]> andersk Git - openssh.git/blame - ChangeLog
- (dtucker) [LICENCE Makefile.in auth-passwd.c auth-shadow.c auth.c auth.h
[openssh.git] / ChangeLog
CommitLineData
cadfc759 120040210
2 - (dtucker) [auth-passwd.c auth.h openbsd-compat/port-aix.c
5a8bd0c3 3 openbsd-compat/port-aix.h] Bug #14: Use do_pwchange to support AIX's
4 native password expiry.
5 - (dtucker) [LICENCE Makefile.in auth-passwd.c auth-shadow.c auth.c auth.h
6 defines.h] Bug #14: Use do_pwchange to support password expiry and force
7 change for platforms using /etc/shadow. ok djm@
cadfc759 8
59d51274 920040207
10 - (dtucker) OpenBSD CVS Sync
11 - dtucker@cvs.openbsd.org 2004/02/06 23:41:13
12 [cipher-ctr.c]
13 Use EVP_CIPHER_CTX_key_length for key length. ok markus@
14 (This will fix builds with OpenSSL 0.9.5)
1c4d41b9 15 - (dtucker) [cipher.c] enable AES counter modes with OpenSSL 0.9.5.
16 ok djm@, markus@
59d51274 17
92d0d880 1820040206
19 - (dtucker) [acss.c acss.h] Fix $Id tags.
c7b91244 20 - (dtucker) [cipher-acss.c cipher.c] Enable acss only if building with
21 OpenSSL >= 0.9.7. ok djm@
72037bc8 22 - (dtucker) [session.c] Bug #789: Do not call do_pam_setcred as a non-root
23 user, since some modules might fail due to lack of privilege. ok djm@
38b69c0b 24 - (dtucker) [configure.ac] Bug #748: Always define BROKEN_GETADDRINFO
25 for HP-UX 11.11. If there are known-good configs where this is not
26 required, please report them. ok djm@
a6cd1e13 27 - (dtucker) [sshd.c] Bug #757: Clear child's environment to prevent
28 accidentally inheriting from root's environment. ok djm@
7ccff316 29 - (dtucker) [openbsd-compat/port-aix.c openbsd-compat/port-aix.h] Bug #796:
30 Restore previous authdb setting after auth calls. Fixes problems with
31 setpcred failing on accounts that use AFS or NIS password registries.
51693efd 32 - (dtucker) [configure.ac includes.h] Include <sys/stream.h> if present,
33 required on Solaris 2.5.1 for queue_t, which is used by <sys/ptms.h>.
37656beb 34 - (dtucker) OpenBSD CVS Sync
35 - markus@cvs.openbsd.org 2004/01/30 09:48:57
36 [auth-passwd.c auth.h pathnames.h session.c]
37 support for password change; ok dtucker@
38 (set password-dead=1w in login.conf to use this).
39 In -Portable, this is currently only platforms using bsdauth.
a9b33b95 40 - dtucker@cvs.openbsd.org 2004/02/05 05:37:17
41 [monitor.c sshd.c]
42 Pass SIGALRM through to privsep child if LoginGraceTime expires. ok markus@
7b0a59c9 43 - markus@cvs.openbsd.org 2004/02/05 15:33:33
44 [progressmeter.c]
45 fix ETA for > 4GB; bugzilla #791; ok henning@ deraadt@
92d0d880 46
d642a47a 4720040129
48 - (dtucker) OpenBSD CVS Sync regress/
49 - dtucker@cvs.openbsd.org 2003/10/11 11:49:49
50 [Makefile banner.sh]
51 Test missing banner file, suppression of banner with ssh -q, check return
52 code from ssh. ok markus@
b3293f64 53 - jmc@cvs.openbsd.org 2003/11/07 10:16:44
54 [ssh-com.sh]
55 adress -> address, and a few more; all from Jonathon Gray;
7267f37e 56 - djm@cvs.openbsd.org 2004/01/13 09:49:06
57 [sftp-batch.sh]
8068d564 58 - (dtucker) [configure.ac] Add --without-zlib-version-check. Feedback from
59 tim@, ok several
c1ad5966 60 - (dtucker) [configure.ac openbsd-compat/bsd-cray.c openbsd-compat/bsd-cray.h]
61 Bug #775: Cray fixes from wendy at cray.com
d642a47a 62
71658852 6320040128
64 - (dtucker) [regress/README.regress] Add tcpwrappers issue, noted by tim@
f5d109e7 65 - (dtucker) [moduli] Import new moduli file from OpenBSD.
71658852 66
268c23e9 6720040127
68 - (djm) OpenBSD CVS Sync
69 - hshoexer@cvs.openbsd.org 2004/01/23 17:06:03
70 [cipher.c]
71 enable acss for ssh
72 ok deraadt@ markus@
0372ae57 73 - mouring@cvs.openbsd.org 2004/01/23 17:57:48
74 [sftp-int.c]
75 Fix issue pointed out with ls not handling large directories
76 with embeded paths correctly. OK damien@
8b557a74 77 - hshoexer@cvs.openbsd.org 2004/01/23 19:26:33
78 [cipher.c]
79 rename acss@opebsd.org to acss@openssh.org
80 ok deraadt@
2daf1db1 81 - djm@cvs.openbsd.org 2004/01/25 03:49:09
82 [sshconnect.c]
83 reset nonblocking flag after ConnectTimeout > 0 connect; (bugzilla #785)
84 from jclonguet AT free.fr; ok millert@
02de7c6e 85 - djm@cvs.openbsd.org 2004/01/27 10:08:10
86 [sftp.c]
87 reorder parsing so user:skey@host:file works (bugzilla #777)
88 patch from admorten AT umich.edu; ok markus@
268c23e9 89 - (djm) [acss.c acss.h cipher-acss.c] Portable support for ACSS
90 if libcrypto lacks it
91
86f807ed 9220040126
93 - (tim) Typo in regress/README.regress
a5753dd4 94 - (tim) [regress/test-exec.sh] RhostsAuthentication is deprecated.
a98550d2 95 - (tim) [defines.h] Add defines for HFIXEDSZ and T_SIG
9e833a9b 96 - (tim) [configure.ac includes.h] add <sys/ptms.h> for grantpt() and friends.
2df78719 97 - (tim) [defines.h openbsd-compat/getrrsetbyname.h] Move defines for HFIXEDSZ
98 and T_SIG to getrrsetbyname.h
86f807ed 99
6e9f4c0f 10020040124
101 - (djm) Typo in openbsd-compat/bsd-openpty.c; from wendyp AT cray.com
102
f4eaee12 10320040123
104 - (djm) Do pam_session processing for systems with HAVE_LOGIN_CAP; from
105 ralf.hack AT pipex.net; ok dtucker@
b6cfb8c2 106 - (djm) Bug #776: Update contrib/redhat/openssh.spec to dynamically detect
107 Kerberos location (and thus work with Fedora Core 1);
108 from jason AT devrandom.org
4ad65809 109 - (dtucker) [configure.ac] Bug #788: Test for zlib.h presence and for
110 zlib >= 1.1.4. Partly from jbasney at ncsa.uiuc.edu. ok djm@
73fd4871 111 - (dtucker) [contrib/cygwin/README] Document new ssh-host-config options.
112 Patch from vinschen at redhat.com.
bcfcc5f9 113 - (dtucker) [acconfig.h configure.ac includes.h servconf.c session.c]
114 Change AFS symbol to USE_AFS to prevent namespace collisions, do not
115 include kafs.h unless necessary. From deengert at anl.gov.
0a15d73b 116 - (tim) [configure.ac] Remove hard coded -L/usr/local/lib and
117 -I/usr/local/include. Users can do LDFLAGS="-L/usr/local/lib" \
118 CPPFLAGS="-I/usr/local/include" ./configure if needed.
f4eaee12 119
5585c441 12020040122
121 - (dtucker) [configure.ac] Use krb5-config where available for Kerberos/
122 GSSAPI detection, libs and includes. ok djm@
6704d19a 123 - (dtucker) [session.c] Enable AFS support in conjunction with KRB5 not
124 just HEIMDAL.
8e8d046c 125 - (tim) [contrib/solaris/buildpkg.sh] Allow for the possibility of
126 /usr/local being a symbolic link. Fixes problem reported by Henry Grebler.
5585c441 127
a8b64bb8 12820040121
129 - (djm) OpenBSD CVS Sync
130 - djm@cvs.openbsd.org 2004/01/13 09:25:05
131 [sftp-int.c sftp.1 sftp.c]
132 Tidy sftp batchmode handling, eliminate junk to stderr (bugzilla #754) and
133 enable use of "-b -" to accept batchfile from stdin; ok markus@
f74de0d7 134 - jmc@cvs.openbsd.org 2004/01/13 12:17:33
135 [sftp.1]
136 remove unnecessary Ic's;
137 kill whitespace at EOL;
138 ok djm@
39dfceeb 139 - markus@cvs.openbsd.org 2004/01/13 19:23:15
140 [compress.c session.c]
141 -Wall; ok henning
33623c65 142 - markus@cvs.openbsd.org 2004/01/13 19:45:15
143 [compress.c]
144 cast for portability; millert@
7741e239 145 - markus@cvs.openbsd.org 2004/01/19 09:24:21
146 [channels.c]
147 fake consumption for half closed channels since the peer is waiting for
148 window adjust messages; bugzilla #790 Matthew Dillon; test + ok dtucker@
149 reproduce with sh -c 'ulimit -f 10; ssh host -n od /bsd | cat > foo'
43f7a4b8 150 - markus@cvs.openbsd.org 2004/01/19 21:25:15
151 [auth2-hostbased.c auth2-pubkey.c serverloop.c ssh-keysign.c sshconnect2.c]
152 fix mem leaks; some fixes from Pete Flugstad; tested dtucker@
ac414e17 153 - djm@cvs.openbsd.org 2004/01/21 03:07:59
154 [sftp.c]
155 initialise infile in main, rather than statically - from portable
a4de1163 156 - deraadt@cvs.openbsd.org 2004/01/11 21:55:06
157 [sshpty.c]
158 for pty opening, only use the openpty() path. the other stuff only needs
159 to be in openssh-p; markus ok
160 - (djm) [openbsd-compat/bsd-openpty.c] Rework old sshpty.c code into an
161 openpty() replacement
a8b64bb8 162
100e6910 16320040114
164 - (dtucker) [auth-pam.c] Have monitor die if PAM authentication thread exits
165 unexpectedly. with & ok djm@
28b49ff8 166 - (dtucker) [auth-pam.c] Reset signal handler in pthread_cancel too, add
167 test for case where cleanup has already run.
90f3c272 168 - (dtucker) [auth-pam.c] Add minor debugging.
100e6910 169
e47e681f 17020040113
171 - (dtucker) [auth-pam.c] Relocate struct pam_ctxt and prototypes. No
172 functional changes.
173
b3f87f4f 17420040108
175 - (dtucker) [auth-pam.c defines.h] Bug #783: move __unused to defines.h and
176 only define if not already. From des at freebsd.org.
24a9171d 177 - (dtucker) [configure.ac] Remove extra (typo) comma.
b3f87f4f 178
e7c060cb 17920040105
180 - (dtucker) [contrib/ssh-copy-id] Bug #781: exit if ssh fails. Patch from
181 cjwatson at debian.org.
309af4e5 182 - (dtucker) [acconfig.h configure.ac includes.h servconf.c session.c]
183 Only enable KerberosGetAFSToken if Heimdal's libkafs is found. with jakob@
e7c060cb 184
ff620033 18520040102
186 - (djm) OSX/Darwin needs BIND_8_COMPAT to build getrrsetbyname. Report from
187 jakob@
c0c10689 188 - (djm) Remove useless DNS support configure summary message. from jakob@
2511d104 189 - (djm) OSX/Darwin put the PAM headers in a different place, detect this.
190 Report from jakob@
ff620033 191
c6fbc95a 19220031231
193 - (dtucker) OpenBSD CVS Sync
194 - djm@cvs.openbsd.org 2003/12/22 09:16:58
195 [moduli.c ssh-keygen.1 ssh-keygen.c]
196 tidy up moduli generation debugging, add -v (verbose/debug) option to
197 ssh-keygen; ok markus@
1dd5f021 198 - markus@cvs.openbsd.org 2003/12/22 20:29:55
199 [cipher-3des1.c]
200 EVP_CIPHER_CTX_cleanup() for the des contexts; pruiksma@freesurf.fr
a1e30b47 201 - jakob@cvs.openbsd.org 2003/12/23 16:12:10
202 [servconf.c servconf.h session.c sshd_config]
203 implement KerberosGetAFSToken server option. ok markus@, beck@
6bb49a16 204 - millert@cvs.openbsd.org 2003/12/29 16:39:50
205 [sshd_config]
206 KeepAlive has been obsoleted, use TCPKeepAlive instead; markus@ OK
b0ca6225 207 - dtucker@cvs.openbsd.org 2003/12/31 00:24:50
208 [auth2-passwd.c]
209 Ignore password change request during password auth (which we currently
210 don't support) and discard proposed new password. corrections/ok markus@
3f176010 211 - (dtucker) [configure.ac] Only test setresuid and setresgid if they exist.
c6fbc95a 212
56b13279 21320031219
214 - (dtucker) [defines.h] Bug #458: Define SIZE_T_MAX as UINT_MAX if we
215 typedef size_t ourselves.
