]> andersk Git - openssh.git/blame - ChangeLog
- (dtucker) [Makefile.in] Bug #644: Fix "make clean" for out-of-tree
[openssh.git] / ChangeLog
CommitLineData
5ba73866 120030923
2 - (dtucker) [configure.ac] Bug #644: Fix "make clean" for out-of-tree
3 builds. Portability corrections from tim@.
4
a801511e 520030919
6 - (djm) Bug #683: Remove reference to --with-ipv4-default from INSTALL;
7 djast AT cs.toronto.edu
48646332 8 - (djm) Bug #661: Remove duplicate check for basename; from
9 bugzilla-openssh AT thewrittenword.com
34799445 10 - (djm) Bug #641: Allow RedHat RPM building without GTK-2; Patch from
11 jason AT devrandom.org
fd79af78 12 - (djm) Bug #646: Fix location of x11-ssh-askpass; Jim
4608d193 13 - (dtucker) [openbsd-compat/port-aix.h] Bug #640: Don't include audit.h
14 unless required. Reorder to reduce warnings.
6f99680f 15 - (dtucker) [session.c] Bug #643: Fix size_t -> u_int and fix null deref
16 when /etc/default/login doesn't exist or isn't readable. Fixes from
17 jparsons-lists at saffron.net and georg.oppenberg at deu mci com.
97e3cf19 18 - (dtucker) [acconfig.h] Updated basename test needs HAVE_BASENAME
a801511e 19
33fb67f0 2020030918
21 - (djm) Bug #652: Fix empty password auth
22
263c65df 2320030917
24 - (djm) Sync with V_3_7 branch
20419cc1 25 - (djm) OpenBSD Sync
26 - markus@cvs.openbsd.org 2003/09/16 21:02:40
27 [buffer.c channels.c version.h]
28 more malloc/fatal fixes; ok millert/deraadt; ghudson at MIT.EDU
38d24e7d 29 - (djm) Crank RPM spec file versions
ddd8e845 30 - (tim) [openbsd-compat/inet_ntoa.c] 20030917 "Sync with V_3_7 branch" undid
31 20030916 "Missed dead header in inet_ntoa.c"
38d24e7d 32
95b99395 3320030916
34 - (dtucker) [acconfig.h configure.ac defines.h session.c] Bug #252: Retrieve
35 PATH (or SUPATH) and UMASK from /etc/default/login on platforms that have it
49525395 36 (eg Solaris, Reliant Unix). Patch from Robert.Dahlem at siemens.com.
37 ok djm@
38 - (bal) OpenBSD Sync
39 - deraadt@cvs.openbsd.org 2003/09/16 03:03:47
40 [buffer.c]
41 do not expand buffer before attempting to reallocate it; markus ok
89bbd457 42 - (tim) [configure.ac] Fix portability issues.
bb6dd12a 43 - (bal) Missed dead header in inet_ntoa.c
95b99395 44
bdb15424 4520030914
46 - (dtucker) [Makefile regress/Makefile] Fix portability issues preventing
47 the regression tests from running with Solaris' make. Patch from Brian
48 Poole (raj at cerias.purdue.edu).
906f3b9d 49 - (dtucker) [regress/Makefile] AIX's make doesn't like " +=", so replace
50 with vanilla "=".
bdb15424 51
b64864e1 5220030913
53 - (dtucker) [regress/agent-timeout.sh] Timeout of 5 sec is borderline for
54 slower hosts, increase to 10 sec.
217a0ad5 55 - (dtucker) [auth-passwd.c] On AIX, call setauthdb() before loginsuccess(),
56 required to correctly reset failed login count when using a password
57 registry other than "files" (eg LDAP, see bug #543).
bcebad47 58 - (tim) [configure.ac] define WITH_ABBREV_NO_TTY for SCO.
59 Report by Roger Cornelius.
01224183 60 - (dtucker) [auth-pam.c] Use SSHD_PAM_SERVICE for PAM service name, patch
61 from cjwatson at debian.org.
b64864e1 62
a473643e 6320030912
64 - (tim) [regress/agent-ptrace.sh] sh doesn't like "if ! shell_function; then".
e43957b9 65 - (tim) [Makefile.in] only mkdir regress if it does not exist.
7126ceb2 66 - (tim) [regress/yes-head.sh] shell portability fix.
a473643e 67
af940dcb 6820030911
69 - (dtucker) [configure.ac] Bug #588, #615: Move other libgen tests to after
70 the dirname test, to allow a broken dirname to be detected correctly.
71 Based partially on patch supplied by alex.kiernan at thus.net. ok djm@
446227d6 72 - (tim) [configure.ac] Move libgen tests to before libwrap to unbreak
73 UnixWare 2.03 using --with-tcp-wrappers.
7ed101c0 74 - (tim) [configure.ac] Prefer setuid/setgid on UnixWare and Open Server.
c1b10a96 75 - (tim) [regress/agent-ptrace.sh regress/dynamic-forward.sh
76 regress/sftp-cmds.sh regress/stderr-after-eof.sh regress/test-exec.sh]
77 no longer depends on which(1). patch by dtucker@
af940dcb 78
7b9a8c6e 7920030910
80 - (dtucker) [configure.ac] Bug #636: Add support for Cray's new X1 machine.
81 Patch from wendyp at cray.com.
3490699c 82 - (dtucker) [configure.ac] Part of bug #615: tcsendbreak might be a macro.
2e8d2c13 83 - (dtucker) [regressh/yes-head.sh] Some platforms (eg Solaris) don't have
84 "yes".
7b9a8c6e 85
12e07a07 8620030909
87 - (tim) [regress/Makefile] Fixes for building outside of a read-only
88 source tree.
5d3cef06 89 - (tim) [regress/agent-timeout.sh] s/TIMEOUT/SSHAGENT_TIMEOUT/ Fixes conflict
90 with shell read-only variable.
2b1bb684 91 - (tim) [regress/sftp-badcmds.sh regress/sftp-cmds.sh] Fix errors like
92 UX:rm: ERROR: Cannot remove '.' or '..'
12e07a07 93
252ff4df 9420030908
95 - (tim) [configure.ac openbsd-compat/getrrsetbyname.c] wrap _getshort and
96 _getlong in #ifndef
078ec045 97 - (tim) [configure.ac acconfig.h openbsd-compat/getrrsetbyname.c] test for
98 HEADER.ad in arpa/nameser.h
8f52069e 99 - (tim) [ssh-keygen.c] s/PATH_MAX/MAXPATHLEN/ ok mouring@
252ff4df 100
c9535c4d 10120030907
102 - (dtucker) [agent-ptrace.sh dynamic-forward.sh (all regress/)]
103 Put "which" inside quotes.
5781bb58 104 - (dtucker) [dynamic-forward.sh forwarding.sh sftp-batch.sh (all regress/)]
105 Add ${EXEEXT}: required to work on Cygwin.
7621a857 106 - (dtucker) [regress/sftp-batch.sh] Make temporary batch file name more
107 distinctive, so "rm ${BATCH}.*" doesn't match the script itself.
ac4a169f 108 - (dtucker) [regress/sftp-cmds.sh] Skip quoted file test on Cygwin.
9a7582f1 109 - (dtucker) [openbsd-compat/xcrypt.c] #elsif -> #elif
110 - (dtucker) [acconfig.h] Typo.
4bbf95fa 111 - (dtucker) [CREDITS Makefile.in configure.ac mdoc2man.awk mdoc2man.pl]
112 Replace mdoc2man.pl with mdoc2man.awk, provided by Peter Stuge.
c9535c4d 113
3b8dff69 11420030906
115 - (dtucker) [acconfig.h configure.ac uidswap.c] Prefer setuid/setgid on AIX.
116
5e6f8a42 11720030905
118 - (dtucker) [Makefile.in] Add distclean target for regress/, fix clean target.
119
7ed6b890 12020030904
121 - (dtucker) Portablize regression tests. Parts contributed by Roumen
122 Petrov, David M. Williams and Corinna Vinschen.
123 - [Makefile.in] Add "make tests" target and "make clean" hooks.
584c5ed9 124 - [regress/agent-getpeereid.sh] Skip test on platforms that don't support
125 getpeereid.
