]> andersk Git - openssh.git/blame - ChangeLog
- (djm) Workaround PAM inconsistencies between Solaris derived PAM code
[openssh.git] / ChangeLog
CommitLineData
adeebd37 120001220
2 - (djm) Workaround PAM inconsistencies between Solaris derived PAM code
3 and Linux-PAM. Based on report and fix from Andrew Morgan
4 <morgan@transmeta.com>
5
f072c47a 620001218
7 - (stevesk) rsa.c: entropy.h not needed.
0c2fb82f 8 - (bal) split CFLAGS into CFLAGS and CPPFLAGS in configure.in and Makefile.
9 Suggested by Wilfredo Sanchez <wsanchez@apple.com>
f072c47a 10
731c1541 1120001216
12 - (stevesk) OpenBSD CVS updates:
13 - markus@cvs.openbsd.org 2000/12/16 02:53:57
14 [scp.c]
15 allow + in usernames; request from Florian.Weimer@RUS.Uni-Stuttgart.DE
16 - markus@cvs.openbsd.org 2000/12/16 02:39:57
17 [scp.c]
18 unused; from stevesk@pobox.com
19
227e8e86 2020001215
9853409f 21 - (stevesk) Old OpenBSD patch wasn't completely applied:
22 - markus@cvs.openbsd.org 2000/01/24 22:11:20
23 [scp.c]
24 allow '.' in usernames; from jedgar@fxp.org
227e8e86 25 - (stevesk) OpenBSD CVS updates:
26 - markus@cvs.openbsd.org 2000/12/13 16:26:53
27 [ssh-keyscan.c]
28 fatal already adds \n; from stevesk@pobox.com
29 - markus@cvs.openbsd.org 2000/12/13 16:25:44
30 [ssh-agent.c]
31 remove redundant spaces; from stevesk@pobox.com
32 - ho@cvs.openbsd.org 2000/12/12 15:50:21
33 [pty.c]
34 When failing to set tty owner and mode on a read-only filesystem, don't
35 abort if the tty already has correct owner and reasonably sane modes.
36 Example; permit 'root' to login to a firewall with read-only root fs.
37 (markus@ ok)
38 - deraadt@cvs.openbsd.org 2000/12/13 06:36:05
39 [pty.c]
40 KNF
6ffc9c88 41 - markus@cvs.openbsd.org 2000/12/12 14:45:21
42 [sshd.c]
43 source port < 1024 is no longer required for rhosts-rsa since it
44 adds no additional security.
45 - markus@cvs.openbsd.org 2000/12/12 16:11:49
46 [ssh.1 ssh.c]
47 rhosts-rsa is no longer automagically disabled if ssh is not privileged.
48 UsePrivilegedPort=no disables rhosts-rsa _only_ for old servers.
49 these changes should not change the visible default behaviour of the ssh client.
71c0d06a 50 - deraadt@cvs.openbsd.org 2000/12/11 10:27:33
51 [scp.c]
52 when copying 0-sized files, do not re-print ETA time at completion
3e1caa83 53 - provos@cvs.openbsd.org 2000/12/15 10:30:15
54 [kex.c kex.h sshconnect2.c sshd.c]
55 compute diffie-hellman in parallel between server and client. okay markus@
227e8e86 56
6c935fbd 5720001213
58 - (djm) Make sure we reset the SIGPIPE disposition after we fork. Report
59 from Andreas M. Kirchwitz <amk@krell.zikzak.de>
227e8e86 60 - (stevesk) OpenBSD CVS update:
1fe6a48f 61 - markus@cvs.openbsd.org 2000/12/12 15:30:02
62 [ssh-keyscan.c ssh.c sshd.c]
63 consistently use __progname; from stevesk@pobox.com
6c935fbd 64
367d1840 6520001211
66 - (bal) Applied patch to include ssh-keyscan into Redhat's package, and
67 patch to install ssh-keyscan manpage. Patch by Pekka Savola
68 <pekka@netcore.fi>
e3a70753 69 - (bal) OpenbSD CVS update
70 - markus@cvs.openbsd.org 2000/12/10 17:01:53
71 [sshconnect1.c]
72 always request new challenge for skey/tis-auth, fixes interop with
73 other implementations; report from roth@feep.net
367d1840 74
6b523bae 7520001210
76 - (bal) OpenBSD CVS updates
77 - markus@cvs.openbsd.org 2000/12/09 13:41:51
78 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
79 undo rijndael changes
80 - markus@cvs.openbsd.org 2000/12/09 13:48:31
81 [rijndael.c]
82 fix byte order bug w/o introducing new implementation
83 - markus@cvs.openbsd.org 2000/12/09 14:08:27
84 [sftp-server.c]
85 "" -> "." for realpath; from vinschen@redhat.com
86 - markus@cvs.openbsd.org 2000/12/09 14:06:54
87 [ssh-agent.c]
88 extern int optind; from stevesk@sweden.hp.com
13af0aa2 89 - provos@cvs.openbsd.org 2000/12/09 23:51:11
90 [compat.c]
91 remove unnecessary '\n'
6b523bae 92
ce9c0b75 9320001209
6b523bae 94 - (bal) OpenBSD CVS updates:
ce9c0b75 95 - djm@cvs.openbsd.org 2000/12/07 4:24:59
96 [ssh.1]
97 Typo fix from Wilfredo Sanchez <wsanchez@apple.com>; ok theo
98
f72fc97f 9920001207
6b523bae 100 - (bal) OpenBSD CVS updates:
f72fc97f 101 - markus@cvs.openbsd.org 2000/12/06 22:58:14
102 [compat.c compat.h packet.c]
103 disable debug messages for ssh.com/f-secure 2.0.1x, 2.1.0
dfe89252 104 - markus@cvs.openbsd.org 2000/12/06 23:10:39
105 [rijndael.c]
106 unexpand(1)
107 - markus@cvs.openbsd.org 2000/12/06 23:05:43
108 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
109 new rijndael implementation. fixes endian bugs
f72fc97f 110
97fb6912 11120001206
6b523bae 112 - (bal) OpenBSD CVS updates:
97fb6912 113 - markus@cvs.openbsd.org 2000/12/05 20:34:09
114 [channels.c channels.h clientloop.c serverloop.c]
115 async connects for -R/-L; ok deraadt@
116 - todd@cvs.openssh.org 2000/12/05 16:47:28
117 [sshd.c]
118 tweak comment to reflect real location of pid file; ok provos@
bf5f69f7 119 - (stevesk) Import <sys/queue.h> from OpenBSD for systems that don't
120 have it (used in ssh-keyscan).
227e8e86 121 - (stevesk) OpenBSD CVS update:
f20255cb 122 - markus@cvs.openbsd.org 2000/12/06 19:57:48
123 [ssh-keyscan.c]
124 err(3) -> internal error(), from stevesk@sweden.hp.com
97fb6912 125
f6fdbddf 12620001205
6b523bae 127 - (bal) OpenBSD CVS updates:
f6fdbddf 128 - markus@cvs.openbsd.org 2000/12/04 19:24:02
129 [ssh-keyscan.c ssh-keyscan.1]
130 David Maziere's ssh-keyscan, ok niels@
131 - (bal) Updated Makefile.in to include ssh-keyscan that was just added
132 to the recent OpenBSD source tree.
835d2104 133 - (stevesk) fix typos in contrib/hpux/README
f6fdbddf 134
cbc5abf9 13520001204
136 - (bal) More C functions defined in NeXT that are unaccessable without
f6fdbddf 137 defining -POSIX.
cbc5abf9 138 - (bal) OpenBSD CVS updates:
139 - markus@cvs.openbsd.org 2000/12/03 11:29:04
140 [compat.c]
141 remove fallback to SSH_BUG_HMAC now that the drafts are updated
142 - markus@cvs.openbsd.org 2000/12/03 11:27:55
143 [compat.c]
97fb6912 144 correctly match "2.1.0.pl2 SSH" etc; from
145 pekkas@netcore.fi/bugzilla.redhat
cbc5abf9 146 - markus@cvs.openbsd.org 2000/12/03 11:15:03
147 [auth2.c compat.c compat.h sshconnect2.c]
148 support f-secure/ssh.com 2.0.12; ok niels@
149
0b6fbf03 15020001203
cbc5abf9 151 - (bal) OpenBSD CVS updates:
0b6fbf03 152 - markus@cvs.openbsd.org 2000/11/30 22:54:31
153 [channels.c]
154 debug->warn if tried to do -R style fwd w/o client requesting this;
155 ok neils@
156 - markus@cvs.openbsd.org 2000/11/29 20:39:17
157 [cipher.c]
158 des_cbc_encrypt -> des_ncbc_encrypt since it already updates the IV
159 - markus@cvs.openbsd.org 2000/11/30 18:33:05
160 [ssh-agent.c]
161 agents must not dump core, ok niels@
162 - markus@cvs.openbsd.org 2000/11/30 07:04:02
163 [ssh.1]
164 T is for both protocols
165 - markus@cvs.openbsd.org 2000/12/01 00:00:51
166 [ssh.1]
167 typo; from green@FreeBSD.org
168 - markus@cvs.openbsd.org 2000/11/30 07:02:35
169 [ssh.c]
170 check -T before isatty()
171 - provos@cvs.openbsd.org 2000/11/29 13:51:27
172 [sshconnect.c]
173 show IP address and hostname when new key is encountered. okay markus@
174 - markus@cvs.openbsd.org 2000/11/30 22:53:35
175 [sshconnect.c]
176 disable agent/x11/port fwding if hostkey has changed; ok niels@
177 - marksu@cvs.openbsd.org 2000/11/29 21:11:59
178 [sshd.c]
179 sshd -D, startup w/o deamon(), for monitoring scripts or inittab;
180 from handler@sub-rosa.com and eric@urbanrange.com; ok niels@
8c9fe09e 181 - (djm) Added patch from Nalin Dahyabhai <nalin@redhat.com> to enable
182 PAM authentication using KbdInteractive.
183 - (djm) Added another TODO
0b6fbf03 184
90f4078a 18520001202
186 - (bal) Backed out of part of Alain St-Denis' loginrec.c patch.
187 - (bal) Irix need some sort of mansubdir, patch by Michael Stone
188 <mstone@cs.loyola.edu>
189
dcef6523 19020001129
7062c40f 191 - (djm) Back out all the serverloop.c hacks. sshd will now hang again
192 if there are background children with open fds.
c193d002 193 - (djm) bsd-rresvport.c bzero -> memset
194 - (djm) Don't fail in defines.h on absence of 64 bit types (we will
195 still fail during compilation of sftp-server).
196 - (djm) Fail if ar is not found during configure
c523303b 197 - (djm) OpenBSD CVS updates:
198 - provos@cvs.openbsd.org 2000/11/22 08:38:31
199 [sshd.8]
200 talk about /etc/primes, okay markus@
201 - markus@cvs.openbsd.org 2000/11/23 14:03:48
202 [ssh.c sshconnect1.c sshconnect2.c]
203 complain about invalid ciphers for ssh1/ssh2, fall back to reasonable
204 defaults
205 - markus@cvs.openbsd.org 2000/11/25 09:42:53
206 [sshconnect1.c]
207 reorder check for illegal ciphers, bugreport from espie@
208 - markus@cvs.openbsd.org 2000/11/25 10:19:34
209 [ssh-keygen.c ssh.h]
210 print keytype when generating a key.
211 reasonable defaults for RSA1/RSA/DSA keys.
b3ec54b4 212 - (djm) Patch from Pekka Savola <Pekka.Savola@netcore.fi> to include a few
213 more manpage paths in fixpaths calls
214 - (djm) Also add xauth path at Pekka's suggestion.
57ce3f00 215 - (djm) Add Redhat RPM patch for AUTHPRIV SyslogFacility
dcef6523 216
e879a080 21720001125
218 - (djm) Give up privs when reading seed file
219
d343d900 22020001123
221 - (bal) Merge OpenBSD changes:
222 - markus@cvs.openbsd.org 2000/11/15 22:31:36
223 [auth-options.c]
224 case insensitive key options; from stevesk@sweeden.hp.com
225 - markus@cvs.openbsd.org 2000/11/16 17:55:43
226 [dh.c]
227 do not use perror() in sshd, after child is forked()
228 - markus@cvs.openbsd.org 2000/11/14 23:42:40
229 [auth-rsa.c]
230 parse option only if key matches; fix some confusing seen by the client
231 - markus@cvs.openbsd.org 2000/11/14 23:44:19
232 [session.c]
233 check no_agent_forward_flag for ssh-2, too
234 - markus@cvs.openbsd.org 2000/11/15
235 [ssh-agent.1]
236 reorder SYNOPSIS; typo, use .It
237 - markus@cvs.openbsd.org 2000/11/14 23:48:55
238 [ssh-agent.c]
239 do not reorder keys if a key is removed
240 - markus@cvs.openbsd.org 2000/11/15 19:58:08
241 [ssh.c]
242 just ignore non existing user keys
243 - millert@cvs.openbsd.org 200/11/15 20:24:43
244 [ssh-keygen.c]
245 Add missing \n at end of error message.
246
0b49a754 24720001122
248 - (bal) Minor patch to ensure platforms lacking IRIX job limit supports
249 are compilable.
250 - (bal) Updated TODO as of 11/18/2000 with known things to resolve.
251
fab2e5d3 25220001117
253 - (bal) Changed from 'primes' to 'primes.out' for consistancy sake. It
254 has no affect the output. Patch by Corinna Vinschen <vinschen@redhat.com>
835d2104 255 - (stevesk) Reworked progname support.
260d427b 256 - (bal) Misplaced #include "includes.h" in bsd-setproctitle.c. Patch by
257 Shinichi Maruyama <marya@st.jip.co.jp>
fab2e5d3 258
c2207f11 25920001116
260 - (bal) Added in MAXSYMLINK test in bsd-realpath.c. Required for some SCO
261 releases.
262 - (bal) Make builds work outside of source tree. Patch by Mark D. Roth
263 <roth@feep.net>
264
3d398e04 26520001113
266 - (djm) Add pointer to http://www.imasy.or.jp/~gotoh/connect.c to
267 contrib/README
fa08c86b 268 - (djm) Merge OpenBSD changes:
269 - markus@cvs.openbsd.org 2000/11/06 16:04:56
270 [channels.c channels.h clientloop.c nchan.c serverloop.c]
271 [session.c ssh.c]
272 agent forwarding and -R for ssh2, based on work from
273 jhuuskon@messi.uku.fi
274 - markus@cvs.openbsd.org 2000/11/06 16:13:27
275 [ssh.c sshconnect.c sshd.c]
276 do not disabled rhosts(rsa) if server port > 1024; from
277 pekkas@netcore.fi
278 - markus@cvs.openbsd.org 2000/11/06 16:16:35
279 [sshconnect.c]
280 downgrade client to 1.3 if server is 1.4; help from mdb@juniper.net
281 - markus@cvs.openbsd.org 2000/11/09 18:04:40
282 [auth1.c]
283 typo; from mouring@pconline.com
284 - markus@cvs.openbsd.org 2000/11/12 12:03:28
285 [ssh-agent.c]
286 off-by-one when removing a key from the agent
287 - markus@cvs.openbsd.org 2000/11/12 12:50:39
288 [auth-rh-rsa.c auth2.c authfd.c authfd.h]
289 [authfile.c hostfile.c kex.c kex.h key.c key.h myproposal.h]
290 [readconf.c readconf.h rsa.c rsa.h servconf.c servconf.h ssh-add.c]
291 [ssh-agent.c ssh-keygen.1 ssh-keygen.c ssh.1 ssh.c ssh_config]
292 [sshconnect1.c sshconnect2.c sshd.8 sshd.c sshd_config ssh-dss.c]
293 [ssh-dss.h ssh-rsa.c ssh-rsa.h dsa.c dsa.h]
294 add support for RSA to SSH2. please test.
295 there are now 3 types of keys: RSA1 is used by ssh-1 only,
296 RSA and DSA are used by SSH2.
297 you can use 'ssh-keygen -t rsa -f ssh2_rsa_file' to generate RSA
298 keys for SSH2 and use the RSA keys for hostkeys or for user keys.
299 SSH2 RSA or DSA keys are added to .ssh/authorised_keys2 as before.
300 - (djm) Fix up Makefile and Redhat init script to create RSA host keys
f001465f 301 - (djm) Change to interim version
5733a41a 302 - (djm) Fix RPM spec file stupidity
6fff1ac4 303 - (djm) fixpaths to DSA and RSA keys too
3d398e04 304
d287c664 30520001112
306 - (bal) SCO Patch to add needed libraries for configure.in. Patch by
307 Phillips Porch <root@theporch.com>
3d398e04 308 - (bal) IRIX patch to adding Job Limits. Patch by Denis Parker
309 <dcp@sgi.com>
a3bf38d0 310 - (stevesk) pty.c: HP-UX 10 and 11 don't define TIOCSCTTY. Add error() to
311 failed ioctl(TIOCSCTTY) call.
d287c664 312
3c4d4fef 31320001111
314 - (djm) Added /etc/primes for kex DH group neg, fixup Makefile.in and
315 packaging files
35325fd4 316 - (djm) Fix new Makefile.in warnings
027bf205 317 - (djm) Fix vsprintf("%h") in bsd-snprintf.c, short int va_args are
318 promoted to type int. Report and fix from Dan Astoorian
319 <djast@cs.toronto.edu>
d287c664 320 - (djm) Hardwire sysconfdir in RPM spec files as some RPM versions get
e3291159 321 it wrong. Report from Bennett Todd <bet@rahul.net>
3c4d4fef 322
3e366738 32320001110
324 - (bal) Fixed dropped answer from skey_keyinfo() in auth1.c
325 - (bal) Changed from --with-skey to --with-skey=PATH in configure.in
326 - (bal) Added in check to verify S/Key library is being detected in
327 configure.in
328 - (bal) next-posix.h - added another prototype wrapped in POSIX ifdef/endif.
329 Patch by Mark Miller <markm@swoon.net>
330 - (bal) Added 'util.h' header to loginrec.c only if HAVE_UTIL_H is defined
331 to remove warnings under MacOS X. Patch by Mark Miller <markm@swoon.net>
332 - (bal) Fixed LDFLAG mispelling in configure.in for --with-afs
333
373998a4 33420001107
e506ee73 335 - (bal) acconfig.in - removed the double "USE_PIPES" entry. Patch by
336 Mark Miller <markm@swoon.net>
373998a4 337 - (bal) sshd.init files corrected to assign $? to RETVAL. Patch by
338 Jarno Huuskonen <jhuuskon@messi.uku.fi>
e506ee73 339 - (bal) fixpaths fixed to stop it from quitely failing. Patch by
340 Mark D. Roth <roth@feep.net>
373998a4 341
ac89998a 34220001106
343 - (djm) Use Jim's new 1.0.3 askpass in Redhat RPMs
6c09e23c 344 - (djm) Manually fix up missed diff hunks (mainly RCS idents)
d6846e6a 345 - (djm) Remove UPGRADING document in favour of a link to the better
346 maintained FAQ on www.openssh.com
73bd30fe 347 - (djm) Fix multiple dependancy on gnome-libs from Pekka Savola
348 <pekkas@netcore.fi>
349 - (djm) Don't need X11-askpass in RPM spec file if building without it
350 from Pekka Savola <pekkas@netcore.fi>
c215ba3b 351 - (djm) Release 2.3.0p1
97b378bf 352 - (bal) typo in configure.in in regards to --with-ldflags from Marko
353 Asplund <aspa@kronodoc.fi>
354 - (bal) fixed next-posix.h. Forgot prototype of getppid().
68f189a9 355
b850ecd9 35620001105
357 - (bal) Sync with OpenBSD:
358 - markus@cvs.openbsd.org 2000/10/31 9:31:58
359 [compat.c]
360 handle all old openssh versions
361 - markus@cvs.openbsd.org 2000/10/31 13:1853
362 [deattack.c]
363 so that large packets do not wrap "n"; from netbsd
364 - (bal) rijndel.c - fix up RCSID to match OpenBSD tree
a30ce26d 365 - (bal) auth2-skey.c - Checked in. Missing from portable tree.