216
0c6a72a5 21720031218
218 - (dtucker) [configure.ac] Don't use setre[ug]id on DG-UX, from Tom Orban.
b3ef7fb7 219 - (dtucker) [auth-pam.c] Do PAM chauthtok during SSH2 keyboard-interactive
220 authentication. Partially fixes bug #423. Feedback & ok djm@
0c6a72a5 221
95ae2076 22220031217
223 - (djm) OpenBSD CVS Sync
224 - markus@cvs.openbsd.org 2003/12/09 15:28:43
225 [serverloop.c]
226 make ClientKeepAlive work for ssh -N, too (no login shell requested).
227 1) send a bogus channel request if we find a channel
228 2) send a bogus global request if we don't have a channel
229 ok + test beck@
c5894280 230 - markus@cvs.openbsd.org 2003/12/09 17:29:04
231 [sshd.c]
232 fix -o and HUP; ok henning@
1aafd17a 233 - markus@cvs.openbsd.org 2003/12/09 17:30:05
234 [ssh.c]
235 don't modify argv for ssh -o; similar to sshd.c 1.283
fd573618 236 - markus@cvs.openbsd.org 2003/12/09 21:53:37
237 [readconf.c readconf.h scp.1 servconf.c servconf.h sftp.1 ssh.1]
238 [ssh_config.5 sshconnect.c sshd.c sshd_config.5]
239 rename keepalive to tcpkeepalive; the old name causes too much
240 confusion; ok djm, dtucker; with help from jmc@
66357af5 241 - dtucker@cvs.openbsd.org 2003/12/09 23:45:32
242 [clientloop.c]
243 Clear exit code when ssh -N is terminated with a SIGTERM. ok markus@
e8dd24a8 244 - markus@cvs.openbsd.org 2003/12/14 12:37:21
245 [ssh_config.5]
246 we don't support GSS KEX; from Simon Wilkinson
5d8d32a3 247 - markus@cvs.openbsd.org 2003/12/16 15:49:51
248 [clientloop.c clientloop.h readconf.c readconf.h scp.1 sftp.1 ssh.1]
249 [ssh.c ssh_config.5]
250 application layer keep alive (ServerAliveInterval ServerAliveCountMax)
251 for ssh(1), similar to the sshd(8) option; ok beck@; with help from
252 jmc and dtucker@
b3c35b71 253 - markus@cvs.openbsd.org 2003/12/16 15:51:54
254 [dh.c]
255 use <= instead of < in dh_estimate; ok provos/hshoexer;
256 do not return < DH_GRP_MIN
9a3fe0e2 257 - (dtucker) [acconfig.h configure.ac uidswap.c] Bug #645: Check for
258 setres[ug]id() present but not implemented (eg some Linux/glibc
259 combinations).
cc1102cb 260 - (bal) [openbsd-compat/bsd-misc.c] unset 'signal' defined if we are
261 using a real 'signal()' (Noticed by a NeXT Compile)
95ae2076 262
ef75d357 26320031209
264 - (dtucker) OpenBSD CVS Sync
265 - matthieu@cvs.openbsd.org 2003/11/25 23:10:08
266 [ssh-add.1]
267 ssh-add doesn't need to be a descendant of ssh-agent. Ok markus@, jmc@.
dfeea606 268 - djm@cvs.openbsd.org 2003/11/26 21:44:29
269 [cipher-aes.c]
270 fix #ifdef before #define; ok markus@
271 (RCS ID sync only, Portable already had this)
adfde93f 272 - markus@cvs.openbsd.org 2003/12/02 12:15:10
273 [progressmeter.c]
274 improvments from andreas@:
275 * saner speed estimate for transfers that takes less than a second by
276 rounding the time to 1 second.
277 * when the transfer is finished calculate the actual total speed
278 rather than the current speed which is given during the transfer
fce39749 279 - markus@cvs.openbsd.org 2003/12/02 17:01:15
280 [channels.c session.c ssh-agent.c ssh.h sshd.c]
281 use SSH_LISTEN_BACKLOG (=128) in listen(2).
69e782ea 282 - djm@cvs.openbsd.org 2003/12/07 06:34:18
283 [moduli.c]
284 remove unused debugging #define templates
5acd7dc1 285 - markus@cvs.openbsd.org 2003/12/08 11:00:47
286 [kexgexc.c]
287 print requested group size in debug; ok djm
eb7a33b8 288 - dtucker@cvs.openbsd.org 2003/12/09 13:52:55
289 [moduli.c]
290 Prevent ssh-keygen -T from outputting moduli with a generator of 0, since
291 they can't be used for Diffie-Hellman. Assistance and ok djm@
b97b4f35 292 - (dtucker) [ssh-keyscan.c] Sync RCSIDs, missed in SSH_SSFDMAX change below.
ef75d357 293
e6354014 29420031208
295 - (tim) [configure.ac] Bug 770. Fix --without-rpath.
296
1639bb8f 29720031123
298 - (djm) [canohost.c] Move IPv4inV6 mapped address normalisation to its own
299 function and call it unconditionally
341c3efe 300 - (djm) OpenBSD CVS Sync
301 - djm@cvs.openbsd.org 2003/11/23 23:17:34
302 [ssh-keyscan.c]
303 from portable - use sysconf to detect fd limit; ok markus@
304 (tidy diff by adding SSH_SSFDMAX macro to defines.h)
e7e3e2c8 305 - djm@cvs.openbsd.org 2003/11/23 23:18:45
306 [ssh-keygen.c]
307 consistency PATH_MAX -> MAXPATHLEN; ok markus@
308 (RCS ID sync only)
309 - djm@cvs.openbsd.org 2003/11/23 23:21:21
310 [scp.c]
311 from portable: rename clashing variable limit-> limit_rate; ok markus@
312 (RCS ID sync only)
f7926e97 313 - dtucker@cvs.openbsd.org 2003/11/24 00:16:35
314 [ssh.1 ssh.c]
315 Make ssh -k mean GSSAPIDelegateCredentials=no. Suggestion & ok markus@
d74671e4 316 - (djm) Annotate OpenBSD-derived files in openbsd-compat/ with original
317 source file path (in OpenBSD tree).
1639bb8f 318
7fbb4189 31920031122
320 - (dtucker) [channels.c] Make AIX write limit code clearer. Suggested by djm@
f0b467ef 321 - (dtucker) [auth-passwd.c openbsd-compat/port-aix.c openbsd-compat/port-aix.h]
322 Move AIX specific password authentication code to port-aix.c, call
323 authenticate() until reenter flag is clear.
dbf8efb3 324 - (dtucker) [auth-sia.c configure.ac] Tru64 update from cmadams at hiwaay.net.
325 Use permanently_set_uid for SIA, only define DISABLE_FD_PASSING when SIA
326 is enabled, rely on SIA to check for locked accounts if enabled. ok djm@
10adbb52 327 - (djm) [scp.c] Rename limitbw -> limit_rate to match upstreamed patch
e20054de 328 - (djm) [sftp-int.c] Remove duplicated code from bogus sync
00df6acd 329 - (djm) [packet.c] Shuffle #ifdef to reduce conditionally compiled code
7fbb4189 330
81b161c2 33120031121
332 - (djm) OpenBSD CVS Sync
333 - markus@cvs.openbsd.org 2003/11/20 11:39:28
334 [progressmeter.c]
335 fix rounding errors; from andreas@
aff51935 336 - djm@cvs.openbsd.org 2003/11/21 11:57:03
337 [everything]
338 unexpand and delete whitespace at EOL; ok markus@
339 (done locally and RCS IDs synced)
81b161c2 340
3eaf3960 34120031118
4d1de3a3 342 - (djm) Fix early exit for root auth success when UsePAM=yes and
343 PermitRootLogin=no
3eaf3960 344 - (dtucker) [auth-pam.c] Convert chauthtok_conv into a generic tty_conv,
95077f48 345 and use it for do_pam_session. Fixes problems like pam_motd not
346 displaying anything. ok djm@
f79a6165 347 - (dtucker) [auth-pam.c] Only use pam_putenv if our platform has it. ok djm@
95077f48 348 - (djm) OpenBSD CVS Sync
349 - dtucker@cvs.openbsd.org 2003/11/18 00:40:05
350 [serverloop.c]
351 Correct check for authctxt->valid. ok djm@
b2a5802b 352 - djm@cvs.openbsd.org 2003/11/18 10:53:07
353 [monitor.c]
354 unbreak fake authloop for non-existent users (my screwup). Spotted and
355 tested by dtucker@; ok markus@
4d1de3a3 356
85a68682 35720031117
358 - (djm) OpenBSD CVS Sync
359 - djm@cvs.openbsd.org 2003/11/03 09:03:37
360 [auth-chall.c]
361 make this a little more idiot-proof; ok markus@
362 (includes portable-specific changes)
1a1bc5d5 363 - jakob@cvs.openbsd.org 2003/11/03 09:09:41
364 [sshconnect.c]
365 move changed key warning into warn_changed_key(). ok markus@
f5da7f70 366 - jakob@cvs.openbsd.org 2003/11/03 09:37:32
367 [sshconnect.c]
368 do not free static type pointer in warn_changed_key()
fdaef11e 369 - djm@cvs.openbsd.org 2003/11/04 08:54:09
370 [auth1.c auth2.c auth2-pubkey.c auth.h auth-krb5.c auth-passwd.c]
371 [auth-rhosts.c auth-rh-rsa.c auth-rsa.c monitor.c serverloop.c]
372 [session.c]
373 standardise arguments to auth methods - they should all take authctxt.
374 check authctxt->valid rather then pw != NULL; ok markus@
dc1759e6 375 - jakob@cvs.openbsd.org 2003/11/08 16:02:40
376 [auth1.c]
377 remove unused variable (pw). ok djm@
378 (id sync only - still used in portable)
512d319a 379 - jmc@cvs.openbsd.org 2003/11/08 19:17:29
380 [sftp-int.c]
381 typos from Jonathon Gray;
b6c7b7b7 382 - jakob@cvs.openbsd.org 2003/11/10 16:23:41
383 [bufaux.c bufaux.h cipher.c cipher.h hostfile.c hostfile.h key.c]
384 [key.h sftp-common.c sftp-common.h sftp-server.c sshconnect.c sshd.c]
385 [ssh-dss.c ssh-rsa.c uuencode.c uuencode.h]
386 constify. ok markus@ & djm@
15c8e3fd 387 - dtucker@cvs.openbsd.org 2003/11/12 10:12:15
388 [scp.c]
389 When called with -q, pass -q to ssh; suppresses SSH2 banner. ok markus@
0161a13d 390 - jakob@cvs.openbsd.org 2003/11/12 16:39:58
391 [dns.c dns.h readconf.c ssh_config.5 sshconnect.c]
392 update SSHFP validation. ok markus@
dd376e92 393 - jmc@cvs.openbsd.org 2003/11/12 20:14:51
394 [ssh_config.5]
395 make verb agree with subject, and kill some whitespace;
b930668c 396 - markus@cvs.openbsd.org 2003/11/14 13:19:09
397 [sshconnect2.c]
398 cleanup and minor fixes for the client code; from Simon Wilkinson
d3cbe6f8 399 - djm@cvs.openbsd.org 2003/11/17 09:45:39
400 [msg.c msg.h sshconnect2.c ssh-keysign.c]
401 return error on msg send/receive failure (rather than fatal); ok markus@
0789992b 402 - markus@cvs.openbsd.org 2003/11/17 11:06:07
403 [auth2-gss.c gss-genr.c gss-serv.c monitor.c monitor.h monitor_wrap.c]
404 [monitor_wrap.h sshconnect2.c ssh-gss.h]
405 replace "gssapi" with "gssapi-with-mic"; from Simon Wilkinson;
406 test + ok jakob.
7b2a0de3 407 - (djm) Bug #632: Don't call pam_end indirectly from within kbd-int
408 conversation function
2212fc98 409 - (djm) Export environment variables from authentication subprocess to
410 parent. Part of Bug #717
85a68682 411
1d58af42 41220031115
413 - (dtucker) [regress/agent-ptrace.sh] Test for GDB output from Solaris and
414 HP-UX, skip test on AIX.
415
74117b26 41620031113
417 - (dtucker) [auth-pam.c] Append newlines to lines output by the
418 pam_chauthtok_conv().
9e936326 419 - (dtucker) [README ssh-host-config ssh-user-config Makefile] (All
420 contrib/cygwin). Major update from vinschen at redhat.com.
421 - Makefile provides a `cygwin-postinstall' target to run right after
422 `make install'.
423 - Better support for Windows 2003 Server.
424 - Try to get permissions as correct as possible.
425 - New command line options to allow full automated host configuration.
426 - Create configs from skeletons in /etc/defaults/etc.
427 - Use /bin/bash, allows reading user input with readline support.
428 - Remove really old configs from /usr/local.
4f1b45b4 429 - (dtucker) [auth-pam.c] Add newline to accumulated PAM_TEXT_INFO and
430 PAM_ERROR_MSG messages.
74117b26 431
53554b24 43220031106
433 - (djm) Clarify UsePAM consequences a little more
434
c3d908f0 43520031103
436 - (dtucker) [contrib/cygwin/ssh-host-config] Ensure entries in /etc/services
437 are created correctly with CRLF line terminations. Patch from vinschen at
438 redhat.com.
