4053 [scp.1 ssh-agent.1 ssh-keygen.1 sshd.8]
bcbf86ec 4054 Insert more missing .El directives. Our troff really should identify
089fbbd2 4055 these and spit out a warning.
4056 - todd@cvs.openbsd.org 2000/07/06 21:55:04
4057 [auth-rsa.c auth2.c ssh-keygen.c]
4058 clean code is good code
4059 - deraadt@cvs.openbsd.org 2000/07/07 02:14:29
4060 [serverloop.c]
4061 sense of port forwarding flag test was backwards
4062 - provos@cvs.openbsd.org 2000/07/08 17:17:31
4063 [compat.c readconf.c]
4064 replace strtok with strsep; from David Young <dyoung@onthejob.net>
4065 - deraadt@cvs.openbsd.org 2000/07/08 19:21:15
4066 [auth.h]
4067 KNF
4068 - ho@cvs.openbsd.org 2000/07/08 19:27:33
4069 [compat.c readconf.c]
4070 Better conditions for strsep() ending.
4071 - ho@cvs.openbsd.org 2000/07/10 10:27:05
4072 [readconf.c]
4073 Get the correct message on errors. (niels@ ok)
4074 - ho@cvs.openbsd.org 2000/07/10 10:30:25
4075 [cipher.c kex.c servconf.c]
4076 strtok() --> strsep(). (niels@ ok)
5540ea9b 4077 - (djm) Fix problem with debug mode and MaxStartups
eb37534b 4078 - (djm) Don't generate host keys when $(DESTDIR) is set (e.g. during RPM
4079 builds)
229f64ee 4080 - (djm) Add strsep function from OpenBSD libc for systems that lack it
56118702 4081
a8545c6c 408220000709
4083 - (djm) Only enable PAM_TTY kludge for Linux. Problem report from
4084 Kevin Steves <stevesk@sweden.hp.com>
ec90a7d6 4085 - (djm) Match prototype and function declaration for rresvport_af.
4086 Problem report from Niklas Edmundsson <nikke@ing.umu.se>
bcbf86ec 4087 - (djm) Missing $(DESTDIR) on host-key target causing problems with RPM
732e8ac5 4088 builds. Problem report from Gregory Leblanc <GLeblanc@cu-portland.edu>
37f1df94 4089 - (djm) Replace ut_name with ut_user. Patch from Jim Watt
4090 <jimw@peisj.pebio.com>
264dce47 4091 - (djm) Fix pam sprintf fix
4092 - (djm) Cleanup entropy collection code a little more. Split initialisation
4093 from seeding, perform intialisation immediatly at start, be careful with
4094 uids. Based on problem report from Jim Watt <jimw@peisj.pebio.com>
5bf9cfe9 4095 - (djm) More NeXT compatibility from Ben Lindstrom <mouring@pconline.com>
4096 Including sigaction() et al. replacements
bcbf86ec 4097 - (djm) AIX getuserattr() session initialisation from Tom Bertelson
eeec075f 4098 <tbert@abac.com>
a8545c6c 4099
e2902a5b 410020000708
bcbf86ec 4101 - (djm) Fix bad fprintf format handling in auth-pam.c. Patch from
e2902a5b 4102 Aaron Hopkins <aaron@die.net>
7a33f831 4103 - (djm) Fix incorrect configure handling of --with-rsh-path option. Fix from
4104 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 4105 - (djm) Fixed undefined variables for OSF SIA. Report from
b3f162ba 4106 Baars, Henk <Hendrik.Baars@nl.origin-it.com>
bcbf86ec 4107 - (djm) Handle EWOULDBLOCK returns from read() and write() in atomicio.c
b28e4a3b 4108 Fix from Marquess, Steve Mr JMLFDC <Steve.Marquess@DET.AMEDD.ARMY.MIL>
bcbf86ec 4109 - (djm) Don't use inet_addr.
e2902a5b 4110
5637650d 411120000702
4112 - (djm) Fix brace mismatch from Corinna Vinschen <vinschen@cygnus.com>
27494968 4113 - (djm) Stop shadow expiry checking from preventing logins with NIS. Based
4114 on fix from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
a4070484 4115 - (djm) Use standard OpenSSL functions in auth-skey.c. Patch from
4116 Chris, the Young One <cky@pobox.com>
bcbf86ec 4117 - (djm) Fix scp progress meter on really wide terminals. Based on patch
88726b31 4118 from James H. Cloos Jr. <cloos@jhcloos.com>
5637650d 4119
388e9f9f 412020000701
4121 - (djm) Fix Tru64 SIA problems reported by John P Speno <speno@isc.upenn.edu>
daaff4d5 4122 - (djm) Login fixes from Tom Bertelson <tbert@abac.com>
82258d68 4123 - (djm) Replace "/bin/sh" with _PATH_BSHELL. Report from Corinna Vinschen
4124 <vinschen@cygnus.com>
30228d7c 4125 - (djm) Replace "/usr/bin/login" with LOGIN_PROGRAM
2647ae26 4126 - (djm) Added check for broken snprintf() functions which do not correctly
4127 terminate output string and attempt to use replacement.
46158300 4128 - (djm) Released 2.1.1p2
388e9f9f 4129
9f32ceb4 413020000628
4131 - (djm) Fixes to lastlog code for Irix
4132 - (djm) Use atomicio in loginrec
3206bb3b 4133 - (djm) Patch from Michael Stone <mstone@cs.loyola.edu> to add support for
4134 Irix 6.x array sessions, project id's, and system audit trail id.
9e0c3e1f 4135 - (djm) Added 'distprep' make target to simplify packaging
bcbf86ec 4136 - (djm) Added patch from Chris Adams <cmadams@hiwaay.net> to add OSF SIA
4d33e531 4137 support. Enable using "USE_SIA=1 ./configure [options]"
61e96248 4138
d8caae24 413920000627
4140 - (djm) Fixes to login code - not setting li->uid, cleanups
a05a70ab 4141 - (djm) Formatting
d8caae24 4142
fe30cc2e 414320000626
3e98362e 4144 - (djm) Better fix to aclocal tests from Garrick James <garrick@james.net>
4cb5ffa0 4145 - (djm) Account expiry support from Andreas Steinmetz <ast@domdv.de>
4146 - (djm) Added password expiry checking (no password change support)
be0b9bb7 4147 - (djm) Make EGD failures non-fatal if OpenSSL's entropy pool is still OK
4148 based on patch from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
b5b3f75d 4149 - (djm) Fix fixed EGD code.
3e98362e 4150 - OpenBSD CVS update
4151 - provos@cvs.openbsd.org 2000/06/25 14:17:58
4152 [channels.c]
4153 correct check for bad channel ids; from Wei Dai <weidai@eskimo.com>
4154
1c04b088 415520000623
bcbf86ec 4156 - (djm) Use sa_family_t in prototype for rresvport_af. Patch from
1c04b088 4157 Svante Signell <svante.signell@telia.com>
4158 - (djm) Autoconf logic to define sa_family_t if it is missing
e5a0294f 4159 - OpenBSD CVS Updates:
4160 - markus@cvs.openbsd.org 2000/06/22 10:32:27
4161 [sshd.c]
4162 missing atomicio; report from Steve.Marquess@DET.AMEDD.ARMY.MIL
4163 - djm@cvs.openbsd.org 2000/06/22 17:55:00
4164 [auth-krb4.c key.c radix.c uuencode.c]
4165 Missing CVS idents; ok markus
1c04b088 4166
f528fdf2 416720000622
4168 - (djm) Automatically generate host key during "make install". Suggested
4169 by Gary E. Miller <gem@rellim.com>
4170 - (djm) Paranoia before kill() system call
74fc9186 4171 - OpenBSD CVS Updates:
4172 - markus@cvs.openbsd.org 2000/06/18 18:50:11
4173 [auth2.c compat.c compat.h sshconnect2.c]
4174 make userauth+pubkey interop with ssh.com-2.2.0
4175 - markus@cvs.openbsd.org 2000/06/18 20:56:17
4176 [dsa.c]
4177 mem leak + be more paranoid in dsa_verify.
4178 - markus@cvs.openbsd.org 2000/06/18 21:29:50
4179 [key.c]
4180 cleanup fingerprinting, less hardcoded sizes
4181 - markus@cvs.openbsd.org 2000/06/19 19:39:45
4182 [atomicio.c auth-options.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c]
4183 [auth-rsa.c auth-skey.c authfd.c authfd.h authfile.c bufaux.c bufaux.h]
bcbf86ec 4184 [buffer.c buffer.h canohost.c channels.c channels.h cipher.c cipher.h]
74fc9186 4185 [clientloop.c compat.c compat.h compress.c compress.h crc32.c crc32.h]
4186 [deattack.c dispatch.c dsa.c fingerprint.c fingerprint.h getput.h hmac.c]
bcbf86ec 4187 [kex.c log-client.c log-server.c login.c match.c mpaux.c mpaux.h nchan.c]
4188 [nchan.h packet.c packet.h pty.c pty.h readconf.c readconf.h readpass.c]
74fc9186 4189 [rsa.c rsa.h scp.c servconf.c servconf.h ssh-add.c ssh-keygen.c ssh.c]
4190 [ssh.h tildexpand.c ttymodes.c ttymodes.h uidswap.c xmalloc.c xmalloc.h]
4191 OpenBSD tag
4192 - markus@cvs.openbsd.org 2000/06/21 10:46:10
4193 sshconnect2.c missing free; nuke old comment
f528fdf2 4194
e5fe9a1f 419520000620
4196 - (djm) Replace use of '-o' and '-a' logical operators in configure tests
986a22ec 4197 with '||' and '&&'. As suggested by Jim Knoble <jmknoble@jmknoble.cx>
e5fe9a1f 4198 to fix SCO Unixware problem reported by Gary E. Miller <gem@rellim.com>
c03aced4 4199 - (djm) Typo in loginrec.c
e5fe9a1f 4200
cbd7492e 420120000618
4202 - (djm) Add summary of configure options to end of ./configure run
bcbf86ec 4203 - (djm) Not all systems define RUSAGE_SELF & RUSAGE_CHILDREN. Report from
cbd7492e 4204 Michael Stone <mstone@cs.loyola.edu>
bcbf86ec 4205 - (djm) rusage is a privileged operation on some Unices (incl.
cbd7492e 4206 Solaris 2.5.1). Report from Paul D. Smith <pausmith@nortelnetworks.com>
bcbf86ec 4207 - (djm) Avoid PAM failures when running without a TTY. Report from
cbd7492e 4208 Martin Petrak <petrak@spsknm.schools.sk>
4209 - (djm) Include sys/types.h when including netinet/in.h in configure tests.
4210 Patch from Jun-ichiro itojun Hagino <itojun@iijlab.net>
729bfe59 4211 - (djm) Started merge of Ben Lindstrom's <mouring@pconline.com> NeXT support
38c295d6 4212 - OpenBSD CVS updates:
4213 - deraadt@cvs.openbsd.org 2000/06/17 09:58:46
4214 [channels.c]
4215 everyone says "nix it" (remove protocol 2 debugging message)
4216 - markus@cvs.openbsd.org 2000/06/17 13:24:34
4217 [sshconnect.c]
4218 allow extended server banners
4219 - markus@cvs.openbsd.org 2000/06/17 14:30:10
4220 [sshconnect.c]
4221 missing atomicio, typo
4222 - jakob@cvs.openbsd.org 2000/06/17 16:52:34
4223 [servconf.c servconf.h session.c sshd.8 sshd_config]
4224 add support for ssh v2 subsystems. ok markus@.