366 - (bal) Reworked NEWS-OS and NeXT ports to extract waitpid() and
367 setsid() into more common files
96054e6f 368 - (stevesk) pty.c: use __hpux to identify HP-UX.
d0127657 369 - (bal) Missed auth-skey.o in Makefile.in and minor correction to
370 bsd-waitpid.c
b850ecd9 371
75b90ced 37220001029
373 - (stevesk) Fix typo in auth.c: USE_PAM not PAM
95273555 374 - (stevesk) Create contrib/cygwin/ directory; patch from
375 Corinna Vinschen <vinschen@redhat.com>
e9e4a1c7 376 - (bal) Resolved more $xno and $xyes issues in configure.in
fd5f0295 377 - (bal) next-posix.h - spelling and forgot a prototype
75b90ced 378
344f2b94 37920001028
380 - (djm) fix select hack in serverloop.c from Philippe WILLEM
381 <Philippe.WILLEM@urssaf.fr>
240ae474 382 - (djm) Fix mangled AIXAUTHENTICATE code
606ea390 383 - (djm) authctxt->pw may be NULL. Fix from Markus Friedl
384 <markus.friedl@informatik.uni-erlangen.de>
a22aff1f 385 - (djm) Sync with OpenBSD:
386 - markus@cvs.openbsd.org 2000/10/16 15:46:32
387 [ssh.1]
388 fixes from pekkas@netcore.fi
389 - markus@cvs.openbsd.org 2000/10/17 14:28:11
390 [atomicio.c]
391 return number of characters processed; ok deraadt@
392 - markus@cvs.openbsd.org 2000/10/18 12:04:02
393 [atomicio.c]
394 undo
395 - markus@cvs.openbsd.org 2000/10/18 12:23:02
396 [scp.c]
397 replace atomicio(read,...) with read(); ok deraadt@
398 - markus@cvs.openbsd.org 2000/10/18 12:42:00
399 [session.c]
400 restore old record login behaviour
401 - deraadt@cvs.openbsd.org 2000/10/19 10:41:13
402 [auth-skey.c]
403 fmt string problem in unused code
404 - provos@cvs.openbsd.org 2000/10/19 10:45:16
405 [sshconnect2.c]
406 don't reference freed memory. okay deraadt@
407 - markus@cvs.openbsd.org 2000/10/21 11:04:23
408 [canohost.c]
409 typo, eramore@era-t.ericsson.se; ok niels@
410 - markus@cvs.openbsd.org 2000/10/23 13:31:55
411 [cipher.c]
412 non-alignment dependent swap_bytes(); from
413 simonb@wasabisystems.com/netbsd
414 - markus@cvs.openbsd.org 2000/10/26 12:38:28
415 [compat.c]
416 add older vandyke products
417 - markus@cvs.openbsd.org 2000/10/27 01:32:19
418 [channels.c channels.h clientloop.c serverloop.c session.c]
419 [ssh.c util.c]
420 enable non-blocking IO on channels, and tty's (except for the
421 client ttys).
344f2b94 422
ddc49b5c 42320001027
424 - (djm) Increase REKEY_BYTES to 2^24 for arc4random
425
48e7916f 42620001025
427 - (djm) Added WARNING.RNG file and modified configure to ask users of the
428 builtin entropy code to read it.
429 - (djm) Prefer builtin regex to PCRE.
00937921 430 - (bal) Added USE_PIPS defined to NeXT configure.in since scp hangs randomly.
431 - (bal) Apply fixes to configure.in pointed out by Pavel Roskin
432 <proski@gnu.org>
48e7916f 433
8dcda1e3 43420001020
435 - (djm) Don't define _REENTRANT for SNI/Reliant Unix
07bee9a7 436 - (bal) Imported NEWS-OS waitpid() macros into NeXT. Since implementation
437 is more correct then current version.
8dcda1e3 438
f5af5cd5 43920001018
440 - (stevesk) Add initial support for setproctitle(). Current
441 support is for the HP-UX pstat(PSTAT_SETCMD, ...) method.
134fd7f6 442 - (stevesk) Add egd startup scripts to contrib/hpux/
f5af5cd5 443
2f31bdd6 44420001017
445 - (djm) Add -lregex to cywin libs from Corinna Vinschen
446 <vinschen@cygnus.com>
ba7a3f40 447 - (djm) Don't rely on atomicio's retval to determine length of askpass
448 supplied passphrase. Problem report from Lutz Jaenicke
449 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
66d6c27e 450 - (bal) Changed from GNU rx to PCRE on suggestion from djm.
451 - (bal) Integrated Sony NEWS-OS patches from NAKAJI Hirouyuki
452 <nakaji@tutrp.tut.ac.jp>
2f31bdd6 453
33de75a3 45420001016
455 - (djm) Sync with OpenBSD:
456 - markus@cvs.openbsd.org 2000/10/14 04:01:15
457 [cipher.c]
458 debug3
459 - markus@cvs.openbsd.org 2000/10/14 04:07:23
460 [scp.c]
461 remove spaces from arguments; from djm@mindrot.org
462 - markus@cvs.openbsd.org 2000/10/14 06:09:46
463 [ssh.1]
464 Cipher is for SSH-1 only
465 - markus@cvs.openbsd.org 2000/10/14 06:12:09
466 [servconf.c servconf.h serverloop.c session.c sshd.8]
467 AllowTcpForwarding; from naddy@
468 - markus@cvs.openbsd.org 2000/10/14 06:16:56
469 [auth2.c compat.c compat.h sshconnect2.c version.h]
470 OpenSSH_2.3; note that is is not complete, but the version number
471 needs to be changed for interoperability reasons
472 - markus@cvs.openbsd.org 2000/10/14 06:19:45
473 [auth-rsa.c]
474 do not send RSA challenge if key is not allowed by key-options; from
475 eivind@ThinkSec.com
476 - markus@cvs.openbsd.org 2000/10/15 08:14:01
477 [rijndael.c session.c]
478 typos; from stevesk@sweden.hp.com
479 - markus@cvs.openbsd.org 2000/10/15 08:18:31
480 [rijndael.c]
481 typo
30d8b039 482 - (djm) Copy manpages back over from OpenBSD - too tedious to wade
483 through diffs
aa0289fe 484 - (djm) Added condrestart to Redhat init script. Patch from Pekka Savola
30d8b039 485 <pekkas@netcore.fi>
aa0289fe 486 - (djm) Update version in Redhat spec file
487 - (djm) Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
488 Redhat 7.0 spec file
5b2d4b75 489 - (djm) Make inability to read/write PRNG seedfile non-fatal
490
33de75a3 491
4d670c24 49220001015
493 - (djm) Fix ssh2 hang on background processes at logout.
494
71dfaf1c 49520001014
443172c4 496 - (bal) Add support for realpath and getcwd for platforms with broken
497 or missing realpath implementations for sftp-server.
498 - (bal) Corrected mistake in INSTALL in regards to GNU rx library
d8f1edd5 499 - (bal) Add support for GNU rx library for those lacking regexp support
71dfaf1c 500 - (djm) Don't accept PAM_PROMPT_ECHO_ON messages during initial auth
02323c45 501 - (djm) Revert SSH2 serverloop hack, will find a better way.
4ee81249 502 - (djm) Add workaround for Linux 2.4's gratuitious errno change. Patch
503 from Martin Johansson <fatbob@acc.umu.se>
94ec8c6b 504 - (djm) Big OpenBSD sync:
505 - markus@cvs.openbsd.org 2000/09/30 10:27:44
506 [log.c]
507 allow loglevel debug
508 - markus@cvs.openbsd.org 2000/10/03 11:59:57
509 [packet.c]
510 hmac->mac
511 - markus@cvs.openbsd.org 2000/10/03 12:03:03
512 [auth-krb4.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth1.c]
513 move fake-auth from auth1.c to individual auth methods, disables s/key in
514 debug-msg
515 - markus@cvs.openbsd.org 2000/10/03 12:16:48
516 ssh.c
517 do not resolve canonname, i have no idea why this was added oin ossh
518 - markus@cvs.openbsd.org 2000/10/09 15:30:44
519 ssh-keygen.1 ssh-keygen.c
520 -X now reads private ssh.com DSA keys, too.
521 - markus@cvs.openbsd.org 2000/10/09 15:32:34
522 auth-options.c
523 clear options on every call.
524 - markus@cvs.openbsd.org 2000/10/09 15:51:00
525 authfd.c authfd.h
526 interop with ssh-agent2, from <res@shore.net>
527 - markus@cvs.openbsd.org 2000/10/10 14:20:45
528 compat.c
529 use rexexp for version string matching
530 - provos@cvs.openbsd.org 2000/10/10 22:02:18
531 [kex.c kex.h myproposal.h ssh.h ssh2.h sshconnect2.c sshd.c dh.c dh.h]
532 First rough implementation of the diffie-hellman group exchange. The
533 client can ask the server for bigger groups to perform the diffie-hellman
534 in, thus increasing the attack complexity when using ciphers with longer
535 keys. University of Windsor provided network, T the company.
536 - markus@cvs.openbsd.org 2000/10/11 13:59:52
537 [auth-rsa.c auth2.c]
538 clear auth options unless auth sucessfull
539 - markus@cvs.openbsd.org 2000/10/11 14:00:27
540 [auth-options.h]
541 clear auth options unless auth sucessfull
542 - markus@cvs.openbsd.org 2000/10/11 14:03:27
543 [scp.1 scp.c]
544 support 'scp -o' with help from mouring@pconline.com
545 - markus@cvs.openbsd.org 2000/10/11 14:11:35
546 [dh.c]
547 Wall
548 - markus@cvs.openbsd.org 2000/10/11 14:14:40
549 [auth.h auth2.c readconf.c readconf.h readpass.c servconf.c servconf.h]
550 [ssh.h sshconnect2.c sshd_config auth2-skey.c cli.c cli.h]
551 add support for s/key (kbd-interactive) to ssh2, based on work by
552 mkiernan@avantgo.com and me
553 - markus@cvs.openbsd.org 2000/10/11 14:27:24
554 [auth.c auth1.c auth2.c authfile.c cipher.c cipher.h kex.c kex.h]
555 [myproposal.h packet.c readconf.c session.c ssh.c ssh.h sshconnect1.c]
556 [sshconnect2.c sshd.c]
557 new cipher framework
558 - markus@cvs.openbsd.org 2000/10/11 14:45:21
559 [cipher.c]
560 remove DES
561 - markus@cvs.openbsd.org 2000/10/12 03:59:20
562 [cipher.c cipher.h sshconnect1.c sshconnect2.c sshd.c]
563 enable DES in SSH-1 clients only
564 - markus@cvs.openbsd.org 2000/10/12 08:21:13
565 [kex.h packet.c]
566 remove unused
567 - markus@cvs.openbsd.org 2000/10/13 12:34:46
568 [sshd.c]
569 Kludge for F-Secure Macintosh < 1.0.2; appro@fy.chalmers.se
570 - markus@cvs.openbsd.org 2000/10/13 12:59:15
571 [cipher.c cipher.h myproposal.h rijndael.c rijndael.h]
572 rijndael/aes support
573 - markus@cvs.openbsd.org 2000/10/13 13:10:54
574 [sshd.8]
575 more info about -V
576 - markus@cvs.openbsd.org 2000/10/13 13:12:02
577 [myproposal.h]
578 prefer no compression
3ed32516 579 - (djm) Fix scp user@host handling
580 - (djm) Don't clobber ssh_prng_cmds on install
6bcf7caa 581 - (stevesk) Include config.h in rijndael.c so we define intXX_t and
582 u_intXX_t types on all platforms.
9ea53ba5 583 - (stevesk) rijndael.c: cleanup missing declaration warnings.
2919e060 584 - (stevesk) ~/.hushlogin shouldn't cause required password change to
585 be bypassed.
f5665f6f 586 - (stevesk) Display correct path to ssh-askpass in configure output.
587 Report from Lutz Jaenicke.
71dfaf1c 588
ebd782f7 58920001007
590 - (stevesk) Print PAM return value in PAM log messages to aid
591 with debugging.
97994d32 592 - (stevesk) Fix detection of pw_class struct member in configure;
593 patch from KAMAHARA Junzo <kamahara@cc.kshosen.ac.jp>
594
47a134c1 59520001002
596 - (djm) Fix USER_PATH, report from Kevin Steves <stevesk@sweden.hp.com>
597 - (djm) Add host system and CC to end-of-configure report. Suggested by
598 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
599
7322ef0e 60020000931
601 - (djm) Cygwin fixes from Corinna Vinschen <vinschen@cygnus.com>
602
6ac7829a 60320000930
b6490dcb 604 - (djm) Irix ssh_prng_cmds path fix from Pekka Savola <pekkas@netcore.fi>
772bd898 605 - (djm) Support in bsd-snprintf.c for long long conversions from
606 Ben Lindstrom <mouring@pconline.com>
607 - (djm) Cleanup NeXT support from Ben Lindstrom <mouring@pconline.com>
857040fb 608 - (djm) Ignore SIGPIPEs from serverloop to child. Fixes crashes with
609 very short lived X connections. Bug report from Tobias Oetiker
610 <oetiker@ee.ethz.ch>. Fix from Markus Friedl <markus@cvs.openbsd.org>
bd2d7f6a 611 - (djm) Add recent InitScripts as a RPM dependancy for openssh-server
612 patch from Pekka Savola <pekkas@netcore.fi>
58665035 613 - (djm) Forgot to cvs add LICENSE file
dc2901a0 614 - (djm) Add LICENSE to RPM spec files
de273eef 615 - (djm) CVS OpenBSD sync:
616 - markus@cvs.openbsd.org 2000/09/26 13:59:59
617 [clientloop.c]
618 use debug2
619 - markus@cvs.openbsd.org 2000/09/27 15:41:34
620 [auth2.c sshconnect2.c]
621 use key_type()
622 - markus@cvs.openbsd.org 2000/09/28 12:03:18
623 [channels.c]
624 debug -> debug2 cleanup
2a7d529a 625 - (djm) Irix strips "/dev/tty" from [uw]tmp entries (other systems only
626 strip "/dev/"). Fix loginrec.c based on patch from Alain St-Denis
627 <Alain.St-Denis@ec.gc.ca>
628 - (djm) Fix 9 character passphrase failure with gnome-ssh-askpass.
629 Problem was caused by interrupted read in ssh-add. Report from Donald
630 J. Barry <don@astro.cornell.edu>
6ac7829a 631
c5d85828 63220000929
633 - (djm) Fix SSH2 not terminating until all background tasks done problem.
2ed85c06 634 - (djm) Another off-by-one fix from Pavel Kankovsky
635 <peak@argo.troja.mff.cuni.cz>
22d89d24 636 - (djm) Clean up. Strip some unnecessary differences with OpenBSD's code,
637 tidy necessary differences. Use Markus' new debugN() in entropy.c
77bb0bca 638 - (djm) Merged big SCO portability patch from Tim Rice
639 <tim@multitalents.net>
c5d85828 640
6fd7f731 64120000926
642 - (djm) Update X11-askpass to 1.0.2 in RPM spec file
c5ae7384 643 - (djm) Define _REENTRANT to pickup strtok_r() on HP/UX
644 - (djm) Security: fix off-by-one buffer overrun in fake-getnameinfo.c.
645 Report and fix from Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
6fd7f731 646
2f125ca1 64720000924
648 - (djm) Merged cleanup patch from Mark Miller <markm@swoon.net>
649 - (djm) A bit more cleanup - created cygwin_util.h
bcdaaeab 650 - (djm) Include strtok_r() from OpenBSD libc. Fixes report from Mark Miller
651 <markm@swoon.net>
2f125ca1 652
764d4113 65320000923
654 - (djm) Fix address logging in utmp from Kevin Steves
655 <stevesk@sweden.hp.com>
777319db 656 - (djm) Redhat spec and manpage fixes from Pekka Savola <pekkas@netcore.fi>
bd590612 657 - (djm) Seperate tests for int64_t and u_int64_t types
37c1c46d 658 - (djm) Tweak password expiry checking at suggestion of Kevin Steves
659 <stevesk@sweden.hp.com>
e79b44e1 660 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
e2144f11 661 - (djm) Use printf %lld instead of %qd in sftp-server.c. Fix from
662 Michael Stone <mstone@cs.loyola.edu>
188adeb2 663 - (djm) OpenBSD CVS sync:
664 - markus@cvs.openbsd.org 2000/09/17 09:38:59
665 [sshconnect2.c sshd.c]
666 fix DEBUG_KEXDH
667 - markus@cvs.openbsd.org 2000/09/17 09:52:51
668 [sshconnect.c]
669 yes no; ok niels@
670 - markus@cvs.openbsd.org 2000/09/21 04:55:11
671 [sshd.8]
672 typo
673 - markus@cvs.openbsd.org 2000/09/21 05:03:54
674 [serverloop.c]
675 typo
676 - markus@cvs.openbsd.org 2000/09/21 05:11:42
677 scp.c
678 utime() to utimes(); mouring@pconline.com
679 - markus@cvs.openbsd.org 2000/09/21 05:25:08
680 sshconnect2.c
681 change login logic in ssh2, allows plugin of other auth methods
682 - markus@cvs.openbsd.org 2000/09/21 05:25:35
683 [auth2.c channels.c channels.h clientloop.c dispatch.c dispatch.h]
684 [serverloop.c]
685 add context to dispatch_run
686 - markus@cvs.openbsd.org 2000/09/21 05:07:52
687 authfd.c authfd.h ssh-agent.c
688 bug compat for old ssh.com software
764d4113 689
7f377177 69020000920
691 - (djm) Fix bad path substitution. Report from Andrew Miner
692 <asminer@cs.iastate.edu>
693
bcbf86ec 69420000916
7950bf97 695 - (djm) Fix SSL search order from Lutz Jaenicke
696 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
19ece6d2 697 - (djm) New SuSE spec from Corinna Vinschen <corinna@vinschen.de>
9cd45ea4 698 - (djm) Update CygWin support from Corinna Vinschen <vinschen@cygnus.com>
995edaac 699 - (djm) Use a real struct sockaddr inside the fake struct sockaddr_storage.
700 Patch from Larry Jones <larry.jones@sdrc.com>
ad55cd03 701 - (djm) Add Steve VanDevender's <stevev@darkwing.uoregon.edu> PAM
702 password change patch.
703 - (djm) Bring licenses on my stuff in line with OpenBSD's
0bbfbdeb 704 - (djm) Cleanup auth-passwd.c and unify HP/UX authentication. Patch from
705 Kevin Steves <stevesk@sweden.hp.com>
7f8f5e00 706 - (djm) Shadow expiry check fix from Pavel Troller <patrol@omni.sinus.cz>
707 - (djm) Re-enable int64_t types - we need them for sftp
708 - (djm) Use libexecdir from configure , rather than libexecdir/ssh
709 - (djm) Update Redhat SPEC file accordingly
710 - (djm) Add Kevin Steves <stevesk@sweden.hp.com> HP/UX contrib files
711 - (djm) Add Charles Levert <charles@comm.polymtl.ca> getpgrp patch
712 - (djm) Fix password auth on HP/UX 10.20. Patch from Dirk De Wachter
713 <Dirk.DeWachter@rug.ac.be>
714 - (djm) Fixprogs and entropy list fixes from Larry Jones
715 <larry.jones@sdrc.com>
716 - (djm) Fix for SuSE spec file from Takashi YOSHIDA
717 <tyoshida@gemini.rc.kyushu-u.ac.jp>
bcbf86ec 718 - (djm) Merge OpenBSD changes:
719 - markus@cvs.openbsd.org 2000/09/05 02:59:57
720 [session.c]
721 print hostname (not hushlogin)
722 - markus@cvs.openbsd.org 2000/09/05 13:18:48
723 [authfile.c ssh-add.c]
724 enable ssh-add -d for DSA keys
725 - markus@cvs.openbsd.org 2000/09/05 13:20:49
726 [sftp-server.c]
727 cleanup
728 - markus@cvs.openbsd.org 2000/09/06 03:46:41
729 [authfile.h]
730 prototype
731 - deraadt@cvs.openbsd.org 2000/09/07 14:27:56
732 [ALL]
733 cleanup copyright notices on all files. I have attempted to be
734 accurate with the details. everything is now under Tatu's licence
735 (which I copied from his readme), and/or the core-sdi bsd-ish thing
736 for deattack, or various openbsd developers under a 2-term bsd
737 licence. We're not changing any rules, just being accurate.