74677ba3 439 - (dtucker) OpenBSD CVS Sync
440 - markus@cvs.openbsd.org 2003/10/15 09:48:45
441 [monitor_wrap.c]
442 check pmonitor != NULL
9da35e2c 443 - markus@cvs.openbsd.org 2003/10/21 09:50:06
444 [auth2-gss.c]
445 make sure the doid is larger than 2
b0b30ca6 446 - avsm@cvs.openbsd.org 2003/10/26 16:57:43
447 [sshconnect2.c]
448 rename 'supported' static var in userauth_gssapi() to 'gss_supported'
449 to avoid shadowing the global version. markus@ ok
f7fb35fe 450 - markus@cvs.openbsd.org 2003/10/28 09:08:06
451 [misc.c]
452 error->debug for getsockopt+TCP_NODELAY; several requests
d8d9afd0 453 - markus@cvs.openbsd.org 2003/11/02 11:01:03
454 [auth2-gss.c compat.c compat.h sshconnect2.c]
455 remove support for SSH_BUG_GSSAPI_BER; simon@sxw.org.uk
61893035 456 - (dtucker) [regress/agent-ptrace.sh] Use numeric uid and gid.
c3d908f0 457
f8ec2373 45820031021
459 - (dtucker) [INSTALL] Some system crypt() functions support MD5 passwords
460 directly. Noted by Darren.Moffat at sun.com.
5c4056b2 461 - (dtucker) [regress/agent-ptrace.sh] Skip agent-test unless SUDO is set,
462 make agent setgid during test.
f8ec2373 463
4897a87c 46420031017
465 - (dtucker) [INSTALL] Note that --with-md5 is now required on platforms with
466 MD5 passwords even if PAM support is enabled. From steev at detritus.net.
467
433e60ac 46820031015
469 - (dtucker) OpenBSD CVS Sync
470 - jmc@cvs.openbsd.org 2003/10/08 08:27:36
471 [scp.1 scp.c sftp-server.8 sftp.1 sftp.c ssh.1 sshd.8]
472 scp and sftp: add options list and sort options. options list requested
473 by deraadt@
474 sshd: use same format as ssh
475 ssh: remove wrong option from list
476 sftp-server: Subsystem is documented in ssh_config(5), not sshd(8)
477 ok deraadt@ markus@
2ecb78df 478 - markus@cvs.openbsd.org 2003/10/08 15:21:24
479 [readconf.c ssh_config.5]
480 default GSS API to no in client, too; ok jakob, deraadt@
d73a67d7 481 - markus@cvs.openbsd.org 2003/10/11 08:24:08
482 [readconf.c readconf.h ssh.1 ssh.c ssh_config.5]
483 remote x11 clients are now untrusted by default, uses xauth(8) to generate
484 untrusted cookies; ForwardX11Trusted=yes restores old behaviour.
485 ok deraadt; feedback and ok djm/fries
b56e99e2 486 - markus@cvs.openbsd.org 2003/10/11 08:26:43
487 [sshconnect2.c]
488 search keys in reverse order; fixes #684
02cd6c56 489 - markus@cvs.openbsd.org 2003/10/11 11:36:23
490 [monitor_wrap.c]
491 return NULL for missing banner; ok djm@
246bb171 492 - jmc@cvs.openbsd.org 2003/10/12 13:12:13
493 [ssh_config.5]
494 note that EnableSSHKeySign should be in the non-hostspecific section;
495 remove unnecessary .Pp;
496 ok markus@
b3054353 497 - markus@cvs.openbsd.org 2003/10/13 08:22:25
498 [scp.1 sftp.1]
499 don't refer to options related to forwarding; ok jmc@
b08b7370 500 - jakob@cvs.openbsd.org 2003/10/14 19:42:10
501 [dns.c dns.h readconf.c ssh-keygen.c sshconnect.c]
502 include SSHFP lookup code (not enabled by default). ok markus@
baf12e3f 503 - jakob@cvs.openbsd.org 2003/10/14 19:43:23
504 [README.dns]
505 update
c88de854 506 - markus@cvs.openbsd.org 2003/10/14 19:54:39
507 [session.c ssh-agent.c]
508 10X for mkdtemp; djm@
c31dc31c 509 - (dtucker) [acconfig.h configure.ac dns.c openbsd-compat/getrrsetbyname.c
510 openbsd-compat/getrrsetbyname.h] DNS fingerprint support is now always
511 compiled in but disabled in config.
11d40248 512 - (dtucker) [auth.c] Check for disabled password expiry on HP-UX Trusted Mode.
ea12f758 513 - (tim) [regress/banner.sh] portability fix.
433e60ac 514
a83a3125 51520031009
516 - (dtucker) [sshd_config.5] UsePAM defaults to "no". ok djm@
517
19e633e7 51820031008
519 - (dtucker) OpenBSD CVS Sync
520 - dtucker@cvs.openbsd.org 2003/10/07 01:47:27
521 [sshconnect2.c]
c8f0cf13 522 Don't use logit for banner, since it truncates to MSGBUFSIZ; bz #668 &
523 #707. ok markus@
7fdf5569 524 - djm@cvs.openbsd.org 2003/10/07 07:04:16
525 [sftp-int.c]
526 sftp quoting fix from admorten AT umich.edu; ok markus@
c8f0cf13 527 - deraadt@cvs.openbsd.org 2003/10/07 21:58:28
528 [sshconnect2.c]
529 set ptr to NULL after free
4c98e94c 530 - dtucker@cvs.openbsd.org 2003/10/07 01:52:13
531 [regress/Makefile regress/banner.sh]
532 Test SSH2 banner. ok markus@
3d3e0ec3 533 - djm@cvs.openbsd.org 2003/10/07 07:04:52
534 [regress/sftp-cmds.sh]
535 more sftp quoting regress tests; ok markus
19e633e7 536
e3df52a9 53720031007
538 - (djm) Delete autom4te.cache after autoreconf
c6630044 539 - (dtucker) [auth-pam.c auth-pam.h session.c] Make PAM use the new static
540 cleanup functions. With & ok djm@
f658a5e8 541 - (dtucker) [contrib/redhat/openssh.spec] Bug #714: Now that UsePAM is a
542 run-time switch, always build --with-md5-passwords.
7111a85c 543 - (dtucker) [configure.ac openbsd-compat/Makefile.in openbsd-compat/strtoul.c]
544 Bug #670: add strtoul() to openbsd-compat for platforms lacking it. ok djm@
605369bb 545 - (dtucker) [configure.ac] Bug #715: Set BROKEN_SETREUID and BROKEN_SETREGID
546 on Reliant Unix. Patch from Robert.Dahlem at siemens.com.
e2798e96 547 - (dtucker) [configure.ac] Bug #710: Check for dlsym() in libdl on
548 Reliant Unix. Based on patch from Robert.Dahlem at siemens.com.
e3df52a9 549
418ae4b4 55020031003
3f1204c3 551 - (dtucker) OpenBSD CVS Sync
418ae4b4 552 - markus@cvs.openbsd.org 2003/10/02 10:41:59
553 [sshd.c]
554 print openssl version, too, several requests; ok henning/djm.
59f552b7 555 - markus@cvs.openbsd.org 2003/10/02 08:26:53
556 [ssh-gss.h]
557 missing $OpenBSD:; dtucker
ba7c26ce 558 - (tim) [contrib/caldera/openssh.spec] Remove obsolete --with-ipv4-default
559 option.
418ae4b4 560
2362db19 56120031002
3f1204c3 562 - (dtucker) OpenBSD CVS Sync
2362db19 563 - markus@cvs.openbsd.org 2003/09/23 20:17:11
564 [Makefile.in auth1.c auth2.c auth.c auth.h auth-krb5.c canohost.c
565 cleanup.c clientloop.c fatal.c gss-serv.c log.c log.h monitor.c monitor.h
566 monitor_wrap.c monitor_wrap.h packet.c serverloop.c session.c session.h
567 ssh-agent.c sshd.c]
568 replace fatal_cleanup() and linked list of fatal callbacks with static
569 cleanup_exit() function. re-refine cleanup_exit() where appropriate,
570 allocate sshd's authctxt eary to allow simpler cleanup in sshd.
571 tested by many, ok deraadt@
0469be42 572 - markus@cvs.openbsd.org 2003/09/23 20:18:52
573 [progressmeter.c]
574 don't print trailing \0; bug #709; Robert.Dahlem@siemens.com
575 ok millert/deraadt@
c15706e2 576 - markus@cvs.openbsd.org 2003/09/23 20:41:11
577 [channels.c channels.h clientloop.c]
578 move client only agent code to clientloop.c
51d2a129 579 - markus@cvs.openbsd.org 2003/09/26 08:19:29
580 [sshd.c]
581 no need to set the listen sockets to non-block; ok deraadt@
5f4a0c58 582 - jmc@cvs.openbsd.org 2003/09/29 11:40:51
583 [ssh.1]
584 - add list of options to -o and .Xr ssh_config(5)
585 - some other cleanup
586 requested by deraadt@;
587 ok deraadt@ markus@
e377c083 588 - markus@cvs.openbsd.org 2003/09/29 20:19:57
589 [servconf.c sshd_config]
590 GSSAPICleanupCreds -> GSSAPICleanupCredentials
97b56d59 591 - (dtucker) [configure.ac] Don't set DISABLE_SHADOW when configuring
592 --with-pam. ok djm@
21c1aca3 593 - (dtucker) [ssh-gss.h] Prototype change missed in sync.
3a23ba0e 594 - (dtucker) [session.c] Fix bus errors on some 64-bit Solaris configurations.
595 Based on patches by Matthias Koeppe and Thomas Baden. ok djm@
2362db19 596
0cdb4344 59720030930
598 - (bal) Fix issues in openbsd-compat/realpath.c
599
4214aa45 60020030925
601 - (dtucker) [configure.ac openbsd-compat/xcrypt.c] Bug #633: Remove
602 DISABLE_SHADOW for HP-UX, use getspnam instead of getprpwnam. Patch from
603 michael_steffens at hp.com, ok djm@
1b4ba39b 604 - (tim) [sshd_config] UsePAM defaults to no.
4214aa45 605
67c4ea7d 60620030924
607 - (djm) Update version.h and spec files for HEAD
cb433561 608 - (dtucker) [configure.ac] IRIX5 needs the same setre[ug]id defines as IRIX6.
67c4ea7d 609
5ba73866 61020030923
291c14e8 611 - (dtucker) [Makefile.in] Bug #644: Fix "make clean" for out-of-tree
5ba73866 612 builds. Portability corrections from tim@.
b27e573d 613 - (dtucker) [configure.ac] Bug #665: uid swapping issues on Mac OS X.
635e0c42 614 Patch from max at quendi.de.
08da2d08 615 - (dtucker) [configure.ac] Bug #657: uid swapping issues on BSDi.
616 - (dtucker) [configure.ac] Bug #653: uid swapping issues on Tru64.
6fb3618d 617 - (dtucker) [configure.ac] Bug #693: uid swapping issues on NCR MP-RAS.
618 Patch from david.haughton at ncr.com
412c0eaa 619 - (dtucker) [configure.ac] Bug #659: uid swapping issues on IRIX 6.
620 Part of patch supplied by bugzilla-openssh at thewrittenword.com
1a086f97 621 - (dtucker) [configure.ac openbsd-compat/fake-rfc2553.c
622 openbsd-compat/fake-rfc2553.h] Bug #659: Test for and handle systems with
623 where gai_strerror is defined as "const char *". Part of patch supplied
624 by bugzilla-openssh at thewrittenword.com
35283c00 625 - (dtucker) [contrib/cygwin/README contrib/cygwin/ssh-host-config] Update
626 ssh-host-config to match current defaults, bump README version. Patch from
627 vinschen at redhat.com.
51e7d820 628 - (dtucker) [uidswap.c] Don't test restoration of uid on Cygwin since the
629 OS does not support permanently dropping privileges. Patch from
630 vinschen at redhat.com.
805dcf3a 631 - (dtucker) [openbsd-compat/port-aix.c] Use correct include for xmalloc.h,
632 add canohost.h to stop warning. Based on patch from openssh-unix-dev at
633 thewrittenword.com
913a4384 634 - (dtucker) [INSTALL] Bug #686: Document requirement for zlib 1.1.4 or
635 higher.
f4f2ff4f 636 - (tim) Fix typo. s/SETEIUD_BREAKS_SETUID/SETEUID_BREAKS_SETUID/
b27e573d 637 - (tim) [configure.ac] Bug 665: move 3 new AC_DEFINES outside of AC_TRY_RUN.