335f57ae 126 - [regress/agent-ptrace.sh] Skip tests if platform doesn't support it or
127 gdb cannot be found.
c4cc19d5 128 - [regress/reconfigure/sh] Make path to sshd fully qualified if required.
e4f79c8f 129 - [regress/rekey.sh] Remove dependence on /dev/zero (not all platforms have
130 it). The sparse file will take less disk space too.
c67d1ba1 131 - [regress/sftp-cmds.sh] Ensure files used for test are readable.
9a7cf6f2 132 - [regress/stderr-after-eof.sh] Search for a usable checksum program.
83d96134 133 - [regress/sftp-badcmds.sh regress/sftp-cmds.sh regress/sftp.sh
134 regress/ssh-com-client.sh regress/ssh-com-sftp.sh regress/stderr-data.sh
135 regress/transfer.sh] Use ${EXEEXT} where appropriate.
302294d5 136 - [regress/sftp.sh regress/ssh-com-sftp.sh] Remove dependency on /dev/stdin.
d23e7be4 137 - [regress/agent-ptrace.sh regress/agent-timeout.sh]
138 "grep -q" -> "grep >/dev/null"
c7751424 139 - [regress/agent.sh regress/proto-version.sh regress/ssh-com.sh
c9535c4d 140 regress/test-exec.sh] Handle different ways of echoing without newlines.
46f493c6 141 - [regress/dynamic-forward.sh] Some "which" programs output on stderr.
a687e172 142 - [regress/sftp-cmds.sh] Use portable "test" option.
4638d96a 143 - [regress/test-exec.sh] Use sudo, search for "whoami" equivalent, always
144 use Strictmodes no, wait longer for sshd startup.
d99acf36 145 - [regress/Makefile] Remove BSDisms.
b0315114 146 - [regress/README.regress] Add a basic readme.
c67d1ba1 147 - [Makefile.in regress/agent-getpeereid.sh] config.h is now in $BUILDDIR
148 not $OBJ.
ccb02b94 149 - [Makefile.in regress/agent-ptrace] Fix minor regress issues on Cygwin.
7ed6b890 150
96d0bf74 15120030903
152 - (djm) OpenBSD CVS Sync
153 - markus@cvs.openbsd.org 2003/08/26 09:58:43
154 [auth-passwd.c auth.c auth.h auth1.c auth2-none.c auth2-passwd.c]
155 [auth2.c monitor.c]
156 fix passwd auth for 'username leaks via timing'; with djm@, original
157 patches from solar
5f2a8485 158 - markus@cvs.openbsd.org 2003/08/28 12:54:34
159 [auth.h]
160 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
161 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
b6f9987b 162 - markus@cvs.openbsd.org 2003/09/02 16:40:29
163 [version.h]
164 enter 3.7
d0445371 165 - jmc@cvs.openbsd.org 2003/09/02 18:50:06
166 [sftp.1 ssh_config.5]
167 escape punctuation;
168 ok deraadt@
96d0bf74 169
408fb07b 17020030902
eb18f58d 171 - (djm) OpenBSD CVS Sync
172 - deraadt@cvs.openbsd.org 2003/08/24 17:36:51
173 [auth2-gss.c]
174 64 bit cleanups; markus ok
8f73f7bb 175 - markus@cvs.openbsd.org 2003/08/28 12:54:34
176 [auth-krb5.c auth.h auth1.c monitor.c monitor.h monitor_wrap.c]
177 [monitor_wrap.h readconf.c servconf.c session.c ssh_config.5]
178 [sshconnect1.c sshd.c sshd_config sshd_config.5]
179 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
180 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
e3e69949 181 - markus@cvs.openbsd.org 2003/08/29 10:03:15
182 [compat.c compat.h]
183 SSH_BUG_K5USER is unused; ok henning@
d7ac5f18 184 - markus@cvs.openbsd.org 2003/08/29 10:04:36
185 [channels.c nchan.c]
186 be less chatty; debug -> debug2, cleanup; ok henning@
8e382949 187 - markus@cvs.openbsd.org 2003/08/31 10:26:04
188 [progressmeter.c]
189 pass file_size + 1 to snprintf: fixes printing of truncated
190 file names; fix based on patch/report from sturm@;
3845a9ac 191 - markus@cvs.openbsd.org 2003/08/31 12:14:22
192 [progressmeter.c]
193 do write to buf[-1]
f89f8ddc 194 - markus@cvs.openbsd.org 2003/08/31 13:29:05
195 [session.c]
196 call ssh_gssapi_storecreds conditionally from do_exec();
197 with sxw@inf.ed.ac.uk
96573c26 198 - markus@cvs.openbsd.org 2003/08/31 13:30:18
199 [gss-serv.c]
200 correct string termination in parse_ename(); sxw@inf.ed.ac.uk
a7958e7b 201 - markus@cvs.openbsd.org 2003/08/31 13:31:57
202 [gss-serv.c]
203 whitspace KNF
105b07db 204 - markus@cvs.openbsd.org 2003/09/01 09:50:04
205 [sshd_config.5]
206 gss kex is not supported; sxw@inf.ed.ac.uk
eac292f8 207 - markus@cvs.openbsd.org 2003/09/01 12:50:46
208 [readconf.c]
209 rm gssapidelegatecreds alias; never supported before
00fee838 210 - markus@cvs.openbsd.org 2003/09/01 13:52:18
211 [ssh.h]
212 rm whitespace
cc4d7cb6 213 - markus@cvs.openbsd.org 2003/09/01 18:15:50
214 [readconf.c readconf.h servconf.c servconf.h ssh.c]
215 remove unused kerberos code; ok henning@
4771605b 216 - markus@cvs.openbsd.org 2003/09/01 20:44:54
217 [auth2-gss.c]
218 fix leak
c53917a9 219 - (djm) Don't initialise pam_conv structures inline. Avoids HP/UX compiler
220 error. Part of Bug #423, patch from michael_steffens AT hp.com
49e82bb9 221 - (djm) Bug #423: reorder setting of PAM_TTY and calling of PAM session
222 management (now done in do_setusercontext). Largely from
223 michael_steffens AT hp.com
5e89e8a5 224 - (djm) Fix openbsd-compat/ again - remove references to strl(cpy|cat).h
225
2274ae66 22620030829
a5aec672 227 - (bal) openbsd-compat/ clean up. Considate headers, add in Id on our
2274ae66 228 files, and added missing license to header.
229
fe46678b 23020030826
231 - (djm) Bug #629: Mark ssh_config option "pamauthenticationviakbdint"
232 as deprecated. Remove mention from README.privsep. Patch from
233 aet AT cc.hut.fi
7364bd04 234 - (dtucker) OpenBSD CVS Sync
235 - markus@cvs.openbsd.org 2003/08/22 10:56:09
236 [auth2.c auth2-gss.c auth.h compat.c compat.h gss-genr.c gss-serv-krb5.c
237 gss-serv.c monitor.c monitor.h monitor_wrap.c monitor_wrap.h readconf.c
238 readconf.h servconf.c servconf.h session.c session.h ssh-gss.h
239 ssh_config.5 sshconnect2.c sshd_config sshd_config.5]
240 support GSS API user authentication; patches from Simon Wilkinson,
241 stripped down and tested by Jakob and myself.
1d9f0c09 242 - markus@cvs.openbsd.org 2003/08/22 13:20:03
243 [sshconnect2.c]
244 remove support for "kerberos-2@ssh.com"
816daa84 245 - markus@cvs.openbsd.org 2003/08/22 13:22:27
246 [auth2.c] (auth2-krb5.c removed)
247 nuke "kerberos-2@ssh.com"
52f6ea0e 248 - markus@cvs.openbsd.org 2003/08/22 20:55:06
249 [LICENCE]
250 add Simon Wilkinson
f99e1ca4 251 - deraadt@cvs.openbsd.org 2003/08/24 17:36:52
252 [monitor.c monitor_wrap.c sshconnect2.c]
253 64 bit cleanups; markus ok
e68d8348 254 - fgsch@cvs.openbsd.org 2003/08/25 08:13:09
255 [sftp-int.c]
256 fix div by zero when listing for filename lengths longer than width.