738 - markus@cvs.openbsd.org 2000/09/07 14:40:30
739 [channels.c channels.h clientloop.c serverloop.c ssh.c]
740 cleanup window and packet sizes for ssh2 flow control; ok niels
741 - markus@cvs.openbsd.org 2000/09/07 14:53:00
742 [scp.c]
743 typo
744 - markus@cvs.openbsd.org 2000/09/07 15:13:37
745 [auth-options.c auth-options.h auth-rh-rsa.c auth-rsa.c auth.c]
746 [authfile.h canohost.c channels.h compat.c hostfile.h log.c match.h]
747 [pty.c readconf.c]
748 some more Copyright fixes
749 - markus@cvs.openbsd.org 2000/09/08 03:02:51
750 [README.openssh2]
751 bye bye
752 - deraadt@cvs.openbsd.org 2000/09/11 18:38:33
753 [LICENCE cipher.c]
754 a few more comments about it being ARC4 not RC4
755 - markus@cvs.openbsd.org 2000/09/12 14:53:11
756 [log-client.c log-server.c log.c ssh.1 ssh.c ssh.h sshd.8 sshd.c]
757 multiple debug levels
758 - markus@cvs.openbsd.org 2000/09/14 14:25:15
759 [clientloop.c]
760 typo
761 - deraadt@cvs.openbsd.org 2000/09/15 01:13:51
762 [ssh-agent.c]
763 check return value for setenv(3) for failure, and deal appropriately
764
deb8d717 76520000913
766 - (djm) Fix server not exiting with jobs in background.
767
b5e300c2 76820000905
769 - (djm) Import OpenBSD CVS changes
770 - markus@cvs.openbsd.org 2000/08/31 15:52:24
771 [Makefile sshd.8 sshd_config sftp-server.8 sftp-server.c]
772 implement a SFTP server. interops with sftp2, scp2 and the windows
773 client from ssh.com
774 - markus@cvs.openbsd.org 2000/08/31 15:56:03
775 [README.openssh2]
776 sync
777 - markus@cvs.openbsd.org 2000/08/31 16:05:42
778 [session.c]
779 Wall
780 - markus@cvs.openbsd.org 2000/08/31 16:09:34
781 [authfd.c ssh-agent.c]
782 add a flag to SSH2_AGENTC_SIGN_REQUEST for future extensions
783 - deraadt@cvs.openbsd.org 2000/09/01 09:25:13
784 [scp.1 scp.c]
785 cleanup and fix -S support; stevesk@sweden.hp.com
786 - markus@cvs.openbsd.org 2000/09/01 16:29:32
787 [sftp-server.c]
788 portability fixes
789 - markus@cvs.openbsd.org 2000/09/01 16:32:41
790 [sftp-server.c]
791 fix cast; mouring@pconline.com
792 - itojun@cvs.openbsd.org 2000/09/03 09:23:28
793 [ssh-add.1 ssh.1]
794 add missing .El against .Bl.
795 - markus@cvs.openbsd.org 2000/09/04 13:03:41
796 [session.c]
797 missing close; ok theo
798 - markus@cvs.openbsd.org 2000/09/04 13:07:21
799 [session.c]
800 fix get_last_login_time order; from andre@van-veen.de
801 - markus@cvs.openbsd.org 2000/09/04 13:10:09
802 [sftp-server.c]
803 more cast fixes; from mouring@pconline.com
804 - markus@cvs.openbsd.org 2000/09/04 13:06:04
805 [session.c]
806 set SSH_ORIGINAL_COMMAND; from Leakin@dfw.nostrum.com, bet@rahul.net
807 - (djm) Cleanup after import. Fix sftp-server compilation, Makefile
3c62e7eb 808 - (djm) Merge cygwin support from Corinna Vinschen <vinschen@cygnus.com>
809
1e61f54a 81020000903
811 - (djm) Fix Redhat init script
812
c80876b4 81320000901
814 - (djm) Pick up Jim's new X11-askpass
815 - (djm) Release 2.2.0p1
816
8b4a0d08 81720000831
bcbf86ec 818 - (djm) Workaround SIGPIPE problems on SCO. Fix from Aran Cox
8b4a0d08 819 <acox@cv.telegroup.com>
b817711d 820 - (djm) Pick up new version (2.2.0) from OpenBSD CVS
8b4a0d08 821
0b65b628 82220000830
823 - (djm) Compile warning fixes from Mark Miller <markm@swoon.net>
10fa00c8 824 - (djm) Periodically rekey arc4random
825 - (djm) Clean up diff against OpenBSD.
bcbf86ec 826 - (djm) HPUX 11 needs USE_PIPES as well: Kevin Steves
2b10f47a 827 <stevesk@sweden.hp.com>
b33a2e6e 828 - (djm) Quieten the pam delete credentials error message
44839801 829 - (djm) Fix printing of $DISPLAY hack if set by system type. Report from
830 Kevin Steves <stevesk@sweden.hp.com>
84a770d1 831 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
7efa2776 832 - (djm) Fix doh in bsd-arc4random.c
0b65b628 833
9aaf9be4 83420000829
bcbf86ec 835 - (djm) Fix ^C ignored issue on Solaris. Diagnosis from Gert
836 Doering <gert@greenie.muc.de>, John Horne <J.Horne@plymouth.ac.uk> and
9aaf9be4 837 Garrick James <garrick@james.net>
b5f90139 838 - (djm) Check for SCO pty naming style (ptyp%d/ttyp%d). Based on fix from
839 Bastian Trompetter <btrompetter@firemail.de>
698d107e 840 - (djm) NeXT tweaks from Ben Lindstrom <mouring@pconline.com>
14a9a859 841 - More OpenBSD updates:
842 - deraadt@cvs.openbsd.org 2000/08/24 15:46:59
843 [scp.c]
844 off_t in sink, to fix files > 2GB, i think, test is still running ;-)
845 - deraadt@cvs.openbsd.org 2000/08/25 10:10:06
846 [session.c]
847 Wall
848 - markus@cvs.openbsd.org 2000/08/26 04:33:43
849 [compat.c]
850 ssh.com-2.3.0
851 - markus@cvs.openbsd.org 2000/08/27 12:18:05
852 [compat.c]
853 compatibility with future ssh.com versions
854 - deraadt@cvs.openbsd.org 2000/08/27 21:50:55
855 [auth-krb4.c session.c ssh-add.c sshconnect.c uidswap.c]
856 print uid/gid as unsigned
857 - markus@cvs.openbsd.org 2000/08/28 13:51:00
858 [ssh.c]
859 enable -n and -f for ssh2
860 - markus@cvs.openbsd.org 2000/08/28 14:19:53
861 [ssh.c]
862 allow combination of -N and -f
863 - markus@cvs.openbsd.org 2000/08/28 14:20:56
864 [util.c]
865 util.c
866 - markus@cvs.openbsd.org 2000/08/28 14:22:02
867 [util.c]
868 undo
869 - markus@cvs.openbsd.org 2000/08/28 14:23:38
870 [util.c]
871 don't complain if setting NONBLOCK fails with ENODEV
9aaf9be4 872
137d7b6c 87320000823
874 - (djm) Define USE_PIPES to avoid socketpair problems on HPUX 10 and SunOS 4
bcbf86ec 875 Avoids "scp never exits" problem. Reports from Lutz Jaenicke
876 <Lutz.Jaenicke@aet.TU-Cottbus.DE> and Tamito KAJIYAMA
137d7b6c 877 <kajiyama@grad.sccs.chukyo-u.ac.jp>
2e73a022 878 - (djm) Pick up LOGIN_PROGRAM from environment or PATH if not set by headers
da40ab4d 879 - (djm) Add local version to version.h
ea788c22 880 - (djm) Don't reseed arc4random everytime it is used
2e73a022 881 - (djm) OpenBSD CVS updates:
882 - deraadt@cvs.openbsd.org 2000/08/18 20:07:23
883 [ssh.c]
884 accept remsh as a valid name as well; roman@buildpoint.com
885 - deraadt@cvs.openbsd.org 2000/08/18 20:17:13
886 [deattack.c crc32.c packet.c]
887 rename crc32() to ssh_crc32() to avoid zlib name clash. do not move to
888 libz crc32 function yet, because it has ugly "long"'s in it;
889 oneill@cs.sfu.ca
890 - deraadt@cvs.openbsd.org 2000/08/18 20:26:08
891 [scp.1 scp.c]
892 -S prog support; tv@debian.org
893 - deraadt@cvs.openbsd.org 2000/08/18 20:50:07
894 [scp.c]
895 knf
896 - deraadt@cvs.openbsd.org 2000/08/18 20:57:33
897 [log-client.c]
898 shorten
899 - markus@cvs.openbsd.org 2000/08/19 12:48:11
900 [channels.c channels.h clientloop.c ssh.c ssh.h]
901 support for ~. in ssh2
902 - deraadt@cvs.openbsd.org 2000/08/19 15:29:40
903 [crc32.h]
904 proper prototype
905 - markus@cvs.openbsd.org 2000/08/19 15:34:44
bcbf86ec 906 [authfd.c authfd.h key.c key.h ssh-add.1 ssh-add.c ssh-agent.1]
907 [ssh-agent.c ssh-keygen.c sshconnect1.c sshconnect2.c Makefile]
2e73a022 908 [fingerprint.c fingerprint.h]
909 add SSH2/DSA support to the agent and some other DSA related cleanups.
910 (note that we cannot talk to ssh.com's ssh2 agents)
911 - markus@cvs.openbsd.org 2000/08/19 15:55:52
912 [channels.c channels.h clientloop.c]
913 more ~ support for ssh2
914 - markus@cvs.openbsd.org 2000/08/19 16:21:19
915 [clientloop.c]
916 oops
917 - millert@cvs.openbsd.org 2000/08/20 12:25:53
918 [session.c]
919 We have to stash the result of get_remote_name_or_ip() before we
920 close our socket or getpeername() will get EBADF and the process
921 will exit. Only a problem for "UseLogin yes".
922 - millert@cvs.openbsd.org 2000/08/20 12:30:59
923 [session.c]
924 Only check /etc/nologin if "UseLogin no" since login(1) may have its
925 own policy on determining who is allowed to login when /etc/nologin
926 is present. Also use the _PATH_NOLOGIN define.
927 - millert@cvs.openbsd.org 2000/08/20 12:42:43
928 [auth1.c auth2.c session.c ssh.c]
929 Add calls to setusercontext() and login_get*(). We basically call
930 setusercontext() in most places where previously we did a setlogin().
931 Add default login.conf file and put root in the "daemon" login class.
932 - millert@cvs.openbsd.org 2000/08/21 10:23:31
933 [session.c]
934 Fix incorrect PATH setting; noted by Markus.
137d7b6c 935
c345cf9d 93620000818
937 - (djm) OpenBSD CVS changes:
938 - markus@cvs.openbsd.org 2000/07/22 03:14:37
939 [servconf.c servconf.h sshd.8 sshd.c sshd_config]
940 random early drop; ok theo, niels
941 - deraadt@cvs.openbsd.org 2000/07/26 11:46:51
942 [ssh.1]
943 typo
944 - deraadt@cvs.openbsd.org 2000/08/01 11:46:11
945 [sshd.8]
946 many fixes from pepper@mail.reppep.com
947 - provos@cvs.openbsd.org 2000/08/01 13:01:42
948 [Makefile.in util.c aux.c]
949 rename aux.c to util.c to help with cygwin port
950 - deraadt@cvs.openbsd.org 2000/08/02 00:23:31
951 [authfd.c]
952 correct sun_len; Alexander@Leidinger.net
953 - provos@cvs.openbsd.org 2000/08/02 10:27:17
954 [readconf.c sshd.8]
955 disable kerberos authentication by default
956 - provos@cvs.openbsd.org 2000/08/02 11:27:05
957 [sshd.8 readconf.c auth-krb4.c]
958 disallow kerberos authentication if we can't verify the TGT; from
959 dugsong@
960 kerberos authentication is on by default only if you have a srvtab.
961 - markus@cvs.openbsd.org 2000/08/04 14:30:07
962 [auth.c]
963 unused
964 - markus@cvs.openbsd.org 2000/08/04 14:30:35
965 [sshd_config]
966 MaxStartups
967 - markus@cvs.openbsd.org 2000/08/15 13:20:46
968 [authfd.c]
969 cleanup; ok niels@
970 - markus@cvs.openbsd.org 2000/08/17 14:05:10
971 [session.c]
972 cleanup login(1)-like jobs, no duplicate utmp entries
973 - markus@cvs.openbsd.org 2000/08/17 14:06:34
974 [session.c sshd.8 sshd.c]
975 sshd -u len, similar to telnetd
1a022229 976 - (djm) Lastlog was not getting closed after writing login entry
39987cc0 977 - (djm) Add Solaris package support from Rip Loomis <loomisg@cist.saic.com>
c345cf9d 978
416ed5a7 97920000816
980 - (djm) Replacement for inet_ntoa for Irix (which breaks on gcc)
bcbf86ec 981 - (djm) Fix strerror replacement for old SunOS. Based on patch from
416ed5a7 982 Charles Levert <charles@comm.polymtl.ca>
bcbf86ec 983 - (djm) Seperate arc4random into seperate file and use OpenSSL's RC4
416ed5a7 984 implementation.
ba606eb2 985 - (djm) SUN_LEN macro for systems which lack it
416ed5a7 986
dbaa2e87 98720000815
988 - (djm) More SunOS 4.1.x fixes from Nate Itkin <nitkin@europa.com>
cd352c82 989 - (djm) Avoid failures on Irix when ssh is not setuid. Fix from
990 Michael Stone <mstone@cs.loyola.edu>
d93a7e5a 991 - (djm) Don't seek in directory based lastlogs
bcbf86ec 992 - (djm) Fix --with-ipaddr-display configure option test. Patch from
d93a7e5a 993 Jarno Huuskonen <jhuuskon@messi.uku.fi>
2a2cb9e7 994 - (djm) Fix AIX limits from Alexandre Oliva <oliva@lsd.ic.unicamp.br>
dbaa2e87 995
6c33bf70 99620000813
997 - (djm) Add $(srcdir) to includes when compiling (for VPATH). Report from
998 Fabrice bacchella <fabrice.bacchella@marchfirst.fr>
999
3fcce26c 100020000809
bcbf86ec 1001 - (djm) Define AIX hard limits if headers don't. Report from
3fcce26c 1002 Bill Painter <william.t.painter@lmco.com>
bcbf86ec 1003 - (djm) utmp direct write & SunOS 4 patch from Charles Levert
32eec038 1004 <charles@comm.polymtl.ca>
3fcce26c 1005
71d43804 100620000808
1007 - (djm) Cleanup Redhat RPMs. Generate keys at runtime rather than install
1008 time, spec file cleanup.
1009
f9bcea07 101020000807
378f2232 1011 - (djm) Set 0755 on binaries during install. Report from Lutz Jaenicke
47670e77 1012 - (djm) Suppress error messages on channel close shutdown() failurs
1013 works around Linux bug. Patch from Zack Weinberg <zack@wolery.cumb.org>
378f2232 1014 - (djm) Add some more entropy collection commands from Lutz Jaenicke
f9bcea07 1015
bcf89935 101620000725
1017 - (djm) Fix autoconf typo: HAVE_BINRESVPORT_AF -> HAVE_BINDRESVPORT_AF
1018
4c8722d9 101920000721
1020 - (djm) OpenBSD CVS updates:
1021 - markus@cvs.openbsd.org 2000/07/16 02:27:22
1022 [authfd.c authfd.h channels.c clientloop.c ssh-add.c ssh-agent.c ssh.c]
1023 [sshconnect1.c sshconnect2.c]
1024 make ssh-add accept dsa keys (the agent does not)
1025 - djm@cvs.openbsd.org 2000/07/17 19:25:02
1026 [sshd.c]
1027 Another closing of stdin; ok deraadt
1028 - markus@cvs.openbsd.org 2000/07/19 18:33:12
1029 [dsa.c]
1030 missing free, reorder
1031 - markus@cvs.openbsd.org 2000/07/20 16:23:14
1032 [ssh-keygen.1]
1033 document input and output files
1034
240777b8 103520000720
4c8722d9 1036 - (djm) Spec file fix from Petr Novotny <Petr.Novotny@antek.cz>
240777b8 1037
3c7def32 103820000716
4c8722d9 1039 - (djm) Release 2.1.1p4
3c7def32 1040
819b676f 104120000715
704b1659 1042 - (djm) OpenBSD CVS updates
1043 - provos@cvs.openbsd.org 2000/07/13 16:53:22
1044 [aux.c readconf.c servconf.c ssh.h]
1045 allow multiple whitespace but only one '=' between tokens, bug report from
1046 Ralf S. Engelschall <rse@engelschall.com> but different fix. okay deraadt@
1047 - provos@cvs.openbsd.org 2000/07/13 17:14:09
1048 [clientloop.c]
1049 typo; todd@fries.net
1050 - provos@cvs.openbsd.org 2000/07/13 17:19:31
1051 [scp.c]
1052 close can fail on AFS, report error; from Greg Hudson <ghudson@mit.edu>
1053 - markus@cvs.openbsd.org 2000/07/14 16:59:46
1054 [readconf.c servconf.c]
1055 allow leading whitespace. ok niels
1056 - djm@cvs.openbsd.org 2000/07/14 22:01:38
1057 [ssh-keygen.c ssh.c]
1058 Always create ~/.ssh with mode 700; ok Markus
819b676f 1059 - Fixes for SunOS 4.1.4 from Gordon Atwood <gordon@cs.ualberta.ca>
1060 - Include floatingpoint.h for entropy.c
1061 - strerror replacement
704b1659 1062
3f7a7e4a 106320000712
c37fb3c1 1064 - (djm) Remove -lresolve for Reliant Unix
3f7a7e4a 1065 - (djm) OpenBSD CVS Updates:
1066 - deraadt@cvs.openbsd.org 2000/07/11 02:11:34
1067 [session.c sshd.c ]
1068 make MaxStartups code still work with -d; djm
1069 - deraadt@cvs.openbsd.org 2000/07/11 13:17:45
1070 [readconf.c ssh_config]
1071 disable FallBackToRsh by default
c37fb3c1 1072 - (djm) Replace in_addr_t with u_int32_t in bsd-inet_aton.c. Report from
1073 Ben Lindstrom <mouring@pconline.com>
1e970014 1074 - (djm) Make building of X11-Askpass and GNOME-Askpass optional in RPM
1075 spec file.
dcb36e5d 1076 - (djm) Released 2.1.1p3
3f7a7e4a 1077
56118702 107820000711
1079 - (djm) Fixup for AIX getuserattr() support from Tom Bertelson
1080 <tbert@abac.com>
132dd316 1081 - (djm) ReliantUNIX support from Udo Schweigert <ust@cert.siemens.de>
bcbf86ec 1082 - (djm) NeXT: dirent structures to get scp working from Ben Lindstrom
c99e5056 1083 <mouring@pconline.com>
bcbf86ec 1084 - (djm) Fix broken inet_ntoa check and ut_user/ut_name confusion, report
dc2a6d09 1085 from Jim Watt <jimw@peisj.pebio.com>
2d9a148e 1086 - (djm) Replaced bsd-snprintf.c with one from Mutt source tree, it is known
1087 to compile on more platforms (incl NeXT).
cc6f2c4c 1088 - (djm) Added bsd-inet_aton and configure support for NeXT
aae19451 1089 - (djm) Misc NeXT fixes from Ben Lindstrom <mouring@pconline.com>
089fbbd2 1090 - (djm) OpenBSD CVS updates:
1091 - markus@cvs.openbsd.org 2000/06/26 03:22:29
1092 [authfd.c]
1093 cleanup, less cut&paste
1094 - markus@cvs.openbsd.org 2000/06/26 15:59:19
1095 [servconf.c servconf.h session.c sshd.8 sshd.c]
bcbf86ec 1096 MaxStartups: limit number of unauthenticated connections, work by
089fbbd2 1097 theo and me
1098 - deraadt@cvs.openbsd.org 2000/07/05 14:18:07
1099 [session.c]
1100 use no_x11_forwarding_flag correctly; provos ok
1101 - provos@cvs.openbsd.org 2000/07/05 15:35:57
1102 [sshd.c]
1103 typo
1104 - aaron@cvs.openbsd.org 2000/07/05 22:06:58
1105 [scp.1 ssh-agent.1 ssh-keygen.1 sshd.8]
bcbf86ec 1106 Insert more missing .El directives. Our troff really should identify
089fbbd2 1107 these and spit out a warning.
