]> andersk Git - openssh.git/blame - ChangeLog
- (bal) mispelling in uidswap.c (portable only)
[openssh.git] / ChangeLog
CommitLineData
ca7e8e1e 120020402
2 - (bal) Hand Sync of scp.c (reverted to upstream code)
3 - deraadt@cvs.openbsd.org 2002/03/30 17:45:46
4 [scp.c]
5 stretch banners
c572a874 6 - (bal) CVS ID sync of uidswap.c
783dbbdc 7 - (bal) OpenBSD CVS Sync (now for the real sync)
8 - markus@cvs.openbsd.org 2002/03/27 22:21:45
9 [ssh-keygen.c]
10 try to import keys with extra trailing === (seen with ssh.com < 2.0.12)
49a34e84 11 - markus@cvs.openbsd.org 2002/03/28 15:34:51
12 [session.c]
13 do not call record_login twice (for use_privsep)
ffbf7323 14 - markus@cvs.openbsd.org 2002/03/29 18:59:32
15 [session.c session.h]
16 retrieve last login time before the pty is allocated, store per session
3bc822df 17 - stevesk@cvs.openbsd.org 2002/03/29 19:16:22
18 [sshd.8]
19 RSA key modulus size minimum 768; ok markus@
82b00264 20 - stevesk@cvs.openbsd.org 2002/03/29 19:18:33
21 [auth-rsa.c ssh-rsa.c ssh.h]
22 make RSA modulus minimum #define; ok markus@
8c38e88b 23 - markus@cvs.openbsd.org 2002/03/30 18:51:15
24 [monitor.c serverloop.c sftp-int.c sftp.c sshd.c]
25 check waitpid for EINTR; based on patch from peter@ifm.liu.se
92053302 26 - markus@cvs.openbsd.org 2002/04/01 22:02:16
27 [sftp-client.c]
28 20480 is an upper limit for older server
9c74a24d 29 - markus@cvs.openbsd.org 2002/04/01 22:07:17
30 [sftp-client.c]
31 fallback to stat if server does not support lstat
b745a2f2 32 - markus@cvs.openbsd.org 2002/04/02 11:49:39
33 [ssh-agent.c]
34 check $SHELL for -k and -d, too;
35 http://bugzilla.mindrot.org/show_bug.cgi?id=199
b69145c2 36 - markus@cvs.openbsd.org 2002/04/02 17:37:48
37 [sftp.c]
38 always call log_init()
c9336aed 39 - markus@cvs.openbsd.org 2002/04/02 20:11:38
40 [ssh-rsa.c]
41 ignore SSH_BUG_SIGBLOB for ssh-rsa; #187
c895376b 42 - (bal) mispelling in uidswap.c (portable only)
ca7e8e1e 43
8b314ec9 4420020401
45 - (stevesk) [monitor.c] PAM should work again; will *not* work with
46 UsePrivilegeSeparation=yes.
3906af0f 47 - (stevesk) [auth1.c] fix password auth for protocol 1 when
48 !USE_PAM && !HAVE_OSF_SIA; merge issue.
8b314ec9 49
267e920e 5020020331
51 - (tim) [configure.ac] use /bin/test -L to work around broken builtin on
52 Solaris 8
ef077e37 53 - (tim) [sshconnect2.c] change uint32_t to u_int32_t
267e920e 54
0461c355 5520020330
56 - (stevesk) [configure.ac] remove header check for sys/ttcompat.h
57 bug 167
58
dd466ff8 5920020327
60 - (bal) 'pw' should be 'authctxt->pw' in auth1.c spotted by
61 kent@lysator.liu.se
17f5e68a 62 - (bal) OpenBSD CVS Sync
63 - markus@cvs.openbsd.org 2002/03/26 11:34:49
64 [ssh.1 sshd.8]
65 update to recent drafts
5fb274c1 66 - markus@cvs.openbsd.org 2002/03/26 11:37:05
67 [ssh.c]
68 update Copyright
19f40184 69 - markus@cvs.openbsd.org 2002/03/26 15:23:40
70 [bufaux.c]
71 do not talk about packets in bufaux
7341fad9 72 - rees@cvs.openbsd.org 2002/03/26 18:46:59
73 [scard.c]
74 try_AUT0 in read_pubkey too, for those paranoid few who want to acl 'sh'
6c112aca 75 - markus@cvs.openbsd.org 2002/03/26 22:50:39
76 [channels.h]
77 CHANNEL_EFD_OUTPUT_ACTIVE is false for CHAN_CLOSE_RCVD, too
52103b10 78 - markus@cvs.openbsd.org 2002/03/26 23:13:03
79 [auth-rsa.c]
80 disallow RSA keys < 768 for protocol 1, too (rhosts-rsa and rsa auth)
76bf34f1 81 - markus@cvs.openbsd.org 2002/03/26 23:14:51
82 [kex.c]
83 generate a new cookie for each SSH2_MSG_KEXINIT message we send out
300e01c4 84 - mouring@cvs.openbsd.org 2002/03/27 11:45:42
85 [monitor.c]
86 monitor_allowed_key() returns int instead of pointer. ok markus@
87
eb4652f4 8820020325
89 - (stevesk) import OpenBSD <sys/tree.h> as "openbsd-compat/tree.h"