4225 - deraadt@cvs.openbsd.org 2000/06/17 18:57:48
4226 [readconf.c servconf.c]
4227 include = in WHITESPACE; markus ok
4228 - markus@cvs.openbsd.org 2000/06/17 19:09:10
4229 [auth2.c]
4230 implement bug compatibility with ssh-2.0.13 pubkey, server side
4231 - markus@cvs.openbsd.org 2000/06/17 21:00:28
4232 [compat.c]
4233 initial support for ssh.com's 2.2.0
4234 - markus@cvs.openbsd.org 2000/06/17 21:16:09
4235 [scp.c]
4236 typo
4237 - markus@cvs.openbsd.org 2000/06/17 22:05:02
4238 [auth-rsa.c auth2.c serverloop.c session.c auth-options.c auth-options.h]
4239 split auth-rsa option parsing into auth-options
4240 add options support to authorized_keys2
4241 - markus@cvs.openbsd.org 2000/06/17 22:42:54
4242 [session.c]
4243 typo
cbd7492e 4244
509b1f88 424520000613
4246 - (djm) Fixes from Andrew McGill <andrewm@datrix.co.za>:
4247 - Platform define for SCO 3.x which breaks on /dev/ptmx
4248 - Detect and try to fix missing MAXPATHLEN
a4d05724 4249 - (djm) Fix short copy in loginrec.c (based on patch from Phill Camp
4250 <P.S.S.Camp@ukc.ac.uk>
509b1f88 4251
09564242 425220000612
4253 - (djm) Glob manpages in RPM spec files to catch compressed files
4254 - (djm) Full license in auth-pam.c
08ae384f 4255 - (djm) Configure fixes from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
383207f7 4256 - (andre) AIX, lastlog, configure fixes from Tom Bertelson <tbert@abac.com>:
4257 - Don't try to retrieve lastlog from wtmp/wtmpx if DISABLE_LASTLOG is
4258 def'd
4259 - Set AIX to use preformatted manpages
61e96248 4260
74b224a0 426120000610
4262 - (djm) Minor doc tweaks
217ab55e 4263 - (djm) Fix for configure on bash2 from Jim Knoble <jmknoble@jmknoble.cx>
74b224a0 4264
32c80420 426520000609
4266 - (djm) Patch from Kenji Miyake <kenji@miyake.org> to disable utmp usage
4267 (in favour of utmpx) on Solaris 8
4268
fa649821 426920000606
48c99b2c 4270 - (djm) Cleanup of entropy.c. Reorganised code, removed second pass through
4271 list of commands (by default). Removed verbose debugging (by default).
bcbf86ec 4272 - (djm) Increased command entropy estimates and default entropy collection
48c99b2c 4273 timeout
f988dce5 4274 - (djm) Remove duplicate headers from loginrec.c
c5fa2eb0 4275 - (djm) Don't add /usr/local/lib to library search path on Irix
bcbf86ec 4276 - (djm) Fix rsh path in RPMs. Report from Jason L Tibbitts III
fa649821 4277 <tibbs@math.uh.edu>
1e83f2a2 4278 - (djm) Warn user if grabs fail in GNOME askpass. Patch from Zack Weinberg
4279 <zack@wolery.cumb.org>
fa649821 4280 - (djm) OpenBSD CVS updates:
4281 - todd@cvs.openbsd.org
4282 [sshconnect2.c]
4283 teach protocol v2 to count login failures properly and also enable an
4284 explanation of why the password prompt comes up again like v1; this is NOT
4285 crypto
61e96248 4286 - markus@cvs.openbsd.org
fa649821 4287 [readconf.c readconf.h servconf.c servconf.h session.c ssh.1 ssh.c sshd.8]
4288 xauth_location support; pr 1234
4289 [readconf.c sshconnect2.c]
4290 typo, unused
4291 [session.c]
4292 allow use_login only for login sessions, otherwise remote commands are
4293 execed with uid==0
4294 [sshd.8]
4295 document UseLogin better
4296 [version.h]
4297 OpenSSH 2.1.1
4298 [auth-rsa.c]
bcbf86ec 4299 fix match_hostname() logic for auth-rsa: deny access if we have a
fa649821 4300 negative match or no match at all
4301 [channels.c hostfile.c match.c]
bcbf86ec 4302 don't panic if mkdtemp fails for authfwd; jkb@yahoo-inc.com via
fa649821 4303 kris@FreeBSD.org
4304
8e7b16f8 430520000606
bcbf86ec 4306 - (djm) Added --with-cflags, --with-ldflags and --with-libs options to
8e7b16f8 4307 configure.
4308
d7c0f3d5 430920000604
4310 - Configure tweaking for new login code on Irix 5.3
2d6c411f 4311 - (andre) login code changes based on djm feedback
d7c0f3d5 4312
2d6c411f 431320000603
4314 - (andre) New login code
4315 - Remove bsd-login.[ch] and all the OpenBSD-derived code in login.c
4316 - Add loginrec.[ch], logintest.c and autoconf code
61e96248 4317
5daf7064 431820000531
4319 - Cleanup of auth.c, login.c and fake-*
4320 - Cleanup of auth-pam.c, save and print "account expired" error messages
e5662474 4321 - Fix EGD read bug by IWAMURO Motonori <iwa@mmp.fujitsu.co.jp>
69134b9b 4322 - Rewrote bsd-login to use proper utmp API if available. Major cleanup
4323 of fallback DIY code.
5daf7064 4324
b9f446d1 432520000530
4326 - Define atexit for old Solaris
b02ebca1 4327 - Fix buffer overrun in login.c for systems which use syslen in utmpx.
4328 patch from YOSHIFUJI Hideaki <yoshfuji@cerberus.nemoto.ecei.tohoku.ac.jp>
71276795 4329 - OpenBSD CVS updates:
4330 - markus@cvs.openbsd.org
4331 [session.c]
4332 make x11-fwd work w/ localhost (xauth add host/unix:11)
4333 [cipher.c compat.c readconf.c servconf.c]
4334 check strtok() != NULL; ok niels@
4335 [key.c]
4336 fix key_read() for uuencoded keys w/o '='
4337 [serverloop.c]
4338 group ssh1 vs. ssh2 in serverloop
4339 [kex.c kex.h myproposal.h sshconnect2.c sshd.c]
4340 split kexinit/kexdh, factor out common code
4341 [readconf.c ssh.1 ssh.c]
4342 forwardagent defaults to no, add ssh -A
4343 - theo@cvs.openbsd.org
4344 [session.c]
4345 just some line shortening
60688ef9 4346 - Released 2.1.0p3
b9f446d1 4347
29611d9c 434820000520
4349 - Xauth fix from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
25422c70 4350 - Don't touch utmp if USE_UTMPX defined
a423beaf 4351 - SunOS 4.x support from Todd C. Miller <Todd.Miller@courtesan.com>
fc1e8bf4 4352 - SIGCHLD fix for AIX and HPUX from Tom Bertelson <tbert@abac.com>
bcbf86ec 4353 - HPUX and Configure fixes from Lutz Jaenicke
fc1e8bf4 4354 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 4355 - Use mkinstalldirs script to make directories instead of non-portable
fc1e8bf4 4356 "install -d". Suggested by Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
a905808d 4357 - Doc cleanup
29611d9c 4358
301e9b01 435920000518
4360 - Include Andre Lucas' fixprogs script. Forgot to "cvs add" it yesterday
4361 - OpenBSD CVS updates:
4362 - markus@cvs.openbsd.org
4363 [sshconnect.c]
4364 copy only ai_addrlen bytes; misiek@pld.org.pl
4365 [auth.c]
bcbf86ec 4366 accept an empty shell in authentication; bug reported by
301e9b01 4367 chris@tinker.ucr.edu
4368 [serverloop.c]
4369 we don't have stderr for interactive terminal sessions (fcntl errors)
4370
ad85db64 437120000517
4372 - Fix from Andre Lucas <andre.lucas@dial.pipex.com>
4373 - Fixes command line printing segfaults (spotter: Bladt Norbert)
4374 - Fixes erroneous printing of debug messages to syslog
4375 - Fixes utmp for MacOS X (spotter: Aristedes Maniatis)
4376 - Gives useful error message if PRNG initialisation fails
4377 - Reduced ssh startup delay
4378 - Measures cumulative command time rather than the time between reads
704b1659 4379 after select()
ad85db64 4380 - 'fixprogs' perl script to eliminate non-working entropy commands, and
704b1659 4381 optionally run 'ent' to measure command entropy
c1ef8333 4382 - Applied Tom Bertelson's <tbert@abac.com> AIX authentication fix
a64009ad 4383 - Avoid WCOREDUMP complation errors for systems that lack it
bcbf86ec 4384 - Avoid SIGCHLD warnings from entropy commands
28c1d5ce 4385 - Fix HAVE_PAM_GETENVLIST setting from Simon Wilkinson <sxw@dcs.ed.ac.uk>
0e73cc53 4386 - OpenBSD CVS update:
bcbf86ec 4387 - markus@cvs.openbsd.org
0e73cc53 4388 [ssh.c]
4389 fix usage()
4390 [ssh2.h]
4391 draft-ietf-secsh-architecture-05.txt
4392 [ssh.1]
4393 document ssh -T -N (ssh2 only)
4394 [channels.c serverloop.c ssh.h sshconnect.c sshd.c aux.c]
4395 enable nonblocking IO for sshd w/ proto 1, too; split out common code
4396 [aux.c]
4397 missing include
c04f75f1 4398 - Several patches from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
4399 - INSTALL typo and URL fix
4400 - Makefile fix
4401 - Solaris fixes
bcbf86ec 4402 - Checking for ssize_t and memmove. Based on patch from SAKAI Kiyotaka
c04f75f1 4403 <ksakai@kso.netwk.ntt-at.co.jp>
afa5ee68 4404 - RSAless operation patch from kevin_oconnor@standardandpoors.com
d45e3d76 4405 - Detect OpenSSL seperatly from RSA
bcbf86ec 4406 - Better test for RSA (more compatible with RSAref). Based on work by
d45e3d76 4407 Ed Eden <ede370@stl.rural.usda.gov>
ad85db64 4408
3d1a1654 440920000513
bcbf86ec 4410 - Fix for non-recognised DSA keys from Arkadiusz Miskiewicz
3d1a1654 4411 <misiek@pld.org.pl>
4412
d02a3a00 441320000511
bcbf86ec 4414 - Fix for prng_seed permissions checking from Lutz Jaenicke
d02a3a00 4415 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
3d1a1654 4416 - "make host-key" fix for Irix
d02a3a00 4417
d0c832f3 441820000509
4419 - OpenBSD CVS update
4420 - markus@cvs.openbsd.org
4421 [cipher.h myproposal.h readconf.c readconf.h servconf.c ssh.1 ssh.c]
4422 [ssh.h sshconnect1.c sshconnect2.c sshd.8]
4423 - complain about invalid ciphers in SSH1 (e.g. arcfour is SSH2 only)
4424 - hugh@cvs.openbsd.org
4425 [ssh.1]
4426 - zap typo
4427 [ssh-keygen.1]
4428 - One last nit fix. (markus approved)
4429 [sshd.8]
4430 - some markus certified spelling adjustments
4431 - markus@cvs.openbsd.org
4432 [auth2.c channels.c clientloop.c compat compat.h dsa.c kex.c]
4433 [sshconnect2.c ]
4434 - bug compat w/ ssh-2.0.13 x11, split out bugs
4435 [nchan.c]
4436 - no drain if ibuf_empty, fixes x11fwd problems; tests by fries@
4437 [ssh-keygen.c]
4438 - handle escapes in real and original key format, ok millert@
4439 [version.h]
4440 - OpenSSH-2.1
3dc1102e 4441 - Moved all the bsd-* and fake-* stuff into new libopenbsd-compat.a
e93ee87a 4442 - Doc updates
bcbf86ec 4443 - Cleanup of bsd-base64 headers, bugfix definitions of __b64_*. Reported
21e5304a 4444 by Andre Lucas <andre.lucas@dial.pipex.com>
d0c832f3 4445
ebdeb9a8 444620000508
4447 - Makefile and RPM spec fixes
4448 - Generate DSA host keys during "make key" or RPM installs
f6cde515 4449 - OpenBSD CVS update
4450 - markus@cvs.openbsd.org
4451 [clientloop.c sshconnect2.c]
4452 - make x11-fwd interop w/ ssh-2.0.13
4453 [README.openssh2]
4454 - interop w/ SecureFX
4455 - Release 2.0.0beta2
ebdeb9a8 4456
bcbf86ec 4457 - Configure caching and cleanup patch from Andre Lucas'
58d100bf 4458 <andre.lucas@dial.pipex.com>
4459
1d1ffb87 446020000507
4461 - Remove references to SSLeay.