1108 - todd@cvs.openbsd.org 2000/07/06 21:55:04
1109 [auth-rsa.c auth2.c ssh-keygen.c]
1110 clean code is good code
1111 - deraadt@cvs.openbsd.org 2000/07/07 02:14:29
1112 [serverloop.c]
1113 sense of port forwarding flag test was backwards
1114 - provos@cvs.openbsd.org 2000/07/08 17:17:31
1115 [compat.c readconf.c]
1116 replace strtok with strsep; from David Young <dyoung@onthejob.net>
1117 - deraadt@cvs.openbsd.org 2000/07/08 19:21:15
1118 [auth.h]
1119 KNF
1120 - ho@cvs.openbsd.org 2000/07/08 19:27:33
1121 [compat.c readconf.c]
1122 Better conditions for strsep() ending.
1123 - ho@cvs.openbsd.org 2000/07/10 10:27:05
1124 [readconf.c]
1125 Get the correct message on errors. (niels@ ok)
1126 - ho@cvs.openbsd.org 2000/07/10 10:30:25
1127 [cipher.c kex.c servconf.c]
1128 strtok() --> strsep(). (niels@ ok)
5540ea9b 1129 - (djm) Fix problem with debug mode and MaxStartups
eb37534b 1130 - (djm) Don't generate host keys when $(DESTDIR) is set (e.g. during RPM
1131 builds)
229f64ee 1132 - (djm) Add strsep function from OpenBSD libc for systems that lack it
56118702 1133
a8545c6c 113420000709
1135 - (djm) Only enable PAM_TTY kludge for Linux. Problem report from
1136 Kevin Steves <stevesk@sweden.hp.com>
ec90a7d6 1137 - (djm) Match prototype and function declaration for rresvport_af.
1138 Problem report from Niklas Edmundsson <nikke@ing.umu.se>
bcbf86ec 1139 - (djm) Missing $(DESTDIR) on host-key target causing problems with RPM
732e8ac5 1140 builds. Problem report from Gregory Leblanc <GLeblanc@cu-portland.edu>
37f1df94 1141 - (djm) Replace ut_name with ut_user. Patch from Jim Watt
1142 <jimw@peisj.pebio.com>
264dce47 1143 - (djm) Fix pam sprintf fix
1144 - (djm) Cleanup entropy collection code a little more. Split initialisation
1145 from seeding, perform intialisation immediatly at start, be careful with
1146 uids. Based on problem report from Jim Watt <jimw@peisj.pebio.com>
5bf9cfe9 1147 - (djm) More NeXT compatibility from Ben Lindstrom <mouring@pconline.com>
1148 Including sigaction() et al. replacements
bcbf86ec 1149 - (djm) AIX getuserattr() session initialisation from Tom Bertelson
eeec075f 1150 <tbert@abac.com>
a8545c6c 1151
e2902a5b 115220000708
bcbf86ec 1153 - (djm) Fix bad fprintf format handling in auth-pam.c. Patch from
e2902a5b 1154 Aaron Hopkins <aaron@die.net>
7a33f831 1155 - (djm) Fix incorrect configure handling of --with-rsh-path option. Fix from
1156 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 1157 - (djm) Fixed undefined variables for OSF SIA. Report from
b3f162ba 1158 Baars, Henk <Hendrik.Baars@nl.origin-it.com>
bcbf86ec 1159 - (djm) Handle EWOULDBLOCK returns from read() and write() in atomicio.c
b28e4a3b 1160 Fix from Marquess, Steve Mr JMLFDC <Steve.Marquess@DET.AMEDD.ARMY.MIL>
bcbf86ec 1161 - (djm) Don't use inet_addr.
e2902a5b 1162
5637650d 116320000702
1164 - (djm) Fix brace mismatch from Corinna Vinschen <vinschen@cygnus.com>
27494968 1165 - (djm) Stop shadow expiry checking from preventing logins with NIS. Based
1166 on fix from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
a4070484 1167 - (djm) Use standard OpenSSL functions in auth-skey.c. Patch from
1168 Chris, the Young One <cky@pobox.com>
bcbf86ec 1169 - (djm) Fix scp progress meter on really wide terminals. Based on patch
88726b31 1170 from James H. Cloos Jr. <cloos@jhcloos.com>
5637650d 1171
388e9f9f 117220000701
1173 - (djm) Fix Tru64 SIA problems reported by John P Speno <speno@isc.upenn.edu>
daaff4d5 1174 - (djm) Login fixes from Tom Bertelson <tbert@abac.com>
82258d68 1175 - (djm) Replace "/bin/sh" with _PATH_BSHELL. Report from Corinna Vinschen
1176 <vinschen@cygnus.com>
30228d7c 1177 - (djm) Replace "/usr/bin/login" with LOGIN_PROGRAM
2647ae26 1178 - (djm) Added check for broken snprintf() functions which do not correctly
1179 terminate output string and attempt to use replacement.
46158300 1180 - (djm) Released 2.1.1p2
388e9f9f 1181
9f32ceb4 118220000628
1183 - (djm) Fixes to lastlog code for Irix
1184 - (djm) Use atomicio in loginrec
3206bb3b 1185 - (djm) Patch from Michael Stone <mstone@cs.loyola.edu> to add support for
1186 Irix 6.x array sessions, project id's, and system audit trail id.
9e0c3e1f 1187 - (djm) Added 'distprep' make target to simplify packaging
bcbf86ec 1188 - (djm) Added patch from Chris Adams <cmadams@hiwaay.net> to add OSF SIA
4d33e531 1189 support. Enable using "USE_SIA=1 ./configure [options]"
bcbf86ec 1190
d8caae24 119120000627
1192 - (djm) Fixes to login code - not setting li->uid, cleanups
a05a70ab 1193 - (djm) Formatting
d8caae24 1194
fe30cc2e 119520000626
3e98362e 1196 - (djm) Better fix to aclocal tests from Garrick James <garrick@james.net>
4cb5ffa0 1197 - (djm) Account expiry support from Andreas Steinmetz <ast@domdv.de>
1198 - (djm) Added password expiry checking (no password change support)
be0b9bb7 1199 - (djm) Make EGD failures non-fatal if OpenSSL's entropy pool is still OK
1200 based on patch from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
b5b3f75d 1201 - (djm) Fix fixed EGD code.
3e98362e 1202 - OpenBSD CVS update
1203 - provos@cvs.openbsd.org 2000/06/25 14:17:58
1204 [channels.c]
1205 correct check for bad channel ids; from Wei Dai <weidai@eskimo.com>
1206
1c04b088 120720000623
bcbf86ec 1208 - (djm) Use sa_family_t in prototype for rresvport_af. Patch from
1c04b088 1209 Svante Signell <svante.signell@telia.com>
1210 - (djm) Autoconf logic to define sa_family_t if it is missing
e5a0294f 1211 - OpenBSD CVS Updates:
1212 - markus@cvs.openbsd.org 2000/06/22 10:32:27
1213 [sshd.c]
1214 missing atomicio; report from Steve.Marquess@DET.AMEDD.ARMY.MIL
1215 - djm@cvs.openbsd.org 2000/06/22 17:55:00
1216 [auth-krb4.c key.c radix.c uuencode.c]
1217 Missing CVS idents; ok markus
1c04b088 1218
f528fdf2 121920000622
1220 - (djm) Automatically generate host key during "make install". Suggested
1221 by Gary E. Miller <gem@rellim.com>
1222 - (djm) Paranoia before kill() system call
74fc9186 1223 - OpenBSD CVS Updates:
1224 - markus@cvs.openbsd.org 2000/06/18 18:50:11
1225 [auth2.c compat.c compat.h sshconnect2.c]
1226 make userauth+pubkey interop with ssh.com-2.2.0
1227 - markus@cvs.openbsd.org 2000/06/18 20:56:17
1228 [dsa.c]
1229 mem leak + be more paranoid in dsa_verify.
1230 - markus@cvs.openbsd.org 2000/06/18 21:29:50
1231 [key.c]
1232 cleanup fingerprinting, less hardcoded sizes
1233 - markus@cvs.openbsd.org 2000/06/19 19:39:45
1234 [atomicio.c auth-options.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c]
1235 [auth-rsa.c auth-skey.c authfd.c authfd.h authfile.c bufaux.c bufaux.h]
bcbf86ec 1236 [buffer.c buffer.h canohost.c channels.c channels.h cipher.c cipher.h]
74fc9186 1237 [clientloop.c compat.c compat.h compress.c compress.h crc32.c crc32.h]
1238 [deattack.c dispatch.c dsa.c fingerprint.c fingerprint.h getput.h hmac.c]
bcbf86ec 1239 [kex.c log-client.c log-server.c login.c match.c mpaux.c mpaux.h nchan.c]
1240 [nchan.h packet.c packet.h pty.c pty.h readconf.c readconf.h readpass.c]
74fc9186 1241 [rsa.c rsa.h scp.c servconf.c servconf.h ssh-add.c ssh-keygen.c ssh.c]
1242 [ssh.h tildexpand.c ttymodes.c ttymodes.h uidswap.c xmalloc.c xmalloc.h]
1243 OpenBSD tag
1244 - markus@cvs.openbsd.org 2000/06/21 10:46:10
1245 sshconnect2.c missing free; nuke old comment
f528fdf2 1246
e5fe9a1f 124720000620
1248 - (djm) Replace use of '-o' and '-a' logical operators in configure tests
bcbf86ec 1249 with '||' and '&&'. As suggested by Jim Knoble <jmknoble@pint-stowp.cx>
e5fe9a1f 1250 to fix SCO Unixware problem reported by Gary E. Miller <gem@rellim.com>
c03aced4 1251 - (djm) Typo in loginrec.c
e5fe9a1f 1252
cbd7492e 125320000618
1254 - (djm) Add summary of configure options to end of ./configure run
bcbf86ec 1255 - (djm) Not all systems define RUSAGE_SELF & RUSAGE_CHILDREN. Report from
cbd7492e 1256 Michael Stone <mstone@cs.loyola.edu>
bcbf86ec 1257 - (djm) rusage is a privileged operation on some Unices (incl.
cbd7492e 1258 Solaris 2.5.1). Report from Paul D. Smith <pausmith@nortelnetworks.com>
bcbf86ec 1259 - (djm) Avoid PAM failures when running without a TTY. Report from
cbd7492e 1260 Martin Petrak <petrak@spsknm.schools.sk>
1261 - (djm) Include sys/types.h when including netinet/in.h in configure tests.
1262 Patch from Jun-ichiro itojun Hagino <itojun@iijlab.net>
729bfe59 1263 - (djm) Started merge of Ben Lindstrom's <mouring@pconline.com> NeXT support
38c295d6 1264 - OpenBSD CVS updates:
1265 - deraadt@cvs.openbsd.org 2000/06/17 09:58:46
1266 [channels.c]
1267 everyone says "nix it" (remove protocol 2 debugging message)
1268 - markus@cvs.openbsd.org 2000/06/17 13:24:34
1269 [sshconnect.c]
1270 allow extended server banners
1271 - markus@cvs.openbsd.org 2000/06/17 14:30:10
1272 [sshconnect.c]
1273 missing atomicio, typo
1274 - jakob@cvs.openbsd.org 2000/06/17 16:52:34
1275 [servconf.c servconf.h session.c sshd.8 sshd_config]
1276 add support for ssh v2 subsystems. ok markus@.
1277 - deraadt@cvs.openbsd.org 2000/06/17 18:57:48
1278 [readconf.c servconf.c]
1279 include = in WHITESPACE; markus ok
1280 - markus@cvs.openbsd.org 2000/06/17 19:09:10
1281 [auth2.c]
1282 implement bug compatibility with ssh-2.0.13 pubkey, server side
1283 - markus@cvs.openbsd.org 2000/06/17 21:00:28
1284 [compat.c]
1285 initial support for ssh.com's 2.2.0
1286 - markus@cvs.openbsd.org 2000/06/17 21:16:09
1287 [scp.c]
1288 typo
1289 - markus@cvs.openbsd.org 2000/06/17 22:05:02
1290 [auth-rsa.c auth2.c serverloop.c session.c auth-options.c auth-options.h]
1291 split auth-rsa option parsing into auth-options
1292 add options support to authorized_keys2
1293 - markus@cvs.openbsd.org 2000/06/17 22:42:54
1294 [session.c]
1295 typo
cbd7492e 1296
509b1f88 129720000613
1298 - (djm) Fixes from Andrew McGill <andrewm@datrix.co.za>:
1299 - Platform define for SCO 3.x which breaks on /dev/ptmx
1300 - Detect and try to fix missing MAXPATHLEN
a4d05724 1301 - (djm) Fix short copy in loginrec.c (based on patch from Phill Camp
1302 <P.S.S.Camp@ukc.ac.uk>
509b1f88 1303
09564242 130420000612
1305 - (djm) Glob manpages in RPM spec files to catch compressed files
1306 - (djm) Full license in auth-pam.c
08ae384f 1307 - (djm) Configure fixes from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
383207f7 1308 - (andre) AIX, lastlog, configure fixes from Tom Bertelson <tbert@abac.com>:
1309 - Don't try to retrieve lastlog from wtmp/wtmpx if DISABLE_LASTLOG is
1310 def'd
1311 - Set AIX to use preformatted manpages
bcbf86ec 1312
74b224a0 131320000610
1314 - (djm) Minor doc tweaks
217ab55e 1315 - (djm) Fix for configure on bash2 from Jim Knoble <jmknoble@jmknoble.cx>
74b224a0 1316
32c80420 131720000609
1318 - (djm) Patch from Kenji Miyake <kenji@miyake.org> to disable utmp usage
1319 (in favour of utmpx) on Solaris 8
1320
fa649821 132120000606
48c99b2c 1322 - (djm) Cleanup of entropy.c. Reorganised code, removed second pass through
1323 list of commands (by default). Removed verbose debugging (by default).
bcbf86ec 1324 - (djm) Increased command entropy estimates and default entropy collection
48c99b2c 1325 timeout
f988dce5 1326 - (djm) Remove duplicate headers from loginrec.c
c5fa2eb0 1327 - (djm) Don't add /usr/local/lib to library search path on Irix
bcbf86ec 1328 - (djm) Fix rsh path in RPMs. Report from Jason L Tibbitts III
fa649821 1329 <tibbs@math.uh.edu>
1e83f2a2 1330 - (djm) Warn user if grabs fail in GNOME askpass. Patch from Zack Weinberg
1331 <zack@wolery.cumb.org>
fa649821 1332 - (djm) OpenBSD CVS updates:
1333 - todd@cvs.openbsd.org
1334 [sshconnect2.c]
1335 teach protocol v2 to count login failures properly and also enable an
1336 explanation of why the password prompt comes up again like v1; this is NOT
1337 crypto
bcbf86ec 1338 - markus@cvs.openbsd.org
fa649821 1339 [readconf.c readconf.h servconf.c servconf.h session.c ssh.1 ssh.c sshd.8]
1340 xauth_location support; pr 1234
1341 [readconf.c sshconnect2.c]
1342 typo, unused
1343 [session.c]
1344 allow use_login only for login sessions, otherwise remote commands are
1345 execed with uid==0
1346 [sshd.8]
1347 document UseLogin better
1348 [version.h]
1349 OpenSSH 2.1.1
1350 [auth-rsa.c]
bcbf86ec 1351 fix match_hostname() logic for auth-rsa: deny access if we have a
fa649821 1352 negative match or no match at all
1353 [channels.c hostfile.c match.c]
bcbf86ec 1354 don't panic if mkdtemp fails for authfwd; jkb@yahoo-inc.com via
fa649821 1355 kris@FreeBSD.org
1356
8e7b16f8 135720000606
bcbf86ec 1358 - (djm) Added --with-cflags, --with-ldflags and --with-libs options to
8e7b16f8 1359 configure.
1360
d7c0f3d5 136120000604
1362 - Configure tweaking for new login code on Irix 5.3
2d6c411f 1363 - (andre) login code changes based on djm feedback
d7c0f3d5 1364
2d6c411f 136520000603
1366 - (andre) New login code
1367 - Remove bsd-login.[ch] and all the OpenBSD-derived code in login.c
1368 - Add loginrec.[ch], logintest.c and autoconf code
bcbf86ec 1369
5daf7064 137020000531
1371 - Cleanup of auth.c, login.c and fake-*
1372 - Cleanup of auth-pam.c, save and print "account expired" error messages
e5662474 1373 - Fix EGD read bug by IWAMURO Motonori <iwa@mmp.fujitsu.co.jp>
69134b9b 1374 - Rewrote bsd-login to use proper utmp API if available. Major cleanup
1375 of fallback DIY code.
5daf7064 1376
b9f446d1 137720000530
1378 - Define atexit for old Solaris
b02ebca1 1379 - Fix buffer overrun in login.c for systems which use syslen in utmpx.