257 markus@ ok.
ea7bee97 258 - djm@cvs.openbsd.org 2003/08/25 10:33:33
259 [sshconnect2.c]
260 fprintf->logit to silence login banner with "ssh -q"; ok markus@
749560dd 261 - (dtucker) [Makefile.in acconfig.h auth-krb5.c auth-pam.c auth-pam.h
262 configure.ac defines.h gss-serv-krb5.c session.c ssh-gss.h sshconnect1.c
263 sshconnect2.c] Add Portable GSSAPI support, patch by Simon Wilkinson.
780efc0f 264 - (dtucker) [Makefile.in] Remove auth2-krb5.
2b7d75f5 265 - (dtucker) [contrib/aix/inventory.sh] Add public domain notice. ok mouring@
266 (the original author)
da67ae18 267 - (dtucker) [auth.c] Do not check for locked accounts when PAM is enabled.
fe46678b 268
4e2e1af3 26920030825
270 - (djm) Bug #621: Select OpenSC keys by usage attributes. Patch from
271 larsch@trustcenter.de
510a42ce 272 - (bal) openbsd-compat/ OpenBSD updates. Mostly licensing, ansifications
f00d1f78 273 and minor fixes. OK djm@
274 - (bal) redo how we handle 'mysignal()'. Move it to
275 openbsd-compat/bsd-misc.c, s/mysignal/signal/ and #define signal to
276 be our 'mysignal' by default. OK djm@
3e6e3da0 277 - (dtucker) [acconfig.h auth.c configure.ac sshd.8] Bug #422 again: deny
278 any access to locked accounts. ok djm@
5b9e2464 279 - (djm) Bug #564: Perform PAM account checks for all authentications when
280 UsePAM=yes; ok dtucker
a6e67b60 281 - (dtucker) [configure.ac] Bug #533, #551: define BROKEN_GETADDRINFO on
282 Tru64, solves getnameinfo and "bad addr or host" errors. ok djm@
ed00d4b7 283 - (dtucker) [README buildbff.sh inventory.sh] (all in contrib/aix)
284 Update package builder: correctly handle config variables, use lsuser
285 rather than /etc/passwd, fix typos, add Id's.
4e2e1af3 286
fda04d7d 28720030822
288 - (djm) s/get_progname/ssh_get_progname/g to avoid conflict with Heimdal
289 -lbroken; ok dtucker
fcd7f067 290 - (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
291 rather that authorized_keys2. Patch from vinschen@redhat.com.
fda04d7d 292
08d035b6 29320030821
294 - (dtucker) OpenBSD CVS Sync
295 - markus@cvs.openbsd.org 2003/08/14 16:08:58
296 [ssh-keygen.c]
297 exit after primetest, ok djm@
a814ba4d 298 - (dtucker) [defines.h] Put CMSG_DATA, CMSG_FIRSTHDR with other CMSG* macros,
299 change CMSG_DATA to use __CMSG_ALIGN (and thus work properly), reformat for
300 consistency.
eacb954e 301 - (dtucker) [configure.ac] Move openpty/ctty test outside of case statement
302 and after normal openpty test.
08d035b6 303
83814987 30420030813
305 - (dtucker) [session.c] Remove #ifdef TIOCSBRK kludge.
8168a86a 306 - (dtucker) OpenBSD CVS Sync
307 - markus@cvs.openbsd.org 2003/08/13 08:33:02
308 [session.c]
309 use more portable tcsendbreak(3) and ignore break_length;
310 ok deraadt, millert
0598d99d 311 - markus@cvs.openbsd.org 2003/08/13 08:46:31
312 [auth1.c readconf.c readconf.h servconf.c servconf.h ssh.c ssh_config
313 ssh_config.5 sshconnect1.c sshd.8 sshd.c sshd_config sshd_config.5]
314 remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,
315 fgsch@, miod@, henning@, jakob@ and others
37ba5172 316 - markus@cvs.openbsd.org 2003/08/13 09:07:10
317 [readconf.c ssh.c]
318 socks4->socks, since with support both 4 and 5; dtucker@zip.com.au
5af25b1d 319 - (dtucker) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
320 Add a tcsendbreak function for platforms that don't have one, based on the
321 one from OpenBSD.
83814987 322
78e43412 32320030811
324 - (dtucker) OpenBSD CVS Sync
325 (thanks to Simon Wilkinson for help with this -dt)
326 - markus@cvs.openbsd.org 2003/07/16 15:02:06
327 [auth-krb5.c]
328 mcc -> fcc; from Love Hörnquist Åstrand <lha@it.su.se>
329 otherwise the kerberos credentinal is stored in a memory cache
330 in the privileged sshd. ok jabob@, hin@ (some time ago)
8c9f0900 331 - (dtucker) [openbsd-compat/xcrypt.c] Remove Cygwin #ifdef block (duplicate
332 in bsd-cygwin_util.h).
78e43412 333
3095daf7 33420030808
335 - (dtucker) [openbsd-compat/fake-rfc2553.h] Older Linuxes have AI_PASSIVE and
336 AI_CANONNAME in netdb.h but not AI_NUMERICHOST, so check each definition
337 separately before defining them.
26b3608b 338 - (dtucker) [auth-pam.c] Don't set PAM_TTY if tty is null. ok djm@
3095daf7 339
a15f16ab 34020030807
341 - (dtucker) [session.c] Have session_break_req not attempt to send a break
342 if TIOCSBRK and TIOCCBRK are not defined (eg Cygwin).
97722976 343 - (dtucker) [canohost.c] Bug #336: Only check ip options if IP_OPTIONS is
a96fbb21 344 defined (fixes compile error on really old Linuxes).
345 - (dtucker) [defines.h] Bug #336: Add CMSG_DATA and CMSG_FIRSTHDR macros if
346 not already defined (eg Linux with some versions of libc5), based on those
347 from OpenBSD.
871e1d12 348 - (dtucker) [openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
349 Remove incorrect filenames from comments (file names are in Id tags).
a3b678a3 350 - (dtucker) [session.c openbsd-compat/bsd-cygwin_util.h] Move Cygwin
351 specific defines and includes to bsd-cygwin_util.h. Fixes build error too.
a15f16ab 352
2616e1bc 35320030802
354 - (dtucker) [monitor.h monitor_wrap.h] Remove excess ident tags.
1c590258 355 - (dtucker) OpenBSD CVS Sync
356 - markus@cvs.openbsd.org 2003/07/22 13:35:22
357 [auth1.c auth.h auth-passwd.c monitor.c monitor.h monitor_wrap.c
358 monitor_wrap.h readconf.c readconf.h servconf.c servconf.h session.c ssh.1
359 ssh.c ssh_config.5 sshconnect1.c sshd.c sshd_config.5 ssh.h]
360 remove (already disabled) KRB4/AFS support, re-enable -k in ssh(1);
361 test+ok henning@
362 - (dtucker) [Makefile.in acconfig.h configure.ac] Remove KRB4/AFS support.
363 - (dtucker) [auth-krb4.c radix.c radix.h] Remove KRB4/AFS specific files.
ac452e85 364 - (dtucker) OpenBSD CVS Sync
365 - markus@cvs.openbsd.org 2003/07/23 07:42:43
366 [sshd_config]
367 remove AFS; itojun@
c35a6dc5 368 - djm@cvs.openbsd.org 2003/07/28 09:49:56
369 [ssh-keygen.1 ssh-keygen.c]
370 Support for generating Diffie-Hellman groups (/etc/moduli) from ssh-keygen.
371 Based on code from Phil Karn, William Allen Simpson and Niels Provos.
372 ok markus@, thanks jmc@
178b1a1d 373 - markus@cvs.openbsd.org 2003/07/29 18:24:00
374 [LICENCE progressmeter.c]
375 replace 4 clause BSD licensed progressmeter code with a replacement
376 from Nils Nordman and myself; ok deraadt@
377 (copied from OpenBSD an re-applied portable changes)
0dd40286 378 - markus@cvs.openbsd.org 2003/07/29 18:26:46
379 [progressmeter.c]
380 fix length for "- stalled -" (included with previous import)
381 - markus@cvs.openbsd.org 2003/07/30 07:44:14
382 [progressmeter.c]
383 use only 4 digits in format_size (included with previous import)
384 - markus@cvs.openbsd.org 2003/07/30 07:53:27
385 [progressmeter.c]
386 whitespace (included with previous import)
0f57e1e6 387 - markus@cvs.openbsd.org 2003/07/31 09:21:02
388 [auth2-none.c]
389 check whether passwd auth is allowd, similar to proto 1; rob@pitman.co.za
390 ok henning
4899ccef 391 - avsm@cvs.openbsd.org 2003/07/31 15:50:16
392 [atomicio.c]
393 correct comment: atomicio takes vwrite, not write; deraadt@ ok
b3a7a008 394 - markus@cvs.openbsd.org 2003/07/31 22:34:03
395 [progressmeter.c]
396 print rate similar old version; round instead truncate;
397 (included in previous progressmeter.c commit)
c5d3dd1b 398 - (dtucker) [openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
399 Add a tcgetpgrp function.
5ae3dc68 400 - (dtucker) [Makefile.in moduli.c moduli.h] Add new files and to Makefile.
f29c37a9 401 - (dtucker) [openbsd-compat/bsd-misc.c] Fix cut-and-paste bug in tcgetpgrp.