4462 - Big OpenBSD CVS update
4463 - markus@cvs.openbsd.org
4464 [clientloop.c]
4465 - typo
4466 [session.c]
4467 - update proctitle on pty alloc/dealloc, e.g. w/ windows client
4468 [session.c]
4469 - update proctitle for proto 1, too
4470 [channels.h nchan.c serverloop.c session.c sshd.c]
4471 - use c-style comments
4472 - deraadt@cvs.openbsd.org
4473 [scp.c]
4474 - more atomicio
bcbf86ec 4475 - markus@cvs.openbsd.org
1d1ffb87 4476 [channels.c]
4477 - set O_NONBLOCK
4478 [ssh.1]
4479 - update AUTHOR
4480 [readconf.c ssh-keygen.c ssh.h]
4481 - default DSA key file ~/.ssh/id_dsa
4482 [clientloop.c]
4483 - typo, rm verbose debug
4484 - deraadt@cvs.openbsd.org
4485 [ssh-keygen.1]
4486 - document DSA use of ssh-keygen
4487 [sshd.8]
4488 - a start at describing what i understand of the DSA side
4489 [ssh-keygen.1]
4490 - document -X and -x
4491 [ssh-keygen.c]
4492 - simplify usage
bcbf86ec 4493 - markus@cvs.openbsd.org
1d1ffb87 4494 [sshd.8]
4495 - there is no rhosts_dsa
4496 [ssh-keygen.1]
4497 - document -y, update -X,-x
4498 [nchan.c]
4499 - fix close for non-open ssh1 channels
4500 [servconf.c servconf.h ssh.h sshd.8 sshd.c ]
4501 - s/DsaKey/HostDSAKey/, document option
4502 [sshconnect2.c]
4503 - respect number_of_password_prompts
4504 [channels.c channels.h servconf.c servconf.h session.c sshd.8]
4505 - GatewayPorts for sshd, ok deraadt@
4506 [ssh-add.1 ssh-agent.1 ssh.1]
4507 - more doc on: DSA, id_dsa, known_hosts2, authorized_keys2
4508 [ssh.1]
4509 - more info on proto 2
4510 [sshd.8]
4511 - sync AUTHOR w/ ssh.1
4512 [key.c key.h sshconnect.c]
4513 - print key type when talking about host keys
4514 [packet.c]
4515 - clear padding in ssh2
4516 [dsa.c key.c radix.c ssh.h sshconnect1.c uuencode.c uuencode.h]
4517 - replace broken uuencode w/ libc b64_ntop
4518 [auth2.c]
4519 - log failure before sending the reply
4520 [key.c radix.c uuencode.c]
4521 - remote trailing comments before calling __b64_pton
4522 [auth2.c readconf.c readconf.h servconf.c servconf.h ssh.1]
4523 [sshconnect2.c sshd.8]
4524 - add DSAAuthetication option to ssh/sshd, document SSH2 in sshd.8
4525 - Bring in b64_ntop and b64_pton from OpenBSD libc (bsd-base64.[ch])
4526
1a11e1ae 452720000502
0fbe8c74 4528 - OpenBSD CVS update
4529 [channels.c]
4530 - init all fds, close all fds.
4531 [sshconnect2.c]
4532 - check whether file exists before asking for passphrase
4533 [servconf.c servconf.h sshd.8 sshd.c]
4534 - PidFile, pr 1210
4535 [channels.c]
4536 - EINTR
4537 [channels.c]
4538 - unbreak, ok niels@
4539 [sshd.c]
4540 - unlink pid file, ok niels@
4541 [auth2.c]
4542 - Add missing #ifdefs; ok - markus
bcbf86ec 4543 - Add Andre Lucas' <andre.lucas@dial.pipex.com> patch to read entropy
d3083fbd 4544 gathering commands from a text file
1a11e1ae 4545 - Release 2.0.0beta1
4546
c4bc58eb 454720000501
4548 - OpenBSD CVS update
4549 [packet.c]
4550 - send debug messages in SSH2 format
3189621b 4551 [scp.c]
4552 - fix very rare EAGAIN/EINTR issues; based on work by djm
4553 [packet.c]
4554 - less debug, rm unused
4555 [auth2.c]
4556 - disable kerb,s/key in ssh2
4557 [sshd.8]
4558 - Minor tweaks and typo fixes.
4559 [ssh-keygen.c]
4560 - Put -d into usage and reorder. markus ok.
bcbf86ec 4561 - Include missing headers for OpenSSL tests. Fix from Phil Karn
44fb55e9 4562 <karn@ka9q.ampr.org>
bcbf86ec 4563 - Fixed __progname symbol collisions reported by Andre Lucas
3fd95d9a 4564 <andre.lucas@dial.pipex.com>
0d5f7abc 4565 - Merged bsd-login ttyslot and AIX utmp patch from Gert Doering
4566 <gd@hilb1.medat.de>
8cb940db 4567 - Add some missing ifdefs to auth2.c
8af50c98 4568 - Deprecate perl-tk askpass.
52bcc044 4569 - Irix portability fixes - don't include netinet headers more than once
4570 - Make sure we don't save PRNG seed more than once
c4bc58eb 4571
2b763e31 457220000430
4573 - Merge HP-UX fixes and TCB support from Ged Lodder <lodder@yacc.com.au>
b7a87eea 4574 - Integrate Andre Lucas' <andre.lucas@dial.pipex.com> entropy collection
4575 patch.
4576 - Adds timeout to entropy collection
4577 - Disables slow entropy sources
4578 - Load and save seed file
bcbf86ec 4579 - Changed entropy seed code to user per-user seeds only (server seed is
b7a87eea 4580 saved in root's .ssh directory)
4581 - Use atexit() and fatal cleanups to save seed on exit
0b242b12 4582 - More OpenBSD updates:
4583 [session.c]
4584 - don't call chan_write_failed() if we are not writing
4585 [auth-rsa.c auth1.c authfd.c hostfile.c ssh-agent.c]
4586 - keysize warnings error() -> log()
2b763e31 4587
a306f2dd 458820000429
4589 - Merge big update to OpenSSH-2.0 from OpenBSD CVS
4590 [README.openssh2]
4591 - interop w/ F-secure windows client
4592 - sync documentation
4593 - ssh_host_dsa_key not ssh_dsa_key
4594 [auth-rsa.c]
4595 - missing fclose
4596 [auth.c authfile.c compat.c dsa.c dsa.h hostfile.c key.c key.h radix.c]
4597 [readconf.c readconf.h ssh-add.c ssh-keygen.c ssh.c ssh.h sshconnect.c]
4598 [sshd.c uuencode.c uuencode.h authfile.h]
4599 - add DSA pubkey auth and other SSH2 fixes. use ssh-keygen -[xX]
4600 for trading keys with the real and the original SSH, directly from the
4601 people who invented the SSH protocol.
4602 [auth.c auth.h authfile.c sshconnect.c auth1.c auth2.c sshconnect.h]
4603 [sshconnect1.c sshconnect2.c]
4604 - split auth/sshconnect in one file per protocol version
4605 [sshconnect2.c]
4606 - remove debug
4607 [uuencode.c]
4608 - add trailing =
4609 [version.h]
4610 - OpenSSH-2.0
4611 [ssh-keygen.1 ssh-keygen.c]
4612 - add -R flag: exit code indicates if RSA is alive
4613 [sshd.c]
4614 - remove unused
4615 silent if -Q is specified
4616 [ssh.h]
4617 - host key becomes /etc/ssh_host_dsa_key
4618 [readconf.c servconf.c ]
4619 - ssh/sshd default to proto 1 and 2
4620 [uuencode.c]
4621 - remove debug
4622 [auth2.c ssh-keygen.c sshconnect2.c sshd.c]
4623 - xfree DSA blobs
4624 [auth2.c serverloop.c session.c]
4625 - cleanup logging for sshd/2, respect PasswordAuth no
4626 [sshconnect2.c]
4627 - less debug, respect .ssh/config
4628 [README.openssh2 channels.c channels.h]
bcbf86ec 4629 - clientloop.c session.c ssh.c
a306f2dd 4630 - support for x11-fwding, client+server
4631
0ac7199f 463220000421
4633 - Merge fix from OpenBSD CVS
4634 [ssh-agent.c]
4635 - Fix memory leak per connection. Report from Andy Spiegl <Andy@Spiegl.de>
4636 via Debian bug #59926
18ba2aab 4637 - Define __progname in session.c if libc doesn't
4638 - Remove indentation on autoconf #include statements to avoid bug in
bcbf86ec 4639 DEC Tru64 compiler. Report and fix from David Del Piero
18ba2aab 4640 <David.DelPiero@qed.qld.gov.au>
0ac7199f 4641
e1b37056 464220000420
bcbf86ec 4643 - Make fixpaths work with perl4, patch from Andre Lucas
e1b37056 4644 <andre.lucas@dial.pipex.com>
9da5c3c9 4645 - Sync with OpenBSD CVS:
4646 [clientloop.c login.c serverloop.c ssh-agent.c ssh.h sshconnect.c sshd.c]
4647 - pid_t
4648 [session.c]
4649 - remove bogus chan_read_failed. this could cause data
4650 corruption (missing data) at end of a SSH2 session.
4e577b89 4651 - Merge fixes from Debian patch from Phil Hands <phil@hands.com>
4652 - Allow setting of PAM service name through CFLAGS (SSHD_PAM_SERVICE)
4653 - Use vhangup to clean up Linux ttys
4654 - Force posix getopt processing on GNU libc systems
371ecff9 4655 - Debian bug #55910 - remove references to ssl(8) manpages
247f1a89 4656 - Debian bug #58031 - ssh_config lies about default cipher
e1b37056 4657
d6f24e45 465820000419
4659 - OpenBSD CVS updates
4660 [channels.c]
4661 - fix pr 1196, listen_port and port_to_connect interchanged
4662 [scp.c]
bcbf86ec 4663 - after completion, replace the progress bar ETA counter with a final
d6f24e45 4664 elapsed time; my idea, aaron wrote the patch
4665 [ssh_config sshd_config]
4666 - show 'Protocol' as an example, ok markus@
4667 [sshd.c]
4668 - missing xfree()
4669 - Add missing header to bsd-misc.c
4670
35484284 467120000416
4672 - Reduce diff against OpenBSD source
bcbf86ec 4673 - All OpenSSL includes are now unconditionally referenced as
35484284 4674 openssl/foo.h
4675 - Pick up formatting changes
4676 - Other minor changed (typecasts, etc) that I missed
4677
6ae2364d 467820000415
4679 - OpenBSD CVS updates.
4680 [ssh.1 ssh.c]
4681 - ssh -2
4682 [auth.c channels.c clientloop.c packet.c packet.h serverloop.c]
4683 [session.c sshconnect.c]
4684 - check payload for (illegal) extra data
4685 [ALL]
4686 whitespace cleanup
4687
c323ac76 468820000413
4689 - INSTALL doc updates
f54651ce 4690 - Merged OpenBSD updates to include paths.
bcbf86ec 4691
a8be9f80 469220000412
4693 - OpenBSD CVS updates:
4694 - [channels.c]
4695 repair x11-fwd
4696 - [sshconnect.c]
4697 fix passwd prompt for ssh2, less debugging output.
4698 - [clientloop.c compat.c dsa.c kex.c sshd.c]
4699 less debugging output
4700 - [kex.c kex.h sshconnect.c sshd.c]
4701 check for reasonable public DH values
4702 - [README.openssh2 cipher.c cipher.h compat.c compat.h readconf.c]
4703 [readconf.h servconf.c servconf.h ssh.c ssh.h sshconnect.c sshd.c]
4704 add Cipher and Protocol options to ssh/sshd, e.g.:
4705 ssh -o 'Protocol 1,2' if you prefer proto 1, ssh -o 'Ciphers
4706 arcfour,3des-cbc'
4707 - [sshd.c]
4708 print 1.99 only if server supports both
4709
18e92801 471020000408
4711 - Avoid some compiler warnings in fake-get*.c
4712 - Add IPTOS macros for systems which lack them
9d98aaf6 4713 - Only set define entropy collection macros if they are found
e78a59f5 4714 - More large OpenBSD CVS updates:
4715 - [auth.c auth.h servconf.c servconf.h serverloop.c session.c]
4716 [session.h ssh.h sshd.c README.openssh2]
4717 ssh2 server side, see README.openssh2; enable with 'sshd -2'
4718 - [channels.c]
4719 no adjust after close
4720 - [sshd.c compat.c ]
4721 interop w/ latest ssh.com windows client.
61e96248 4722
8ce64345 472320000406
4724 - OpenBSD CVS update:
4725 - [channels.c]
4726 close efd on eof
4727 - [clientloop.c compat.c ssh.c sshconnect.c myproposal.h]
4728 ssh2 client implementation, interops w/ ssh.com and lsh servers.
4729 - [sshconnect.c]
4730 missing free.