1380 patch from YOSHIFUJI Hideaki <yoshfuji@cerberus.nemoto.ecei.tohoku.ac.jp>
71276795 1381 - OpenBSD CVS updates:
1382 - markus@cvs.openbsd.org
1383 [session.c]
1384 make x11-fwd work w/ localhost (xauth add host/unix:11)
1385 [cipher.c compat.c readconf.c servconf.c]
1386 check strtok() != NULL; ok niels@
1387 [key.c]
1388 fix key_read() for uuencoded keys w/o '='
1389 [serverloop.c]
1390 group ssh1 vs. ssh2 in serverloop
1391 [kex.c kex.h myproposal.h sshconnect2.c sshd.c]
1392 split kexinit/kexdh, factor out common code
1393 [readconf.c ssh.1 ssh.c]
1394 forwardagent defaults to no, add ssh -A
1395 - theo@cvs.openbsd.org
1396 [session.c]
1397 just some line shortening
60688ef9 1398 - Released 2.1.0p3
b9f446d1 1399
29611d9c 140020000520
1401 - Xauth fix from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
25422c70 1402 - Don't touch utmp if USE_UTMPX defined
a423beaf 1403 - SunOS 4.x support from Todd C. Miller <Todd.Miller@courtesan.com>
fc1e8bf4 1404 - SIGCHLD fix for AIX and HPUX from Tom Bertelson <tbert@abac.com>
bcbf86ec 1405 - HPUX and Configure fixes from Lutz Jaenicke
fc1e8bf4 1406 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 1407 - Use mkinstalldirs script to make directories instead of non-portable
fc1e8bf4 1408 "install -d". Suggested by Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
a905808d 1409 - Doc cleanup
29611d9c 1410
301e9b01 141120000518
1412 - Include Andre Lucas' fixprogs script. Forgot to "cvs add" it yesterday
1413 - OpenBSD CVS updates:
1414 - markus@cvs.openbsd.org
1415 [sshconnect.c]
1416 copy only ai_addrlen bytes; misiek@pld.org.pl
1417 [auth.c]
bcbf86ec 1418 accept an empty shell in authentication; bug reported by
301e9b01 1419 chris@tinker.ucr.edu
1420 [serverloop.c]
1421 we don't have stderr for interactive terminal sessions (fcntl errors)
1422
ad85db64 142320000517
1424 - Fix from Andre Lucas <andre.lucas@dial.pipex.com>
1425 - Fixes command line printing segfaults (spotter: Bladt Norbert)
1426 - Fixes erroneous printing of debug messages to syslog
1427 - Fixes utmp for MacOS X (spotter: Aristedes Maniatis)
1428 - Gives useful error message if PRNG initialisation fails
1429 - Reduced ssh startup delay
1430 - Measures cumulative command time rather than the time between reads
704b1659 1431 after select()
ad85db64 1432 - 'fixprogs' perl script to eliminate non-working entropy commands, and
704b1659 1433 optionally run 'ent' to measure command entropy
c1ef8333 1434 - Applied Tom Bertelson's <tbert@abac.com> AIX authentication fix
a64009ad 1435 - Avoid WCOREDUMP complation errors for systems that lack it
bcbf86ec 1436 - Avoid SIGCHLD warnings from entropy commands
28c1d5ce 1437 - Fix HAVE_PAM_GETENVLIST setting from Simon Wilkinson <sxw@dcs.ed.ac.uk>
0e73cc53 1438 - OpenBSD CVS update:
bcbf86ec 1439 - markus@cvs.openbsd.org
0e73cc53 1440 [ssh.c]
1441 fix usage()
1442 [ssh2.h]
1443 draft-ietf-secsh-architecture-05.txt
1444 [ssh.1]
1445 document ssh -T -N (ssh2 only)
1446 [channels.c serverloop.c ssh.h sshconnect.c sshd.c aux.c]
1447 enable nonblocking IO for sshd w/ proto 1, too; split out common code
1448 [aux.c]
1449 missing include
c04f75f1 1450 - Several patches from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
1451 - INSTALL typo and URL fix
1452 - Makefile fix
1453 - Solaris fixes
bcbf86ec 1454 - Checking for ssize_t and memmove. Based on patch from SAKAI Kiyotaka
c04f75f1 1455 <ksakai@kso.netwk.ntt-at.co.jp>
afa5ee68 1456 - RSAless operation patch from kevin_oconnor@standardandpoors.com
d45e3d76 1457 - Detect OpenSSL seperatly from RSA
bcbf86ec 1458 - Better test for RSA (more compatible with RSAref). Based on work by
d45e3d76 1459 Ed Eden <ede370@stl.rural.usda.gov>
ad85db64 1460
3d1a1654 146120000513
bcbf86ec 1462 - Fix for non-recognised DSA keys from Arkadiusz Miskiewicz
3d1a1654 1463 <misiek@pld.org.pl>
1464
d02a3a00 146520000511
bcbf86ec 1466 - Fix for prng_seed permissions checking from Lutz Jaenicke
d02a3a00 1467 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
3d1a1654 1468 - "make host-key" fix for Irix
d02a3a00 1469
d0c832f3 147020000509
1471 - OpenBSD CVS update
1472 - markus@cvs.openbsd.org
1473 [cipher.h myproposal.h readconf.c readconf.h servconf.c ssh.1 ssh.c]
1474 [ssh.h sshconnect1.c sshconnect2.c sshd.8]
1475 - complain about invalid ciphers in SSH1 (e.g. arcfour is SSH2 only)
1476 - hugh@cvs.openbsd.org
1477 [ssh.1]
1478 - zap typo
1479 [ssh-keygen.1]
1480 - One last nit fix. (markus approved)
1481 [sshd.8]
1482 - some markus certified spelling adjustments
1483 - markus@cvs.openbsd.org
1484 [auth2.c channels.c clientloop.c compat compat.h dsa.c kex.c]
1485 [sshconnect2.c ]
1486 - bug compat w/ ssh-2.0.13 x11, split out bugs
1487 [nchan.c]
1488 - no drain if ibuf_empty, fixes x11fwd problems; tests by fries@
1489 [ssh-keygen.c]
1490 - handle escapes in real and original key format, ok millert@
1491 [version.h]
1492 - OpenSSH-2.1
3dc1102e 1493 - Moved all the bsd-* and fake-* stuff into new libopenbsd-compat.a
e93ee87a 1494 - Doc updates
bcbf86ec 1495 - Cleanup of bsd-base64 headers, bugfix definitions of __b64_*. Reported
21e5304a 1496 by Andre Lucas <andre.lucas@dial.pipex.com>
d0c832f3 1497
ebdeb9a8 149820000508
1499 - Makefile and RPM spec fixes
1500 - Generate DSA host keys during "make key" or RPM installs
f6cde515 1501 - OpenBSD CVS update
1502 - markus@cvs.openbsd.org
1503 [clientloop.c sshconnect2.c]
1504 - make x11-fwd interop w/ ssh-2.0.13
1505 [README.openssh2]
1506 - interop w/ SecureFX
1507 - Release 2.0.0beta2
ebdeb9a8 1508
bcbf86ec 1509 - Configure caching and cleanup patch from Andre Lucas'
58d100bf 1510 <andre.lucas@dial.pipex.com>
1511
1d1ffb87 151220000507
1513 - Remove references to SSLeay.
1514 - Big OpenBSD CVS update
1515 - markus@cvs.openbsd.org
1516 [clientloop.c]
1517 - typo
1518 [session.c]
1519 - update proctitle on pty alloc/dealloc, e.g. w/ windows client
1520 [session.c]
1521 - update proctitle for proto 1, too
1522 [channels.h nchan.c serverloop.c session.c sshd.c]
1523 - use c-style comments
1524 - deraadt@cvs.openbsd.org
1525 [scp.c]
1526 - more atomicio
bcbf86ec 1527 - markus@cvs.openbsd.org
1d1ffb87 1528 [channels.c]
1529 - set O_NONBLOCK
1530 [ssh.1]
1531 - update AUTHOR
1532 [readconf.c ssh-keygen.c ssh.h]
1533 - default DSA key file ~/.ssh/id_dsa
1534 [clientloop.c]
1535 - typo, rm verbose debug
1536 - deraadt@cvs.openbsd.org
1537 [ssh-keygen.1]
1538 - document DSA use of ssh-keygen
1539 [sshd.8]
1540 - a start at describing what i understand of the DSA side
1541 [ssh-keygen.1]
1542 - document -X and -x
1543 [ssh-keygen.c]
1544 - simplify usage
bcbf86ec 1545 - markus@cvs.openbsd.org
1d1ffb87 1546 [sshd.8]
1547 - there is no rhosts_dsa
1548 [ssh-keygen.1]
1549 - document -y, update -X,-x
1550 [nchan.c]
1551 - fix close for non-open ssh1 channels
1552 [servconf.c servconf.h ssh.h sshd.8 sshd.c ]
1553 - s/DsaKey/HostDSAKey/, document option
1554 [sshconnect2.c]
1555 - respect number_of_password_prompts
1556 [channels.c channels.h servconf.c servconf.h session.c sshd.8]
1557 - GatewayPorts for sshd, ok deraadt@
1558 [ssh-add.1 ssh-agent.1 ssh.1]
1559 - more doc on: DSA, id_dsa, known_hosts2, authorized_keys2
1560 [ssh.1]
1561 - more info on proto 2
1562 [sshd.8]
1563 - sync AUTHOR w/ ssh.1
1564 [key.c key.h sshconnect.c]
1565 - print key type when talking about host keys
1566 [packet.c]
1567 - clear padding in ssh2
1568 [dsa.c key.c radix.c ssh.h sshconnect1.c uuencode.c uuencode.h]
1569 - replace broken uuencode w/ libc b64_ntop
1570 [auth2.c]
1571 - log failure before sending the reply
1572 [key.c radix.c uuencode.c]
1573 - remote trailing comments before calling __b64_pton
1574 [auth2.c readconf.c readconf.h servconf.c servconf.h ssh.1]
1575 [sshconnect2.c sshd.8]
1576 - add DSAAuthetication option to ssh/sshd, document SSH2 in sshd.8
1577 - Bring in b64_ntop and b64_pton from OpenBSD libc (bsd-base64.[ch])
1578
1a11e1ae 157920000502
0fbe8c74 1580 - OpenBSD CVS update
1581 [channels.c]
1582 - init all fds, close all fds.
1583 [sshconnect2.c]
1584 - check whether file exists before asking for passphrase
1585 [servconf.c servconf.h sshd.8 sshd.c]
1586 - PidFile, pr 1210
1587 [channels.c]
1588 - EINTR
1589 [channels.c]
1590 - unbreak, ok niels@
1591 [sshd.c]
1592 - unlink pid file, ok niels@
1593 [auth2.c]
1594 - Add missing #ifdefs; ok - markus
bcbf86ec 1595 - Add Andre Lucas' <andre.lucas@dial.pipex.com> patch to read entropy
d3083fbd 1596 gathering commands from a text file
1a11e1ae 1597 - Release 2.0.0beta1
1598
c4bc58eb 159920000501
1600 - OpenBSD CVS update
1601 [packet.c]
1602 - send debug messages in SSH2 format
3189621b 1603 [scp.c]
1604 - fix very rare EAGAIN/EINTR issues; based on work by djm
1605 [packet.c]
1606 - less debug, rm unused
1607 [auth2.c]
1608 - disable kerb,s/key in ssh2
1609 [sshd.8]
1610 - Minor tweaks and typo fixes.
1611 [ssh-keygen.c]
1612 - Put -d into usage and reorder. markus ok.
bcbf86ec 1613 - Include missing headers for OpenSSL tests. Fix from Phil Karn
44fb55e9 1614 <karn@ka9q.ampr.org>
bcbf86ec 1615 - Fixed __progname symbol collisions reported by Andre Lucas
3fd95d9a 1616 <andre.lucas@dial.pipex.com>
0d5f7abc 1617 - Merged bsd-login ttyslot and AIX utmp patch from Gert Doering
1618 <gd@hilb1.medat.de>
8cb940db 1619 - Add some missing ifdefs to auth2.c
8af50c98 1620 - Deprecate perl-tk askpass.
52bcc044 1621 - Irix portability fixes - don't include netinet headers more than once
1622 - Make sure we don't save PRNG seed more than once
c4bc58eb 1623
2b763e31 162420000430
1625 - Merge HP-UX fixes and TCB support from Ged Lodder <lodder@yacc.com.au>
b7a87eea 1626 - Integrate Andre Lucas' <andre.lucas@dial.pipex.com> entropy collection
1627 patch.
1628 - Adds timeout to entropy collection
1629 - Disables slow entropy sources
1630 - Load and save seed file
bcbf86ec 1631 - Changed entropy seed code to user per-user seeds only (server seed is
b7a87eea 1632 saved in root's .ssh directory)
1633 - Use atexit() and fatal cleanups to save seed on exit
0b242b12 1634 - More OpenBSD updates:
1635 [session.c]
1636 - don't call chan_write_failed() if we are not writing
1637 [auth-rsa.c auth1.c authfd.c hostfile.c ssh-agent.c]
1638 - keysize warnings error() -> log()
2b763e31 1639
a306f2dd 164020000429
1641 - Merge big update to OpenSSH-2.0 from OpenBSD CVS
1642 [README.openssh2]
1643 - interop w/ F-secure windows client
1644 - sync documentation
1645 - ssh_host_dsa_key not ssh_dsa_key
1646 [auth-rsa.c]
1647 - missing fclose
1648 [auth.c authfile.c compat.c dsa.c dsa.h hostfile.c key.c key.h radix.c]
1649 [readconf.c readconf.h ssh-add.c ssh-keygen.c ssh.c ssh.h sshconnect.c]
1650 [sshd.c uuencode.c uuencode.h authfile.h]
1651 - add DSA pubkey auth and other SSH2 fixes. use ssh-keygen -[xX]
1652 for trading keys with the real and the original SSH, directly from the
1653 people who invented the SSH protocol.
1654 [auth.c auth.h authfile.c sshconnect.c auth1.c auth2.c sshconnect.h]
1655 [sshconnect1.c sshconnect2.c]
1656 - split auth/sshconnect in one file per protocol version
1657 [sshconnect2.c]
1658 - remove debug
1659 [uuencode.c]
1660 - add trailing =
1661 [version.h]
1662 - OpenSSH-2.0
1663 [ssh-keygen.1 ssh-keygen.c]
1664 - add -R flag: exit code indicates if RSA is alive
1665 [sshd.c]
1666 - remove unused
1667 silent if -Q is specified
1668 [ssh.h]
1669 - host key becomes /etc/ssh_host_dsa_key
1670 [readconf.c servconf.c ]
1671 - ssh/sshd default to proto 1 and 2
1672 [uuencode.c]
1673 - remove debug
1674 [auth2.c ssh-keygen.c sshconnect2.c sshd.c]
1675 - xfree DSA blobs
1676 [auth2.c serverloop.c session.c]
1677 - cleanup logging for sshd/2, respect PasswordAuth no
1678 [sshconnect2.c]
1679 - less debug, respect .ssh/config
1680 [README.openssh2 channels.c channels.h]
bcbf86ec 1681 - clientloop.c session.c ssh.c
a306f2dd 1682 - support for x11-fwding, client+server
1683
0ac7199f 168420000421
1685 - Merge fix from OpenBSD CVS
1686 [ssh-agent.c]
1687 - Fix memory leak per connection. Report from Andy Spiegl <Andy@Spiegl.de>
1688 via Debian bug #59926
18ba2aab 1689 - Define __progname in session.c if libc doesn't
1690 - Remove indentation on autoconf #include statements to avoid bug in
bcbf86ec 1691 DEC Tru64 compiler. Report and fix from David Del Piero
18ba2aab 1692 <David.DelPiero@qed.qld.gov.au>
0ac7199f 1693
e1b37056 169420000420
bcbf86ec 1695 - Make fixpaths work with perl4, patch from Andre Lucas
e1b37056 1696 <andre.lucas@dial.pipex.com>
9da5c3c9 1697 - Sync with OpenBSD CVS:
1698 [clientloop.c login.c serverloop.c ssh-agent.c ssh.h sshconnect.c sshd.c]
1699 - pid_t
1700 [session.c]
1701 - remove bogus chan_read_failed. this could cause data
1702 corruption (missing data) at end of a SSH2 session.
4e577b89 1703 - Merge fixes from Debian patch from Phil Hands <phil@hands.com>
1704 - Allow setting of PAM service name through CFLAGS (SSHD_PAM_SERVICE)
1705 - Use vhangup to clean up Linux ttys
1706 - Force posix getopt processing on GNU libc systems
371ecff9 1707 - Debian bug #55910 - remove references to ssl(8) manpages
247f1a89 1708 - Debian bug #58031 - ssh_config lies about default cipher
e1b37056 1709
d6f24e45 171020000419
1711 - OpenBSD CVS updates
1712 [channels.c]
1713 - fix pr 1196, listen_port and port_to_connect interchanged
1714 [scp.c]
bcbf86ec 1715 - after completion, replace the progress bar ETA counter with a final
d6f24e45 1716 elapsed time; my idea, aaron wrote the patch
1717 [ssh_config sshd_config]
1718 - show 'Protocol' as an example, ok markus@
1719 [sshd.c]
1720 - missing xfree()
1721 - Add missing header to bsd-misc.c
1722
35484284 172320000416
1724 - Reduce diff against OpenBSD source
bcbf86ec 1725 - All OpenSSL includes are now unconditionally referenced as
35484284 1726 openssl/foo.h
1727 - Pick up formatting changes
1728 - Other minor changed (typecasts, etc) that I missed
1729
6ae2364d 173020000415
1731 - OpenBSD CVS updates.
1732 [ssh.1 ssh.c]
1733 - ssh -2
1734 [auth.c channels.c clientloop.c packet.c packet.h serverloop.c]
1735 [session.c sshconnect.c]
1736 - check payload for (illegal) extra data
1737 [ALL]
1738 whitespace cleanup
1739
c323ac76 174020000413
1741 - INSTALL doc updates
f54651ce 1742 - Merged OpenBSD updates to include paths.
bcbf86ec 1743
a8be9f80 174420000412
1745 - OpenBSD CVS updates:
1746 - [channels.c]
1747 repair x11-fwd
1748 - [sshconnect.c]
1749 fix passwd prompt for ssh2, less debugging output.
1750 - [clientloop.c compat.c dsa.c kex.c sshd.c]
1751 less debugging output
1752 - [kex.c kex.h sshconnect.c sshd.c]
1753 check for reasonable public DH values
1754 - [README.openssh2 cipher.c cipher.h compat.c compat.h readconf.c]
1755 [readconf.h servconf.c servconf.h ssh.c ssh.h sshconnect.c sshd.c]
1756 add Cipher and Protocol options to ssh/sshd, e.g.:
1757 ssh -o 'Protocol 1,2' if you prefer proto 1, ssh -o 'Ciphers
1758 arcfour,3des-cbc'
1759 - [sshd.c]
1760 print 1.99 only if server supports both
1761
18e92801 176220000408
1763 - Avoid some compiler warnings in fake-get*.c
1764 - Add IPTOS macros for systems which lack them
9d98aaf6 1765 - Only set define entropy collection macros if they are found
e78a59f5 1766 - More large OpenBSD CVS updates:
1767 - [auth.c auth.h servconf.c servconf.h serverloop.c session.c]
1768 [session.h ssh.h sshd.c README.openssh2]
1769 ssh2 server side, see README.openssh2; enable with 'sshd -2'
1770 - [channels.c]
1771 no adjust after close
1772 - [sshd.c compat.c ]
1773 interop w/ latest ssh.com windows client.
bcbf86ec 1774
8ce64345 177520000406
1776 - OpenBSD CVS update:
1777 - [channels.c]
1778 close efd on eof
1779 - [clientloop.c compat.c ssh.c sshconnect.c myproposal.h]
1780 ssh2 client implementation, interops w/ ssh.com and lsh servers.
1781 - [sshconnect.c]
1782 missing free.
1783 - [authfile.c cipher.c cipher.h packet.c sshconnect.c sshd.c]
1784 remove unused argument, split cipher_mask()
1785 - [clientloop.c]
1786 re-order: group ssh1 vs. ssh2
1787 - Make Redhat spec require openssl >= 0.9.5a
1788
e7627112 178920000404
1790 - Add tests for RAND_add function when searching for OpenSSL
7e7327a1 1791 - OpenBSD CVS update:
1792 - [packet.h packet.c]
1793 ssh2 packet format
1794 - [packet.h packet.c nchan2.ms nchan.h compat.h compat.c]
1795 [channels.h channels.c]
1796 channel layer support for ssh2
1797 - [kex.h kex.c hmac.h hmac.c dsa.c dsa.h]
1798 DSA, keyexchange, algorithm agreement for ssh2
6c081128 1799 - Generate manpages before make install not at the end of make all
1800 - Don't seed the rng quite so often
1801 - Always reseed rng when requested
e7627112 1802
bfc9a610 180320000403
1804 - Wrote entropy collection routines for systems that lack /dev/random
1805 and EGD
837c30b8 1806 - Disable tests and typedefs for 64 bit types. They are currently unused.
bfc9a610 1807
7368a6c8 180820000401
1809 - Big OpenBSD CVS update (mainly beginnings of SSH2 infrastructure)
1810 - [auth.c session.c sshd.c auth.h]
1811 split sshd.c -> auth.c session.c sshd.c plus cleanup and goto-removal
1812 - [bufaux.c bufaux.h]
1813 support ssh2 bignums
1814 - [channels.c channels.h clientloop.c sshd.c nchan.c nchan.h packet.c]
1815 [readconf.c ssh.c ssh.h serverloop.c]
1816 replace big switch() with function tables (prepare for ssh2)
1817 - [ssh2.h]
1818 ssh2 message type codes
1819 - [sshd.8]
1820 reorder Xr to avoid cutting
1821 - [serverloop.c]
1822 close(fdin) if fdin != fdout, shutdown otherwise, ok theo@
1823 - [channels.c]
1824 missing close
1825 allow bigger packets
1826 - [cipher.c cipher.h]
1827 support ssh2 ciphers
1828 - [compress.c]
1829 cleanup, less code
1830 - [dispatch.c dispatch.h]
1831 function tables for different message types
1832 - [log-server.c]
1833 do not log() if debuggin to stderr
1834 rename a cpp symbol, to avoid param.h collision
1835 - [mpaux.c]
1836 KNF
1837 - [nchan.c]
1838 sync w/ channels.c
1839
f5238bee 184020000326
1841 - Better tests for OpenSSL w/ RSAref
bcbf86ec 1842 - Added replacement setenv() function from OpenBSD libc. Suggested by
f5238bee 1843 Ben Lindstrom <mouring@pconline.com>
4fe2af09 1844 - OpenBSD CVS update
1845 - [auth-krb4.c]
1846 -Wall
1847 - [auth-rh-rsa.c auth-rsa.c hostfile.c hostfile.h key.c key.h match.c]
1848 [match.h ssh.c ssh.h sshconnect.c sshd.c]
1849 initial support for DSA keys. ok deraadt@, niels@
1850 - [cipher.c cipher.h]
1851 remove unused cipher_attack_detected code
1852 - [scp.1 ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
1853 Fix some formatting problems I missed before.
1854 - [ssh.1 sshd.8]
1855 fix spelling errors, From: FreeBSD
1856 - [ssh.c]
1857 switch to raw mode only if he _get_ a pty (not if we _want_ a pty).
f5238bee 1858
0024a081 185920000324
1860 - Released 1.2.3
1861
bd499f9e 186220000317
1863 - Clarified --with-default-path option.