638 Report by distler AT golem ph utexas edu.
ca043cac 639 - (dtucker) [contrib/aix/pam.conf] Include example pam.conf for AIX from
640 article by genty at austin.ibm.com, included with the author's permission.
ce26c02a 641 - (dtucker) OpenBSD CVS Sync
642 - markus@cvs.openbsd.org 2003/09/18 07:52:54
643 [sshconnect.c]
644 missing {}; bug #656; jclonguet at free.fr
5bd34316 645 - markus@cvs.openbsd.org 2003/09/18 07:54:48
646 [buffer.c]
647 protect against double free; #660; zardoz at users.sf.net
1bd71826 648 - markus@cvs.openbsd.org 2003/09/18 07:56:05
649 [authfile.c]
650 missing buffer_free(&encrypted); #662; zardoz at users.sf.net
c46e584f 651 - markus@cvs.openbsd.org 2003/09/18 08:49:45
652 [deattack.c misc.c session.c ssh-agent.c]
653 more buffer allocation fixes; from Solar Designer; CAN-2003-0682;
654 ok millert@
bb92e5cc 655 - miod@cvs.openbsd.org 2003/09/18 13:02:21
656 [authfd.c bufaux.c dh.c mac.c ssh-keygen.c]
657 A few signedness fixes for harmless situations; markus@ ok
9adbb4a4 658 - markus@cvs.openbsd.org 2003/09/19 09:02:02
659 [packet.c]
660 buffer_dump only if PACKET_DEBUG is defined; Jedi/Sector One; pr 3471
f04181fe 661 - markus@cvs.openbsd.org 2003/09/19 09:03:00
662 [buffer.c]
663 sign fix in buffer_dump; Jedi/Sector One; pr 3473
cd25664d 664 - markus@cvs.openbsd.org 2003/09/19 11:29:40
665 [ssh-agent.c]
666 provide a ssh-agent specific fatal() function; ok deraadt
eec6d341 667 - markus@cvs.openbsd.org 2003/09/19 11:30:39
668 [ssh-keyscan.c]
669 avoid fatal_cleanup, just call exit(); ok deraadt
364b1cde 670 - markus@cvs.openbsd.org 2003/09/19 11:31:33
671 [channels.c]
672 do not call channel_free_all on fatal; ok deraadt
72c4301f 673 - markus@cvs.openbsd.org 2003/09/19 11:33:09
674 [packet.c sshd.c]
675 do not call packet_close on fatal; ok deraadt
815a8407 676 - markus@cvs.openbsd.org 2003/09/19 17:40:20
677 [scp.c]
678 error handling for remote-remote copy; #638; report Harald Koenig;
679 ok millert, fgs, henning, deraadt
82de775c 680 - markus@cvs.openbsd.org 2003/09/19 17:43:35
681 [clientloop.c sshtty.c sshtty.h]
682 remove fatal callbacks from client code; ok deraadt
9e3191db 683 - (bal) "extration" -> "extraction" in ssh-rand-helper.c; repoted by john
684 on #unixhelp@efnet
daa41e62 685 - (tim) [configure.ac] add --disable-etc-default-login option. ok djm
0a23d79f 686 - (djm) Sync with V_3_7 branch:
687 - (djm) Fix SSH1 challenge kludge
688 - (djm) Bug #671: Fix builds on OpenBSD
689 - (djm) Bug #676: Fix PAM stack corruption
690 - (djm) Fix bad free() in PAM code
691 - (djm) Don't call pam_end before pam_init
692 - (djm) Enable build with old OpenSSL again
693 - (djm) Trim deprecated options from INSTALL. Mention UsePAM
694 - (djm) Fix quote handling in sftp; Patch from admorten AT umich.edu
5ba73866 695
a801511e 69620030919
697 - (djm) Bug #683: Remove reference to --with-ipv4-default from INSTALL;
698 djast AT cs.toronto.edu
48646332 699 - (djm) Bug #661: Remove duplicate check for basename; from
700 bugzilla-openssh AT thewrittenword.com
34799445 701 - (djm) Bug #641: Allow RedHat RPM building without GTK-2; Patch from
702 jason AT devrandom.org
fd79af78 703 - (djm) Bug #646: Fix location of x11-ssh-askpass; Jim
4608d193 704 - (dtucker) [openbsd-compat/port-aix.h] Bug #640: Don't include audit.h
705 unless required. Reorder to reduce warnings.
6f99680f 706 - (dtucker) [session.c] Bug #643: Fix size_t -> u_int and fix null deref
707 when /etc/default/login doesn't exist or isn't readable. Fixes from
708 jparsons-lists at saffron.net and georg.oppenberg at deu mci com.
97e3cf19 709 - (dtucker) [acconfig.h] Updated basename test needs HAVE_BASENAME
a801511e 710
33fb67f0 71120030918
712 - (djm) Bug #652: Fix empty password auth
713
263c65df 71420030917
715 - (djm) Sync with V_3_7 branch
20419cc1 716 - (djm) OpenBSD Sync
717 - markus@cvs.openbsd.org 2003/09/16 21:02:40
718 [buffer.c channels.c version.h]
719 more malloc/fatal fixes; ok millert/deraadt; ghudson at MIT.EDU
38d24e7d 720 - (djm) Crank RPM spec file versions
ddd8e845 721 - (tim) [openbsd-compat/inet_ntoa.c] 20030917 "Sync with V_3_7 branch" undid
722 20030916 "Missed dead header in inet_ntoa.c"
38d24e7d 723
95b99395 72420030916
725 - (dtucker) [acconfig.h configure.ac defines.h session.c] Bug #252: Retrieve
726 PATH (or SUPATH) and UMASK from /etc/default/login on platforms that have it
49525395 727 (eg Solaris, Reliant Unix). Patch from Robert.Dahlem at siemens.com.
728 ok djm@
729 - (bal) OpenBSD Sync
730 - deraadt@cvs.openbsd.org 2003/09/16 03:03:47
731 [buffer.c]
732 do not expand buffer before attempting to reallocate it; markus ok
89bbd457 733 - (tim) [configure.ac] Fix portability issues.
bb6dd12a 734 - (bal) Missed dead header in inet_ntoa.c
95b99395 735
bdb15424 73620030914
737 - (dtucker) [Makefile regress/Makefile] Fix portability issues preventing
738 the regression tests from running with Solaris' make. Patch from Brian
739 Poole (raj at cerias.purdue.edu).
906f3b9d 740 - (dtucker) [regress/Makefile] AIX's make doesn't like " +=", so replace
741 with vanilla "=".
bdb15424 742
b64864e1 74320030913
744 - (dtucker) [regress/agent-timeout.sh] Timeout of 5 sec is borderline for
745 slower hosts, increase to 10 sec.
217a0ad5 746 - (dtucker) [auth-passwd.c] On AIX, call setauthdb() before loginsuccess(),
747 required to correctly reset failed login count when using a password
748 registry other than "files" (eg LDAP, see bug #543).
bcebad47 749 - (tim) [configure.ac] define WITH_ABBREV_NO_TTY for SCO.
750 Report by Roger Cornelius.
01224183 751 - (dtucker) [auth-pam.c] Use SSHD_PAM_SERVICE for PAM service name, patch
752 from cjwatson at debian.org.
b64864e1 753
a473643e 75420030912
755 - (tim) [regress/agent-ptrace.sh] sh doesn't like "if ! shell_function; then".
e43957b9 756 - (tim) [Makefile.in] only mkdir regress if it does not exist.
7126ceb2 757 - (tim) [regress/yes-head.sh] shell portability fix.
a473643e 758
af940dcb 75920030911
760 - (dtucker) [configure.ac] Bug #588, #615: Move other libgen tests to after
761 the dirname test, to allow a broken dirname to be detected correctly.
762 Based partially on patch supplied by alex.kiernan at thus.net. ok djm@
446227d6 763 - (tim) [configure.ac] Move libgen tests to before libwrap to unbreak
764 UnixWare 2.03 using --with-tcp-wrappers.
7ed101c0 765 - (tim) [configure.ac] Prefer setuid/setgid on UnixWare and Open Server.
c1b10a96 766 - (tim) [regress/agent-ptrace.sh regress/dynamic-forward.sh
767 regress/sftp-cmds.sh regress/stderr-after-eof.sh regress/test-exec.sh]
768 no longer depends on which(1). patch by dtucker@
af940dcb 769
7b9a8c6e 77020030910
771 - (dtucker) [configure.ac] Bug #636: Add support for Cray's new X1 machine.
772 Patch from wendyp at cray.com.
3490699c 773 - (dtucker) [configure.ac] Part of bug #615: tcsendbreak might be a macro.
2e8d2c13 774 - (dtucker) [regressh/yes-head.sh] Some platforms (eg Solaris) don't have
775 "yes".
7b9a8c6e 776
12e07a07 77720030909
778 - (tim) [regress/Makefile] Fixes for building outside of a read-only
779 source tree.
5d3cef06 780 - (tim) [regress/agent-timeout.sh] s/TIMEOUT/SSHAGENT_TIMEOUT/ Fixes conflict
781 with shell read-only variable.
2b1bb684 782 - (tim) [regress/sftp-badcmds.sh regress/sftp-cmds.sh] Fix errors like
783 UX:rm: ERROR: Cannot remove '.' or '..'
12e07a07 784
252ff4df 78520030908
786 - (tim) [configure.ac openbsd-compat/getrrsetbyname.c] wrap _getshort and
787 _getlong in #ifndef
078ec045 788 - (tim) [configure.ac acconfig.h openbsd-compat/getrrsetbyname.c] test for
789 HEADER.ad in arpa/nameser.h
8f52069e 790 - (tim) [ssh-keygen.c] s/PATH_MAX/MAXPATHLEN/ ok mouring@
252ff4df 791
c9535c4d 79220030907
793 - (dtucker) [agent-ptrace.sh dynamic-forward.sh (all regress/)]
794 Put "which" inside quotes.
5781bb58 795 - (dtucker) [dynamic-forward.sh forwarding.sh sftp-batch.sh (all regress/)]
796 Add ${EXEEXT}: required to work on Cygwin.
7621a857 797 - (dtucker) [regress/sftp-batch.sh] Make temporary batch file name more
798 distinctive, so "rm ${BATCH}.*" doesn't match the script itself.
ac4a169f 799 - (dtucker) [regress/sftp-cmds.sh] Skip quoted file test on Cygwin.
9a7582f1 800 - (dtucker) [openbsd-compat/xcrypt.c] #elsif -> #elif
801 - (dtucker) [acconfig.h] Typo.
4bbf95fa 802 - (dtucker) [CREDITS Makefile.in configure.ac mdoc2man.awk mdoc2man.pl]
803 Replace mdoc2man.pl with mdoc2man.awk, provided by Peter Stuge.
c9535c4d 804
3b8dff69 80520030906
806 - (dtucker) [acconfig.h configure.ac uidswap.c] Prefer setuid/setgid on AIX.
807
5e6f8a42 80820030905
809 - (dtucker) [Makefile.in] Add distclean target for regress/, fix clean target.
810
7ed6b890 81120030904
812 - (dtucker) Portablize regression tests. Parts contributed by Roumen
813 Petrov, David M. Williams and Corinna Vinschen.
814 - [Makefile.in] Add "make tests" target and "make clean" hooks.
584c5ed9 815 - [regress/agent-getpeereid.sh] Skip test on platforms that don't support
816 getpeereid.
335f57ae 817 - [regress/agent-ptrace.sh] Skip tests if platform doesn't support it or
818 gdb cannot be found.
c4cc19d5 819 - [regress/reconfigure/sh] Make path to sshd fully qualified if required.
e4f79c8f 820 - [regress/rekey.sh] Remove dependence on /dev/zero (not all platforms have
821 it). The sparse file will take less disk space too.
c67d1ba1 822 - [regress/sftp-cmds.sh] Ensure files used for test are readable.
9a7cf6f2 823 - [regress/stderr-after-eof.sh] Search for a usable checksum program.
83d96134 824 - [regress/sftp-badcmds.sh regress/sftp-cmds.sh regress/sftp.sh
825 regress/ssh-com-client.sh regress/ssh-com-sftp.sh regress/stderr-data.sh
826 regress/transfer.sh] Use ${EXEEXT} where appropriate.
302294d5 827 - [regress/sftp.sh regress/ssh-com-sftp.sh] Remove dependency on /dev/stdin.
d23e7be4 828 - [regress/agent-ptrace.sh regress/agent-timeout.sh]
829 "grep -q" -> "grep >/dev/null"
c7751424 830 - [regress/agent.sh regress/proto-version.sh regress/ssh-com.sh
c9535c4d 831 regress/test-exec.sh] Handle different ways of echoing without newlines.
46f493c6 832 - [regress/dynamic-forward.sh] Some "which" programs output on stderr.
a687e172 833 - [regress/sftp-cmds.sh] Use portable "test" option.
4638d96a 834 - [regress/test-exec.sh] Use sudo, search for "whoami" equivalent, always
835 use Strictmodes no, wait longer for sshd startup.
d99acf36 836 - [regress/Makefile] Remove BSDisms.
b0315114 837 - [regress/README.regress] Add a basic readme.
c67d1ba1 838 - [Makefile.in regress/agent-getpeereid.sh] config.h is now in $BUILDDIR
839 not $OBJ.
ccb02b94 840 - [Makefile.in regress/agent-ptrace] Fix minor regress issues on Cygwin.