4731 - [authfile.c cipher.c cipher.h packet.c sshconnect.c sshd.c]
4732 remove unused argument, split cipher_mask()
4733 - [clientloop.c]
4734 re-order: group ssh1 vs. ssh2
4735 - Make Redhat spec require openssl >= 0.9.5a
4736
e7627112 473720000404
4738 - Add tests for RAND_add function when searching for OpenSSL
7e7327a1 4739 - OpenBSD CVS update:
4740 - [packet.h packet.c]
4741 ssh2 packet format
4742 - [packet.h packet.c nchan2.ms nchan.h compat.h compat.c]
4743 [channels.h channels.c]
4744 channel layer support for ssh2
4745 - [kex.h kex.c hmac.h hmac.c dsa.c dsa.h]
4746 DSA, keyexchange, algorithm agreement for ssh2
6c081128 4747 - Generate manpages before make install not at the end of make all
4748 - Don't seed the rng quite so often
4749 - Always reseed rng when requested
e7627112 4750
bfc9a610 475120000403
4752 - Wrote entropy collection routines for systems that lack /dev/random
4753 and EGD
837c30b8 4754 - Disable tests and typedefs for 64 bit types. They are currently unused.
bfc9a610 4755
7368a6c8 475620000401
4757 - Big OpenBSD CVS update (mainly beginnings of SSH2 infrastructure)
4758 - [auth.c session.c sshd.c auth.h]
4759 split sshd.c -> auth.c session.c sshd.c plus cleanup and goto-removal
4760 - [bufaux.c bufaux.h]
4761 support ssh2 bignums
4762 - [channels.c channels.h clientloop.c sshd.c nchan.c nchan.h packet.c]
4763 [readconf.c ssh.c ssh.h serverloop.c]
4764 replace big switch() with function tables (prepare for ssh2)
4765 - [ssh2.h]
4766 ssh2 message type codes
4767 - [sshd.8]
4768 reorder Xr to avoid cutting
4769 - [serverloop.c]
4770 close(fdin) if fdin != fdout, shutdown otherwise, ok theo@
4771 - [channels.c]
4772 missing close
4773 allow bigger packets
4774 - [cipher.c cipher.h]
4775 support ssh2 ciphers
4776 - [compress.c]
4777 cleanup, less code
4778 - [dispatch.c dispatch.h]
4779 function tables for different message types
4780 - [log-server.c]
4781 do not log() if debuggin to stderr
4782 rename a cpp symbol, to avoid param.h collision
4783 - [mpaux.c]
4784 KNF
4785 - [nchan.c]
4786 sync w/ channels.c
4787
f5238bee 478820000326
4789 - Better tests for OpenSSL w/ RSAref
bcbf86ec 4790 - Added replacement setenv() function from OpenBSD libc. Suggested by
f5238bee 4791 Ben Lindstrom <mouring@pconline.com>
4fe2af09 4792 - OpenBSD CVS update
4793 - [auth-krb4.c]
4794 -Wall
4795 - [auth-rh-rsa.c auth-rsa.c hostfile.c hostfile.h key.c key.h match.c]
4796 [match.h ssh.c ssh.h sshconnect.c sshd.c]
4797 initial support for DSA keys. ok deraadt@, niels@
4798 - [cipher.c cipher.h]
4799 remove unused cipher_attack_detected code
4800 - [scp.1 ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
4801 Fix some formatting problems I missed before.
4802 - [ssh.1 sshd.8]
4803 fix spelling errors, From: FreeBSD
4804 - [ssh.c]
4805 switch to raw mode only if he _get_ a pty (not if we _want_ a pty).
f5238bee 4806
0024a081 480720000324
4808 - Released 1.2.3
4809
bd499f9e 481020000317
4811 - Clarified --with-default-path option.
4812 - Added -blibpath handling for AIX to work around stupid runtime linking.
4813 Problem elucidated by gshapiro@SENDMAIL.ORG by way of Jim Knoble
986a22ec 4814 <jmknoble@jmknoble.cx>
474b5fef 4815 - Checks for 64 bit int types. Problem report from Mats Fredholm
4816 <matsf@init.se>
610cd5c6 4817 - OpenBSD CVS updates:
bcbf86ec 4818 - [atomicio.c auth-krb4.c bufaux.c channels.c compress.c fingerprint.c]
610cd5c6 4819 [packet.h radix.c rsa.c scp.c ssh-agent.c ssh-keygen.c sshconnect.c]
4820 [sshd.c]
4821 pedantic: signed vs. unsigned, void*-arithm, etc
4822 - [ssh.1 sshd.8]
4823 Various cleanups and standardizations.
bcbf86ec 4824 - Runtime error fix for HPUX from Otmar Stahl
be48d23c 4825 <O.Stahl@lsw.uni-heidelberg.de>
bd499f9e 4826
4696775a 482720000316
bcbf86ec 4828 - Fixed configure not passing LDFLAGS to Solaris. Report from David G.
4696775a 4829 Hesprich <dghespri@sprintparanet.com>
d423d822 4830 - Propogate LD through to Makefile
b7a9ce47 4831 - Doc cleanups
2ba2a610 4832 - Added blurb about "scp: command not found" errors to UPGRADING
4696775a 4833
cb0b7ea4 483420000315
4835 - Fix broken CFLAGS handling during search for OpenSSL. Fixes va_list
4836 problems with gcc/Solaris.
bcbf86ec 4837 - Don't free argument to putenv() after use (in setenv() replacement).
db55a3ea 4838 Report from Seigo Tanimura <tanimura@r.dl.itc.u-tokyo.ac.jp>
bcbf86ec 4839 - Created contrib/ subdirectory. Included helpers from Phil Hands'
13652e52 4840 Debian package, README file and chroot patch from Ricardo Cerqueira
4841 <rmcc@clix.pt>
bcbf86ec 4842 - Moved gnome-ssh-askpass.c to contrib directory and removed config
13652e52 4843 option.
4844 - Slight cleanup to doc files
b14b2ae7 4845 - Configure fix from Bratislav ILICH <bilic@zepter.ru>
cb0b7ea4 4846
a8ed9fd9 484720000314
bcbf86ec 4848 - Include macro for IN6_IS_ADDR_V4MAPPED. Report from
a8ed9fd9 4849 peter@frontierflying.com
84afc958 4850 - Include /usr/local/include and /usr/local/lib for systems that don't
4851 do it themselves
4852 - -R/usr/local/lib for Solaris
4853 - Fix RSAref detection
4854 - Fix IN6_IS_ADDR_V4MAPPED macro
a8ed9fd9 4855
bcf36c78 485620000311
4857 - Detect RSAref
43e48848 4858 - OpenBSD CVS change
4859 [sshd.c]
4860 - disallow guessing of root password
867dbf40 4861 - More configure fixes
80faa19f 4862 - IPv6 workarounds from Hideaki YOSHIFUJI <yoshfuji@ecei.tohoku.ac.jp>
bcf36c78 4863
c8d54615 486420000309
4865 - OpenBSD CVS updates to v1.2.3
704b1659 4866 [ssh.h atomicio.c]
4867 - int atomicio -> ssize_t (for alpha). ok deraadt@
4868 [auth-rsa.c]
4869 - delay MD5 computation until client sends response, free() early, cleanup.
4870 [cipher.c]
4871 - void* -> unsigned char*, ok niels@
4872 [hostfile.c]
4873 - remove unused variable 'len'. fix comments.
4874 - remove unused variable
4875 [log-client.c log-server.c]
4876 - rename a cpp symbol, to avoid param.h collision
4877 [packet.c]
4878 - missing xfree()
4879 - getsockname() requires initialized tolen; andy@guildsoftware.com
4880 - use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
4881 from Holger.Trapp@Informatik.TU-Chemnitz.DE
4882 [pty.c pty.h]
bcbf86ec 4883 - register cleanup for pty earlier. move code for pty-owner handling to
c8d54615 4884 pty.c ok provos@, dugsong@
704b1659 4885 [readconf.c]
4886 - turn off x11-fwd for the client, too.
4887 [rsa.c]
4888 - PKCS#1 padding
4889 [scp.c]
4890 - allow '.' in usernames; from jedgar@fxp.org
4891 [servconf.c]
4892 - typo: ignore_user_known_hosts int->flag; naddy@mips.rhein-neckar.de
4893 - sync with sshd_config
4894 [ssh-keygen.c]
4895 - enable ssh-keygen -l -f ~/.ssh/known_hosts, ok deraadt@
4896 [ssh.1]
4897 - Change invalid 'CHAT' loglevel to 'VERBOSE'
4898 [ssh.c]
4899 - suppress AAAA query host when '-4' is used; from shin@nd.net.fujitsu.co.jp
4900 - turn off x11-fwd for the client, too.
4901 [sshconnect.c]
4902 - missing xfree()
4903 - retry rresvport_af(), too. from sumikawa@ebina.hitachi.co.jp.
4904 - read error vs. "Connection closed by remote host"
4905 [sshd.8]
4906 - ie. -> i.e.,
4907 - do not link to a commercial page..
4908 - sync with sshd_config
4909 [sshd.c]
4910 - no need for poll.h; from bright@wintelcom.net
4911 - log with level log() not fatal() if peer behaves badly.
4912 - don't panic if client behaves strange. ok deraadt@
4913 - make no-port-forwarding for RSA keys deny both -L and -R style fwding
4914 - delay close() of pty until the pty has been chowned back to root
4915 - oops, fix comment, too.
4916 - missing xfree()
4917 - move XAUTHORITY to subdir. ok dugsong@. fixes debian bug #57907, too.
4918 (http://cgi.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=57907)
bcbf86ec 4919 - register cleanup for pty earlier. move code for pty-owner handling to
704b1659 4920 pty.c ok provos@, dugsong@
4921 - create x11 cookie file
4922 - fix pr 1113, fclose() -> pclose(), todo: remote popen()
4923 - version 1.2.3
c8d54615 4924 - Cleaned up
bcbf86ec 4925 - Removed warning workaround for Linux and devpts filesystems (no longer
d8223847 4926 required after OpenBSD updates)
c8d54615 4927
07055445 492820000308
4929 - Configure fix from Hiroshi Takekawa <takekawa@sr3.t.u-tokyo.ac.jp>
4930
493120000307
4932 - Released 1.2.2p1
4933
9c8c3fc6 493420000305
4935 - Fix DEC compile fix
54096dcc 4936 - Explicitly seed OpenSSL's PRNG before checking rsa_alive()
aa6bd60a 4937 - Check for getpagesize in libucb.a if not found in libc. Fix for old
4938 Solaris from Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 4939 - Check for libwrap if --with-tcp-wrappers option specified. Suggestion
9fc7867e 4940 Mate Wierdl <mw@moni.msci.memphis.edu>
9c8c3fc6 4941
6bf4d066 494220000303
4943 - Added "make host-key" target, Suggestion from Dominik Brettnacher
4944 <domi@saargate.de>
bcbf86ec 4945 - Don't permanently fail on bind() if getaddrinfo has more choices left for
16218745 4946 us. Needed to work around messy IPv6 on Linux. Patch from Arkadiusz
4947 Miskiewicz <misiek@pld.org.pl>
22fa590f 4948 - DEC Unix compile fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
4949 - Manpage fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
6bf4d066 4950
a0391976 495120000302
4952 - Big cleanup of autoconf code
4953 - Rearranged to be a little more logical
4954 - Added -R option for Solaris
4955 - Rewrote OpenSSL detection code. Now uses AC_TRY_RUN with a test program
4956 to detect library and header location _and_ ensure library has proper
4957 RSA support built in (this is a problem with OpenSSL 0.9.5).
817175bc 4958 - Applied pty cleanup patch from markus.friedl@informatik.uni-erlangen.de
0a1718dc 4959 - Avoid warning message with Unix98 ptys
bcbf86ec 4960 - Warning was valid - possible race condition on PTYs. Avoided using
3276571c 4961 platform-specific code.
4962 - Document some common problems
bcbf86ec 4963 - Allow root access to any key. Patch from
81eef326 4964 markus.friedl@informatik.uni-erlangen.de
a0391976 4965
f55afe71 496620000207
4967 - Removed SOCKS code. Will support through a ProxyCommand.
4968
d07d1c58 496920000203
4970 - Fixed SEGVs in authloop, fix from vbzoli@hbrt.hu
d581b7ae 4971 - Add --with-ssl-dir option
d07d1c58 4972
9d5f374b 497320000202
bcbf86ec 4974 - Fix lastlog code for directory based lastlogs. Fix from Josh Durham
9d5f374b 4975 <jmd@aoe.vt.edu>
6b1f3fdb 4976 - Documentation fixes from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 4977 - Added URLs to Japanese translations of documents by HARUYAMA Seigo
6b1f3fdb 4978 <haruyama@nt.phys.s.u-tokyo.ac.jp>
9d5f374b 4979
bc8c2601 498020000201
4981 - Use socket pairs by default (instead of pipes). Prevents race condition
4982 on several (buggy) OSs. Report and fix from tridge@linuxcare.com
4983
69c76614 498420000127
4985 - Seed OpenSSL's random number generator before generating RSA keypairs
4986 - Split random collector into seperate file
aaf2abd7 4987 - Compile fix from Andre Lucas <andre.lucas@dial.pipex.com>
69c76614 4988
f9507c24 498920000126
4990 - Released 1.2.2 stable
4991
bcbf86ec 4992 - NeXT keeps it lastlog in /usr/adm. Report from
f9507c24 4993 mouring@newton.pconline.com
bcbf86ec 4994 - Added note in UPGRADING re interop with commercial SSH using idea.