2616e1bc 402
cbdeccf3 40320030730
404 - (djm) [auth-pam.c] Don't use crappy APIs like sprintf. Thanks bal
405
a9705c94 40620030726
407 - (dtucker) [openbsd-compat/xcrypt.c] Fix typo: DISABLED_SHADOW ->
408 DISABLE_SHADOW. Fixes HP-UX compile error.
409
7c6eb32f 41020030724
411 - (bal) [auth-passwd.c openbsd-compat/Makefile.in openbsd-compat/xcrypt.c
412 openbsd-compat/xcrypt.h] Split off encryption into xcrypt() interface,
413 and isolate shadow password functions. Tested in Solaris, but should
414 not break other platforms too badly (except maybe HP =). Also brings
415 auth-passwd.c into full sync with OpenBSD tree.
416
82e5907c 41720030723
418 - (dtucker) [configure.ac] Back out change for bug #620.
419
defb525d 42020030719
421 - (dtucker) [configure.ac] Bug #620: Define BROKEN_GETADDRINFO for
422 Solaris/x86. Patch from jrhett at isite.net.
7b390973 423 - (dtucker) OpenBSD CVS Sync
424 - markus@cvs.openbsd.org 2003/07/14 12:36:37
425 [sshd.c]
426 remove undocumented -V option. would be only useful if openssh is used
427 as ssh v1 server for ssh.com's ssh v2.
e053cd2c 428 - markus@cvs.openbsd.org 2003/07/16 10:34:53
429 [ssh.c sshd.c]
430 don't exit on multiple -v or -d; ok deraadt@
145d23ca 431 - markus@cvs.openbsd.org 2003/07/16 10:36:28
432 [sshtty.c]
433 clear IUCLC in enter_raw_mode; from rob@pitman.co.za; ok deraadt@, fgs@
261bd618 434 - deraadt@cvs.openbsd.org 2003/07/18 01:54:25
435 [scp.c]
436 userid is unsigned, but well, force it anyways; andrushock@korovino.net
b3d04e37 437 - djm@cvs.openbsd.org 2003/07/19 00:45:53
438 [sftp-int.c]
439 fix sftp filename parsing for arguments with escaped quotes. bz #517;
440 ok markus
86d0260c 441 - djm@cvs.openbsd.org 2003/07/19 00:46:31
442 [regress/sftp-cmds.sh]
443 regress test for sftp arguments with escaped quotes; ok markus
defb525d 444
e351e493 44520030714
446 - (dtucker) [acconfig.h configure.ac port-aix.c] Older AIXes don't declare
447 loginfailed at all, so assume 3-arg loginfailed if not declared.
1cd5765d 448 - (dtucker) [port-aix.h] Work around name collision on AIX for r_type by
449 undef'ing it.
2aa3a16c 450 - (dtucker) Bug #543: [configure.ac port-aix.c port-aix.h]
451 Call setauthdb() before loginfailed(), which may load password registry-
defb525d 452 specific functions. Based on patch by cawlfiel at us.ibm.com.
b4777c18 453 - (dtucker) [port-aix.h] Fix prototypes.
956b0f56 454 - (dtucker) OpenBSD CVS Sync
455 - avsm@cvs.openbsd.org 2003/07/09 13:58:19
456 [key.c]
457 minor tweak: when generating the hex fingerprint, give strlcat the full
458 bound to the buffer, and add a comment below explaining why the
459 zero-termination is one less than the bound. markus@ ok
40729edd 460 - markus@cvs.openbsd.org 2003/07/10 14:42:28
461 [packet.c]
462 the 2^(blocksize*2) rekeying limit is too expensive for 3DES,
463 blowfish, etc, so enforce a 1GB limit for small blocksizes.
659912db 464 - markus@cvs.openbsd.org 2003/07/10 20:05:55
465 [sftp.c]
466 sync usage with manpage, add missing -R
e351e493 467
f58c0e01 46820030708
469 - (dtucker) [acconfig.h auth-passwd.c configure.ac session.c port-aix.[ch]]
470 Include AIX headers for authentication functions and make calls match
e351e493 471 prototypes. Test for and handle 3-arg and 4-arg variants of loginfailed.
bc7dfc06 472 - (dtucker) [session.c] Check return value of setpcred().
473 - (dtucker) [auth-passwd.c auth.c session.c sshd.c port-aix.c port-aix.h]
474 Convert aixloginmsg into platform-independant Buffer loginmsg.
f58c0e01 475
309709db 47620030707
477 - (dtucker) [configure.ac] Bug #600: Check that getrusage is declared before
478 searching libraries for it. Fixes build errors on NCR MP-RAS.
479
d72f7b79 48020030706
481 - (dtucker) [ssh-rand-helper.c loginrec.c]
482 Apply atomicio typing change to these too.
483
71b9ced0 48420030703
485 - (dtucker) OpenBSD CVS Sync
486 - djm@cvs.openbsd.org 2003/06/28 07:48:10
487 [sshd.c]
488 report pidfile creation errors, based on patch from Roumen Petrov;
489 ok markus@
dc54438a 490 - deraadt@cvs.openbsd.org 2003/06/28 16:23:06
491 [atomicio.c atomicio.h authfd.c clientloop.c monitor_wrap.c msg.c
492 progressmeter.c scp.c sftp-client.c ssh-keyscan.c ssh.h sshconnect.c
493 sshd.c]
494 deal with typing of write vs read in atomicio
7caca6d4 495 - markus@cvs.openbsd.org 2003/06/29 12:44:38
496 [sshconnect.c]
497 memset 0, not \0; andrushock@korovino.net
8e7c9afc 498 - markus@cvs.openbsd.org 2003/07/02 12:56:34
499 [channels.c]
500 deny dynamic forwarding with -R for v1, too; ok djm@
f49658f5 501 - markus@cvs.openbsd.org 2003/07/02 14:51:16
502 [channels.c ssh.1 ssh_config.5]
503 (re)add socks5 suppport to -D; ok djm@
504 now ssh(1) can act both as a socks 4 and socks 5 server and
505 dynamically forward ports.
03c82656 506 - markus@cvs.openbsd.org 2003/07/02 20:37:48
507 [ssh.c]
508 convert hostkeyalias to lowercase, otherwise uppercase aliases will
509 not match at all; ok henning@
1768a611 510 - markus@cvs.openbsd.org 2003/07/03 08:21:46
511 [regress/dynamic-forward.sh]
512 add socks5; speedup; reformat; based on patch from dtucker@zip.com.au
7664edb6 513 - markus@cvs.openbsd.org 2003/07/03 08:24:13
514 [regress/Makefile]
515 enable tests for dynamic fwd via socks (-D), uses nc(1)
1572b90f 516 - djm@cvs.openbsd.org 2003/07/03 08:09:06
517 [readconf.c readconf.h ssh-keysign.c ssh.c]
518 fix AddressFamily option in config file, from brent@graveland.net;
519 ok markus@
71b9ced0 520
4e00038c 52120030630
522 - (djm) Search for support functions necessary to build our
523 getrrsetbyname() replacement. Patch from Roumen Petrov
524
9f59c5a3 52520030629
c5829391 526 - (dtucker) [includes.h] Bug #602: move #include of netdb.h to after in.h
527 (fixes compiler warnings on Solaris 2.5.1).