7ed6b890 841
96d0bf74 84220030903
843 - (djm) OpenBSD CVS Sync
844 - markus@cvs.openbsd.org 2003/08/26 09:58:43
845 [auth-passwd.c auth.c auth.h auth1.c auth2-none.c auth2-passwd.c]
846 [auth2.c monitor.c]
847 fix passwd auth for 'username leaks via timing'; with djm@, original
848 patches from solar
5f2a8485 849 - markus@cvs.openbsd.org 2003/08/28 12:54:34
850 [auth.h]
851 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
852 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
b6f9987b 853 - markus@cvs.openbsd.org 2003/09/02 16:40:29
854 [version.h]
855 enter 3.7
d0445371 856 - jmc@cvs.openbsd.org 2003/09/02 18:50:06
857 [sftp.1 ssh_config.5]
858 escape punctuation;
859 ok deraadt@
96d0bf74 860
408fb07b 86120030902
eb18f58d 862 - (djm) OpenBSD CVS Sync
863 - deraadt@cvs.openbsd.org 2003/08/24 17:36:51
864 [auth2-gss.c]
865 64 bit cleanups; markus ok
8f73f7bb 866 - markus@cvs.openbsd.org 2003/08/28 12:54:34
867 [auth-krb5.c auth.h auth1.c monitor.c monitor.h monitor_wrap.c]
868 [monitor_wrap.h readconf.c servconf.c session.c ssh_config.5]
869 [sshconnect1.c sshd.c sshd_config sshd_config.5]
870 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
871 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
e3e69949 872 - markus@cvs.openbsd.org 2003/08/29 10:03:15
873 [compat.c compat.h]
874 SSH_BUG_K5USER is unused; ok henning@
d7ac5f18 875 - markus@cvs.openbsd.org 2003/08/29 10:04:36
876 [channels.c nchan.c]
877 be less chatty; debug -> debug2, cleanup; ok henning@
8e382949 878 - markus@cvs.openbsd.org 2003/08/31 10:26:04
879 [progressmeter.c]
880 pass file_size + 1 to snprintf: fixes printing of truncated
881 file names; fix based on patch/report from sturm@;
3845a9ac 882 - markus@cvs.openbsd.org 2003/08/31 12:14:22
883 [progressmeter.c]
884 do write to buf[-1]
f89f8ddc 885 - markus@cvs.openbsd.org 2003/08/31 13:29:05
886 [session.c]
887 call ssh_gssapi_storecreds conditionally from do_exec();
888 with sxw@inf.ed.ac.uk
96573c26 889 - markus@cvs.openbsd.org 2003/08/31 13:30:18
890 [gss-serv.c]
891 correct string termination in parse_ename(); sxw@inf.ed.ac.uk
a7958e7b 892 - markus@cvs.openbsd.org 2003/08/31 13:31:57
893 [gss-serv.c]
894 whitspace KNF
105b07db 895 - markus@cvs.openbsd.org 2003/09/01 09:50:04
896 [sshd_config.5]
897 gss kex is not supported; sxw@inf.ed.ac.uk
eac292f8 898 - markus@cvs.openbsd.org 2003/09/01 12:50:46
899 [readconf.c]
900 rm gssapidelegatecreds alias; never supported before
00fee838 901 - markus@cvs.openbsd.org 2003/09/01 13:52:18
902 [ssh.h]
903 rm whitespace
cc4d7cb6 904 - markus@cvs.openbsd.org 2003/09/01 18:15:50
905 [readconf.c readconf.h servconf.c servconf.h ssh.c]
906 remove unused kerberos code; ok henning@
4771605b 907 - markus@cvs.openbsd.org 2003/09/01 20:44:54
908 [auth2-gss.c]
909 fix leak
c53917a9 910 - (djm) Don't initialise pam_conv structures inline. Avoids HP/UX compiler
911 error. Part of Bug #423, patch from michael_steffens AT hp.com
49e82bb9 912 - (djm) Bug #423: reorder setting of PAM_TTY and calling of PAM session
913 management (now done in do_setusercontext). Largely from
914 michael_steffens AT hp.com
5e89e8a5 915 - (djm) Fix openbsd-compat/ again - remove references to strl(cpy|cat).h
916
2274ae66 91720030829
a5aec672 918 - (bal) openbsd-compat/ clean up. Considate headers, add in Id on our
2274ae66 919 files, and added missing license to header.
920
fe46678b 92120030826
922 - (djm) Bug #629: Mark ssh_config option "pamauthenticationviakbdint"
923 as deprecated. Remove mention from README.privsep. Patch from
924 aet AT cc.hut.fi
7364bd04 925 - (dtucker) OpenBSD CVS Sync
926 - markus@cvs.openbsd.org 2003/08/22 10:56:09
927 [auth2.c auth2-gss.c auth.h compat.c compat.h gss-genr.c gss-serv-krb5.c
928 gss-serv.c monitor.c monitor.h monitor_wrap.c monitor_wrap.h readconf.c
929 readconf.h servconf.c servconf.h session.c session.h ssh-gss.h
930 ssh_config.5 sshconnect2.c sshd_config sshd_config.5]
931 support GSS API user authentication; patches from Simon Wilkinson,
932 stripped down and tested by Jakob and myself.
1d9f0c09 933 - markus@cvs.openbsd.org 2003/08/22 13:20:03
934 [sshconnect2.c]
935 remove support for "kerberos-2@ssh.com"
816daa84 936 - markus@cvs.openbsd.org 2003/08/22 13:22:27
937 [auth2.c] (auth2-krb5.c removed)
938 nuke "kerberos-2@ssh.com"
52f6ea0e 939 - markus@cvs.openbsd.org 2003/08/22 20:55:06
940 [LICENCE]
941 add Simon Wilkinson
f99e1ca4 942 - deraadt@cvs.openbsd.org 2003/08/24 17:36:52
943 [monitor.c monitor_wrap.c sshconnect2.c]
944 64 bit cleanups; markus ok
e68d8348 945 - fgsch@cvs.openbsd.org 2003/08/25 08:13:09
946 [sftp-int.c]
947 fix div by zero when listing for filename lengths longer than width.
948 markus@ ok.
ea7bee97 949 - djm@cvs.openbsd.org 2003/08/25 10:33:33
950 [sshconnect2.c]
951 fprintf->logit to silence login banner with "ssh -q"; ok markus@
749560dd 952 - (dtucker) [Makefile.in acconfig.h auth-krb5.c auth-pam.c auth-pam.h
953 configure.ac defines.h gss-serv-krb5.c session.c ssh-gss.h sshconnect1.c
954 sshconnect2.c] Add Portable GSSAPI support, patch by Simon Wilkinson.
780efc0f 955 - (dtucker) [Makefile.in] Remove auth2-krb5.
2b7d75f5 956 - (dtucker) [contrib/aix/inventory.sh] Add public domain notice. ok mouring@
957 (the original author)
da67ae18 958 - (dtucker) [auth.c] Do not check for locked accounts when PAM is enabled.
fe46678b 959
4e2e1af3 96020030825
961 - (djm) Bug #621: Select OpenSC keys by usage attributes. Patch from
962 larsch@trustcenter.de
510a42ce 963 - (bal) openbsd-compat/ OpenBSD updates. Mostly licensing, ansifications
f00d1f78 964 and minor fixes. OK djm@
965 - (bal) redo how we handle 'mysignal()'. Move it to
966 openbsd-compat/bsd-misc.c, s/mysignal/signal/ and #define signal to
967 be our 'mysignal' by default. OK djm@
3e6e3da0 968 - (dtucker) [acconfig.h auth.c configure.ac sshd.8] Bug #422 again: deny
969 any access to locked accounts. ok djm@
5b9e2464 970 - (djm) Bug #564: Perform PAM account checks for all authentications when
971 UsePAM=yes; ok dtucker
a6e67b60 972 - (dtucker) [configure.ac] Bug #533, #551: define BROKEN_GETADDRINFO on
973 Tru64, solves getnameinfo and "bad addr or host" errors. ok djm@
ed00d4b7 974 - (dtucker) [README buildbff.sh inventory.sh] (all in contrib/aix)
975 Update package builder: correctly handle config variables, use lsuser
976 rather than /etc/passwd, fix typos, add Id's.
4e2e1af3 977
fda04d7d 97820030822
979 - (djm) s/get_progname/ssh_get_progname/g to avoid conflict with Heimdal
980 -lbroken; ok dtucker
fcd7f067 981 - (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
982 rather that authorized_keys2. Patch from vinschen@redhat.com.
fda04d7d 983
08d035b6 98420030821
985 - (dtucker) OpenBSD CVS Sync
986 - markus@cvs.openbsd.org 2003/08/14 16:08:58
987 [ssh-keygen.c]
988 exit after primetest, ok djm@
a814ba4d 989 - (dtucker) [defines.h] Put CMSG_DATA, CMSG_FIRSTHDR with other CMSG* macros,
990 change CMSG_DATA to use __CMSG_ALIGN (and thus work properly), reformat for
991 consistency.
eacb954e 992 - (dtucker) [configure.ac] Move openpty/ctty test outside of case statement
993 and after normal openpty test.
08d035b6 994
83814987 99520030813
996 - (dtucker) [session.c] Remove #ifdef TIOCSBRK kludge.
8168a86a 997 - (dtucker) OpenBSD CVS Sync
998 - markus@cvs.openbsd.org 2003/08/13 08:33:02
999 [session.c]
1000 use more portable tcsendbreak(3) and ignore break_length;
1001 ok deraadt, millert
0598d99d 1002 - markus@cvs.openbsd.org 2003/08/13 08:46:31
1003 [auth1.c readconf.c readconf.h servconf.c servconf.h ssh.c ssh_config
1004 ssh_config.5 sshconnect1.c sshd.8 sshd.c sshd_config sshd_config.5]
1005 remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,
1006 fgsch@, miod@, henning@, jakob@ and others
37ba5172 1007 - markus@cvs.openbsd.org 2003/08/13 09:07:10
1008 [readconf.c ssh.c]
1009 socks4->socks, since with support both 4 and 5; dtucker@zip.com.au
5af25b1d 1010 - (dtucker) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
1011 Add a tcsendbreak function for platforms that don't have one, based on the
1012 one from OpenBSD.
83814987 1013
78e43412 101420030811
1015 - (dtucker) OpenBSD CVS Sync
1016 (thanks to Simon Wilkinson for help with this -dt)
1017 - markus@cvs.openbsd.org 2003/07/16 15:02:06
1018 [auth-krb5.c]
1019 mcc -> fcc; from Love Hörnquist Åstrand <lha@it.su.se>
1020 otherwise the kerberos credentinal is stored in a memory cache
1021 in the privileged sshd. ok jabob@, hin@ (some time ago)
8c9f0900 1022 - (dtucker) [openbsd-compat/xcrypt.c] Remove Cygwin #ifdef block (duplicate
1023 in bsd-cygwin_util.h).
78e43412 1024
3095daf7 102520030808
1026 - (dtucker) [openbsd-compat/fake-rfc2553.h] Older Linuxes have AI_PASSIVE and
1027 AI_CANONNAME in netdb.h but not AI_NUMERICHOST, so check each definition
1028 separately before defining them.
26b3608b 1029 - (dtucker) [auth-pam.c] Don't set PAM_TTY if tty is null. ok djm@
3095daf7 1030
a15f16ab 103120030807
1032 - (dtucker) [session.c] Have session_break_req not attempt to send a break
1033 if TIOCSBRK and TIOCCBRK are not defined (eg Cygwin).
97722976 1034 - (dtucker) [canohost.c] Bug #336: Only check ip options if IP_OPTIONS is
a96fbb21 1035 defined (fixes compile error on really old Linuxes).
1036 - (dtucker) [defines.h] Bug #336: Add CMSG_DATA and CMSG_FIRSTHDR macros if
1037 not already defined (eg Linux with some versions of libc5), based on those
1038 from OpenBSD.
871e1d12 1039 - (dtucker) [openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
1040 Remove incorrect filenames from comments (file names are in Id tags).
a3b678a3 1041 - (dtucker) [session.c openbsd-compat/bsd-cygwin_util.h] Move Cygwin
1042 specific defines and includes to bsd-cygwin_util.h. Fixes build error too.
a15f16ab 1043
2616e1bc 104420030802
1045 - (dtucker) [monitor.h monitor_wrap.h] Remove excess ident tags.
1c590258 1046 - (dtucker) OpenBSD CVS Sync
1047 - markus@cvs.openbsd.org 2003/07/22 13:35:22
1048 [auth1.c auth.h auth-passwd.c monitor.c monitor.h monitor_wrap.c
1049 monitor_wrap.h readconf.c readconf.h servconf.c servconf.h session.c ssh.1
1050 ssh.c ssh_config.5 sshconnect1.c sshd.c sshd_config.5 ssh.h]
1051 remove (already disabled) KRB4/AFS support, re-enable -k in ssh(1);
1052 test+ok henning@
1053 - (dtucker) [Makefile.in acconfig.h configure.ac] Remove KRB4/AFS support.
1054 - (dtucker) [auth-krb4.c radix.c radix.h] Remove KRB4/AFS specific files.
ac452e85 1055 - (dtucker) OpenBSD CVS Sync
1056 - markus@cvs.openbsd.org 2003/07/23 07:42:43
1057 [sshd_config]
1058 remove AFS; itojun@
c35a6dc5 1059 - djm@cvs.openbsd.org 2003/07/28 09:49:56
1060 [ssh-keygen.1 ssh-keygen.c]
1061 Support for generating Diffie-Hellman groups (/etc/moduli) from ssh-keygen.
1062 Based on code from Phil Karn, William Allen Simpson and Niels Provos.
1063 ok markus@, thanks jmc@
178b1a1d 1064 - markus@cvs.openbsd.org 2003/07/29 18:24:00
1065 [LICENCE progressmeter.c]
1066 replace 4 clause BSD licensed progressmeter code with a replacement
1067 from Nils Nordman and myself; ok deraadt@
1068 (copied from OpenBSD an re-applied portable changes)
0dd40286 1069 - markus@cvs.openbsd.org 2003/07/29 18:26:46
1070 [progressmeter.c]
1071 fix length for "- stalled -" (included with previous import)
1072 - markus@cvs.openbsd.org 2003/07/30 07:44:14
1073 [progressmeter.c]
1074 use only 4 digits in format_size (included with previous import)
1075 - markus@cvs.openbsd.org 2003/07/30 07:53:27
1076 [progressmeter.c]
1077 whitespace (included with previous import)
0f57e1e6 1078 - markus@cvs.openbsd.org 2003/07/31 09:21:02
1079 [auth2-none.c]
1080 check whether passwd auth is allowd, similar to proto 1; rob@pitman.co.za
1081 ok henning
4899ccef 1082 - avsm@cvs.openbsd.org 2003/07/31 15:50:16
1083 [atomicio.c]
1084 correct comment: atomicio takes vwrite, not write; deraadt@ ok
b3a7a008 1085 - markus@cvs.openbsd.org 2003/07/31 22:34:03
1086 [progressmeter.c]
1087 print rate similar old version; round instead truncate;
1088 (included in previous progressmeter.c commit)
c5d3dd1b 1089 - (dtucker) [openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
1090 Add a tcgetpgrp function.
5ae3dc68 1091 - (dtucker) [Makefile.in moduli.c moduli.h] Add new files and to Makefile.
f29c37a9 1092 - (dtucker) [openbsd-compat/bsd-misc.c] Fix cut-and-paste bug in tcgetpgrp.