986a22ec 4995 Report from Jim Knoble <jmknoble@jmknoble.cx>
587120ad 4996 - Fix linking order for Kerberos/AFS. Fix from Holget Trapp
4997 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
f9507c24 4998
bfae20ad 499920000125
bcbf86ec 5000 - Fix NULL pointer dereference in login.c. Fix from Andre Lucas
bfae20ad 5001 <andre.lucas@dial.pipex.com>
07b0cb78 5002 - Reorder PAM initialisation so it does not mess up lastlog. Reported
5003 by Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 5004 - Use preformatted manpages on SCO, report from Gary E. Miller
9755cbdb 5005 <gem@rellim.com>
5006 - New URL for x11-ssh-askpass.
bcbf86ec 5007 - Fixpaths was missing /etc/ssh_known_hosts. Report from Jim Knoble
986a22ec 5008 <jmknoble@jmknoble.cx>
bcbf86ec 5009 - Added 'DESTDIR' option to Makefile to ease package building. Patch from
986a22ec 5010 Jim Knoble <jmknoble@jmknoble.cx>
ff8ecdb8 5011 - Updated RPM spec files to use DESTDIR
bfae20ad 5012
bb58aa4b 501320000124
5014 - Pick up version 1.2.2 from OpenBSD CVS (no changes, just version number
5015 increment)
5016
d45317d8 501720000123
5018 - OpenBSD CVS:
5019 - [packet.c]
5020 getsockname() requires initialized tolen; andy@guildsoftware.com
bcbf86ec 5021 - AIX patch from Matt Richards <v2matt@btv.ibm.com> and David Rankin
4c40f834 5022 <drankin@bohemians.lexington.ky.us>
12aa90af 5023 - Fix lastlog support, patch from Andre Lucas <andre.lucas@dial.pipex.com>
d45317d8 5024
e844f761 502520000122
5026 - Fix compilation of bsd-snprintf.c on Solaris, fix from Ben Taylor
5027 <bent@clark.net>
c54a6257 5028 - Merge preformatted manpage patch from Andre Lucas
5029 <andre.lucas@dial.pipex.com>
8eb34e02 5030 - Make IPv4 use the default in RPM packages
5031 - Irix uses preformatted manpages
1e64903d 5032 - Missing htons() in bsd-bindresvport.c, fix from Holger Trapp
5033 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
9bc5ddfe 5034 - OpenBSD CVS updates:
5035 - [packet.c]
5036 use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
5037 from Holger.Trapp@Informatik.TU-Chemnitz.DE
5038 - [sshd.c]
5039 log with level log() not fatal() if peer behaves badly.
5040 - [readpass.c]
bcbf86ec 5041 instead of blocking SIGINT, catch it ourselves, so that we can clean
5042 the tty modes up and kill ourselves -- instead of our process group
61e96248 5043 leader (scp, cvs, ...) going away and leaving us in noecho mode.
9bc5ddfe 5044 people with cbreak shells never even noticed..
399d9d44 5045 - [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
5046 ie. -> i.e.,
e844f761 5047
4c8ef3fb 504820000120
5049 - Don't use getaddrinfo on AIX
7b2ea3a1 5050 - Update to latest OpenBSD CVS:
5051 - [auth-rsa.c]
5052 - fix user/1056, sshd keeps restrictions; dbt@meat.net
5053 - [sshconnect.c]
5054 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
5055 - destroy keys earlier
bcbf86ec 5056 - split key exchange (kex) and user authentication (user-auth),
d468fc76 5057 ok: provos@
7b2ea3a1 5058 - [sshd.c]
5059 - no need for poll.h; from bright@wintelcom.net
5060 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
bcbf86ec 5061 - split key exchange (kex) and user authentication (user-auth),
d468fc76 5062 ok: provos@
f3bba493 5063 - Big manpage and config file cleanup from Andre Lucas
5064 <andre.lucas@dial.pipex.com>
5f4fdfae 5065 - Re-added latest (unmodified) OpenBSD manpages
47f9a56a 5066 - Doc updates
d468fc76 5067 - NetBSD patch from David Rankin <drankin@bohemians.lexington.ky.us> and
5068 Christos Zoulas <christos@netbsd.org>
4c8ef3fb 5069
082bbfb3 507020000119
20af321f 5071 - SCO compile fixes from Gary E. Miller <gem@rellim.com>
082bbfb3 5072 - Compile fix from Darren_Hall@progressive.com
59e76f33 5073 - Linux/glibc-2.1.2 takes a *long* time to look up names for AF_UNSPEC
5074 addresses using getaddrinfo(). Added a configure switch to make the
5075 default lookup mode AF_INET
082bbfb3 5076
a63a7f37 507720000118
5078 - Fixed --with-pid-dir option
51a6baf8 5079 - Makefile fix from Gary E. Miller <gem@rellim.com>
61e96248 5080 - Compile fix for HPUX and Solaris from Andre Lucas
976f7e19 5081 <andre.lucas@dial.pipex.com>
a63a7f37 5082
f914c7fb 508320000117
5084 - Clean up bsd-bindresvport.c. Use arc4random() for picking initial
5085 port, ignore EINVAL errors (Linux) when searching for free port.
bcbf86ec 5086 - Revert __snprintf -> snprintf aliasing. Apparently Solaris
de93b046 5087 __snprintf isn't. Report from Theo de Raadt <theo@cvs.openbsd.org>
9b363e1c 5088 - Document location of Redhat PAM file in INSTALL.
bcbf86ec 5089 - Fixed X11 forwarding bug on Linux. libc advertises AF_INET6
5090 INADDR_ANY_INIT addresses via getaddrinfo, but may not be able to
f4a7cf29 5091 deliver (no IPv6 kernel support)
80a44451 5092 - Released 1.2.1pre27
f914c7fb 5093
f4a7cf29 5094 - Fix rresvport_af failure errors (logic error in bsd-bindresvport.c)
bcbf86ec 5095 - Fix --with-ipaddr-display option test. Fix from Jarno Huuskonen
cf8ad170 5096 <jhuuskon@hytti.uku.fi>
bcbf86ec 5097 - Fix hang on logout if processes are still using the pty. Needs
691a8a9f 5098 further testing.
5957fd29 5099 - Patch from Christos Zoulas <christos@zoulas.com>
5100 - Try $prefix first when looking for OpenSSL.
5101 - Include sys/types.h when including sys/socket.h in test programs
bcbf86ec 5102 - Substitute PID directory in sshd.8. Suggestion from Andrew
19d9ac2a 5103 Stribblehill <a.d.stribblehill@durham.ac.uk>
f4a7cf29 5104
47e45e44 510520000116
5106 - Renamed --with-xauth-path to --with-xauth
5107 - Added --with-pid-dir option
5108 - Released 1.2.1pre26
5109
a82ef8ae 5110 - Compilation fix from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
bcbf86ec 5111 - Fixed broken bugfix for /dev/ptmx on Linux systems which lack
66be05a1 5112 openpty(). Report from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
a82ef8ae 5113
5cdfe03f 511420000115
5115 - Add --with-xauth-path configure directive and explicit test for
bcbf86ec 5116 /usr/openwin/bin/xauth for Solaris systems. Report from Anders
5cdfe03f 5117 Nordby <anders@fix.no>
bcbf86ec 5118 - Fix incorrect detection of /dev/ptmx on Linux systems that lack
5cdfe03f 5119 openpty. Report from John Seifarth <john@waw.be>
5120 - Look for intXX_t and u_intXX_t in sys/bitypes.h if they are not in
bcbf86ec 5121 sys/types.h. Fixes problems on SCO, report from Gary E. Miller
5cdfe03f 5122 <gem@rellim.com>
5123 - Use __snprintf and __vnsprintf if they are found where snprintf and
5124 vnsprintf are lacking. Suggested by Ben Taylor <bent@shell.clark.net>
5125 and others.
5126
48e671d5 512720000114
5128 - Merged OpenBSD IPv6 patch:
5129 - [sshd.c sshd.8 sshconnect.c ssh.h ssh.c servconf.h servconf.c scp.1]
5130 [scp.c packet.h packet.c login.c log.c canohost.c channels.c]
5131 [hostfile.c sshd_config]
5132 ipv6 support: mostly gethostbyname->getaddrinfo/getnameinfo, new
bcbf86ec 5133 features: sshd allows multiple ListenAddress and Port options. note
5134 that libwrap is not IPv6-ready. (based on patches from
48e671d5 5135 fujiwara@rcac.tdi.co.jp)
5136 - [ssh.c canohost.c]
bcbf86ec 5137 more hints (hints.ai_socktype=SOCK_STREAM) for getaddrinfo,
48e671d5 5138 from itojun@
5139 - [channels.c]
5140 listen on _all_ interfaces for X11-Fwd (hints.ai_flags = AI_PASSIVE)
5141 - [packet.h]
5142 allow auth-kerberos for IPv4 only
5143 - [scp.1 sshd.8 servconf.h scp.c]
5144 document -4, -6, and 'ssh -L 2022/::1/22'
5145 - [ssh.c]
bcbf86ec 5146 'ssh @host' is illegal (null user name), from
48e671d5 5147 karsten@gedankenpolizei.de
5148 - [sshconnect.c]
5149 better error message
5150 - [sshd.c]
5151 allow auth-kerberos for IPv4 only
5152 - Big IPv6 merge:
5153 - Cleanup overrun in sockaddr copying on RHL 6.1
5154 - Replacements for getaddrinfo, getnameinfo, etc based on versions
5155 from patch from KIKUCHI Takahiro <kick@kyoto.wide.ad.jp>
5156 - Replacement for missing structures on systems that lack IPv6
5157 - record_login needed to know about AF_INET6 addresses
5158 - Borrowed more code from OpenBSD: rresvport_af and requisites
5159
2598df62 516020000110
5161 - Fixes to auth-skey to enable it to use the standard OpenSSL libraries
5162
b8a0310d 516320000107
5164 - New config.sub and config.guess to fix problems on SCO. Supplied
5165 by Gary E. Miller <gem@rellim.com>
b6a98a85 5166 - SCO build fix from Gary E. Miller <gem@rellim.com>
2598df62 5167 - Released 1.2.1pre25
b8a0310d 5168
dfb95100 516920000106
5170 - Documentation update & cleanup
5171 - Better KrbIV / AFS detection, based on patch from:
5172 Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
5173
b9795b89 517420000105
bcbf86ec 5175 - Fixed annoying DES corruption problem. libcrypt has been
b9795b89 5176 overriding symbols in libcrypto. Removed libcrypt and crypt.h
5177 altogether (libcrypto includes its own crypt(1) replacement)
5178 - Added platform-specific rules for Irix 6.x. Included warning that
5179 they are untested.
5180
a1ec4d79 518120000103
5182 - Add explicit make rules for files proccessed by fixpaths.
61e96248 5183 - Fix "make install" in RPM spec files. Report from Tenkou N. Hattori
a1ec4d79 5184 <tnh@kondara.org>
bcbf86ec 5185 - Removed "nullok" directive from default PAM configuration files.
5186 Added information on enabling EmptyPasswords on openssh+PAM in
607d73e6 5187 UPGRADING file.
e02735bb 5188 - OpenBSD CVS updates
5189 - [ssh-agent.c]
bcbf86ec 5190 cleanup_exit() for SIGTERM/SIGHUP, too. from fgsch@ and
e02735bb 5191 dgaudet@arctic.org
5192 - [sshconnect.c]
5193 compare correct version for 1.3 compat mode
a1ec4d79 5194
93c7f644 519520000102
5196 - Prevent multiple inclusion of config.h and defines.h. Suggested
5197 by Andre Lucas <andre.lucas@dial.pipex.com>
5198 - Properly clean up on exit of ssh-agent. Patch from Dean Gaudet
5199 <dgaudet@arctic.org>
5200
76b8607f 520119991231
bcbf86ec 5202 - Fix password support on systems with a mixture of shadowed and
5203 non-shadowed passwords (e.g. NIS). Report and fix from
76b8607f 5204 HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 5205 - Fix broken autoconf typedef detection. Report from Marc G.