1864 - Added -blibpath handling for AIX to work around stupid runtime linking.
1865 Problem elucidated by gshapiro@SENDMAIL.ORG by way of Jim Knoble
1866 <jmknoble@pobox.com>
474b5fef 1867 - Checks for 64 bit int types. Problem report from Mats Fredholm
1868 <matsf@init.se>
610cd5c6 1869 - OpenBSD CVS updates:
bcbf86ec 1870 - [atomicio.c auth-krb4.c bufaux.c channels.c compress.c fingerprint.c]
610cd5c6 1871 [packet.h radix.c rsa.c scp.c ssh-agent.c ssh-keygen.c sshconnect.c]
1872 [sshd.c]
1873 pedantic: signed vs. unsigned, void*-arithm, etc
1874 - [ssh.1 sshd.8]
1875 Various cleanups and standardizations.
bcbf86ec 1876 - Runtime error fix for HPUX from Otmar Stahl
be48d23c 1877 <O.Stahl@lsw.uni-heidelberg.de>
bd499f9e 1878
4696775a 187920000316
bcbf86ec 1880 - Fixed configure not passing LDFLAGS to Solaris. Report from David G.
4696775a 1881 Hesprich <dghespri@sprintparanet.com>
d423d822 1882 - Propogate LD through to Makefile
b7a9ce47 1883 - Doc cleanups
2ba2a610 1884 - Added blurb about "scp: command not found" errors to UPGRADING
4696775a 1885
cb0b7ea4 188620000315
1887 - Fix broken CFLAGS handling during search for OpenSSL. Fixes va_list
1888 problems with gcc/Solaris.
bcbf86ec 1889 - Don't free argument to putenv() after use (in setenv() replacement).
db55a3ea 1890 Report from Seigo Tanimura <tanimura@r.dl.itc.u-tokyo.ac.jp>
bcbf86ec 1891 - Created contrib/ subdirectory. Included helpers from Phil Hands'
13652e52 1892 Debian package, README file and chroot patch from Ricardo Cerqueira
1893 <rmcc@clix.pt>
bcbf86ec 1894 - Moved gnome-ssh-askpass.c to contrib directory and removed config
13652e52 1895 option.
1896 - Slight cleanup to doc files
b14b2ae7 1897 - Configure fix from Bratislav ILICH <bilic@zepter.ru>
cb0b7ea4 1898
a8ed9fd9 189920000314
bcbf86ec 1900 - Include macro for IN6_IS_ADDR_V4MAPPED. Report from
a8ed9fd9 1901 peter@frontierflying.com
84afc958 1902 - Include /usr/local/include and /usr/local/lib for systems that don't
1903 do it themselves
1904 - -R/usr/local/lib for Solaris
1905 - Fix RSAref detection
1906 - Fix IN6_IS_ADDR_V4MAPPED macro
a8ed9fd9 1907
bcf36c78 190820000311
1909 - Detect RSAref
43e48848 1910 - OpenBSD CVS change
1911 [sshd.c]
1912 - disallow guessing of root password
867dbf40 1913 - More configure fixes
80faa19f 1914 - IPv6 workarounds from Hideaki YOSHIFUJI <yoshfuji@ecei.tohoku.ac.jp>
bcf36c78 1915
c8d54615 191620000309
1917 - OpenBSD CVS updates to v1.2.3
704b1659 1918 [ssh.h atomicio.c]
1919 - int atomicio -> ssize_t (for alpha). ok deraadt@
1920 [auth-rsa.c]
1921 - delay MD5 computation until client sends response, free() early, cleanup.
1922 [cipher.c]
1923 - void* -> unsigned char*, ok niels@
1924 [hostfile.c]
1925 - remove unused variable 'len'. fix comments.
1926 - remove unused variable
1927 [log-client.c log-server.c]
1928 - rename a cpp symbol, to avoid param.h collision
1929 [packet.c]
1930 - missing xfree()
1931 - getsockname() requires initialized tolen; andy@guildsoftware.com
1932 - use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
1933 from Holger.Trapp@Informatik.TU-Chemnitz.DE
1934 [pty.c pty.h]
bcbf86ec 1935 - register cleanup for pty earlier. move code for pty-owner handling to
c8d54615 1936 pty.c ok provos@, dugsong@
704b1659 1937 [readconf.c]
1938 - turn off x11-fwd for the client, too.
1939 [rsa.c]
1940 - PKCS#1 padding
1941 [scp.c]
1942 - allow '.' in usernames; from jedgar@fxp.org
1943 [servconf.c]
1944 - typo: ignore_user_known_hosts int->flag; naddy@mips.rhein-neckar.de
1945 - sync with sshd_config
1946 [ssh-keygen.c]
1947 - enable ssh-keygen -l -f ~/.ssh/known_hosts, ok deraadt@
1948 [ssh.1]
1949 - Change invalid 'CHAT' loglevel to 'VERBOSE'
1950 [ssh.c]
1951 - suppress AAAA query host when '-4' is used; from shin@nd.net.fujitsu.co.jp
1952 - turn off x11-fwd for the client, too.
1953 [sshconnect.c]
1954 - missing xfree()
1955 - retry rresvport_af(), too. from sumikawa@ebina.hitachi.co.jp.
1956 - read error vs. "Connection closed by remote host"
1957 [sshd.8]
1958 - ie. -> i.e.,
1959 - do not link to a commercial page..
1960 - sync with sshd_config
1961 [sshd.c]
1962 - no need for poll.h; from bright@wintelcom.net
1963 - log with level log() not fatal() if peer behaves badly.
1964 - don't panic if client behaves strange. ok deraadt@
1965 - make no-port-forwarding for RSA keys deny both -L and -R style fwding
1966 - delay close() of pty until the pty has been chowned back to root
1967 - oops, fix comment, too.
1968 - missing xfree()
1969 - move XAUTHORITY to subdir. ok dugsong@. fixes debian bug #57907, too.
1970 (http://cgi.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=57907)
bcbf86ec 1971 - register cleanup for pty earlier. move code for pty-owner handling to
704b1659 1972 pty.c ok provos@, dugsong@
1973 - create x11 cookie file
1974 - fix pr 1113, fclose() -> pclose(), todo: remote popen()
1975 - version 1.2.3
c8d54615 1976 - Cleaned up
bcbf86ec 1977 - Removed warning workaround for Linux and devpts filesystems (no longer
d8223847 1978 required after OpenBSD updates)
c8d54615 1979
07055445 198020000308
1981 - Configure fix from Hiroshi Takekawa <takekawa@sr3.t.u-tokyo.ac.jp>
1982
198320000307
1984 - Released 1.2.2p1
1985
9c8c3fc6 198620000305
1987 - Fix DEC compile fix
54096dcc 1988 - Explicitly seed OpenSSL's PRNG before checking rsa_alive()
aa6bd60a 1989 - Check for getpagesize in libucb.a if not found in libc. Fix for old
1990 Solaris from Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 1991 - Check for libwrap if --with-tcp-wrappers option specified. Suggestion
9fc7867e 1992 Mate Wierdl <mw@moni.msci.memphis.edu>
9c8c3fc6 1993
6bf4d066 199420000303
1995 - Added "make host-key" target, Suggestion from Dominik Brettnacher
1996 <domi@saargate.de>
bcbf86ec 1997 - Don't permanently fail on bind() if getaddrinfo has more choices left for
16218745 1998 us. Needed to work around messy IPv6 on Linux. Patch from Arkadiusz
1999 Miskiewicz <misiek@pld.org.pl>
22fa590f 2000 - DEC Unix compile fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
2001 - Manpage fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
6bf4d066 2002
a0391976 200320000302
2004 - Big cleanup of autoconf code
2005 - Rearranged to be a little more logical
2006 - Added -R option for Solaris
2007 - Rewrote OpenSSL detection code. Now uses AC_TRY_RUN with a test program
2008 to detect library and header location _and_ ensure library has proper
2009 RSA support built in (this is a problem with OpenSSL 0.9.5).
817175bc 2010 - Applied pty cleanup patch from markus.friedl@informatik.uni-erlangen.de
0a1718dc 2011 - Avoid warning message with Unix98 ptys
bcbf86ec 2012 - Warning was valid - possible race condition on PTYs. Avoided using
3276571c 2013 platform-specific code.
2014 - Document some common problems
bcbf86ec 2015 - Allow root access to any key. Patch from
81eef326 2016 markus.friedl@informatik.uni-erlangen.de
a0391976 2017
f55afe71 201820000207
2019 - Removed SOCKS code. Will support through a ProxyCommand.
2020
d07d1c58 202120000203
2022 - Fixed SEGVs in authloop, fix from vbzoli@hbrt.hu
d581b7ae 2023 - Add --with-ssl-dir option
d07d1c58 2024
9d5f374b 202520000202
bcbf86ec 2026 - Fix lastlog code for directory based lastlogs. Fix from Josh Durham
9d5f374b 2027 <jmd@aoe.vt.edu>
6b1f3fdb 2028 - Documentation fixes from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 2029 - Added URLs to Japanese translations of documents by HARUYAMA Seigo
6b1f3fdb 2030 <haruyama@nt.phys.s.u-tokyo.ac.jp>
9d5f374b 2031
bc8c2601 203220000201
2033 - Use socket pairs by default (instead of pipes). Prevents race condition
2034 on several (buggy) OSs. Report and fix from tridge@linuxcare.com
2035
69c76614 203620000127
2037 - Seed OpenSSL's random number generator before generating RSA keypairs
2038 - Split random collector into seperate file
aaf2abd7 2039 - Compile fix from Andre Lucas <andre.lucas@dial.pipex.com>
69c76614 2040
f9507c24 204120000126
2042 - Released 1.2.2 stable
2043
bcbf86ec 2044 - NeXT keeps it lastlog in /usr/adm. Report from
f9507c24 2045 mouring@newton.pconline.com
bcbf86ec 2046 - Added note in UPGRADING re interop with commercial SSH using idea.
587120ad 2047 Report from Jim Knoble <jmknoble@pobox.com>
2048 - Fix linking order for Kerberos/AFS. Fix from Holget Trapp
2049 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
f9507c24 2050
bfae20ad 205120000125
bcbf86ec 2052 - Fix NULL pointer dereference in login.c. Fix from Andre Lucas
bfae20ad 2053 <andre.lucas@dial.pipex.com>
07b0cb78 2054 - Reorder PAM initialisation so it does not mess up lastlog. Reported
2055 by Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 2056 - Use preformatted manpages on SCO, report from Gary E. Miller
9755cbdb 2057 <gem@rellim.com>
2058 - New URL for x11-ssh-askpass.
bcbf86ec 2059 - Fixpaths was missing /etc/ssh_known_hosts. Report from Jim Knoble
7e31dc81 2060 <jmknoble@pobox.com>
bcbf86ec 2061 - Added 'DESTDIR' option to Makefile to ease package building. Patch from
ff8ecdb8 2062 Jim Knoble <jmknoble@pobox.com>
2063 - Updated RPM spec files to use DESTDIR
bfae20ad 2064
bb58aa4b 206520000124
2066 - Pick up version 1.2.2 from OpenBSD CVS (no changes, just version number
2067 increment)
2068
d45317d8 206920000123
2070 - OpenBSD CVS:
2071 - [packet.c]
2072 getsockname() requires initialized tolen; andy@guildsoftware.com
bcbf86ec 2073 - AIX patch from Matt Richards <v2matt@btv.ibm.com> and David Rankin
4c40f834 2074 <drankin@bohemians.lexington.ky.us>
12aa90af 2075 - Fix lastlog support, patch from Andre Lucas <andre.lucas@dial.pipex.com>
d45317d8 2076
e844f761 207720000122
2078 - Fix compilation of bsd-snprintf.c on Solaris, fix from Ben Taylor
2079 <bent@clark.net>
c54a6257 2080 - Merge preformatted manpage patch from Andre Lucas
2081 <andre.lucas@dial.pipex.com>
8eb34e02 2082 - Make IPv4 use the default in RPM packages
2083 - Irix uses preformatted manpages
1e64903d 2084 - Missing htons() in bsd-bindresvport.c, fix from Holger Trapp
2085 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
9bc5ddfe 2086 - OpenBSD CVS updates:
2087 - [packet.c]
2088 use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
2089 from Holger.Trapp@Informatik.TU-Chemnitz.DE
2090 - [sshd.c]
2091 log with level log() not fatal() if peer behaves badly.
2092 - [readpass.c]
bcbf86ec 2093 instead of blocking SIGINT, catch it ourselves, so that we can clean
2094 the tty modes up and kill ourselves -- instead of our process group
2095 leader (scp, cvs, ...) going away and leaving us in noecho mode.
9bc5ddfe 2096 people with cbreak shells never even noticed..
399d9d44 2097 - [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
2098 ie. -> i.e.,
e844f761 2099
4c8ef3fb 210020000120
2101 - Don't use getaddrinfo on AIX
7b2ea3a1 2102 - Update to latest OpenBSD CVS:
2103 - [auth-rsa.c]
2104 - fix user/1056, sshd keeps restrictions; dbt@meat.net
2105 - [sshconnect.c]
2106 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
2107 - destroy keys earlier
bcbf86ec 2108 - split key exchange (kex) and user authentication (user-auth),
d468fc76 2109 ok: provos@
7b2ea3a1 2110 - [sshd.c]
2111 - no need for poll.h; from bright@wintelcom.net
2112 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
bcbf86ec 2113 - split key exchange (kex) and user authentication (user-auth),
d468fc76 2114 ok: provos@
f3bba493 2115 - Big manpage and config file cleanup from Andre Lucas
2116 <andre.lucas@dial.pipex.com>
5f4fdfae 2117 - Re-added latest (unmodified) OpenBSD manpages
47f9a56a 2118 - Doc updates
d468fc76 2119 - NetBSD patch from David Rankin <drankin@bohemians.lexington.ky.us> and
2120 Christos Zoulas <christos@netbsd.org>
4c8ef3fb 2121
082bbfb3 212220000119
20af321f 2123 - SCO compile fixes from Gary E. Miller <gem@rellim.com>
082bbfb3 2124 - Compile fix from Darren_Hall@progressive.com
59e76f33 2125 - Linux/glibc-2.1.2 takes a *long* time to look up names for AF_UNSPEC
2126 addresses using getaddrinfo(). Added a configure switch to make the
2127 default lookup mode AF_INET
082bbfb3 2128
a63a7f37 212920000118
2130 - Fixed --with-pid-dir option
51a6baf8 2131 - Makefile fix from Gary E. Miller <gem@rellim.com>
bcbf86ec 2132 - Compile fix for HPUX and Solaris from Andre Lucas
976f7e19 2133 <andre.lucas@dial.pipex.com>
a63a7f37 2134
f914c7fb 213520000117
2136 - Clean up bsd-bindresvport.c. Use arc4random() for picking initial
2137 port, ignore EINVAL errors (Linux) when searching for free port.
bcbf86ec 2138 - Revert __snprintf -> snprintf aliasing. Apparently Solaris
de93b046 2139 __snprintf isn't. Report from Theo de Raadt <theo@cvs.openbsd.org>
9b363e1c 2140 - Document location of Redhat PAM file in INSTALL.
bcbf86ec 2141 - Fixed X11 forwarding bug on Linux. libc advertises AF_INET6
2142 INADDR_ANY_INIT addresses via getaddrinfo, but may not be able to
f4a7cf29 2143 deliver (no IPv6 kernel support)
80a44451 2144 - Released 1.2.1pre27
f914c7fb 2145
f4a7cf29 2146 - Fix rresvport_af failure errors (logic error in bsd-bindresvport.c)
bcbf86ec 2147 - Fix --with-ipaddr-display option test. Fix from Jarno Huuskonen
cf8ad170 2148 <jhuuskon@hytti.uku.fi>
bcbf86ec 2149 - Fix hang on logout if processes are still using the pty. Needs
691a8a9f 2150 further testing.
5957fd29 2151 - Patch from Christos Zoulas <christos@zoulas.com>
2152 - Try $prefix first when looking for OpenSSL.
2153 - Include sys/types.h when including sys/socket.h in test programs
bcbf86ec 2154 - Substitute PID directory in sshd.8. Suggestion from Andrew
19d9ac2a 2155 Stribblehill <a.d.stribblehill@durham.ac.uk>
f4a7cf29 2156
47e45e44 215720000116
2158 - Renamed --with-xauth-path to --with-xauth
2159 - Added --with-pid-dir option
2160 - Released 1.2.1pre26
2161
a82ef8ae 2162 - Compilation fix from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
bcbf86ec 2163 - Fixed broken bugfix for /dev/ptmx on Linux systems which lack
66be05a1 2164 openpty(). Report from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
a82ef8ae 2165
5cdfe03f 216620000115
2167 - Add --with-xauth-path configure directive and explicit test for
bcbf86ec 2168 /usr/openwin/bin/xauth for Solaris systems. Report from Anders
5cdfe03f 2169 Nordby <anders@fix.no>
bcbf86ec 2170 - Fix incorrect detection of /dev/ptmx on Linux systems that lack
5cdfe03f 2171 openpty. Report from John Seifarth <john@waw.be>
2172 - Look for intXX_t and u_intXX_t in sys/bitypes.h if they are not in
bcbf86ec 2173 sys/types.h. Fixes problems on SCO, report from Gary E. Miller
5cdfe03f 2174 <gem@rellim.com>
2175 - Use __snprintf and __vnsprintf if they are found where snprintf and
2176 vnsprintf are lacking. Suggested by Ben Taylor <bent@shell.clark.net>
2177 and others.