2616e1bc 1093
cbdeccf3 109420030730
1095 - (djm) [auth-pam.c] Don't use crappy APIs like sprintf. Thanks bal
1096
a9705c94 109720030726
1098 - (dtucker) [openbsd-compat/xcrypt.c] Fix typo: DISABLED_SHADOW ->
1099 DISABLE_SHADOW. Fixes HP-UX compile error.
1100
7c6eb32f 110120030724
1102 - (bal) [auth-passwd.c openbsd-compat/Makefile.in openbsd-compat/xcrypt.c
1103 openbsd-compat/xcrypt.h] Split off encryption into xcrypt() interface,
1104 and isolate shadow password functions. Tested in Solaris, but should
1105 not break other platforms too badly (except maybe HP =). Also brings
1106 auth-passwd.c into full sync with OpenBSD tree.
1107
82e5907c 110820030723
1109 - (dtucker) [configure.ac] Back out change for bug #620.
1110
defb525d 111120030719
1112 - (dtucker) [configure.ac] Bug #620: Define BROKEN_GETADDRINFO for
1113 Solaris/x86. Patch from jrhett at isite.net.
7b390973 1114 - (dtucker) OpenBSD CVS Sync
1115 - markus@cvs.openbsd.org 2003/07/14 12:36:37
1116 [sshd.c]
1117 remove undocumented -V option. would be only useful if openssh is used
1118 as ssh v1 server for ssh.com's ssh v2.
e053cd2c 1119 - markus@cvs.openbsd.org 2003/07/16 10:34:53
1120 [ssh.c sshd.c]
1121 don't exit on multiple -v or -d; ok deraadt@
145d23ca 1122 - markus@cvs.openbsd.org 2003/07/16 10:36:28
1123 [sshtty.c]
1124 clear IUCLC in enter_raw_mode; from rob@pitman.co.za; ok deraadt@, fgs@
261bd618 1125 - deraadt@cvs.openbsd.org 2003/07/18 01:54:25
1126 [scp.c]
1127 userid is unsigned, but well, force it anyways; andrushock@korovino.net
b3d04e37 1128 - djm@cvs.openbsd.org 2003/07/19 00:45:53
1129 [sftp-int.c]
1130 fix sftp filename parsing for arguments with escaped quotes. bz #517;
1131 ok markus
86d0260c 1132 - djm@cvs.openbsd.org 2003/07/19 00:46:31
1133 [regress/sftp-cmds.sh]
1134 regress test for sftp arguments with escaped quotes; ok markus
defb525d 1135
e351e493 113620030714
1137 - (dtucker) [acconfig.h configure.ac port-aix.c] Older AIXes don't declare
1138 loginfailed at all, so assume 3-arg loginfailed if not declared.
1cd5765d 1139 - (dtucker) [port-aix.h] Work around name collision on AIX for r_type by
1140 undef'ing it.
2aa3a16c 1141 - (dtucker) Bug #543: [configure.ac port-aix.c port-aix.h]
1142 Call setauthdb() before loginfailed(), which may load password registry-
defb525d 1143 specific functions. Based on patch by cawlfiel at us.ibm.com.
b4777c18 1144 - (dtucker) [port-aix.h] Fix prototypes.
956b0f56 1145 - (dtucker) OpenBSD CVS Sync
1146 - avsm@cvs.openbsd.org 2003/07/09 13:58:19
1147 [key.c]
1148 minor tweak: when generating the hex fingerprint, give strlcat the full
1149 bound to the buffer, and add a comment below explaining why the
1150 zero-termination is one less than the bound. markus@ ok
40729edd 1151 - markus@cvs.openbsd.org 2003/07/10 14:42:28
1152 [packet.c]
1153 the 2^(blocksize*2) rekeying limit is too expensive for 3DES,
1154 blowfish, etc, so enforce a 1GB limit for small blocksizes.
659912db 1155 - markus@cvs.openbsd.org 2003/07/10 20:05:55
1156 [sftp.c]
1157 sync usage with manpage, add missing -R
e351e493 1158
f58c0e01 115920030708
1160 - (dtucker) [acconfig.h auth-passwd.c configure.ac session.c port-aix.[ch]]
1161 Include AIX headers for authentication functions and make calls match
e351e493 1162 prototypes. Test for and handle 3-arg and 4-arg variants of loginfailed.
bc7dfc06 1163 - (dtucker) [session.c] Check return value of setpcred().
1164 - (dtucker) [auth-passwd.c auth.c session.c sshd.c port-aix.c port-aix.h]
1165 Convert aixloginmsg into platform-independant Buffer loginmsg.
f58c0e01 1166
309709db 116720030707
1168 - (dtucker) [configure.ac] Bug #600: Check that getrusage is declared before
1169 searching libraries for it. Fixes build errors on NCR MP-RAS.
1170
d72f7b79 117120030706
1172 - (dtucker) [ssh-rand-helper.c loginrec.c]
1173 Apply atomicio typing change to these too.
1174
71b9ced0 117520030703
1176 - (dtucker) OpenBSD CVS Sync
1177 - djm@cvs.openbsd.org 2003/06/28 07:48:10
1178 [sshd.c]
1179 report pidfile creation errors, based on patch from Roumen Petrov;
1180 ok markus@
dc54438a 1181 - deraadt@cvs.openbsd.org 2003/06/28 16:23:06
1182 [atomicio.c atomicio.h authfd.c clientloop.c monitor_wrap.c msg.c
1183 progressmeter.c scp.c sftp-client.c ssh-keyscan.c ssh.h sshconnect.c
1184 sshd.c]
1185 deal with typing of write vs read in atomicio
7caca6d4 1186 - markus@cvs.openbsd.org 2003/06/29 12:44:38
1187 [sshconnect.c]
1188 memset 0, not \0; andrushock@korovino.net
8e7c9afc 1189 - markus@cvs.openbsd.org 2003/07/02 12:56:34
1190 [channels.c]
1191 deny dynamic forwarding with -R for v1, too; ok djm@
f49658f5 1192 - markus@cvs.openbsd.org 2003/07/02 14:51:16
1193 [channels.c ssh.1 ssh_config.5]
1194 (re)add socks5 suppport to -D; ok djm@
1195 now ssh(1) can act both as a socks 4 and socks 5 server and
1196 dynamically forward ports.
03c82656 1197 - markus@cvs.openbsd.org 2003/07/02 20:37:48
1198 [ssh.c]
1199 convert hostkeyalias to lowercase, otherwise uppercase aliases will
1200 not match at all; ok henning@
1768a611 1201 - markus@cvs.openbsd.org 2003/07/03 08:21:46
1202 [regress/dynamic-forward.sh]
1203 add socks5; speedup; reformat; based on patch from dtucker@zip.com.au
7664edb6 1204 - markus@cvs.openbsd.org 2003/07/03 08:24:13
1205 [regress/Makefile]
1206 enable tests for dynamic fwd via socks (-D), uses nc(1)
1572b90f 1207 - djm@cvs.openbsd.org 2003/07/03 08:09:06
1208 [readconf.c readconf.h ssh-keysign.c ssh.c]
1209 fix AddressFamily option in config file, from brent@graveland.net;
1210 ok markus@
71b9ced0 1211
4e00038c 121220030630
1213 - (djm) Search for support functions necessary to build our
1214 getrrsetbyname() replacement. Patch from Roumen Petrov
1215
9f59c5a3 121620030629
c5829391 1217 - (dtucker) [includes.h] Bug #602: move #include of netdb.h to after in.h
1218 (fixes compiler warnings on Solaris 2.5.1).
1219 - (dtucker) [configure.ac] Add sanity test after system-dependant compiler
1220 flag modifications.
9f59c5a3 1221
9ea150a7 122220030628
1223 - (djm) Bug #591: use PKCS#15 private key label as a comment in case
1224 of OpenSC. Report and patch from larsch@trustcenter.de
d2168412 1225 - (djm) Bug #593: Sanity check OpenSC card reader number; patch from
1226 aj@dungeon.inka.de
f0677b69 1227 - (dtucker) OpenBSD CVS Sync
1228 - markus@cvs.openbsd.org 2003/06/23 09:02:44
1229 [ssh_config.5]
1230 document EnableSSHKeysign; bugzilla #599; ok deraadt@, jmc@
a27002e5 1231 - markus@cvs.openbsd.org 2003/06/24 08:23:46
1232 [auth2-hostbased.c auth2-pubkey.c auth2.c channels.c key.c key.h
1233 monitor.c packet.c packet.h serverloop.c sshconnect2.c sshd.c]
1234 int -> u_int; ok djm@, deraadt@, mouring@
d7ded285 1235 - miod@cvs.openbsd.org 2003/06/25 22:39:36
1236 [sftp-server.c]
1237 Typo police: attribute is better written with an 'r'.
2d9c1828 1238 - markus@cvs.openbsd.org 2003/06/26 20:08:33
1239 [readconf.c]
1240 do not dump core for 'ssh -o proxycommand host'; ok deraadt@
78b2dd04 1241 - (dtucker) [regress/dynamic-forward.sh] Import new regression test.
ddb154b3 1242 - (dtucker) [configure.ac] Bug #570: Have ./configure --enable-FEATURE
1243 actually enable the feature, for those normally disabled. Patch by
1244 openssh (at) roumenpetrov.info.
f0677b69 1245
e15ba28b 124620030624
1247 - (dtucker) Have configure refer the user to config.log and
1248 contrib/findssl.sh for OpenSSL header/library mismatches.
1249
63a556df 125020030622
c1ffd4bd 1251 - (dtucker) OpenBSD CVS Sync
63a556df 1252 - markus@cvs.openbsd.org 2003/06/21 09:14:05
c1ffd4bd 1253 [regress/reconfigure.sh]
63a556df 1254 missing $SUDO; from dtucker@zip.com.au
93527718 1255 - markus@cvs.openbsd.org 2003/06/18 11:28:11
c1ffd4bd 1256 [ssh-rsa.c]
1257 backout last change, since it violates pkcs#1
1258 switch to share/misc/license.template
1891396b 1259 - djm@cvs.openbsd.org 2003/06/20 05:47:58
1260 [sshd_config.5]
1261 sync description of protocol 2 cipher proposal; ok markus
4db4d313 1262 - djm@cvs.openbsd.org 2003/06/20 05:48:21
1263 [sshd_config]
1264 sync some implemented options; ok markus@
63a556df 1265 - (dtucker) [regress/authorized_keys_root] Remove temp data file from CVS.
39ef3618 1266 - (dtucker) [openbsd-compat/setproctitle.c] Ensure SPT_TYPE is defined before
1267 testing its value.
63a556df 1268
b8e04133 126920030618
1270 - (djm) OpenBSD CVS Sync
1271 - markus@cvs.openbsd.org 2003/06/12 07:57:38
1272 [monitor.c sshlogin.c sshpty.c]
1273 typos; dtucker at zip.com.au
b9ad9d13 1274 - djm@cvs.openbsd.org 2003/06/12 12:22:47
1275 [LICENCE]
1276 mention more copyright holders; ok markus@
1fb23629 1277 - nino@cvs.openbsd.org 2003/06/12 15:34:09
1278 [scp.c]
1279 Typo. Ok markus@.
244e796f 1280 - markus@cvs.openbsd.org 2003/06/12 19:12:03
1281 [scard.c scard.h ssh-agent.c ssh.c]
1282 add sc_get_key_label; larsch at trustcenter.de; bugzilla#591
9250058a 1283 - markus@cvs.openbsd.org 2003/06/16 08:22:35
1284 [ssh-rsa.c]
1285 make sure the signature has at least the expected length (don't
1286 insist on len == hlen + oidlen, since this breaks some smartcards)
1287 bugzilla #592; ok djm@
360a4aae 1288 - markus@cvs.openbsd.org 2003/06/16 10:22:45
1289 [ssh-add.c]
1290 print out key comment on each prompt; make ssh-askpass more useable; ok djm@
0a59bd6b 1291 - markus@cvs.openbsd.org 2003/06/17 18:14:23
1292 [cipher-ctr.c]
1293 use license from /usr/share/misc/license.template for new code
1d6c0b69 1294 - (dtucker) [reconfigure.sh rekey.sh sftp-badcmds.sh]
1295 Import new regression tests from OpenBSD
d4d84f5f 1296 - (dtucker) [regress/copy.1 regress/copy.2] Remove temp data files from CVS.