723221b5 5206 Fournier <marc.fournier@acadiau.ca>
b92964b7 5207 - Fix occasional crash on LinuxPPC. Patch from Franz Sirl
5208 <Franz.Sirl-kernel@lauterbach.com>
bcbf86ec 5209 - Prevent typedefs from being compiled more than once. Report from
a6ddc88b 5210 Marc G. Fournier <marc.fournier@acadiau.ca>
4811cc0b 5211 - Fill in ut_utaddr utmp field. Report from Benjamin Charron
5212 <iretd@bigfoot.com>
bcbf86ec 5213 - Really fix broken default path. Fix from Jim Knoble
986a22ec 5214 <jmknoble@jmknoble.cx>
ae3a3d31 5215 - Remove test for quad_t. No longer needed.
76a8e733 5216 - Released 1.2.1pre24
5217
5218 - Added support for directory-based lastlogs
5219 - Really fix typedefs, patch from Ben Taylor <bent@clark.net>
76b8607f 5220
13f825f4 522119991230
5222 - OpenBSD CVS updates:
5223 - [auth-passwd.c]
5224 check for NULL 1st
bcbf86ec 5225 - Removed most of the pam code into its own file auth-pam.[ch]. This
a5c9cd31 5226 cleaned up sshd.c up significantly.
bcbf86ec 5227 - PAM authentication was incorrectly interpreting
76b8607f 5228 "PermitRootLogin without-password". Report from Matthias Andree
5229 <ma@dt.e-technik.uni-dortmund.de
a5c9cd31 5230 - Several other cleanups
0bc5b6fb 5231 - Merged Dante SOCKS support patch from David Rankin
5232 <drankin@bohemians.lexington.ky.us>
5233 - Updated documentation with ./configure options
76b8607f 5234 - Released 1.2.1pre23
13f825f4 5235
c73a0cb5 523619991229
bcbf86ec 5237 - Applied another NetBSD portability patch from David Rankin
c73a0cb5 5238 <drankin@bohemians.lexington.ky.us>
5239 - Fix --with-default-path option.
bcbf86ec 5240 - Autodetect perl, patch from David Rankin
a0f84251 5241 <drankin@bohemians.lexington.ky.us>
bcbf86ec 5242 - Print whether OpenSSH was compiled with RSARef, patch from
0a2ff95d 5243 Nalin Dahyabhai <nalin@thermo.stat.ncsu.edu>
bcbf86ec 5244 - Calls to pam_setcred, patch from Nalin Dahyabhai
f91bacbd 5245 <nalin@thermo.stat.ncsu.edu>
e3a93db0 5246 - Detect missing size_t and typedef it.
5ab44a92 5247 - Rename helper.[ch] to (more appropriate) bsd-misc.[ch]
5248 - Minor Makefile cleaning
c73a0cb5 5249
b6019d68 525019991228
5251 - Replacement for getpagesize() for systems which lack it
bcbf86ec 5252 - NetBSD login.c compile fix from David Rankin
70e0115b 5253 <drankin@bohemians.lexington.ky.us>
5254 - Fully set ut_tv if present in utmp or utmpx
d94aa2ae 5255 - Portability fixes for Irix 5.3 (now compiles OK!)
5256 - autoconf and other misc cleanups
ea1970a3 5257 - Merged AIX patch from Darren Hall <dhall@virage.org>
5258 - Cleaned up defines.h
fa9a2dd6 5259 - Released 1.2.1pre22
b6019d68 5260
d2dcff5f 526119991227
5262 - Automatically correct paths in manpages and configuration files. Patch
5263 and script from Andre Lucas <andre.lucas@dial.pipex.com>
5264 - Removed credits from README to CREDITS file, updated.
cb807f40 5265 - Added --with-default-path to specify custom path for server
5266 - Removed #ifdef trickery from acconfig.h into defines.h
36a5b38e 5267 - PAM bugfix. PermitEmptyPassword was being ignored.
5268 - Fixed PAM config files to allow empty passwords if server does.
5269 - Explained spurious PAM auth warning workaround in UPGRADING
21feb5fa 5270 - Use last few chars of tty line as ut_id
5a7794be 5271 - New SuSE RPM spec file from Chris Saia <csaia@wtower.com>
00e6dd70 5272 - OpenBSD CVS updates:
5273 - [packet.h auth-rhosts.c]
5274 check format string for packet_disconnect and packet_send_debug, too
5275 - [channels.c]
5276 use packet_get_maxsize for channels. consistence.
d2dcff5f 5277
f74efc8d 527819991226
5279 - Enabled utmpx support by default for Solaris
5280 - Cleanup sshd.c PAM a little more
986a22ec 5281 - Revised RPM package to include Jim Knoble's <jmknoble@jmknoble.cx>
bc7ea646 5282 X11 ssh-askpass program.
20c43d8c 5283 - Disable logging of PAM success and failures, PAM is verbose enough.
bcbf86ec 5284 Unfortunatly there is currently no way to disable auth failure
5285 messages. Mention this in UPGRADING file and sent message to PAM
20c43d8c 5286 developers
83b7f649 5287 - OpenBSD CVS update:
5288 - [ssh-keygen.1 ssh.1]
bcbf86ec 5289 remove ref to .ssh/random_seed, mention .ssh/environment in
83b7f649 5290 .Sh FILES, too
72251cb6 5291 - Released 1.2.1pre21
bcbf86ec 5292 - Fixed implicit '.' in default path, report from Jim Knoble
986a22ec 5293 <jmknoble@jmknoble.cx>
5294 - Redhat RPM spec fixes from Jim Knoble <jmknoble@jmknoble.cx>
f74efc8d 5295
f498ed15 529619991225
5297 - More fixes from Andre Lucas <andre.lucas@dial.pipex.com>
5298 - Cleanup of auth-passwd.c for shadow and MD5 passwords
5299 - Cleanup and bugfix of PAM authentication code
f74efc8d 5300 - Released 1.2.1pre20
5301
5302 - Merged fixes from Ben Taylor <bent@clark.net>
5303 - Fixed configure support for PAM. Reported by Naz <96na@eng.cam.ac.uk>
5304 - Disabled logging of PAM password authentication failures when password
5305 is empty. (e.g start of authentication loop). Reported by Naz
5306 <96na@eng.cam.ac.uk>)
f498ed15 5307
530819991223
bcbf86ec 5309 - Merged later HPUX patch from Andre Lucas
f498ed15 5310 <andre.lucas@dial.pipex.com>
5311 - Above patch included better utmpx support from Ben Taylor
f74efc8d 5312 <bent@clark.net>
f498ed15 5313
eef6f7e9 531419991222
bcbf86ec 5315 - Fix undefined fd_set type in ssh.h from Povl H. Pedersen
eef6f7e9 5316 <pope@netguide.dk>
ae28776a 5317 - Fix login.c breakage on systems which lack ut_host in struct
5318 utmp. Reported by Willard Dawson <willard.dawson@sbs.siemens.com>
eef6f7e9 5319
a7effaac 532019991221
bcbf86ec 5321 - Integration of large HPUX patch from Andre Lucas
5322 <andre.lucas@dial.pipex.com>. Integrating it had a few other
a7effaac 5323 benefits:
5324 - Ability to disable shadow passwords at configure time
5325 - Ability to disable lastlog support at configure time
5326 - Support for IP address in $DISPLAY
ae2f7af7 5327 - OpenBSD CVS update:
5328 - [sshconnect.c]
5329 say "REMOTE HOST IDENTIFICATION HAS CHANGED"
59dd7a31 5330 - Fix DISABLE_SHADOW support
5331 - Allow MD5 passwords even if shadow passwords are disabled
16034de9 5332 - Release 1.2.1pre19
a7effaac 5333
3f1d9bcd 533419991218
bcbf86ec 5335 - Redhat init script patch from Chun-Chung Chen
3f1d9bcd 5336 <cjj@u.washington.edu>
7e1c2490 5337 - Avoid breakage on systems without IPv6 headers
3f1d9bcd 5338
60d804c8 533919991216
bcbf86ec 5340 - Makefile changes for Solaris from Peter Kocks
60d804c8 5341 <peter.kocks@baygate.com>
89cafde6 5342 - Minor updates to docs
5343 - Merged OpenBSD CVS changes:
5344 - [authfd.c ssh-agent.c]
5345 keysize warnings talk about identity files
5346 - [packet.c]
5347 "Connection closed by x.x.x.x": fatal() -> log()
bcbf86ec 5348 - Correctly handle empty passwords in shadow file. Patch from:
c9d323f0 5349 "Chris, the Young One" <cky@pobox.com>
5350 - Released 1.2.1pre18
60d804c8 5351
7dc6fc6d 535219991215
5353 - Integrated patchs from Juergen Keil <jk@tools.de>
5354 - Avoid void* pointer arithmatic
5355 - Use LDFLAGS correctly
68227e6d 5356 - Fix SIGIO error in scp
5357 - Simplify status line printing in scp
61e96248 5358 - Added better test for inline functions compiler support from
906a2515 5359 Darren_Hall@progressive.com
7dc6fc6d 5360
95f1eccc 536119991214
5362 - OpenBSD CVS Changes
5363 - [canohost.c]
bcbf86ec 5364 fix get_remote_port() and friends for sshd -i;
95f1eccc 5365 Holger.Trapp@Informatik.TU-Chemnitz.DE
5366 - [mpaux.c]
5367 make code simpler. no need for memcpy. niels@ ok
5368 - [pty.c]
5369 namebuflen not sizeof namebuflen; bnd@ep-ag.com via djm@mindrot.org
5370 fix proto; markus
5371 - [ssh.1]
5372 typo; mark.baushke@solipsa.com
5373 - [channels.c ssh.c ssh.h sshd.c]
5374 type conflict for 'extern Type *options' in channels.c; dot@dotat.at
5375 - [sshconnect.c]
5376 move checking of hostkey into own function.
5377 - [version.h]
5378 OpenSSH-1.2.1
884bcb37 5379 - Clean up broken includes in pty.c
7303768f 5380 - Some older systems don't have poll.h, they use sys/poll.h instead
5381 - Doc updates
95f1eccc 5382
847e8865 538319991211
bcbf86ec 5384 - Fix compilation on systems with AFS. Reported by
847e8865 5385 aloomis@glue.umd.edu
bcbf86ec 5386 - Fix installation on Solaris. Reported by
847e8865 5387 Gordon Rowell <gordonr@gormand.com.au>
5388 - Fix gccisms (__attribute__ and inline). Report by edgy@us.ibm.com,
5389 patch from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
5390 - Auto-locate xauth. Patch from David Agraz <dagraz@jahoopa.com>
5391 - Compile fix from David Agraz <dagraz@jahoopa.com>
5392 - Avoid compiler warning in bsd-snprintf.c
bcbf86ec 5393 - Added pam_limits.so to default PAM config. Suggested by
986a22ec 5394 Jim Knoble <jmknoble@jmknoble.cx>
847e8865 5395
8946db53 539619991209
5397 - Import of patch from Ben Taylor <bent@clark.net>:
5398 - Improved PAM support
5399 - "uninstall" rule for Makefile
5400 - utmpx support
5401 - Should fix PAM problems on Solaris
2d86a6cc 5402 - OpenBSD CVS updates:
5403 - [readpass.c]
5404 avoid stdio; based on work by markus, millert, and I
5405 - [sshd.c]
5406 make sure the client selects a supported cipher
5407 - [sshd.c]
bcbf86ec 5408 fix sighup handling. accept would just restart and daemon handled
5409 sighup only after the next connection was accepted. use poll on
2d86a6cc 5410 listen sock now.
5411 - [sshd.c]
5412 make that a fatal
87e91331 5413 - Applied patch from David Rankin <drankin@bohemians.lexington.ky.us>
5414 to fix libwrap support on NetBSD
5001b9e4 5415 - Released 1.2pre17
8946db53 5416
6d8c4ea4 541719991208
bcbf86ec 5418 - Compile fix for Solaris with /dev/ptmx from
6d8c4ea4 5419 David Agraz <dagraz@jahoopa.com>
5420
4285816a 542119991207
986a22ec 5422 - sshd Redhat init script patch from Jim Knoble <jmknoble@jmknoble.cx>
4285816a 5423 fixes compatability with 4.x and 5.x
db28aeb5 5424 - Fixed default SSH_ASKPASS
bcbf86ec 5425 - Fix PAM account and session being called multiple times. Problem
d465f2ca 5426 reported by Adrian Baugh <adrian@merlin.keble.ox.ac.uk>
a408af76 5427 - Merged more OpenBSD changes:
5428 - [atomicio.c authfd.c scp.c serverloop.c ssh.h sshconnect.c sshd.c]
bcbf86ec 5429 move atomicio into it's own file. wrap all socket write()s which
a408af76 5430 were doing write(sock, buf, len) != len, with atomicio() calls.