528 - (dtucker) [configure.ac] Add sanity test after system-dependant compiler
529 flag modifications.
9f59c5a3 530
9ea150a7 53120030628
532 - (djm) Bug #591: use PKCS#15 private key label as a comment in case
533 of OpenSC. Report and patch from larsch@trustcenter.de
d2168412 534 - (djm) Bug #593: Sanity check OpenSC card reader number; patch from
535 aj@dungeon.inka.de
f0677b69 536 - (dtucker) OpenBSD CVS Sync
537 - markus@cvs.openbsd.org 2003/06/23 09:02:44
538 [ssh_config.5]
539 document EnableSSHKeysign; bugzilla #599; ok deraadt@, jmc@
a27002e5 540 - markus@cvs.openbsd.org 2003/06/24 08:23:46
541 [auth2-hostbased.c auth2-pubkey.c auth2.c channels.c key.c key.h
542 monitor.c packet.c packet.h serverloop.c sshconnect2.c sshd.c]
543 int -> u_int; ok djm@, deraadt@, mouring@
d7ded285 544 - miod@cvs.openbsd.org 2003/06/25 22:39:36
545 [sftp-server.c]
546 Typo police: attribute is better written with an 'r'.
2d9c1828 547 - markus@cvs.openbsd.org 2003/06/26 20:08:33
548 [readconf.c]
549 do not dump core for 'ssh -o proxycommand host'; ok deraadt@
78b2dd04 550 - (dtucker) [regress/dynamic-forward.sh] Import new regression test.
ddb154b3 551 - (dtucker) [configure.ac] Bug #570: Have ./configure --enable-FEATURE
552 actually enable the feature, for those normally disabled. Patch by
553 openssh (at) roumenpetrov.info.
f0677b69 554
e15ba28b 55520030624
556 - (dtucker) Have configure refer the user to config.log and
557 contrib/findssl.sh for OpenSSL header/library mismatches.
558
63a556df 55920030622
c1ffd4bd 560 - (dtucker) OpenBSD CVS Sync
63a556df 561 - markus@cvs.openbsd.org 2003/06/21 09:14:05
c1ffd4bd 562 [regress/reconfigure.sh]
63a556df 563 missing $SUDO; from dtucker@zip.com.au
93527718 564 - markus@cvs.openbsd.org 2003/06/18 11:28:11
c1ffd4bd 565 [ssh-rsa.c]
566 backout last change, since it violates pkcs#1
567 switch to share/misc/license.template
1891396b 568 - djm@cvs.openbsd.org 2003/06/20 05:47:58
569 [sshd_config.5]
570 sync description of protocol 2 cipher proposal; ok markus
4db4d313 571 - djm@cvs.openbsd.org 2003/06/20 05:48:21
572 [sshd_config]
573 sync some implemented options; ok markus@
63a556df 574 - (dtucker) [regress/authorized_keys_root] Remove temp data file from CVS.
39ef3618 575 - (dtucker) [openbsd-compat/setproctitle.c] Ensure SPT_TYPE is defined before
576 testing its value.
63a556df 577
b8e04133 57820030618
579 - (djm) OpenBSD CVS Sync
580 - markus@cvs.openbsd.org 2003/06/12 07:57:38
581 [monitor.c sshlogin.c sshpty.c]
582 typos; dtucker at zip.com.au
b9ad9d13 583 - djm@cvs.openbsd.org 2003/06/12 12:22:47
584 [LICENCE]
585 mention more copyright holders; ok markus@
1fb23629 586 - nino@cvs.openbsd.org 2003/06/12 15:34:09
587 [scp.c]
588 Typo. Ok markus@.
244e796f 589 - markus@cvs.openbsd.org 2003/06/12 19:12:03
590 [scard.c scard.h ssh-agent.c ssh.c]
591 add sc_get_key_label; larsch at trustcenter.de; bugzilla#591
9250058a 592 - markus@cvs.openbsd.org 2003/06/16 08:22:35
593 [ssh-rsa.c]
594 make sure the signature has at least the expected length (don't
595 insist on len == hlen + oidlen, since this breaks some smartcards)
596 bugzilla #592; ok djm@
360a4aae 597 - markus@cvs.openbsd.org 2003/06/16 10:22:45
598 [ssh-add.c]
599 print out key comment on each prompt; make ssh-askpass more useable; ok djm@
0a59bd6b 600 - markus@cvs.openbsd.org 2003/06/17 18:14:23
601 [cipher-ctr.c]
602 use license from /usr/share/misc/license.template for new code
1d6c0b69 603 - (dtucker) [reconfigure.sh rekey.sh sftp-badcmds.sh]
604 Import new regression tests from OpenBSD
d4d84f5f 605 - (dtucker) [regress/copy.1 regress/copy.2] Remove temp data files from CVS.
ed49cc81 606 - (dtucker) OpenBSD CVS Sync (regress/)
607 - markus@cvs.openbsd.org 2003/04/02 12:21:13
608 [Makefile]
609 enable rekey test
2c670155 610 - djm@cvs.openbsd.org 2003/04/04 09:34:22
611 [Makefile sftp-cmds.sh]
612 More regression tests, including recent directory rename bug; ok markus@
737447ad 613 - markus@cvs.openbsd.org 2003/05/14 22:08:27
614 [ssh-com-client.sh ssh-com-keygen.sh ssh-com-sftp.sh ssh-com.sh]
615 test against some new commerical versions
68df2aa0 616 - mouring@cvs.openbsd.org 2003/05/15 04:07:12
617 [sftp-cmds.sh]
618 Advanced put/get testing for sftp. OK @djm
eb9bf761 619 - markus@cvs.openbsd.org 2003/06/12 15:40:01
620 [try-ciphers.sh]
621 add ctr
39c0191e 622 - markus@cvs.openbsd.org 2003/06/12 15:43:32
623 [Makefile]
624 test -HUP; dtucker at zip.com.au
b8e04133 625
f5827134 62620030614
627 - (djm) Update license on fake-rfc2553.[ch]; ok itojun@
628
be193d89 62920030611
c12c6ef8 630 - (djm) Mention portable copyright holders in LICENSE
e52ca1e5 631 - (djm) Put licenses on substantial header files
8cb3fa9d 632 - (djm) Sync LICENSE against OpenBSD
be193d89 633 - (djm) OpenBSD CVS Sync
634 - jmc@cvs.openbsd.org 2003/06/10 09:12:11
635 [scp.1 sftp-server.8 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5]
636 [sshd.8 sshd_config.5 ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
637 - section reorder
638 - COMPATIBILITY merge
639 - macro cleanup
640 - kill whitespace at EOL
641 - new sentence, new line
642 ssh pages ok markus@
0daa6547 643 - deraadt@cvs.openbsd.org 2003/06/10 22:20:52
644 [packet.c progressmeter.c]
645 mostly ansi cleanup; pval ok
1432b5c4 646 - jakob@cvs.openbsd.org 2003/06/11 10:16:16
647 [sshconnect.c]
648 clean up check_host_key() and improve SSHFP feedback. ok markus@
cc263107 649 - jakob@cvs.openbsd.org 2003/06/11 10:18:47
650 [dns.c]
651 sync with check_host_key() change
ca719034 652 - djm@cvs.openbsd.org 2003/06/11 11:18:38
653 [authfd.c authfd.h ssh-add.c ssh-agent.c]
654 make agent constraints (lifetime, confirm) work with smartcard keys;
655 ok markus@
be193d89 656
657
8a547250 65820030609
659 - (djm) Sync README.smartcard with OpenBSD -current
a1864983 660 - (djm) Re-merge OpenSC info into README.smartcard
8a547250 661
f5db6a03 66220030606
663 - (dtucker) [uidswap.c] Fix setreuid and add missing args to fatal(). ok djm@
664
02e2a074 66520030605
666 - (djm) Support AI_NUMERICHOST in fake-getaddrinfo.c. Needed for recent
667 canohost.c changes.