2178
48e671d5 217920000114
2180 - Merged OpenBSD IPv6 patch:
2181 - [sshd.c sshd.8 sshconnect.c ssh.h ssh.c servconf.h servconf.c scp.1]
2182 [scp.c packet.h packet.c login.c log.c canohost.c channels.c]
2183 [hostfile.c sshd_config]
2184 ipv6 support: mostly gethostbyname->getaddrinfo/getnameinfo, new
bcbf86ec 2185 features: sshd allows multiple ListenAddress and Port options. note
2186 that libwrap is not IPv6-ready. (based on patches from
48e671d5 2187 fujiwara@rcac.tdi.co.jp)
2188 - [ssh.c canohost.c]
bcbf86ec 2189 more hints (hints.ai_socktype=SOCK_STREAM) for getaddrinfo,
48e671d5 2190 from itojun@
2191 - [channels.c]
2192 listen on _all_ interfaces for X11-Fwd (hints.ai_flags = AI_PASSIVE)
2193 - [packet.h]
2194 allow auth-kerberos for IPv4 only
2195 - [scp.1 sshd.8 servconf.h scp.c]
2196 document -4, -6, and 'ssh -L 2022/::1/22'
2197 - [ssh.c]
bcbf86ec 2198 'ssh @host' is illegal (null user name), from
48e671d5 2199 karsten@gedankenpolizei.de
2200 - [sshconnect.c]
2201 better error message
2202 - [sshd.c]
2203 allow auth-kerberos for IPv4 only
2204 - Big IPv6 merge:
2205 - Cleanup overrun in sockaddr copying on RHL 6.1
2206 - Replacements for getaddrinfo, getnameinfo, etc based on versions
2207 from patch from KIKUCHI Takahiro <kick@kyoto.wide.ad.jp>
2208 - Replacement for missing structures on systems that lack IPv6
2209 - record_login needed to know about AF_INET6 addresses
2210 - Borrowed more code from OpenBSD: rresvport_af and requisites
2211
2598df62 221220000110
2213 - Fixes to auth-skey to enable it to use the standard OpenSSL libraries
2214
b8a0310d 221520000107
2216 - New config.sub and config.guess to fix problems on SCO. Supplied
2217 by Gary E. Miller <gem@rellim.com>
b6a98a85 2218 - SCO build fix from Gary E. Miller <gem@rellim.com>
2598df62 2219 - Released 1.2.1pre25
b8a0310d 2220
dfb95100 222120000106
2222 - Documentation update & cleanup
2223 - Better KrbIV / AFS detection, based on patch from:
2224 Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
2225
b9795b89 222620000105
bcbf86ec 2227 - Fixed annoying DES corruption problem. libcrypt has been
b9795b89 2228 overriding symbols in libcrypto. Removed libcrypt and crypt.h
2229 altogether (libcrypto includes its own crypt(1) replacement)
2230 - Added platform-specific rules for Irix 6.x. Included warning that
2231 they are untested.
2232
a1ec4d79 223320000103
2234 - Add explicit make rules for files proccessed by fixpaths.
bcbf86ec 2235 - Fix "make install" in RPM spec files. Report from Tenkou N. Hattori
a1ec4d79 2236 <tnh@kondara.org>
bcbf86ec 2237 - Removed "nullok" directive from default PAM configuration files.
2238 Added information on enabling EmptyPasswords on openssh+PAM in
607d73e6 2239 UPGRADING file.
e02735bb 2240 - OpenBSD CVS updates
2241 - [ssh-agent.c]
bcbf86ec 2242 cleanup_exit() for SIGTERM/SIGHUP, too. from fgsch@ and
e02735bb 2243 dgaudet@arctic.org
2244 - [sshconnect.c]
2245 compare correct version for 1.3 compat mode
a1ec4d79 2246
93c7f644 224720000102
2248 - Prevent multiple inclusion of config.h and defines.h. Suggested
2249 by Andre Lucas <andre.lucas@dial.pipex.com>
2250 - Properly clean up on exit of ssh-agent. Patch from Dean Gaudet
2251 <dgaudet@arctic.org>
2252
76b8607f 225319991231
bcbf86ec 2254 - Fix password support on systems with a mixture of shadowed and
2255 non-shadowed passwords (e.g. NIS). Report and fix from
76b8607f 2256 HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 2257 - Fix broken autoconf typedef detection. Report from Marc G.
723221b5 2258 Fournier <marc.fournier@acadiau.ca>
b92964b7 2259 - Fix occasional crash on LinuxPPC. Patch from Franz Sirl
2260 <Franz.Sirl-kernel@lauterbach.com>
bcbf86ec 2261 - Prevent typedefs from being compiled more than once. Report from
a6ddc88b 2262 Marc G. Fournier <marc.fournier@acadiau.ca>
4811cc0b 2263 - Fill in ut_utaddr utmp field. Report from Benjamin Charron
2264 <iretd@bigfoot.com>
bcbf86ec 2265 - Really fix broken default path. Fix from Jim Knoble
c43d69a9 2266 <jmknoble@pobox.com>
ae3a3d31 2267 - Remove test for quad_t. No longer needed.
76a8e733 2268 - Released 1.2.1pre24
2269
2270 - Added support for directory-based lastlogs
2271 - Really fix typedefs, patch from Ben Taylor <bent@clark.net>
76b8607f 2272
13f825f4 227319991230
2274 - OpenBSD CVS updates:
2275 - [auth-passwd.c]
2276 check for NULL 1st
bcbf86ec 2277 - Removed most of the pam code into its own file auth-pam.[ch]. This
a5c9cd31 2278 cleaned up sshd.c up significantly.
bcbf86ec 2279 - PAM authentication was incorrectly interpreting
76b8607f 2280 "PermitRootLogin without-password". Report from Matthias Andree
2281 <ma@dt.e-technik.uni-dortmund.de
a5c9cd31 2282 - Several other cleanups
0bc5b6fb 2283 - Merged Dante SOCKS support patch from David Rankin
2284 <drankin@bohemians.lexington.ky.us>
2285 - Updated documentation with ./configure options
76b8607f 2286 - Released 1.2.1pre23
13f825f4 2287
c73a0cb5 228819991229
bcbf86ec 2289 - Applied another NetBSD portability patch from David Rankin
c73a0cb5 2290 <drankin@bohemians.lexington.ky.us>
2291 - Fix --with-default-path option.
bcbf86ec 2292 - Autodetect perl, patch from David Rankin
a0f84251 2293 <drankin@bohemians.lexington.ky.us>
bcbf86ec 2294 - Print whether OpenSSH was compiled with RSARef, patch from
0a2ff95d 2295 Nalin Dahyabhai <nalin@thermo.stat.ncsu.edu>
bcbf86ec 2296 - Calls to pam_setcred, patch from Nalin Dahyabhai
f91bacbd 2297 <nalin@thermo.stat.ncsu.edu>
e3a93db0 2298 - Detect missing size_t and typedef it.
5ab44a92 2299 - Rename helper.[ch] to (more appropriate) bsd-misc.[ch]
2300 - Minor Makefile cleaning
c73a0cb5 2301
b6019d68 230219991228
2303 - Replacement for getpagesize() for systems which lack it
bcbf86ec 2304 - NetBSD login.c compile fix from David Rankin
70e0115b 2305 <drankin@bohemians.lexington.ky.us>
2306 - Fully set ut_tv if present in utmp or utmpx
d94aa2ae 2307 - Portability fixes for Irix 5.3 (now compiles OK!)
2308 - autoconf and other misc cleanups
ea1970a3 2309 - Merged AIX patch from Darren Hall <dhall@virage.org>
2310 - Cleaned up defines.h
fa9a2dd6 2311 - Released 1.2.1pre22
b6019d68 2312
d2dcff5f 231319991227
2314 - Automatically correct paths in manpages and configuration files. Patch
2315 and script from Andre Lucas <andre.lucas@dial.pipex.com>
2316 - Removed credits from README to CREDITS file, updated.
cb807f40 2317 - Added --with-default-path to specify custom path for server
2318 - Removed #ifdef trickery from acconfig.h into defines.h
36a5b38e 2319 - PAM bugfix. PermitEmptyPassword was being ignored.
2320 - Fixed PAM config files to allow empty passwords if server does.
2321 - Explained spurious PAM auth warning workaround in UPGRADING
21feb5fa 2322 - Use last few chars of tty line as ut_id
5a7794be 2323 - New SuSE RPM spec file from Chris Saia <csaia@wtower.com>
00e6dd70 2324 - OpenBSD CVS updates:
2325 - [packet.h auth-rhosts.c]
2326 check format string for packet_disconnect and packet_send_debug, too
2327 - [channels.c]
2328 use packet_get_maxsize for channels. consistence.
d2dcff5f 2329
f74efc8d 233019991226
2331 - Enabled utmpx support by default for Solaris
2332 - Cleanup sshd.c PAM a little more
bc7ea646 2333 - Revised RPM package to include Jim Knoble's <jmknoble@pobox.com>
2334 X11 ssh-askpass program.
20c43d8c 2335 - Disable logging of PAM success and failures, PAM is verbose enough.
bcbf86ec 2336 Unfortunatly there is currently no way to disable auth failure
2337 messages. Mention this in UPGRADING file and sent message to PAM
20c43d8c 2338 developers
83b7f649 2339 - OpenBSD CVS update:
2340 - [ssh-keygen.1 ssh.1]
bcbf86ec 2341 remove ref to .ssh/random_seed, mention .ssh/environment in
83b7f649 2342 .Sh FILES, too
72251cb6 2343 - Released 1.2.1pre21
bcbf86ec 2344 - Fixed implicit '.' in default path, report from Jim Knoble
72251cb6 2345 <jmknoble@pobox.com>
30a39691 2346 - Redhat RPM spec fixes from Jim Knoble <jmknoble@pobox.com>
f74efc8d 2347
f498ed15 234819991225
2349 - More fixes from Andre Lucas <andre.lucas@dial.pipex.com>
2350 - Cleanup of auth-passwd.c for shadow and MD5 passwords
2351 - Cleanup and bugfix of PAM authentication code
f74efc8d 2352 - Released 1.2.1pre20
2353
2354 - Merged fixes from Ben Taylor <bent@clark.net>
2355 - Fixed configure support for PAM. Reported by Naz <96na@eng.cam.ac.uk>
2356 - Disabled logging of PAM password authentication failures when password
2357 is empty. (e.g start of authentication loop). Reported by Naz
2358 <96na@eng.cam.ac.uk>)
f498ed15 2359
236019991223
bcbf86ec 2361 - Merged later HPUX patch from Andre Lucas
f498ed15 2362 <andre.lucas@dial.pipex.com>
2363 - Above patch included better utmpx support from Ben Taylor
f74efc8d 2364 <bent@clark.net>
f498ed15 2365
eef6f7e9 236619991222
bcbf86ec 2367 - Fix undefined fd_set type in ssh.h from Povl H. Pedersen
eef6f7e9 2368 <pope@netguide.dk>
ae28776a 2369 - Fix login.c breakage on systems which lack ut_host in struct
2370 utmp. Reported by Willard Dawson <willard.dawson@sbs.siemens.com>
eef6f7e9 2371
a7effaac 237219991221
bcbf86ec 2373 - Integration of large HPUX patch from Andre Lucas
2374 <andre.lucas@dial.pipex.com>. Integrating it had a few other
a7effaac 2375 benefits:
2376 - Ability to disable shadow passwords at configure time
2377 - Ability to disable lastlog support at configure time
2378 - Support for IP address in $DISPLAY
ae2f7af7 2379 - OpenBSD CVS update:
2380 - [sshconnect.c]
2381 say "REMOTE HOST IDENTIFICATION HAS CHANGED"
59dd7a31 2382 - Fix DISABLE_SHADOW support
2383 - Allow MD5 passwords even if shadow passwords are disabled
16034de9 2384 - Release 1.2.1pre19
a7effaac 2385
3f1d9bcd 238619991218
bcbf86ec 2387 - Redhat init script patch from Chun-Chung Chen
3f1d9bcd 2388 <cjj@u.washington.edu>
7e1c2490 2389 - Avoid breakage on systems without IPv6 headers
3f1d9bcd 2390
60d804c8 239119991216
bcbf86ec 2392 - Makefile changes for Solaris from Peter Kocks
60d804c8 2393 <peter.kocks@baygate.com>
89cafde6 2394 - Minor updates to docs
2395 - Merged OpenBSD CVS changes:
2396 - [authfd.c ssh-agent.c]
2397 keysize warnings talk about identity files
2398 - [packet.c]
2399 "Connection closed by x.x.x.x": fatal() -> log()
bcbf86ec 2400 - Correctly handle empty passwords in shadow file. Patch from:
c9d323f0 2401 "Chris, the Young One" <cky@pobox.com>
2402 - Released 1.2.1pre18
60d804c8 2403
7dc6fc6d 240419991215
2405 - Integrated patchs from Juergen Keil <jk@tools.de>
2406 - Avoid void* pointer arithmatic
2407 - Use LDFLAGS correctly
68227e6d 2408 - Fix SIGIO error in scp
2409 - Simplify status line printing in scp
bcbf86ec 2410 - Added better test for inline functions compiler support from
906a2515 2411 Darren_Hall@progressive.com
7dc6fc6d 2412
95f1eccc 241319991214
2414 - OpenBSD CVS Changes
2415 - [canohost.c]
bcbf86ec 2416 fix get_remote_port() and friends for sshd -i;
95f1eccc 2417 Holger.Trapp@Informatik.TU-Chemnitz.DE
2418 - [mpaux.c]
2419 make code simpler. no need for memcpy. niels@ ok
2420 - [pty.c]
2421 namebuflen not sizeof namebuflen; bnd@ep-ag.com via djm@mindrot.org
2422 fix proto; markus
2423 - [ssh.1]
2424 typo; mark.baushke@solipsa.com
2425 - [channels.c ssh.c ssh.h sshd.c]
2426 type conflict for 'extern Type *options' in channels.c; dot@dotat.at
2427 - [sshconnect.c]
2428 move checking of hostkey into own function.
2429 - [version.h]
2430 OpenSSH-1.2.1
884bcb37 2431 - Clean up broken includes in pty.c
7303768f 2432 - Some older systems don't have poll.h, they use sys/poll.h instead
2433 - Doc updates
95f1eccc 2434
847e8865 243519991211
bcbf86ec 2436 - Fix compilation on systems with AFS. Reported by
847e8865 2437 aloomis@glue.umd.edu
bcbf86ec 2438 - Fix installation on Solaris. Reported by
847e8865 2439 Gordon Rowell <gordonr@gormand.com.au>
2440 - Fix gccisms (__attribute__ and inline). Report by edgy@us.ibm.com,
2441 patch from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
2442 - Auto-locate xauth. Patch from David Agraz <dagraz@jahoopa.com>
2443 - Compile fix from David Agraz <dagraz@jahoopa.com>
2444 - Avoid compiler warning in bsd-snprintf.c
bcbf86ec 2445 - Added pam_limits.so to default PAM config. Suggested by
847e8865 2446 Jim Knoble <jmknoble@pobox.com>
2447
8946db53 244819991209
2449 - Import of patch from Ben Taylor <bent@clark.net>:
2450 - Improved PAM support
2451 - "uninstall" rule for Makefile
2452 - utmpx support
2453 - Should fix PAM problems on Solaris
2d86a6cc 2454 - OpenBSD CVS updates:
2455 - [readpass.c]
2456 avoid stdio; based on work by markus, millert, and I
2457 - [sshd.c]
2458 make sure the client selects a supported cipher
2459 - [sshd.c]
bcbf86ec 2460 fix sighup handling. accept would just restart and daemon handled
2461 sighup only after the next connection was accepted. use poll on
2d86a6cc 2462 listen sock now.
2463 - [sshd.c]
2464 make that a fatal
87e91331 2465 - Applied patch from David Rankin <drankin@bohemians.lexington.ky.us>
2466 to fix libwrap support on NetBSD
5001b9e4 2467 - Released 1.2pre17
8946db53 2468
6d8c4ea4 246919991208
bcbf86ec 2470 - Compile fix for Solaris with /dev/ptmx from
6d8c4ea4 2471 David Agraz <dagraz@jahoopa.com>
2472
4285816a 247319991207
2474 - sshd Redhat init script patch from Jim Knoble <jmknoble@pobox.com>
2475 fixes compatability with 4.x and 5.x
db28aeb5 2476 - Fixed default SSH_ASKPASS
bcbf86ec 2477 - Fix PAM account and session being called multiple times. Problem
d465f2ca 2478 reported by Adrian Baugh <adrian@merlin.keble.ox.ac.uk>
a408af76 2479 - Merged more OpenBSD changes:
2480 - [atomicio.c authfd.c scp.c serverloop.c ssh.h sshconnect.c sshd.c]
bcbf86ec 2481 move atomicio into it's own file. wrap all socket write()s which
a408af76 2482 were doing write(sock, buf, len) != len, with atomicio() calls.
2483 - [auth-skey.c]
2484 fd leak
2485 - [authfile.c]
2486 properly name fd variable
2487 - [channels.c]
2488 display great hatred towards strcpy
2489 - [pty.c pty.h sshd.c]
2490 use openpty() if it exists (it does on BSD4_4)
2491 - [tildexpand.c]
2492 check for ~ expansion past MAXPATHLEN
2493 - Modified helper.c to use new atomicio function.
2494 - Reformat Makefile a little
2495 - Moved RC4 routines from rc4.[ch] into helper.c
2496 - Added autoconf code to detect /dev/ptmx (Solaris) and /dev/ptc (AIX)
9983a8ca 2497 - Updated SuSE spec from Chris Saia <csaia@wtower.com>
2498 - Tweaked Redhat spec
9158d92f 2499 - Clean up bad imports of a few files (forgot -kb)
2500 - Released 1.2pre16
4285816a 2501
9c7b6dfd 250219991204
2503 - Small cleanup of PAM code in sshd.c
57112b5a 2504 - Merged OpenBSD CVS changes:
2505 - [auth-krb4.c auth-passwd.c auth-skey.c ssh.h]
2506 move skey-auth from auth-passwd.c to auth-skey.c, same for krb4
2507 - [auth-rsa.c]
2508 warn only about mismatch if key is _used_
2509 warn about keysize-mismatch with log() not error()
2510 channels.c readconf.c readconf.h ssh.c ssh.h sshconnect.c
2511 ports are u_short
2512 - [hostfile.c]
2513 indent, shorter warning
2514 - [nchan.c]
2515 use error() for internal errors
2516 - [packet.c]
2517 set loglevel for SSH_MSG_DISCONNECT to log(), not fatal()
2518 serverloop.c
2519 indent
2520 - [ssh-add.1 ssh-add.c ssh.h]
2521 document $SSH_ASKPASS, reasonable default
2522 - [ssh.1]
2523 CheckHostIP is not available for connects via proxy command
2524 - [sshconnect.c]
2525 typo
2526 easier to read client code for passwd and skey auth
2527 turn of checkhostip for proxy connects, since we don't know the remote ip
9c7b6dfd 2528
dad3b556 252919991126
2530 - Add definition for __P()
2531 - Added [v]snprintf() replacement for systems that lack it
2532
0ce43ae4 253319991125
2534 - More reformatting merged from OpenBSD CVS
2535 - Merged OpenBSD CVS changes:
2536 - [channels.c]
2537 fix packet_integrity_check() for !have_hostname_in_open.
2538 report from mrwizard@psu.edu via djm@ibs.com.au
2539 - [channels.c]
2540 set SO_REUSEADDR and SO_LINGER for forwarded ports.
2541 chip@valinux.com via damien@ibs.com.au
2542 - [nchan.c]
2543 it's not an error() if shutdown_write failes in nchan.