5431 - [auth-skey.c]
5432 fd leak
5433 - [authfile.c]
5434 properly name fd variable
5435 - [channels.c]
5436 display great hatred towards strcpy
5437 - [pty.c pty.h sshd.c]
5438 use openpty() if it exists (it does on BSD4_4)
5439 - [tildexpand.c]
5440 check for ~ expansion past MAXPATHLEN
5441 - Modified helper.c to use new atomicio function.
5442 - Reformat Makefile a little
5443 - Moved RC4 routines from rc4.[ch] into helper.c
5444 - Added autoconf code to detect /dev/ptmx (Solaris) and /dev/ptc (AIX)
9983a8ca 5445 - Updated SuSE spec from Chris Saia <csaia@wtower.com>
5446 - Tweaked Redhat spec
9158d92f 5447 - Clean up bad imports of a few files (forgot -kb)
5448 - Released 1.2pre16
4285816a 5449
9c7b6dfd 545019991204
5451 - Small cleanup of PAM code in sshd.c
57112b5a 5452 - Merged OpenBSD CVS changes:
5453 - [auth-krb4.c auth-passwd.c auth-skey.c ssh.h]
5454 move skey-auth from auth-passwd.c to auth-skey.c, same for krb4
5455 - [auth-rsa.c]
5456 warn only about mismatch if key is _used_
5457 warn about keysize-mismatch with log() not error()
5458 channels.c readconf.c readconf.h ssh.c ssh.h sshconnect.c
5459 ports are u_short
5460 - [hostfile.c]
5461 indent, shorter warning
5462 - [nchan.c]
5463 use error() for internal errors
5464 - [packet.c]
5465 set loglevel for SSH_MSG_DISCONNECT to log(), not fatal()
5466 serverloop.c
5467 indent
5468 - [ssh-add.1 ssh-add.c ssh.h]
5469 document $SSH_ASKPASS, reasonable default
5470 - [ssh.1]
5471 CheckHostIP is not available for connects via proxy command
5472 - [sshconnect.c]
5473 typo
5474 easier to read client code for passwd and skey auth
5475 turn of checkhostip for proxy connects, since we don't know the remote ip
9c7b6dfd 5476
dad3b556 547719991126
5478 - Add definition for __P()
5479 - Added [v]snprintf() replacement for systems that lack it
5480
0ce43ae4 548119991125
5482 - More reformatting merged from OpenBSD CVS
5483 - Merged OpenBSD CVS changes:
5484 - [channels.c]
5485 fix packet_integrity_check() for !have_hostname_in_open.
5486 report from mrwizard@psu.edu via djm@ibs.com.au
5487 - [channels.c]
5488 set SO_REUSEADDR and SO_LINGER for forwarded ports.
5489 chip@valinux.com via damien@ibs.com.au
5490 - [nchan.c]
5491 it's not an error() if shutdown_write failes in nchan.
5492 - [readconf.c]
5493 remove dead #ifdef-0-code
5494 - [readconf.c servconf.c]
5495 strcasecmp instead of tolower
5496 - [scp.c]
5497 progress meter overflow fix from damien@ibs.com.au
5498 - [ssh-add.1 ssh-add.c]
5499 SSH_ASKPASS support
5500 - [ssh.1 ssh.c]
5501 postpone fork_after_authentication until command execution,
5502 request/patch from jahakala@cc.jyu.fi via damien@ibs.com.au
5503 plus: use daemon() for backgrounding
cf8dd513 5504 - Added BSD compatible install program and autoconf test, thanks to
5505 Niels Kristian Bech Jensen <nkbj@image.dk>
5506 - Solaris fixing, thanks to Ben Taylor <bent@clark.net>
09041313 5507 - Merged beginnings of AIX support from Tor-Ake Fransson <torake@hotmail.com>
3dbefdb8 5508 - Release 1.2pre15
0ce43ae4 5509
5260325f 551019991124
5511 - Merged very large OpenBSD source code reformat
5512 - OpenBSD CVS updates
5513 - [channels.c cipher.c compat.c log-client.c scp.c serverloop.c]
5514 [ssh.h sshd.8 sshd.c]
5515 syslog changes:
5516 * Unified Logmessage for all auth-types, for success and for failed
5517 * Standard connections get only ONE line in the LOG when level==LOG:
5518 Auth-attempts are logged only, if authentication is:
5519 a) successfull or
5520 b) with passwd or
5521 c) we had more than AUTH_FAIL_LOG failues
5522 * many log() became verbose()
5523 * old behaviour with level=VERBOSE
5524 - [readconf.c readconf.h ssh.1 ssh.h sshconnect.c sshd.c]
5525 tranfer s/key challenge/response data in SSH_SMSG_AUTH_TIS_CHALLENGE
5526 messages. allows use of s/key in windows (ttssh, securecrt) and
5527 ssh-1.2.27 clients without 'ssh -v', ok: niels@
5528 - [sshd.8]
5529 -V, for fallback to openssh in SSH2 compatibility mode
5530 - [sshd.c]
5531 fix sigchld race; cjc5@po.cwru.edu
5532
4655fe80 553319991123
5534 - Added SuSE package files from Chris Saia <csaia@wtower.com>
8b241e50 5535 - Restructured package-related files under packages/*
4655fe80 5536 - Added generic PAM config
8b241e50 5537 - Numerous little Solaris fixes
9c08d6ce 5538 - Add recommendation to use GNU make to INSTALL document
4655fe80 5539
60bed5fd 554019991122
5541 - Make <enter> close gnome-ssh-askpass (Debian bug #50299)
2f2cc3f9 5542 - OpenBSD CVS Changes
bcbf86ec 5543 - [ssh-keygen.c]
5544 don't create ~/.ssh only if the user wants to store the private
5545 key there. show fingerprint instead of public-key after
2f2cc3f9 5546 keygeneration. ok niels@
b09a984b 5547 - Added OpenBSD bsd-strlcat.c, created bsd-strlcat.h
96ad4350 5548 - Added timersub() macro
b09a984b 5549 - Tidy RCSIDs of bsd-*.c
bcbf86ec 5550 - Added autoconf test and macro to deal with old PAM libraries
96ad4350 5551 pam_strerror definition (one arg vs two).
530f1889 5552 - Fix EGD problems (Thanks to Ben Taylor <bent@clark.net>)
bcbf86ec 5553 - Retry /dev/urandom reads interrupted by signal (report from
530f1889 5554 Robert Hardy <rhardy@webcon.net>)
1647c2b5 5555 - Added a setenv replacement for systems which lack it
d84a9a44 5556 - Only display public key comment when presenting ssh-askpass dialog
5557 - Released 1.2pre14
60bed5fd 5558
bcbf86ec 5559 - Configure, Make and changelog corrections from Tudor Bosman
2ddcfdf3 5560 <tudorb@jm.nu> and Niels Kristian Bech Jensen <nkbj@image.dk>
5561
9d6b7add 556219991121
2f2cc3f9 5563 - OpenBSD CVS Changes:
60bed5fd 5564 - [channels.c]
5565 make this compile, bad markus
5566 - [log.c readconf.c servconf.c ssh.h]
5567 bugfix: loglevels are per host in clientconfig,
5568 factor out common log-level parsing code.
5569 - [servconf.c]
5570 remove unused index (-Wall)
5571 - [ssh-agent.c]
5572 only one 'extern char *__progname'
5573 - [sshd.8]
5574 document SIGHUP, -Q to synopsis
5575 - [sshconnect.c serverloop.c sshd.c packet.c packet.h]
5576 [channels.c clientloop.c]
5577 SSH_CMSG_MAX_PACKET_SIZE, some clients use this, some need this, niels@
5578 [hope this time my ISP stays alive during commit]
5579 - [OVERVIEW README] typos; green@freebsd
5580 - [ssh-keygen.c]
5581 replace xstrdup+strcat with strlcat+fixed buffer, fixes OF (bad me)
5582 exit if writing the key fails (no infinit loop)
5583 print usage() everytime we get bad options
5584 - [ssh-keygen.c] overflow, djm@mindrot.org
5585 - [sshd.c] fix sigchld race; cjc5@po.cwru.edu
61e96248 5586
2b942fe0 558719991120
bcbf86ec 5588 - Merged more Solaris support from Marc G. Fournier
2b942fe0 5589 <marc.fournier@acadiau.ca>
5590 - Wrote autoconf tests for integer bit-types
5591 - Fixed enabling kerberos support
bcbf86ec 5592 - Fix segfault in ssh-keygen caused by buffer overrun in filename
13c36c4c 5593 handling.
2b942fe0 5594
06479889 559519991119
5596 - Merged PAM buffer overrun patch from Chip Salzenberg <chip@valinux.com>
2ad77510 5597 - Merged OpenBSD CVS changes
5598 - [auth-rhosts.c auth-rsa.c ssh-agent.c sshconnect.c sshd.c]
5599 more %d vs. %s in fmt-strings
5600 - [authfd.c]
5601 Integers should not be printed with %s
7b1cc56c 5602 - EGD uses a socket, not a named pipe. Duh.
5603 - Fix includes in fingerprint.c
29dbde15 5604 - Fix scp progress bar bug again.
bcbf86ec 5605 - Move ssh-askpass from ${libdir}/ssh to ${libexecdir}/ssh at request of
736890c4 5606 David Rankin <drankin@bohemians.lexington.ky.us>
91b8065d 5607 - Added autoconf option to enable Kerberos 4 support (untested)
5608 - Added autoconf option to enable AFS support (untested)
5609 - Added autoconf option to enable S/Key support (untested)
5610 - Added autoconf option to enable TCP wrappers support (compiles OK)
beb43d31 5611 - Renamed BSD helper function files to bsd-*
bcbf86ec 5612 - Added tests for login and daemon and enable OpenBSD replacements for
caf3bc51 5613 when they are absent.
5614 - Added non-PAM MD5 password support patch from Tudor Bosman <tudorb@jm.nu>
06479889 5615
2bd61362 561619991118
5617 - Merged OpenBSD CVS changes
5618 - [scp.c] foregroundproc() in scp
5619 - [sshconnect.h] include fingerprint.h
bcbf86ec 5620 - [sshd.c] bugfix: the log() for passwd-auth escaped during logging
2bd61362 5621 changes.
0c16a097 5622 - [ssh.1] Spell my name right.
2bd61362 5623 - Added openssh.com info to README
5624
f095fcc7 562519991117
5626 - Merged OpenBSD CVS changes
5627 - [ChangeLog.Ylonen] noone needs this anymore
5628 - [authfd.c] close-on-exec for auth-socket, ok deraadt
bcbf86ec 5629 - [hostfile.c]
5630 in known_hosts key lookup the entry for the bits does not need
5631 to match, all the information is contained in n and e. This
5632 solves the problem with buggy servers announcing the wrong
f095fcc7 5633 modulus length. markus and me.
bcbf86ec 5634 - [serverloop.c]
5635 bugfix: check for space if child has terminated, from:
f095fcc7 5636 iedowse@maths.tcd.ie
5637 - [ssh-add.1 ssh-add.c ssh-keygen.1 ssh-keygen.c sshconnect.c]
5638 [fingerprint.c fingerprint.h]
5639 rsa key fingerprints, idea from Bjoern Groenvall <bg@sics.se>
5640 - [ssh-agent.1] typo
5641 - [ssh.1] add OpenSSH information to AUTHOR section. okay markus@
bcbf86ec 5642 - [sshd.c]
f095fcc7 5643 force logging to stderr while loading private key file
5644 (lost while converting to new log-levels)
5645
4d195447 564619991116
5647 - Fix some Linux libc5 problems reported by Miles Wilson <mw@mctitle.com>
5648 - Merged OpenBSD CVS changes:
5649 - [auth-rh-rsa.c auth-rsa.c authfd.c authfd.h hostfile.c mpaux.c]
5650 [mpaux.h ssh-add.c ssh-agent.c ssh.h ssh.c sshd.c]
5651 the keysize of rsa-parameter 'n' is passed implizit,
5652 a few more checks and warnings about 'pretended' keysizes.