688eed4a 668 - (djm) Implement paranoid priv dropping checks, based on:
669 "SetUID demystified" - Hao Chen, David Wagner and Drew Dean
670 Proceedings of USENIX Security Symposium 2002
d6bd2b5a 671 - (djm) Don't use xmalloc() or pull in toplevel headers in fake-* code
52d58495 672 - (djm) Merge all the openbsd/fake-* into fake-rfc2553.[ch]
57c917f8 673 - (djm) Bug #588 - Add scard-opensc.o back to Makefile.in
674 Patch from larsch@trustcenter.de
7b7f164b 675 - (djm) Bug #589 - scard-opensc: load only keys with a private keys
676 Patch from larsch@trustcenter.de
4ed465ec 677 - (dtucker) Add includes.h to fake-rfc2553.c so it will build.
e932f447 678 - (dtucker) Define EAI_NONAME in fake-rfc2553.h (used by fake-rfc2553.c).
02e2a074 679
b08a39ff 68020030604
d60e487c 681 - (djm) Bug #573 - Remove unneeded Krb headers and compat goop. Patch from
682 simon@sxw.org.uk (Also matches a change in OpenBSD a while ago)
8acdec60 683 - (djm) Bug #577 - wrong flag in scard-opensc.c sc_private_decrypt.
11f1e60e 684 Patch from larsch@trustcenter.de; ok markus@
685 - (djm) Bug #584: scard-opensc.c doesn't work without PIN. Patch from
686 larsch@trustcenter.de; ok markus@
d453a600 687 - (djm) OpenBSD CVS Sync
688 - djm@cvs.openbsd.org 2003/06/04 08:25:18
689 [sshconnect.c]
690 disable challenge/response and keyboard-interactive auth methods
691 upon hostkey mismatch. based on patch from fcusack AT fcusack.com.
692 bz #580; ok markus@
ee50371d 693 - djm@cvs.openbsd.org 2003/06/04 10:23:48
694 [sshd.c]
695 remove duplicated group-dropping code; ok markus@
b08a39ff 696 - djm@cvs.openbsd.org 2003/06/04 12:03:59
697 [serverloop.c]
698 remove bitrotten commet; ok markus@
cf3248b8 699 - djm@cvs.openbsd.org 2003/06/04 12:18:49
700 [scp.c]
701 ansify; ok markus@
0f764b2f 702 - djm@cvs.openbsd.org 2003/06/04 12:40:39
703 [scp.c]
704 kill ssh process upon receipt of signal, bz #241.
705 based on patch from esb AT hawaii.edu; ok markus@
1b558925 706 - djm@cvs.openbsd.org 2003/06/04 12:41:22
707 [sftp.c]
708 kill ssh process on receipt of signal; ok markus@
fba33e81 709 - (djm) Update to fix of bug #584: lock card before return.
710 From larsch@trustcenter.de
8d9bb5dd 711 - (djm) Always use mysignal() for SIGALRM
d60e487c 712
3a2b2b44 71320030603
714 - (djm) Replace setproctitle replacement with code derived from
715 UCB sendmail
c5a7d788 716 - (djm) OpenBSD CVS Sync
717 - markus@cvs.openbsd.org 2003/06/02 09:17:34
718 [auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
719 [canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
720 [sshd_config.5]
721 deprecate VerifyReverseMapping since it's dangerous if combined
722 with IP based access control as noted by Mike Harding; replace with
723 a UseDNS option, UseDNS is on by default and includes the
724 VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
725 ok deraadt@, djm@
d981089c 726 - millert@cvs.openbsd.org 2003/06/03 02:56:16
727 [scp.c]
728 Remove the advertising clause in the UCB license which Berkeley
729 rescinded 22 July 1999. Proofed by myself and Theo.
c5a7d788 730 - (djm) Fix portable-specific uses of verify_reverse_mapping too
3e67f7df 731 - (djm) Sync openbsd-compat with OpenBSD CVS.
484d59c7 732 - No more 4-term BSD licenses in linked code
5d8ca8c7 733 - (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
3a2b2b44 734
aff561f9 73520030602
736 - (djm) Fix segv from bad reordering in auth-pam.c
416c732d 737 - (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
738 clobber
1b7342ab 739 - (tim) openbsd-compat/xmmap.[ch] License clarifications. Add missing
740 CVS ID.
8862e142 741 - (djm) Remove "noip6" option from RedHat spec file. This may now be
742 set at runtime using AddressFamily option.
58ba3cb7 743 - (djm) Fix use of macro before #define in cipher-aes.c
382fe2fa 744 - (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
b0545fe6 745 - (djm) OpenBSD CVS Sync
746 - djm@cvs.openbsd.org 2003/05/26 12:54:40
747 [sshconnect.c]
748 fix format strings; ok markus@
fa5120a0 749 - deraadt@cvs.openbsd.org 2003/05/29 16:58:45
750 [sshd.c uidswap.c]
751 seteuid and setegid; markus ok
0f92946c 752 - jakob@cvs.openbsd.org 2003/06/02 08:31:10
753 [ssh_config.5]
754 VerifyHostKeyDNS is v2 only. ok markus@
aff561f9 755
4f178be8 75620030530
757 - (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
758 roumenpetrov.info
eabb99c6 759 - (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
4f178be8 760
4881aebb 76120030526
762 - (djm) Avoid auth2-chall.c warning when compiling without
763 PAM, BSD_AUTH and SKEY
764
5b0fe364 76520030525
766- (djm) OpenBSD CVS Sync
767 - djm@cvs.openbsd.org 2003/05/24 09:02:22
768 [log.c]
769 pass logged data through strnvis; ok markus
b9ed513a 770 - djm@cvs.openbsd.org 2003/05/24 09:30:40
771 [authfile.c monitor.c sftp-common.c sshpty.c]
772 cast some types for printing; ok markus@
5b0fe364 773
44c78996 77420030524
775 - (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
776
d83ebe4a 77720030523
778 - (djm) Use VIS_SAFE on logged strings rather than default strnvis
779 encoding (which encodes many more characters)
bd47824b 780 - OpenBSD CVS Sync
781 - jmc@cvs.openbsd.org 2003/05/20 12:03:35
782 [sftp.1]
783 - new sentence, new line
784 - added .Xr's
785 - typos
786 ok djm@
3cbc677d 787 - jmc@cvs.openbsd.org 2003/05/20 12:09:31
788 [ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
789 new sentence, new line
da54f5be 790 - djm@cvs.openbsd.org 2003/05/23 08:29:30
791 [sshconnect.c]
792 fix leak; ok markus@
d83ebe4a 793
c453493f 79420030520
795 - (djm) OpenBSD CVS Sync
796 - deraadt@cvs.openbsd.org 2003/05/18 23:22:01
797 [log.c]
798 use syslog_r() in a signal handler called place; markus ok
79d4fc55 799 - (djm) Configure logic to detect syslog_r and friends
c453493f 800
acb50584 80120030519
802 - (djm) Sync auth-pam.h with what we actually implement
803
80420030518
5ff453c0 805 - (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
806 recent merge
f811e52a 807 - (djm) OpenBSD CVS Sync
808 - djm@cvs.openbsd.org 2003/05/16 03:27:12
809 [readconf.c ssh_config ssh_config.5 ssh-keysign.c]
810 add AddressFamily option to ssh_config (like -4, -6 on commandline).
811 Portable bug #534; ok markus@
013b1214 812 - itojun@cvs.openbsd.org 2003/05/17 03:25:58
813 [auth-rhosts.c]
814 just in case, put numbers to sscanf %s arg.