ed49cc81 1297 - (dtucker) OpenBSD CVS Sync (regress/)
1298 - markus@cvs.openbsd.org 2003/04/02 12:21:13
1299 [Makefile]
1300 enable rekey test
2c670155 1301 - djm@cvs.openbsd.org 2003/04/04 09:34:22
1302 [Makefile sftp-cmds.sh]
1303 More regression tests, including recent directory rename bug; ok markus@
737447ad 1304 - markus@cvs.openbsd.org 2003/05/14 22:08:27
1305 [ssh-com-client.sh ssh-com-keygen.sh ssh-com-sftp.sh ssh-com.sh]
1306 test against some new commerical versions
68df2aa0 1307 - mouring@cvs.openbsd.org 2003/05/15 04:07:12
1308 [sftp-cmds.sh]
1309 Advanced put/get testing for sftp. OK @djm
eb9bf761 1310 - markus@cvs.openbsd.org 2003/06/12 15:40:01
1311 [try-ciphers.sh]
1312 add ctr
39c0191e 1313 - markus@cvs.openbsd.org 2003/06/12 15:43:32
1314 [Makefile]
1315 test -HUP; dtucker at zip.com.au
b8e04133 1316
f5827134 131720030614
1318 - (djm) Update license on fake-rfc2553.[ch]; ok itojun@
1319
be193d89 132020030611
c12c6ef8 1321 - (djm) Mention portable copyright holders in LICENSE
e52ca1e5 1322 - (djm) Put licenses on substantial header files
8cb3fa9d 1323 - (djm) Sync LICENSE against OpenBSD
be193d89 1324 - (djm) OpenBSD CVS Sync
1325 - jmc@cvs.openbsd.org 2003/06/10 09:12:11
1326 [scp.1 sftp-server.8 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5]
1327 [sshd.8 sshd_config.5 ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
1328 - section reorder
1329 - COMPATIBILITY merge
1330 - macro cleanup
1331 - kill whitespace at EOL
1332 - new sentence, new line
1333 ssh pages ok markus@
0daa6547 1334 - deraadt@cvs.openbsd.org 2003/06/10 22:20:52
1335 [packet.c progressmeter.c]
1336 mostly ansi cleanup; pval ok
1432b5c4 1337 - jakob@cvs.openbsd.org 2003/06/11 10:16:16
1338 [sshconnect.c]
1339 clean up check_host_key() and improve SSHFP feedback. ok markus@
cc263107 1340 - jakob@cvs.openbsd.org 2003/06/11 10:18:47
1341 [dns.c]
1342 sync with check_host_key() change
ca719034 1343 - djm@cvs.openbsd.org 2003/06/11 11:18:38
1344 [authfd.c authfd.h ssh-add.c ssh-agent.c]
1345 make agent constraints (lifetime, confirm) work with smartcard keys;
1346 ok markus@
be193d89 1347
1348
8a547250 134920030609
1350 - (djm) Sync README.smartcard with OpenBSD -current
a1864983 1351 - (djm) Re-merge OpenSC info into README.smartcard
8a547250 1352
f5db6a03 135320030606
1354 - (dtucker) [uidswap.c] Fix setreuid and add missing args to fatal(). ok djm@
1355
02e2a074 135620030605
1357 - (djm) Support AI_NUMERICHOST in fake-getaddrinfo.c. Needed for recent
1358 canohost.c changes.
688eed4a 1359 - (djm) Implement paranoid priv dropping checks, based on:
1360 "SetUID demystified" - Hao Chen, David Wagner and Drew Dean
1361 Proceedings of USENIX Security Symposium 2002
d6bd2b5a 1362 - (djm) Don't use xmalloc() or pull in toplevel headers in fake-* code
52d58495 1363 - (djm) Merge all the openbsd/fake-* into fake-rfc2553.[ch]
57c917f8 1364 - (djm) Bug #588 - Add scard-opensc.o back to Makefile.in
1365 Patch from larsch@trustcenter.de
7b7f164b 1366 - (djm) Bug #589 - scard-opensc: load only keys with a private keys
1367 Patch from larsch@trustcenter.de
4ed465ec 1368 - (dtucker) Add includes.h to fake-rfc2553.c so it will build.
e932f447 1369 - (dtucker) Define EAI_NONAME in fake-rfc2553.h (used by fake-rfc2553.c).
02e2a074 1370
b08a39ff 137120030604
d60e487c 1372 - (djm) Bug #573 - Remove unneeded Krb headers and compat goop. Patch from
1373 simon@sxw.org.uk (Also matches a change in OpenBSD a while ago)
8acdec60 1374 - (djm) Bug #577 - wrong flag in scard-opensc.c sc_private_decrypt.
11f1e60e 1375 Patch from larsch@trustcenter.de; ok markus@
1376 - (djm) Bug #584: scard-opensc.c doesn't work without PIN. Patch from
1377 larsch@trustcenter.de; ok markus@
d453a600 1378 - (djm) OpenBSD CVS Sync
1379 - djm@cvs.openbsd.org 2003/06/04 08:25:18
1380 [sshconnect.c]
1381 disable challenge/response and keyboard-interactive auth methods
1382 upon hostkey mismatch. based on patch from fcusack AT fcusack.com.
1383 bz #580; ok markus@
ee50371d 1384 - djm@cvs.openbsd.org 2003/06/04 10:23:48
1385 [sshd.c]
1386 remove duplicated group-dropping code; ok markus@
b08a39ff 1387 - djm@cvs.openbsd.org 2003/06/04 12:03:59
1388 [serverloop.c]
1389 remove bitrotten commet; ok markus@
cf3248b8 1390 - djm@cvs.openbsd.org 2003/06/04 12:18:49
1391 [scp.c]
1392 ansify; ok markus@
0f764b2f 1393 - djm@cvs.openbsd.org 2003/06/04 12:40:39
1394 [scp.c]
1395 kill ssh process upon receipt of signal, bz #241.
1396 based on patch from esb AT hawaii.edu; ok markus@
1b558925 1397 - djm@cvs.openbsd.org 2003/06/04 12:41:22
1398 [sftp.c]
1399 kill ssh process on receipt of signal; ok markus@
fba33e81 1400 - (djm) Update to fix of bug #584: lock card before return.
1401 From larsch@trustcenter.de
8d9bb5dd 1402 - (djm) Always use mysignal() for SIGALRM
d60e487c 1403
3a2b2b44 140420030603
1405 - (djm) Replace setproctitle replacement with code derived from
1406 UCB sendmail
c5a7d788 1407 - (djm) OpenBSD CVS Sync
1408 - markus@cvs.openbsd.org 2003/06/02 09:17:34
1409 [auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
1410 [canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
1411 [sshd_config.5]
1412 deprecate VerifyReverseMapping since it's dangerous if combined
1413 with IP based access control as noted by Mike Harding; replace with
1414 a UseDNS option, UseDNS is on by default and includes the
1415 VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
1416 ok deraadt@, djm@
d981089c 1417 - millert@cvs.openbsd.org 2003/06/03 02:56:16
1418 [scp.c]
1419 Remove the advertising clause in the UCB license which Berkeley
1420 rescinded 22 July 1999. Proofed by myself and Theo.
c5a7d788 1421 - (djm) Fix portable-specific uses of verify_reverse_mapping too
3e67f7df 1422 - (djm) Sync openbsd-compat with OpenBSD CVS.
484d59c7 1423 - No more 4-term BSD licenses in linked code
5d8ca8c7 1424 - (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
3a2b2b44 1425
aff561f9 142620030602
1427 - (djm) Fix segv from bad reordering in auth-pam.c
416c732d 1428 - (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
1429 clobber
1b7342ab 1430 - (tim) openbsd-compat/xmmap.[ch] License clarifications. Add missing
1431 CVS ID.
8862e142 1432 - (djm) Remove "noip6" option from RedHat spec file. This may now be
1433 set at runtime using AddressFamily option.
58ba3cb7 1434 - (djm) Fix use of macro before #define in cipher-aes.c
382fe2fa 1435 - (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
b0545fe6 1436 - (djm) OpenBSD CVS Sync
1437 - djm@cvs.openbsd.org 2003/05/26 12:54:40
1438 [sshconnect.c]
1439 fix format strings; ok markus@
fa5120a0 1440 - deraadt@cvs.openbsd.org 2003/05/29 16:58:45
1441 [sshd.c uidswap.c]
1442 seteuid and setegid; markus ok
0f92946c 1443 - jakob@cvs.openbsd.org 2003/06/02 08:31:10
1444 [ssh_config.5]
1445 VerifyHostKeyDNS is v2 only. ok markus@
aff561f9 1446
4f178be8 144720030530
1448 - (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
1449 roumenpetrov.info
eabb99c6 1450 - (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
4f178be8 1451
4881aebb 145220030526
1453 - (djm) Avoid auth2-chall.c warning when compiling without
1454 PAM, BSD_AUTH and SKEY
1455
5b0fe364 145620030525
1457- (djm) OpenBSD CVS Sync
1458 - djm@cvs.openbsd.org 2003/05/24 09:02:22
1459 [log.c]
1460 pass logged data through strnvis; ok markus
b9ed513a 1461 - djm@cvs.openbsd.org 2003/05/24 09:30:40
1462 [authfile.c monitor.c sftp-common.c sshpty.c]
1463 cast some types for printing; ok markus@
5b0fe364 1464
44c78996 146520030524
1466 - (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
1467
d83ebe4a 146820030523
1469 - (djm) Use VIS_SAFE on logged strings rather than default strnvis
1470 encoding (which encodes many more characters)
bd47824b 1471 - OpenBSD CVS Sync
1472 - jmc@cvs.openbsd.org 2003/05/20 12:03:35
1473 [sftp.1]
1474 - new sentence, new line
1475 - added .Xr's
1476 - typos
1477 ok djm@
3cbc677d 1478 - jmc@cvs.openbsd.org 2003/05/20 12:09:31
1479 [ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
1480 new sentence, new line
da54f5be 1481 - djm@cvs.openbsd.org 2003/05/23 08:29:30
1482 [sshconnect.c]
1483 fix leak; ok markus@
d83ebe4a 1484
c453493f 148520030520
1486 - (djm) OpenBSD CVS Sync
1487 - deraadt@cvs.openbsd.org 2003/05/18 23:22:01
1488 [log.c]
1489 use syslog_r() in a signal handler called place; markus ok
79d4fc55 1490 - (djm) Configure logic to detect syslog_r and friends
c453493f 1491
acb50584 149220030519
1493 - (djm) Sync auth-pam.h with what we actually implement
1494
149520030518
5ff453c0 1496 - (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
1497 recent merge
f811e52a 1498 - (djm) OpenBSD CVS Sync
1499 - djm@cvs.openbsd.org 2003/05/16 03:27:12
1500 [readconf.c ssh_config ssh_config.5 ssh-keysign.c]
1501 add AddressFamily option to ssh_config (like -4, -6 on commandline).
1502 Portable bug #534; ok markus@
013b1214 1503 - itojun@cvs.openbsd.org 2003/05/17 03:25:58
1504 [auth-rhosts.c]
1505 just in case, put numbers to sscanf %s arg.
25b66522 1506 - markus@cvs.openbsd.org 2003/05/17 04:27:52
1507 [cipher.c cipher-ctr.c myproposal.h]
1508 experimental support for aes-ctr modes from
1509 http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
1510 ok djm@
25351757 1511 - (djm) Remove IPv4 by default hack now that we can specify AF in config
3bf784bc 1512 - (djm) Tidy and trim TODO
bffa6723 1513 - (djm) Sync openbsd-compat/ with OpenBSD CVS head
9901cb37 1514 - (djm) Big KNF on openbsd-compat/
f1da2b8b 1515 - (djm) KNF on md5crypt.[ch]
1516 - (djm) KNF on auth-sia.[ch]
5ff453c0 1517
f123055b 151820030517
1519 - (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
1520
c936c243 152120030516
1522 - (djm) OpenBSD CVS Sync
1523 - djm@cvs.openbsd.org 2003/05/15 13:52:10
1524 [ssh.c]
1525 Make "ssh -V" print the OpenSSL version in a human readable form. Patch
1526 from Craig Leres (mindrot at ee.lbl.gov); ok markus@
a2144546 1527 - jakob@cvs.openbsd.org 2003/05/15 14:02:47
1528 [readconf.c servconf.c]
1529 warn for unsupported config option. ok markus@
5bdfde81 1530 - markus@cvs.openbsd.org 2003/05/15 14:09:21
1531 [auth2-krb5.c]
1532 fix 64bit issue; report itojun@
09ab3296 1533 - djm@cvs.openbsd.org 2003/05/15 14:55:25
1534 [readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
1535 add a ConnectTimeout option to ssh, based on patch from
1536 Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
b06b11ad 1537 - (djm) Add warning for UsePAM when built without PAM support
7be625e1 1538 - (djm) A few type mismatch fixes from Bug #565
0eb6370a 1539 - (djm) Guard free_pam_environment against NULL argument. Works around
1540 HP/UX PAM problems debugged by dtucker
c936c243 1541
7efc7f57 154220030515
1543 - (djm) OpenBSD CVS Sync
1544 - jmc@cvs.openbsd.org 2003/05/14 13:11:56
1545 [ssh-agent.1]
1546 setup -> set up;
1547 from wiz@netbsd
21289cd0 1548 - jakob@cvs.openbsd.org 2003/05/14 18:16:20
1549 [key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
1550 [dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
1551 add experimental support for verifying hos keys using DNS as described
1552 in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
1553 ok markus@ and henning@
16a79097 1554 - markus@cvs.openbsd.org 2003/05/14 22:24:42
1555 [clientloop.c session.c ssh.1]
1556 allow to send a BREAK to the remote system; ok various
b8c2031b 1557 - markus@cvs.openbsd.org 2003/05/15 00:28:28
1558 [sshconnect2.c]
1559 cleanup unregister of per-method packet handlers; ok djm@
d0ec7f42 1560 - jakob@cvs.openbsd.org 2003/05/15 01:48:10
1561 [readconf.c readconf.h servconf.c servconf.h]
1562 always parse kerberos options. ok djm@ markus@
b414a17b 1563 - jakob@cvs.openbsd.org 2003/05/15 02:27:15
1564 [dns.c]
1565 add missing freerrset
3b6e3da9 1566 - markus@cvs.openbsd.org 2003/05/15 03:08:29
1567 [cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
1568 split out custom EVP ciphers
02159d9b 1569 - djm@cvs.openbsd.org 2003/05/15 03:10:52
1570 [ssh-keygen.c]
1571 avoid warning; ok jakob@
4a26f5c5 1572 - mouring@cvs.openbsd.org 2003/05/15 03:39:07
1573 [sftp-int.c]
1574 Make put/get (globed and nonglobed) code more consistant. OK djm@
c44f10c6 1575 - mouring@cvs.openbsd.org 2003/05/15 03:43:59
dc69f53c 1576 [sftp-int.c sftp.c]
c44f10c6 1577 Teach ls how to display multiple column display and allow users
1578 to return to single column format via 'ls -1'. OK @djm
1457e7ff 1579 - jakob@cvs.openbsd.org 2003/05/15 04:08:44
1580 [readconf.c servconf.c]
1581 disable kerberos when not supported. ok markus@
861f0365 1582 - markus@cvs.openbsd.org 2003/05/15 04:08:41
1583 [ssh.1]
1584 ~B is ssh2 only
d0ec7f42 1585 - (djm) Always parse UsePAM
3e05e934 1586 - (djm) Configure glue for DNS support (code doesn't work in portable yet)
4460d509 1587 - (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
86ee6794 1588 - (djm) Tidy Makefile clean targets
2636769c 1589 - (djm) Adapt README.dns for portable
2d2e4a34 1590 - (djm) Avoid uuencode.c warnings
1457e7ff 1591 - (djm) Enable UsePAM when built --with-pam
67467c30 1592 - (djm) Only build getrrsetbyname replacement when using --with-dns
f420d2ba 1593 - (djm) Bug #529: sshd doesn't work correctly after SIGHUP (copy argv
1594 correctly)
3c49ef10 1595 - (djm) Bug #444: Wrong paths after reconfigure
321735c7 1596 - (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
f420d2ba 1597
dd3ebb5a 159820030514
1599 - (djm) Bug #117: Don't lie to PAM about username
0608f8a7 1600 - (djm) RCSID sync w/ OpenBSD
204fde99 1601 - (djm) OpenBSD CVS Sync
1602 - djm@cvs.openbsd.org 2003/04/09 12:00:37
1603 [readconf.c]
1604 strip trailing whitespace from config lines before parsing.