2544 - [readconf.c]
2545 remove dead #ifdef-0-code
2546 - [readconf.c servconf.c]
2547 strcasecmp instead of tolower
2548 - [scp.c]
2549 progress meter overflow fix from damien@ibs.com.au
2550 - [ssh-add.1 ssh-add.c]
2551 SSH_ASKPASS support
2552 - [ssh.1 ssh.c]
2553 postpone fork_after_authentication until command execution,
2554 request/patch from jahakala@cc.jyu.fi via damien@ibs.com.au
2555 plus: use daemon() for backgrounding
cf8dd513 2556 - Added BSD compatible install program and autoconf test, thanks to
2557 Niels Kristian Bech Jensen <nkbj@image.dk>
2558 - Solaris fixing, thanks to Ben Taylor <bent@clark.net>
09041313 2559 - Merged beginnings of AIX support from Tor-Ake Fransson <torake@hotmail.com>
3dbefdb8 2560 - Release 1.2pre15
0ce43ae4 2561
5260325f 256219991124
2563 - Merged very large OpenBSD source code reformat
2564 - OpenBSD CVS updates
2565 - [channels.c cipher.c compat.c log-client.c scp.c serverloop.c]
2566 [ssh.h sshd.8 sshd.c]
2567 syslog changes:
2568 * Unified Logmessage for all auth-types, for success and for failed
2569 * Standard connections get only ONE line in the LOG when level==LOG:
2570 Auth-attempts are logged only, if authentication is:
2571 a) successfull or
2572 b) with passwd or
2573 c) we had more than AUTH_FAIL_LOG failues
2574 * many log() became verbose()
2575 * old behaviour with level=VERBOSE
2576 - [readconf.c readconf.h ssh.1 ssh.h sshconnect.c sshd.c]
2577 tranfer s/key challenge/response data in SSH_SMSG_AUTH_TIS_CHALLENGE
2578 messages. allows use of s/key in windows (ttssh, securecrt) and
2579 ssh-1.2.27 clients without 'ssh -v', ok: niels@
2580 - [sshd.8]
2581 -V, for fallback to openssh in SSH2 compatibility mode
2582 - [sshd.c]
2583 fix sigchld race; cjc5@po.cwru.edu
2584
4655fe80 258519991123
2586 - Added SuSE package files from Chris Saia <csaia@wtower.com>
8b241e50 2587 - Restructured package-related files under packages/*
4655fe80 2588 - Added generic PAM config
8b241e50 2589 - Numerous little Solaris fixes
9c08d6ce 2590 - Add recommendation to use GNU make to INSTALL document
4655fe80 2591
60bed5fd 259219991122
2593 - Make <enter> close gnome-ssh-askpass (Debian bug #50299)
2f2cc3f9 2594 - OpenBSD CVS Changes
bcbf86ec 2595 - [ssh-keygen.c]
2596 don't create ~/.ssh only if the user wants to store the private
2597 key there. show fingerprint instead of public-key after
2f2cc3f9 2598 keygeneration. ok niels@
b09a984b 2599 - Added OpenBSD bsd-strlcat.c, created bsd-strlcat.h
96ad4350 2600 - Added timersub() macro
b09a984b 2601 - Tidy RCSIDs of bsd-*.c
bcbf86ec 2602 - Added autoconf test and macro to deal with old PAM libraries
96ad4350 2603 pam_strerror definition (one arg vs two).
530f1889 2604 - Fix EGD problems (Thanks to Ben Taylor <bent@clark.net>)
bcbf86ec 2605 - Retry /dev/urandom reads interrupted by signal (report from
530f1889 2606 Robert Hardy <rhardy@webcon.net>)
1647c2b5 2607 - Added a setenv replacement for systems which lack it
d84a9a44 2608 - Only display public key comment when presenting ssh-askpass dialog
2609 - Released 1.2pre14
60bed5fd 2610
bcbf86ec 2611 - Configure, Make and changelog corrections from Tudor Bosman
2ddcfdf3 2612 <tudorb@jm.nu> and Niels Kristian Bech Jensen <nkbj@image.dk>
2613
9d6b7add 261419991121
2f2cc3f9 2615 - OpenBSD CVS Changes:
60bed5fd 2616 - [channels.c]
2617 make this compile, bad markus
2618 - [log.c readconf.c servconf.c ssh.h]
2619 bugfix: loglevels are per host in clientconfig,
2620 factor out common log-level parsing code.
2621 - [servconf.c]
2622 remove unused index (-Wall)
2623 - [ssh-agent.c]
2624 only one 'extern char *__progname'
2625 - [sshd.8]
2626 document SIGHUP, -Q to synopsis
2627 - [sshconnect.c serverloop.c sshd.c packet.c packet.h]
2628 [channels.c clientloop.c]
2629 SSH_CMSG_MAX_PACKET_SIZE, some clients use this, some need this, niels@
2630 [hope this time my ISP stays alive during commit]
2631 - [OVERVIEW README] typos; green@freebsd
2632 - [ssh-keygen.c]
2633 replace xstrdup+strcat with strlcat+fixed buffer, fixes OF (bad me)
2634 exit if writing the key fails (no infinit loop)
2635 print usage() everytime we get bad options
2636 - [ssh-keygen.c] overflow, djm@mindrot.org
2637 - [sshd.c] fix sigchld race; cjc5@po.cwru.edu
bcbf86ec 2638
2b942fe0 263919991120
bcbf86ec 2640 - Merged more Solaris support from Marc G. Fournier
2b942fe0 2641 <marc.fournier@acadiau.ca>
2642 - Wrote autoconf tests for integer bit-types
2643 - Fixed enabling kerberos support
bcbf86ec 2644 - Fix segfault in ssh-keygen caused by buffer overrun in filename
13c36c4c 2645 handling.
2b942fe0 2646
06479889 264719991119
2648 - Merged PAM buffer overrun patch from Chip Salzenberg <chip@valinux.com>
2ad77510 2649 - Merged OpenBSD CVS changes
2650 - [auth-rhosts.c auth-rsa.c ssh-agent.c sshconnect.c sshd.c]
2651 more %d vs. %s in fmt-strings
2652 - [authfd.c]
2653 Integers should not be printed with %s
7b1cc56c 2654 - EGD uses a socket, not a named pipe. Duh.
2655 - Fix includes in fingerprint.c
29dbde15 2656 - Fix scp progress bar bug again.
bcbf86ec 2657 - Move ssh-askpass from ${libdir}/ssh to ${libexecdir}/ssh at request of
736890c4 2658 David Rankin <drankin@bohemians.lexington.ky.us>
91b8065d 2659 - Added autoconf option to enable Kerberos 4 support (untested)
2660 - Added autoconf option to enable AFS support (untested)
2661 - Added autoconf option to enable S/Key support (untested)
2662 - Added autoconf option to enable TCP wrappers support (compiles OK)
beb43d31 2663 - Renamed BSD helper function files to bsd-*
bcbf86ec 2664 - Added tests for login and daemon and enable OpenBSD replacements for
caf3bc51 2665 when they are absent.
2666 - Added non-PAM MD5 password support patch from Tudor Bosman <tudorb@jm.nu>
06479889 2667
2bd61362 266819991118
2669 - Merged OpenBSD CVS changes
2670 - [scp.c] foregroundproc() in scp
2671 - [sshconnect.h] include fingerprint.h
bcbf86ec 2672 - [sshd.c] bugfix: the log() for passwd-auth escaped during logging
2bd61362 2673 changes.
0c16a097 2674 - [ssh.1] Spell my name right.
2bd61362 2675 - Added openssh.com info to README
2676
f095fcc7 267719991117
2678 - Merged OpenBSD CVS changes
2679 - [ChangeLog.Ylonen] noone needs this anymore
2680 - [authfd.c] close-on-exec for auth-socket, ok deraadt
bcbf86ec 2681 - [hostfile.c]
2682 in known_hosts key lookup the entry for the bits does not need
2683 to match, all the information is contained in n and e. This
2684 solves the problem with buggy servers announcing the wrong
f095fcc7 2685 modulus length. markus and me.
bcbf86ec 2686 - [serverloop.c]
2687 bugfix: check for space if child has terminated, from:
f095fcc7 2688 iedowse@maths.tcd.ie
2689 - [ssh-add.1 ssh-add.c ssh-keygen.1 ssh-keygen.c sshconnect.c]
2690 [fingerprint.c fingerprint.h]
2691 rsa key fingerprints, idea from Bjoern Groenvall <bg@sics.se>
2692 - [ssh-agent.1] typo
2693 - [ssh.1] add OpenSSH information to AUTHOR section. okay markus@
bcbf86ec 2694 - [sshd.c]
f095fcc7 2695 force logging to stderr while loading private key file
2696 (lost while converting to new log-levels)
2697
4d195447 269819991116
2699 - Fix some Linux libc5 problems reported by Miles Wilson <mw@mctitle.com>
2700 - Merged OpenBSD CVS changes:
2701 - [auth-rh-rsa.c auth-rsa.c authfd.c authfd.h hostfile.c mpaux.c]
2702 [mpaux.h ssh-add.c ssh-agent.c ssh.h ssh.c sshd.c]
2703 the keysize of rsa-parameter 'n' is passed implizit,
2704 a few more checks and warnings about 'pretended' keysizes.
2705 - [cipher.c cipher.h packet.c packet.h sshd.c]
2706 remove support for cipher RC4
2707 - [ssh.c]
2708 a note for legay systems about secuity issues with permanently_set_uid(),
2709 the private hostkey and ptrace()
2710 - [sshconnect.c]
2711 more detailed messages about adding and checking hostkeys
2712
dad9a31e 271319991115
2714 - Merged OpenBSD CVS changes:
bcbf86ec 2715 - [ssh-add.c] change passphrase loop logic and remove ref to
dad9a31e 2716 $DISPLAY, ok niels
2717 - Changed to ssh-add.c broke askpass support. Revised it to be a little more
bcbf86ec 2718 modular.
dad9a31e 2719 - Revised autoconf support for enabling/disabling askpass support.
e7c0f9d5 2720 - Merged more OpenBSD CVS changes:
704b1659 2721 [auth-krb4.c]
2722 - disconnect if getpeername() fails
2723 - missing xfree(*client)
2724 [canohost.c]
2725 - disconnect if getpeername() fails
2726 - fix comment: we _do_ disconnect if ip-options are set
2727 [sshd.c]
2728 - disconnect if getpeername() fails
2729 - move checking of remote port to central place
2730 [auth-rhosts.c] move checking of remote port to central place
2731 [log-server.c] avoid extra fd per sshd, from millert@
2732 [readconf.c] print _all_ bad config-options in ssh(1), too
2733 [readconf.h] print _all_ bad config-options in ssh(1), too
2734 [ssh.c] print _all_ bad config-options in ssh(1), too
2735 [sshconnect.c] disconnect if getpeername() fails
e7c0f9d5 2736 - OpenBSD's changes to sshd.c broke the PAM stuff, re-merged it.
c75a1a66 2737 - Various small cleanups to bring diff (against OpenBSD) size down.
f601d847 2738 - Merged more Solaris compability from Marc G. Fournier
2739 <marc.fournier@acadiau.ca>
2740 - Wrote autoconf tests for __progname symbol
8c119fd0 2741 - RPM spec file fixes from Jim Knoble <jmknoble@pobox.com>
0c372277 2742 - Released 1.2pre12
2743
2744 - Another OpenBSD CVS update:
2745 - [ssh-keygen.1] fix .Xr
dad9a31e 2746
92da7197 274719991114
2748 - Solaris compilation fixes (still imcomplete)
2749
94f7bb9e 275019991113
dd092f97 2751 - Build patch from Niels Kristian Bech Jensen <nkbj@image.dk>
2752 - Don't install config files if they already exist
2753 - Fix inclusion of additional preprocessor directives from acconfig.h
94f7bb9e 2754 - Removed redundant inclusions of config.h
e9c75a39 2755 - Added 'Obsoletes' lines to RPM spec file
94f7bb9e 2756 - Merged OpenBSD CVS changes:
2757 - [bufaux.c] save a view malloc/memcpy/memset/free's, ok niels
bcbf86ec 2758 - [scp.c] fix overflow reported by damien@ibs.com.au: off_t
94f7bb9e 2759 totalsize, ok niels,aaron
bcbf86ec 2760 - Delay fork (-f option) in ssh until after port forwarded connections
94f7bb9e 2761 have been initialised. Patch from Jani Hakala <jahakala@cc.jyu.fi>
b2344d54 2762 - Added shadow password patch from Thomas Neumann <tom@smart.ruhr.de>
2763 - Added ifdefs to auth-passwd.c to exclude it when PAM is enabled
dd092f97 2764 - Tidied default config file some more
2765 - Revised Redhat initscript to fix bug: sshd (re)start would fail
2766 if executed from inside a ssh login.
94f7bb9e 2767
e35c1dc2 276819991112
2769 - Merged changes from OpenBSD CVS
2770 - [sshd.c] session_key_int may be zero
b4748e2f 2771 - [auth-rh-rsa.c servconf.c servconf.h ssh.h sshd.8 sshd.c sshd_config]
bcbf86ec 2772 IgnoreUserKnownHosts(default=no), used for RhostRSAAuth, ok
b4748e2f 2773 deraadt,millert
2774 - Brought default sshd_config more in line with OpenBSD's
547c9f30 2775 - Grab server in gnome-ssh-askpass (Debian bug #49872)
2776 - Released 1.2pre10
e35c1dc2 2777
8bc7973f 2778 - Added INSTALL documentation
6fa724bc 2779 - Merged yet more changes from OpenBSD CVS
2780 - [auth-rh-rsa.c auth-rhosts.c auth-rsa.c channels.c clientloop.c]
2781 [ssh.c ssh.h sshconnect.c sshd.c]
2782 make all access to options via 'extern Options options'
2783 and 'extern ServerOptions options' respectively;
2784 options are no longer passed as arguments:
2785 * make options handling more consistent
2786 * remove #include "readconf.h" from ssh.h
2787 * readconf.h is only included if necessary
2788 - [mpaux.c] clear temp buffer
2789 - [servconf.c] print _all_ bad options found in configfile
045672f9 2790 - Make ssh-askpass support optional through autoconf
59b0f0d4 2791 - Fix nasty division-by-zero error in scp.c
2792 - Released 1.2pre11
8bc7973f 2793
4cca272e 279419991111
2795 - Added (untested) Entropy Gathering Daemon (EGD) support
67d68e3a 2796 - Fixed /dev/urandom fd leak (Debian bug #49722)
5bbb5681 2797 - Merged OpenBSD CVS changes:
2798 - [auth-rh-rsa.c] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
2799 - [ssh.1] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
2800 - [sshd.8] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
bcbf86ec 2801 - Fix integer overflow which was messing up scp's progress bar for large
3f1d9bcd 2802 file transfers. Fix submitted to OpenBSD developers. Report and fix
2803 from Kees Cook <cook@cpoint.net>
6a17f9c2 2804 - Merged more OpenBSD CVS changes:
bcbf86ec 2805 - [auth-krb4.c auth-passwd.c] remove x11- and krb-cleanup from fatal()
6a17f9c2 2806 + krb-cleanup cleanup
2807 - [clientloop.c log-client.c log-server.c ]
2808 [readconf.c readconf.h servconf.c servconf.h ]
2809 [ssh.1 ssh.c ssh.h sshd.8]
2810 add LogLevel {QUIET, FATAL, ERROR, INFO, CHAT, DEBUG} to ssh/sshd,
2811 obsoletes QuietMode and FascistLogging in sshd.
e35c1dc2 2812 - [sshd.c] fix fatal/assert() bug reported by damien@ibs.com.au:
2813 allow session_key_int != sizeof(session_key)
2814 [this should fix the pre-assert-removal-core-files]
2815 - Updated default config file to use new LogLevel option and to improve
2816 readability
2817
f370266e 281819991110
67d68e3a 2819 - Merged several minor fixes:
f370266e 2820 - ssh-agent commandline parsing
2821 - RPM spec file now installs ssh setuid root
2822 - Makefile creates libdir
4cca272e 2823 - Merged beginnings of Solaris compability from Marc G. Fournier
2824 <marc.fournier@acadiau.ca>
f370266e 2825
d4f11b59 282619991109
2827 - Autodetection of SSL/Crypto library location via autoconf
2828 - Fixed location of ssh-askpass to follow autoconf
2829 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
2830 - Autodetection of RSAref library for US users
2831 - Minor doc updates
560557bb 2832 - Merged OpenBSD CVS changes:
2833 - [rsa.c] bugfix: use correct size for memset()
2834 - [sshconnect.c] warn if announced size of modulus 'n' != real size
f025becb 2835 - Added GNOME passphrase requestor (use --with-gnome-askpass)
d397b172 2836 - RPM build now creates subpackages
aa51e7cc 2837 - Released 1.2pre9
d4f11b59 2838
e1a9c08d 283919991108
2840 - Removed debian/ directory. This is now being maintained separately.
2841 - Added symlinks for slogin in RPM spec file
2842 - Fixed permissions on manpages in RPM spec file
2843 - Added references to required libraries in README file
2844 - Removed config.h.in from CVS
2845 - Removed pwdb support (better pluggable auth is provided by glibc)
2846 - Made PAM and requisite libdl optional
2847 - Removed lots of unnecessary checks from autoconf
2848 - Added support and autoconf test for openpty() function (Unix98 pty support)
2849 - Fix for scp not finding ssh if not installed as /usr/bin/ssh
2850 - Added TODO file
2851 - Merged parts of Debian patch From Phil Hands <phil@hands.com>:
2852 - Added ssh-askpass program
2853 - Added ssh-askpass support to ssh-add.c
2854 - Create symlinks for slogin on install
2855 - Fix "distclean" target in makefile
2856 - Added example for ssh-agent to manpage
2857 - Added support for PAM_TEXT_INFO messages
2858 - Disable internal /etc/nologin support if PAM enabled
2859 - Merged latest OpenBSD CVS changes:
5bae4ab8 2860 - [all] replace assert() with error, fatal or packet_disconnect
e1a9c08d 2861 - [sshd.c] don't send fail-msg but disconnect if too many authentication
2862 failures
e1a9c08d 2863 - [sshd.c] remove unused argument. ok dugsong
2864 - [sshd.c] typo
2865 - [rsa.c] clear buffers used for encryption. ok: niels
2866 - [rsa.c] replace assert() with error, fatal or packet_disconnect
ade6fccd 2867 - [auth-krb4.c] remove unused argument. ok dugsong
e1a9c08d 2868 - Fixed coredump after merge of OpenBSD rsa.c patch
9010d60a 2869 - Released 1.2pre8
e1a9c08d 2870
3028328e 287119991102
2872 - Merged change from OpenBSD CVS
2873 - One-line cleanup in sshd.c
2874
474832c5 287519991030
2876 - Integrated debian package support from Dan Brosemer <odin@linuxfreak.com>
69256d9d 2877 - Merged latest updates for OpenBSD CVS:
2878 - channels.[ch] - remove broken x11 fix and document istate/ostate
2879 - ssh-agent.c - call setsid() regardless of argv[]
2880 - ssh.c - save a few lines when disabling rhosts-{rsa-}auth
2881 - Documentation cleanups
2882 - Renamed README -> README.Ylonen
2883 - Renamed README.openssh ->README
474832c5 2884
339660f6 288519991029
2886 - Renamed openssh* back to ssh* at request of Theo de Raadt
2887 - Incorporated latest changes from OpenBSD's CVS
2888 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
2889 - Integrated PAM env patch from Nalin Dahyabhai <nalin.dahyabhai@pobox.com>
549b3eed 2890 - Make distclean now removed configure script
2891 - Improved PAM logging
2892 - Added some debug() calls for PAM
4ecd19ea 2893 - Removed redundant subdirectories
bcbf86ec 2894 - Integrated part of a patch from Dan Brosemer <odin@linuxfreak.com> for
4ecd19ea 2895 building on Debian.
242588e6 2896 - Fixed off-by-one error in PAM env patch
2897 - Released 1.2pre6
339660f6 2898
5881cd60 289919991028
2900 - Further PAM enhancements.
2901 - Much cleaner
2902 - Now uses account and session modules for all logins.
2903 - Integrated patch from Dan Brosemer <odin@linuxfreak.com>
2904 - Build fixes
2905 - Autoconf
2906 - Change binary names to open*
2907 - Fixed autoconf script to detect PAM on RH6.1
2908 - Added tests for libpwdb, and OpenBSD functions to autoconf
221395b3 2909 - Released 1.2pre4
fca82d2e 2910
2911 - Imported latest OpenBSD CVS code
2912 - Updated README.openssh
93f04616 2913 - Released 1.2pre5
fca82d2e 2914
5881cd60 291519991027
2916 - Adapted PAM patch.
2917 - Released 1.0pre2
2918
2919 - Excised my buggy replacements for strlcpy and mkdtemp
2920 - Imported correct OpenBSD strlcpy and mkdtemp routines.
2921 - Reduced arc4random_stir entropy read to 32 bytes (256 bits)
2922 - Picked up correct version number from OpenBSD
2923 - Added sshd.pam PAM configuration file
2924 - Added sshd.init Redhat init script
2925 - Added openssh.spec RPM spec file
2926 - Released 1.2pre3
2927
292819991026
2929 - Fixed include paths of OpenSSL functions
2930 - Use OpenSSL MD5 routines
2931 - Imported RC4 code from nanocrypt
2932 - Wrote replacements for OpenBSD arc4random* functions
2933 - Wrote replacements for strlcpy and mkdtemp
2934 - Released 1.0pre1
This page took 0.566566 seconds and 5 git commands to generate.