25b66522 815 - markus@cvs.openbsd.org 2003/05/17 04:27:52
816 [cipher.c cipher-ctr.c myproposal.h]
817 experimental support for aes-ctr modes from
818 http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
819 ok djm@
25351757 820 - (djm) Remove IPv4 by default hack now that we can specify AF in config
3bf784bc 821 - (djm) Tidy and trim TODO
bffa6723 822 - (djm) Sync openbsd-compat/ with OpenBSD CVS head
9901cb37 823 - (djm) Big KNF on openbsd-compat/
f1da2b8b 824 - (djm) KNF on md5crypt.[ch]
825 - (djm) KNF on auth-sia.[ch]
5ff453c0 826
f123055b 82720030517
828 - (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
829
c936c243 83020030516
831 - (djm) OpenBSD CVS Sync
832 - djm@cvs.openbsd.org 2003/05/15 13:52:10
833 [ssh.c]
834 Make "ssh -V" print the OpenSSL version in a human readable form. Patch
835 from Craig Leres (mindrot at ee.lbl.gov); ok markus@
a2144546 836 - jakob@cvs.openbsd.org 2003/05/15 14:02:47
837 [readconf.c servconf.c]
838 warn for unsupported config option. ok markus@
5bdfde81 839 - markus@cvs.openbsd.org 2003/05/15 14:09:21
840 [auth2-krb5.c]
841 fix 64bit issue; report itojun@
09ab3296 842 - djm@cvs.openbsd.org 2003/05/15 14:55:25
843 [readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
844 add a ConnectTimeout option to ssh, based on patch from
845 Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
b06b11ad 846 - (djm) Add warning for UsePAM when built without PAM support
7be625e1 847 - (djm) A few type mismatch fixes from Bug #565
0eb6370a 848 - (djm) Guard free_pam_environment against NULL argument. Works around
849 HP/UX PAM problems debugged by dtucker
c936c243 850
7efc7f57 85120030515
852 - (djm) OpenBSD CVS Sync
853 - jmc@cvs.openbsd.org 2003/05/14 13:11:56
854 [ssh-agent.1]
855 setup -> set up;
856 from wiz@netbsd
21289cd0 857 - jakob@cvs.openbsd.org 2003/05/14 18:16:20
858 [key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
859 [dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
860 add experimental support for verifying hos keys using DNS as described
861 in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
862 ok markus@ and henning@
16a79097 863 - markus@cvs.openbsd.org 2003/05/14 22:24:42
864 [clientloop.c session.c ssh.1]
865 allow to send a BREAK to the remote system; ok various
b8c2031b 866 - markus@cvs.openbsd.org 2003/05/15 00:28:28
867 [sshconnect2.c]
868 cleanup unregister of per-method packet handlers; ok djm@
d0ec7f42 869 - jakob@cvs.openbsd.org 2003/05/15 01:48:10
870 [readconf.c readconf.h servconf.c servconf.h]
871 always parse kerberos options. ok djm@ markus@
b414a17b 872 - jakob@cvs.openbsd.org 2003/05/15 02:27:15
873 [dns.c]
874 add missing freerrset
3b6e3da9 875 - markus@cvs.openbsd.org 2003/05/15 03:08:29
876 [cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
877 split out custom EVP ciphers
02159d9b 878 - djm@cvs.openbsd.org 2003/05/15 03:10:52
879 [ssh-keygen.c]
880 avoid warning; ok jakob@
4a26f5c5 881 - mouring@cvs.openbsd.org 2003/05/15 03:39:07
882 [sftp-int.c]
883 Make put/get (globed and nonglobed) code more consistant. OK djm@
c44f10c6 884 - mouring@cvs.openbsd.org 2003/05/15 03:43:59
dc69f53c 885 [sftp-int.c sftp.c]
c44f10c6 886 Teach ls how to display multiple column display and allow users
887 to return to single column format via 'ls -1'. OK @djm
1457e7ff 888 - jakob@cvs.openbsd.org 2003/05/15 04:08:44
889 [readconf.c servconf.c]
890 disable kerberos when not supported. ok markus@
861f0365 891 - markus@cvs.openbsd.org 2003/05/15 04:08:41
892 [ssh.1]
893 ~B is ssh2 only
d0ec7f42 894 - (djm) Always parse UsePAM
3e05e934 895 - (djm) Configure glue for DNS support (code doesn't work in portable yet)
4460d509 896 - (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
86ee6794 897 - (djm) Tidy Makefile clean targets
2636769c 898 - (djm) Adapt README.dns for portable
2d2e4a34 899 - (djm) Avoid uuencode.c warnings
1457e7ff 900 - (djm) Enable UsePAM when built --with-pam
67467c30 901 - (djm) Only build getrrsetbyname replacement when using --with-dns
f420d2ba 902 - (djm) Bug #529: sshd doesn't work correctly after SIGHUP (copy argv
903 correctly)
3c49ef10 904 - (djm) Bug #444: Wrong paths after reconfigure
321735c7 905 - (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
f420d2ba 906
dd3ebb5a 90720030514
908 - (djm) Bug #117: Don't lie to PAM about username
0608f8a7 909 - (djm) RCSID sync w/ OpenBSD
204fde99 910 - (djm) OpenBSD CVS Sync
911 - djm@cvs.openbsd.org 2003/04/09 12:00:37
912 [readconf.c]
913 strip trailing whitespace from config lines before parsing.
914 Fixes bz 528; ok markus@
18ae3c67 915 - markus@cvs.openbsd.org 2003/04/12 10:13:57
916 [cipher.c]
917 hide cipher details; ok djm@
45c42d58 918 - markus@cvs.openbsd.org 2003/04/12 10:15:36
919 [misc.c]
920 debug->debug2
c825cd79 921 - naddy@cvs.openbsd.org 2003/04/12 11:40:15
922 [ssh.1]
923 document -V switch, fix wording; ok markus@
3e131a6d 924 - markus@cvs.openbsd.org 2003/04/14 14:17:50
925 [channels.c sshconnect.c sshd.c ssh-keyscan.c]
926 avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
927e9f8b 927 - mouring@cvs.openbsd.org 2003/04/14 21:31:27
928 [sftp-int.c]
929 Missing globfree(&g) in process_put() spotted by Vince Brimhall
930 <VBrimhall@novell.com>. ok@ Theo
931 - markus@cvs.openbsd.org 2003/04/16 14:35:27
932 [auth.h]
933 document struct Authctxt; with solar
b9e5aff6 934 - deraadt@cvs.openbsd.org 2003/04/26 04:29:49
935 [ssh-keyscan.c]
936 -t in usage(); rogier@quaak.org
9a26a6e2 937 - mouring@cvs.openbsd.org 2003/04/30 01:16:20
938 [sshd.8 sshd_config.5]
939 Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
940 Bug #550 and * escaping suggested by jmc@.
09dc8896 941 - david@cvs.openbsd.org 2003/04/30 20:41:07
942 [sshd.8]
943 fix invalid .Pf macro usage introduced in previous commit
944 ok jmc@ mouring@
3566c73c 945 - markus@cvs.openbsd.org 2003/05/11 16:56:48
946 [authfile.c ssh-keygen.c]
947 change key_load_public to try to read a public from:
948 rsa1 private or rsa1 public and ssh2 keys.
949 this makes ssh-keygen -e fail for ssh1 keys more gracefully
950 for example; report from itojun (netbsd pr 20550).
0d942eff 951 - markus@cvs.openbsd.org 2003/05/11 20:30:25
952 [channels.c clientloop.c serverloop.c session.c ssh.c]
953 make channel_new() strdup the 'remote_name' (not the caller); ok theo
43348518 954 - markus@cvs.openbsd.org 2003/05/12 16:55:37
955 [sshconnect2.c]
956 for pubkey authentication try the user keys in the following order:
957 1. agent keys that are found in the config file
958 2. other agent keys
959 3. keys that are only listed in the config file
960 this helps when an agent has many keys, where the server might
961 close the connection before the correct key is used. report & ok pb@
dc109cfe 962 - markus@cvs.openbsd.org 2003/05/12 18:35:18
963 [ssh-keyscan.1]
964 typo: DSA keys are of type ssh-dss; Brian Poole
81466908 965 - markus@cvs.openbsd.org 2003/05/14 00:52:59
966 [ssh2.h]
967 ranges for per auth method messages
968 - djm@cvs.openbsd.org 2003/05/14 01:00:44
969 [sftp.1]
970 emphasise the batchmode functionality and make reference to pubkey auth,
971 both of which are FAQs; ok markus@
802e01b8 972 - markus@cvs.openbsd.org 2003/05/14 02:15:47
973 [auth2.c monitor.c sshconnect2.c auth2-krb5.c]
974 implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
975 server interops with commercial client; ok jakob@ djm@
72c5fe79 976 - jmc@cvs.openbsd.org 2003/05/14 08:25:39
977 [sftp.1]
978 - better formatting in SYNOPSIS
979 - whitespace at EOL
980 ok djm@
3a39206f 981 - markus@cvs.openbsd.org 2003/05/14 08:57:49
982 [monitor.c]