1605 Fixes bz 528; ok markus@
18ae3c67 1606 - markus@cvs.openbsd.org 2003/04/12 10:13:57
1607 [cipher.c]
1608 hide cipher details; ok djm@
45c42d58 1609 - markus@cvs.openbsd.org 2003/04/12 10:15:36
1610 [misc.c]
1611 debug->debug2
c825cd79 1612 - naddy@cvs.openbsd.org 2003/04/12 11:40:15
1613 [ssh.1]
1614 document -V switch, fix wording; ok markus@
3e131a6d 1615 - markus@cvs.openbsd.org 2003/04/14 14:17:50
1616 [channels.c sshconnect.c sshd.c ssh-keyscan.c]
1617 avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
927e9f8b 1618 - mouring@cvs.openbsd.org 2003/04/14 21:31:27
1619 [sftp-int.c]
1620 Missing globfree(&g) in process_put() spotted by Vince Brimhall
1621 <VBrimhall@novell.com>. ok@ Theo
1622 - markus@cvs.openbsd.org 2003/04/16 14:35:27
1623 [auth.h]
1624 document struct Authctxt; with solar
b9e5aff6 1625 - deraadt@cvs.openbsd.org 2003/04/26 04:29:49
1626 [ssh-keyscan.c]
1627 -t in usage(); rogier@quaak.org
9a26a6e2 1628 - mouring@cvs.openbsd.org 2003/04/30 01:16:20
1629 [sshd.8 sshd_config.5]
1630 Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
1631 Bug #550 and * escaping suggested by jmc@.
09dc8896 1632 - david@cvs.openbsd.org 2003/04/30 20:41:07
1633 [sshd.8]
1634 fix invalid .Pf macro usage introduced in previous commit
1635 ok jmc@ mouring@
3566c73c 1636 - markus@cvs.openbsd.org 2003/05/11 16:56:48
1637 [authfile.c ssh-keygen.c]
1638 change key_load_public to try to read a public from:
1639 rsa1 private or rsa1 public and ssh2 keys.
1640 this makes ssh-keygen -e fail for ssh1 keys more gracefully
1641 for example; report from itojun (netbsd pr 20550).
0d942eff 1642 - markus@cvs.openbsd.org 2003/05/11 20:30:25
1643 [channels.c clientloop.c serverloop.c session.c ssh.c]
1644 make channel_new() strdup the 'remote_name' (not the caller); ok theo
43348518 1645 - markus@cvs.openbsd.org 2003/05/12 16:55:37
1646 [sshconnect2.c]
1647 for pubkey authentication try the user keys in the following order:
1648 1. agent keys that are found in the config file
1649 2. other agent keys
1650 3. keys that are only listed in the config file
1651 this helps when an agent has many keys, where the server might
1652 close the connection before the correct key is used. report & ok pb@
dc109cfe 1653 - markus@cvs.openbsd.org 2003/05/12 18:35:18
1654 [ssh-keyscan.1]
1655 typo: DSA keys are of type ssh-dss; Brian Poole
81466908 1656 - markus@cvs.openbsd.org 2003/05/14 00:52:59
1657 [ssh2.h]
1658 ranges for per auth method messages
1659 - djm@cvs.openbsd.org 2003/05/14 01:00:44
1660 [sftp.1]
1661 emphasise the batchmode functionality and make reference to pubkey auth,
1662 both of which are FAQs; ok markus@
802e01b8 1663 - markus@cvs.openbsd.org 2003/05/14 02:15:47
1664 [auth2.c monitor.c sshconnect2.c auth2-krb5.c]
1665 implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
1666 server interops with commercial client; ok jakob@ djm@
72c5fe79 1667 - jmc@cvs.openbsd.org 2003/05/14 08:25:39
1668 [sftp.1]
1669 - better formatting in SYNOPSIS
1670 - whitespace at EOL
1671 ok djm@
3a39206f 1672 - markus@cvs.openbsd.org 2003/05/14 08:57:49
1673 [monitor.c]
1674 http://bugzilla.mindrot.org/show_bug.cgi?id=560
1675 Privsep child continues to run after monitor killed.
1676 Pass monitor signals through to child; Darren Tucker
751092f9 1677 - (djm) Make portable build with MIT krb5 (some issues remain)
7fceb20d 1678 - (djm) Add new UsePAM configuration directive to allow runtime control
1679 over usage of PAM. This allows non-root use of sshd when built with
1680 --with-pam
817e6d38 1681 - (djm) Die screaming if start_pam() is called when UsePAM=no
83ccf11a 1682 - (djm) Avoid KrbV leak for MIT Kerberos
b1848832 1683 - (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
fa065de2 1684 - (djm) Bug #258: sscanf("[0-9]") -> sscanf("[0123456789]") for portability
dd3ebb5a 1685
91f3aa9b 168620030512
1687 - (djm) Redhat spec: Don't install profile.d scripts when not
1688 building with GNOME/GTK askpass (patch from bet@rahul.net)
1689
5def520a 169020030510
1691 - (dtucker) Bug #318: Create ssh_prng_cmds.out during "make" rather than
1692 "make install". Patch by roth@feep.net.
ad84c479 1693 - (dtucker) Bug #536: Test for and work around openpty/controlling tty
1694 problem on Linux (fixes "could not set controlling tty" errors).
05114c74 1695 - (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
1696 proper challenge-response module
23ab1f36 1697 - (djm) 2-clause license on loginrec.c, with permission from
1698 andre@ae-35.com
5def520a 1699
43ce025d 170020030504
dd594f99 1701 - (dtucker) Bug #497: Move #include of bsd-cygwin_util.h to openbsd-compat.h.
1702 Patch from vinschen@redhat.com.
43ce025d 1703
2cd5dbba 170420030503
1705 - (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
1706 by wendyp@cray.com.
1707
bf7c1e6c 170820030502
1709 - (dtucker) Bug #544: ignore invalid cmsg_type on Linux 2.0 kernels,
1710 privsep should now work.
73d9dad3 1711 - (dtucker) Move handling of bad password authentications into a platform
990278ef 1712 specific record_failed_login() function (affects AIX & Unicos). ok mouring@
bf7c1e6c 1713
68ece370 171420030429
1715 - (djm) Add back radix.o (used by AFS support), after it went missing from
1716 Makefile many moons ago
1717 - (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
1718 - (djm) Fix blibpath specification for AIX/gcc
1719 - (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
1720
ded9dd18 172120030428
1722 - (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
1723 hacked code.
1724
aceb0423 172520030427
1726 - (bal) Bug #541: return; was dropped by mistake. Reported by
1727 furrier@iglou.com
c8a50a34 1728 - (bal) Since we don't support platforms lacking u_int_64. We may
1729 as well clean out some of those evil #ifdefs
9a6fee8b 1730 - (bal) auth1.c minor resync while looking at the code.
d7cf277b 1731 - (bal) auth2.c same changed as above.
aceb0423 1732
0a626302 173320030409
1734 - (djm) Bug #539: Specify creation mode with O_CREAT for lastlog. Report
1735 from matth@eecs.berkeley.edu
d35929b5 1736 - (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
ffd7b36b 1737 - (djm) OpenBSD CVS Sync
1738 - markus@cvs.openbsd.org 2003/04/02 09:48:07
1739 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1740 [readconf.h serverloop.c sshconnect2.c]
1741 reapply rekeying chage, tested by henning@, ok djm@
16f1b5ca 1742 - markus@cvs.openbsd.org 2003/04/02 14:36:26
1743 [ssh-keysign.c]
1744 potential segfault if KEY_UNSPEC; cjwatson@debian.org; bug #526
6c1bc5c5 1745 - itojun@cvs.openbsd.org 2003/04/03 07:25:27
1746 [progressmeter.c]
1747 $OpenBSD$
1748 - itojun@cvs.openbsd.org 2003/04/03 10:17:35
1749 [progressmeter.c]
1750 remove $OpenBSD$, as other *.c does not have it.
806e4c11 1751 - markus@cvs.openbsd.org 2003/04/07 08:29:57
1752 [monitor_wrap.c]
1753 typo: get correct counters; introduced during rekeying change.
2f5b2528 1754 - millert@cvs.openbsd.org 2003/04/07 21:58:05
1755 [progressmeter.c]
1756 The UCB copyright here is incorrect. This code did not originate
1757 at UCB, it was written by Luke Mewburn. Updated the copyright at
1758 the author's request. markus@ OK
1759 - itojun@cvs.openbsd.org 2003/04/08 20:21:29
1760 [*.c *.h]
1761 rename log() into logit() to avoid name conflict. markus ok, from
1762 netbsd
1763 - (djm) XXX - Performed locally using:
1764 "perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
70e1f62f 1765 - hin@cvs.openbsd.org 2003/04/09 08:23:52
1766 [servconf.c]
1767 Don't include <krb.h> when compiling with Kerberos 5 support
2f5b2528 1768 - (djm) Fix up missing include for packet.c
a3568201 1769 - (djm) Fix missed log => logit occurance (reference by function pointer)
0a626302 1770
4d0cb2e5 177120030402
1772 - (bal) if IP_TOS is not found or broken don't try to compile in
1773 packet_set_tos() function call. bug #527
1774
a4e5acef 177520030401
1776 - (djm) OpenBSD CVS Sync
1777 - jmc@cvs.openbsd.org 2003/03/28 10:11:43
1778 [scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
1779 [ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
1780 - killed whitespace
1781 - new sentence new line
1782 - .Bk for arguments
1783 ok markus@
177f584b 1784 - markus@cvs.openbsd.org 2003/04/01 10:10:23
1785 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1786 [readconf.h serverloop.c sshconnect2.c]
1787 rekeying bugfixes and automatic rekeying:
1788 * both client and server rekey _automatically_
1789 (a) after 2^31 packets, because after 2^32 packets
1790 the sequence number for packets wraps
1791 (b) after 2^(blocksize_in_bits/4) blocks
1792 (see: draft-ietf-secsh-newmodes-00.txt)
1793 (a) and (b) are _enabled_ by default, and only disabled for known
1794 openssh versions, that don't support rekeying properly.
1795 * client option 'RekeyLimit'
1796 * do not reply to requests during rekeying
1797 - markus@cvs.openbsd.org 2003/04/01 10:22:21
1798 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1799 [readconf.h serverloop.c sshconnect2.c]
1800 backout rekeying changes (for 3.6.1)
519bdfe8 1801 - markus@cvs.openbsd.org 2003/04/01 10:31:26
1802 [compat.c compat.h kex.c]
1803 bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
1804 tested by ho@ and myself
9dd240a3 1805 - markus@cvs.openbsd.org 2003/04/01 10:56:46
1806 [version.h]
1807 3.6.1
ac01b518 1808 - (djm) Crank spec file versions
b32453fe 1809 - (djm) Release 3.6.1p1
a4e5acef 1810
fd77a40f 181120030326
1812 - (djm) OpenBSD CVS Sync
1813 - deraadt@cvs.openbsd.org 2003/03/26 04:02:51
1814 [sftp-server.c]
1815 one last fix to the tree: race fix broke stuff; pr 3169;
1816 srp@srparish.net, help from djm
1817
8021857c 181820030325
1819 - (djm) Fix getpeerid support for 64 bit BE systems. From
1820 Arnd Bergmann <arndb@de.ibm.com>
1821
cdb64c4d 182220030324
1823 - (djm) OpenBSD CVS Sync
1824 - markus@cvs.openbsd.org 2003/03/23 19:02:00
1825 [monitor.c]
1826 unbreak rekeying for privsep; ok millert@
1827 - Release 3.6p1
62086365 1828 - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
1829 Report from murple@murple.net, diagnosis from dtucker@zip.com.au
cdb64c4d 1830
0b202697 1831$Id$
This page took 0.63608 seconds and 5 git commands to generate.