5653 - [cipher.c cipher.h packet.c packet.h sshd.c]
5654 remove support for cipher RC4
5655 - [ssh.c]
5656 a note for legay systems about secuity issues with permanently_set_uid(),
5657 the private hostkey and ptrace()
5658 - [sshconnect.c]
5659 more detailed messages about adding and checking hostkeys
5660
dad9a31e 566119991115
5662 - Merged OpenBSD CVS changes:
bcbf86ec 5663 - [ssh-add.c] change passphrase loop logic and remove ref to
dad9a31e 5664 $DISPLAY, ok niels
5665 - Changed to ssh-add.c broke askpass support. Revised it to be a little more
bcbf86ec 5666 modular.
dad9a31e 5667 - Revised autoconf support for enabling/disabling askpass support.
e7c0f9d5 5668 - Merged more OpenBSD CVS changes:
704b1659 5669 [auth-krb4.c]
5670 - disconnect if getpeername() fails
5671 - missing xfree(*client)
5672 [canohost.c]
5673 - disconnect if getpeername() fails
5674 - fix comment: we _do_ disconnect if ip-options are set
5675 [sshd.c]
5676 - disconnect if getpeername() fails
5677 - move checking of remote port to central place
5678 [auth-rhosts.c] move checking of remote port to central place
5679 [log-server.c] avoid extra fd per sshd, from millert@
5680 [readconf.c] print _all_ bad config-options in ssh(1), too
5681 [readconf.h] print _all_ bad config-options in ssh(1), too
5682 [ssh.c] print _all_ bad config-options in ssh(1), too
5683 [sshconnect.c] disconnect if getpeername() fails
e7c0f9d5 5684 - OpenBSD's changes to sshd.c broke the PAM stuff, re-merged it.
c75a1a66 5685 - Various small cleanups to bring diff (against OpenBSD) size down.
f601d847 5686 - Merged more Solaris compability from Marc G. Fournier
5687 <marc.fournier@acadiau.ca>
5688 - Wrote autoconf tests for __progname symbol
986a22ec 5689 - RPM spec file fixes from Jim Knoble <jmknoble@jmknoble.cx>
0c372277 5690 - Released 1.2pre12
5691
5692 - Another OpenBSD CVS update:
5693 - [ssh-keygen.1] fix .Xr
dad9a31e 5694
92da7197 569519991114
5696 - Solaris compilation fixes (still imcomplete)
5697
94f7bb9e 569819991113
dd092f97 5699 - Build patch from Niels Kristian Bech Jensen <nkbj@image.dk>
5700 - Don't install config files if they already exist
5701 - Fix inclusion of additional preprocessor directives from acconfig.h
94f7bb9e 5702 - Removed redundant inclusions of config.h
e9c75a39 5703 - Added 'Obsoletes' lines to RPM spec file
94f7bb9e 5704 - Merged OpenBSD CVS changes:
5705 - [bufaux.c] save a view malloc/memcpy/memset/free's, ok niels
bcbf86ec 5706 - [scp.c] fix overflow reported by damien@ibs.com.au: off_t
94f7bb9e 5707 totalsize, ok niels,aaron
bcbf86ec 5708 - Delay fork (-f option) in ssh until after port forwarded connections
94f7bb9e 5709 have been initialised. Patch from Jani Hakala <jahakala@cc.jyu.fi>
b2344d54 5710 - Added shadow password patch from Thomas Neumann <tom@smart.ruhr.de>
5711 - Added ifdefs to auth-passwd.c to exclude it when PAM is enabled
dd092f97 5712 - Tidied default config file some more
5713 - Revised Redhat initscript to fix bug: sshd (re)start would fail
5714 if executed from inside a ssh login.
94f7bb9e 5715
e35c1dc2 571619991112
5717 - Merged changes from OpenBSD CVS
5718 - [sshd.c] session_key_int may be zero
b4748e2f 5719 - [auth-rh-rsa.c servconf.c servconf.h ssh.h sshd.8 sshd.c sshd_config]
bcbf86ec 5720 IgnoreUserKnownHosts(default=no), used for RhostRSAAuth, ok
b4748e2f 5721 deraadt,millert
5722 - Brought default sshd_config more in line with OpenBSD's
547c9f30 5723 - Grab server in gnome-ssh-askpass (Debian bug #49872)
5724 - Released 1.2pre10
e35c1dc2 5725
8bc7973f 5726 - Added INSTALL documentation
6fa724bc 5727 - Merged yet more changes from OpenBSD CVS
5728 - [auth-rh-rsa.c auth-rhosts.c auth-rsa.c channels.c clientloop.c]
5729 [ssh.c ssh.h sshconnect.c sshd.c]
5730 make all access to options via 'extern Options options'
5731 and 'extern ServerOptions options' respectively;
5732 options are no longer passed as arguments:
5733 * make options handling more consistent
5734 * remove #include "readconf.h" from ssh.h
5735 * readconf.h is only included if necessary
5736 - [mpaux.c] clear temp buffer
5737 - [servconf.c] print _all_ bad options found in configfile
045672f9 5738 - Make ssh-askpass support optional through autoconf
59b0f0d4 5739 - Fix nasty division-by-zero error in scp.c
5740 - Released 1.2pre11
8bc7973f 5741
4cca272e 574219991111
5743 - Added (untested) Entropy Gathering Daemon (EGD) support
67d68e3a 5744 - Fixed /dev/urandom fd leak (Debian bug #49722)
5bbb5681 5745 - Merged OpenBSD CVS changes:
5746 - [auth-rh-rsa.c] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
5747 - [ssh.1] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
5748 - [sshd.8] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
bcbf86ec 5749 - Fix integer overflow which was messing up scp's progress bar for large
3f1d9bcd 5750 file transfers. Fix submitted to OpenBSD developers. Report and fix
5751 from Kees Cook <cook@cpoint.net>
6a17f9c2 5752 - Merged more OpenBSD CVS changes:
bcbf86ec 5753 - [auth-krb4.c auth-passwd.c] remove x11- and krb-cleanup from fatal()
6a17f9c2 5754 + krb-cleanup cleanup
5755 - [clientloop.c log-client.c log-server.c ]
5756 [readconf.c readconf.h servconf.c servconf.h ]
5757 [ssh.1 ssh.c ssh.h sshd.8]
5758 add LogLevel {QUIET, FATAL, ERROR, INFO, CHAT, DEBUG} to ssh/sshd,
5759 obsoletes QuietMode and FascistLogging in sshd.
e35c1dc2 5760 - [sshd.c] fix fatal/assert() bug reported by damien@ibs.com.au:
5761 allow session_key_int != sizeof(session_key)
5762 [this should fix the pre-assert-removal-core-files]
5763 - Updated default config file to use new LogLevel option and to improve
5764 readability
5765
f370266e 576619991110
67d68e3a 5767 - Merged several minor fixes:
f370266e 5768 - ssh-agent commandline parsing
5769 - RPM spec file now installs ssh setuid root
5770 - Makefile creates libdir
4cca272e 5771 - Merged beginnings of Solaris compability from Marc G. Fournier
5772 <marc.fournier@acadiau.ca>
f370266e 5773
d4f11b59 577419991109
5775 - Autodetection of SSL/Crypto library location via autoconf
5776 - Fixed location of ssh-askpass to follow autoconf
5777 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
5778 - Autodetection of RSAref library for US users
5779 - Minor doc updates
560557bb 5780 - Merged OpenBSD CVS changes:
5781 - [rsa.c] bugfix: use correct size for memset()
5782 - [sshconnect.c] warn if announced size of modulus 'n' != real size
f025becb 5783 - Added GNOME passphrase requestor (use --with-gnome-askpass)
d397b172 5784 - RPM build now creates subpackages
aa51e7cc 5785 - Released 1.2pre9
d4f11b59 5786
e1a9c08d 578719991108
5788 - Removed debian/ directory. This is now being maintained separately.
5789 - Added symlinks for slogin in RPM spec file
5790 - Fixed permissions on manpages in RPM spec file
5791 - Added references to required libraries in README file
5792 - Removed config.h.in from CVS
5793 - Removed pwdb support (better pluggable auth is provided by glibc)
5794 - Made PAM and requisite libdl optional
5795 - Removed lots of unnecessary checks from autoconf
5796 - Added support and autoconf test for openpty() function (Unix98 pty support)
5797 - Fix for scp not finding ssh if not installed as /usr/bin/ssh
5798 - Added TODO file
5799 - Merged parts of Debian patch From Phil Hands <phil@hands.com>:
5800 - Added ssh-askpass program
5801 - Added ssh-askpass support to ssh-add.c
5802 - Create symlinks for slogin on install
5803 - Fix "distclean" target in makefile
5804 - Added example for ssh-agent to manpage
5805 - Added support for PAM_TEXT_INFO messages
5806 - Disable internal /etc/nologin support if PAM enabled
5807 - Merged latest OpenBSD CVS changes:
5bae4ab8 5808 - [all] replace assert() with error, fatal or packet_disconnect
e1a9c08d 5809 - [sshd.c] don't send fail-msg but disconnect if too many authentication
5810 failures
e1a9c08d 5811 - [sshd.c] remove unused argument. ok dugsong
5812 - [sshd.c] typo
5813 - [rsa.c] clear buffers used for encryption. ok: niels
5814 - [rsa.c] replace assert() with error, fatal or packet_disconnect
ade6fccd 5815 - [auth-krb4.c] remove unused argument. ok dugsong
e1a9c08d 5816 - Fixed coredump after merge of OpenBSD rsa.c patch
9010d60a 5817 - Released 1.2pre8
e1a9c08d 5818
3028328e 581919991102
5820 - Merged change from OpenBSD CVS
5821 - One-line cleanup in sshd.c
5822
474832c5 582319991030
5824 - Integrated debian package support from Dan Brosemer <odin@linuxfreak.com>
69256d9d 5825 - Merged latest updates for OpenBSD CVS:
5826 - channels.[ch] - remove broken x11 fix and document istate/ostate
5827 - ssh-agent.c - call setsid() regardless of argv[]
5828 - ssh.c - save a few lines when disabling rhosts-{rsa-}auth
5829 - Documentation cleanups
5830 - Renamed README -> README.Ylonen
5831 - Renamed README.openssh ->README
474832c5 5832
339660f6 583319991029
5834 - Renamed openssh* back to ssh* at request of Theo de Raadt
5835 - Incorporated latest changes from OpenBSD's CVS
5836 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
5837 - Integrated PAM env patch from Nalin Dahyabhai <nalin.dahyabhai@pobox.com>
549b3eed 5838 - Make distclean now removed configure script
5839 - Improved PAM logging
5840 - Added some debug() calls for PAM
4ecd19ea 5841 - Removed redundant subdirectories
bcbf86ec 5842 - Integrated part of a patch from Dan Brosemer <odin@linuxfreak.com> for
4ecd19ea 5843 building on Debian.
242588e6 5844 - Fixed off-by-one error in PAM env patch
5845 - Released 1.2pre6
339660f6 5846
5881cd60 584719991028
5848 - Further PAM enhancements.
5849 - Much cleaner
5850 - Now uses account and session modules for all logins.
5851 - Integrated patch from Dan Brosemer <odin@linuxfreak.com>
5852 - Build fixes
5853 - Autoconf
5854 - Change binary names to open*
5855 - Fixed autoconf script to detect PAM on RH6.1
5856 - Added tests for libpwdb, and OpenBSD functions to autoconf
221395b3 5857 - Released 1.2pre4
fca82d2e 5858
5859 - Imported latest OpenBSD CVS code
5860 - Updated README.openssh
93f04616 5861 - Released 1.2pre5
fca82d2e 5862
5881cd60 586319991027
5864 - Adapted PAM patch.
5865 - Released 1.0pre2
5866
5867 - Excised my buggy replacements for strlcpy and mkdtemp
5868 - Imported correct OpenBSD strlcpy and mkdtemp routines.
5869 - Reduced arc4random_stir entropy read to 32 bytes (256 bits)
5870 - Picked up correct version number from OpenBSD
5871 - Added sshd.pam PAM configuration file
5872 - Added sshd.init Redhat init script
5873 - Added openssh.spec RPM spec file
5874 - Released 1.2pre3
5875
587619991026
5877 - Fixed include paths of OpenSSL functions
5878 - Use OpenSSL MD5 routines
5879 - Imported RC4 code from nanocrypt
5880 - Wrote replacements for OpenBSD arc4random* functions
5881 - Wrote replacements for strlcpy and mkdtemp
5882 - Released 1.0pre1
0b202697 5883
5884$Id$
This page took 1.248966 seconds and 5 git commands to generate.