983 http://bugzilla.mindrot.org/show_bug.cgi?id=560
984 Privsep child continues to run after monitor killed.
985 Pass monitor signals through to child; Darren Tucker
751092f9 986 - (djm) Make portable build with MIT krb5 (some issues remain)
7fceb20d 987 - (djm) Add new UsePAM configuration directive to allow runtime control
988 over usage of PAM. This allows non-root use of sshd when built with
989 --with-pam
817e6d38 990 - (djm) Die screaming if start_pam() is called when UsePAM=no
83ccf11a 991 - (djm) Avoid KrbV leak for MIT Kerberos
b1848832 992 - (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
fa065de2 993 - (djm) Bug #258: sscanf("[0-9]") -> sscanf("[0123456789]") for portability
dd3ebb5a 994
91f3aa9b 99520030512
996 - (djm) Redhat spec: Don't install profile.d scripts when not
997 building with GNOME/GTK askpass (patch from bet@rahul.net)
998
5def520a 99920030510
1000 - (dtucker) Bug #318: Create ssh_prng_cmds.out during "make" rather than
1001 "make install". Patch by roth@feep.net.
ad84c479 1002 - (dtucker) Bug #536: Test for and work around openpty/controlling tty
1003 problem on Linux (fixes "could not set controlling tty" errors).
05114c74 1004 - (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
1005 proper challenge-response module
23ab1f36 1006 - (djm) 2-clause license on loginrec.c, with permission from
1007 andre@ae-35.com
5def520a 1008
43ce025d 100920030504
dd594f99 1010 - (dtucker) Bug #497: Move #include of bsd-cygwin_util.h to openbsd-compat.h.
1011 Patch from vinschen@redhat.com.
43ce025d 1012
2cd5dbba 101320030503
1014 - (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
1015 by wendyp@cray.com.
1016
bf7c1e6c 101720030502
1018 - (dtucker) Bug #544: ignore invalid cmsg_type on Linux 2.0 kernels,
1019 privsep should now work.
73d9dad3 1020 - (dtucker) Move handling of bad password authentications into a platform
990278ef 1021 specific record_failed_login() function (affects AIX & Unicos). ok mouring@
bf7c1e6c 1022
68ece370 102320030429
1024 - (djm) Add back radix.o (used by AFS support), after it went missing from
1025 Makefile many moons ago
1026 - (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
1027 - (djm) Fix blibpath specification for AIX/gcc
1028 - (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
1029
ded9dd18 103020030428
1031 - (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
1032 hacked code.
1033
aceb0423 103420030427
1035 - (bal) Bug #541: return; was dropped by mistake. Reported by
1036 furrier@iglou.com
c8a50a34 1037 - (bal) Since we don't support platforms lacking u_int_64. We may
1038 as well clean out some of those evil #ifdefs
9a6fee8b 1039 - (bal) auth1.c minor resync while looking at the code.
d7cf277b 1040 - (bal) auth2.c same changed as above.
aceb0423 1041
0a626302 104220030409
1043 - (djm) Bug #539: Specify creation mode with O_CREAT for lastlog. Report
1044 from matth@eecs.berkeley.edu
d35929b5 1045 - (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
ffd7b36b 1046 - (djm) OpenBSD CVS Sync
1047 - markus@cvs.openbsd.org 2003/04/02 09:48:07
1048 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1049 [readconf.h serverloop.c sshconnect2.c]
1050 reapply rekeying chage, tested by henning@, ok djm@
16f1b5ca 1051 - markus@cvs.openbsd.org 2003/04/02 14:36:26
1052 [ssh-keysign.c]
1053 potential segfault if KEY_UNSPEC; cjwatson@debian.org; bug #526
6c1bc5c5 1054 - itojun@cvs.openbsd.org 2003/04/03 07:25:27
1055 [progressmeter.c]
1056 $OpenBSD$
1057 - itojun@cvs.openbsd.org 2003/04/03 10:17:35
1058 [progressmeter.c]
1059 remove $OpenBSD$, as other *.c does not have it.
806e4c11 1060 - markus@cvs.openbsd.org 2003/04/07 08:29:57
1061 [monitor_wrap.c]
1062 typo: get correct counters; introduced during rekeying change.
2f5b2528 1063 - millert@cvs.openbsd.org 2003/04/07 21:58:05
1064 [progressmeter.c]
1065 The UCB copyright here is incorrect. This code did not originate
1066 at UCB, it was written by Luke Mewburn. Updated the copyright at
1067 the author's request. markus@ OK
1068 - itojun@cvs.openbsd.org 2003/04/08 20:21:29
1069 [*.c *.h]
1070 rename log() into logit() to avoid name conflict. markus ok, from
1071 netbsd
1072 - (djm) XXX - Performed locally using:
1073 "perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
70e1f62f 1074 - hin@cvs.openbsd.org 2003/04/09 08:23:52
1075 [servconf.c]
1076 Don't include <krb.h> when compiling with Kerberos 5 support
2f5b2528 1077 - (djm) Fix up missing include for packet.c
a3568201 1078 - (djm) Fix missed log => logit occurance (reference by function pointer)
0a626302 1079
4d0cb2e5 108020030402
1081 - (bal) if IP_TOS is not found or broken don't try to compile in
1082 packet_set_tos() function call. bug #527
1083
a4e5acef 108420030401
1085 - (djm) OpenBSD CVS Sync
1086 - jmc@cvs.openbsd.org 2003/03/28 10:11:43
1087 [scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
1088 [ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
1089 - killed whitespace
1090 - new sentence new line
1091 - .Bk for arguments
1092 ok markus@
177f584b 1093 - markus@cvs.openbsd.org 2003/04/01 10:10:23
1094 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1095 [readconf.h serverloop.c sshconnect2.c]
1096 rekeying bugfixes and automatic rekeying:
1097 * both client and server rekey _automatically_
1098 (a) after 2^31 packets, because after 2^32 packets
1099 the sequence number for packets wraps
1100 (b) after 2^(blocksize_in_bits/4) blocks
1101 (see: draft-ietf-secsh-newmodes-00.txt)
1102 (a) and (b) are _enabled_ by default, and only disabled for known
1103 openssh versions, that don't support rekeying properly.
1104 * client option 'RekeyLimit'
1105 * do not reply to requests during rekeying
1106 - markus@cvs.openbsd.org 2003/04/01 10:22:21
1107 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1108 [readconf.h serverloop.c sshconnect2.c]
1109 backout rekeying changes (for 3.6.1)
519bdfe8 1110 - markus@cvs.openbsd.org 2003/04/01 10:31:26
1111 [compat.c compat.h kex.c]
1112 bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
1113 tested by ho@ and myself
9dd240a3 1114 - markus@cvs.openbsd.org 2003/04/01 10:56:46
1115 [version.h]
1116 3.6.1
ac01b518 1117 - (djm) Crank spec file versions
b32453fe 1118 - (djm) Release 3.6.1p1
a4e5acef 1119
fd77a40f 112020030326
1121 - (djm) OpenBSD CVS Sync
1122 - deraadt@cvs.openbsd.org 2003/03/26 04:02:51
1123 [sftp-server.c]
1124 one last fix to the tree: race fix broke stuff; pr 3169;
1125 srp@srparish.net, help from djm
1126
8021857c 112720030325
1128 - (djm) Fix getpeerid support for 64 bit BE systems. From
1129 Arnd Bergmann <arndb@de.ibm.com>
1130
cdb64c4d 113120030324
1132 - (djm) OpenBSD CVS Sync
1133 - markus@cvs.openbsd.org 2003/03/23 19:02:00
1134 [monitor.c]
1135 unbreak rekeying for privsep; ok millert@
1136 - Release 3.6p1
62086365 1137 - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
1138 Report from murple@murple.net, diagnosis from dtucker@zip.com.au
cdb64c4d 1139
0b202697 1140$Id$
This page took 0.486077 seconds and 5 git commands to generate.