47c36e5b 90 - (bal) OpenBSD CVS Sync
91 - stevesk@cvs.openbsd.org 2002/03/23 20:57:26
92 [sshd.c]
93 setproctitle() after preauth child; ok markus@
d452ec1a 94 - markus@cvs.openbsd.org 2002/03/24 16:00:27
95 [serverloop.c]
96 remove unused debug
a49dfdec 97 - markus@cvs.openbsd.org 2002/03/24 16:01:13
98 [packet.c]
99 debug->debug3 for extra padding
5b0d7dc1 100 - stevesk@cvs.openbsd.org 2002/03/24 17:27:03
101 [kexgex.c]
102 typo; ok markus@
d4355079 103 - stevesk@cvs.openbsd.org 2002/03/24 17:53:16
104 [monitor_fdpass.c]
105 minor cleanup and more error checking; ok markus@
9fc0407d 106 - markus@cvs.openbsd.org 2002/03/24 18:05:29
107 [scard.c]
108 we need to figure out AUT0 for sc_private_encrypt, too
38c1c52a 109 - stevesk@cvs.openbsd.org 2002/03/24 23:20:00
110 [monitor.c]
111 remove "\n" from fatal()
159897f3 112 - markus@cvs.openbsd.org 2002/03/25 09:21:13
113 [auth-rsa.c]
114 return 0 (not NULL); tomh@po.crl.go.jp
6f33c8cd 115 - markus@cvs.openbsd.org 2002/03/25 09:25:06
116 [auth-rh-rsa.c]
117 rm bogus comment
0659cace 118 - markus@cvs.openbsd.org 2002/03/25 17:34:27
119 [scard.c scard.h ssh-agent.c ssh-keygen.c ssh.c]
120 change sc_get_key to sc_get_keys and hide smartcard details in scard.c
3074b20c 121 - stevesk@cvs.openbsd.org 2002/03/25 20:12:10
122 [monitor_mm.c monitor_wrap.c]
123 ssize_t args use "%ld" and cast to (long)
124 size_t args use "%lu" and cast to (u_long)
125 ok markus@ and thanks millert@
1c2deed1 126 - markus@cvs.openbsd.org 2002/03/25 21:04:02
127 [ssh.c]
128 simplify num_identity_files handling
d2296ed7 129 - markus@cvs.openbsd.org 2002/03/25 21:13:51
130 [channels.c channels.h compat.c compat.h nchan.c]
131 don't send stderr data after EOF, accept this from older known (broken)
132 sshd servers only, fixes http://bugzilla.mindrot.org/show_bug.cgi?id=179
8e4fd4a1 133 - stevesk@cvs.openbsd.org 2002/03/26 03:24:01
134 [monitor.h monitor_fdpass.h monitor_mm.h monitor_wrap.h]
135 $OpenBSD$
eb4652f4 136
1178e8db 13720020324
138 - (stevesk) [session.c] disable LOGIN_NEEDS_TERM until we are sure
139 it can be removed. only used on solaris. will no longer compile with
140 privsep shuffling.
141
6f34652e 14220020322
143 - (stevesk) HAVE_ACCRIGHTS_IN_MSGHDR configure support
7b18c353 144 - (stevesk) [monitor.c monitor_wrap.c] #ifdef HAVE_PW_CLASS_IN_PASSWD
c921ee00 145 - (stevesk) configure and cpp __FUNCTION__ gymnastics to handle nielsisms
dc90b259 146 - (stevesk) [monitor_fdpass.c] support for access rights style file
147 descriptor passing
f7ed12f1 148 - (stevesk) [auth2.c] merge cleanup/sync
cfadc43b 149 - (stevesk) [defines.h] hp-ux 11 has ancillary data style fd passing, but
150 is missing CMSG_LEN() and CMSG_SPACE() macros.
cc58061e 151 - (stevesk) [defines.h] #define MAP_ANON MAP_ANONYMOUS for HP-UX; other
152 platforms may need this--I'm not sure. mmap() issues will need to be
153 addressed further.
05976246 154 - (tim) [cipher.c] fix problem with OpenBSD sync
9242fa1b 155 - (stevesk) [LICENCE] OpenBSD sync
6f34652e 156
8627f3e0 15720020321
158 - (bal) OpenBSD CVS Sync
159 - itojun@cvs.openbsd.org 2002/03/08 06:10:16
160 [sftp-client.c]
161 printf type mismatch
bfa7f960 162 - itojun@cvs.openbsd.org 2002/03/11 03:18:49
163 [sftp-client.c]
164 correct type mismatches (u_int64_t != unsigned long long)
5fc7dbc9 165 - itojun@cvs.openbsd.org 2002/03/11 03:19:53
166 [sftp-client.c]
167 indent
150a5466 168 - markus@cvs.openbsd.org 2002/03/14 15:24:27
169 [sshconnect1.c]
170 don't trust size sent by (rogue) server; noted by s.esser@e-matters.de
4f08e98d 171 - markus@cvs.openbsd.org 2002/03/14 16:38:26
172 [sshd.c]
173 split out ssh1 session key decryption; ok provos@
46f1eece 174 - markus@cvs.openbsd.org 2002/03/14 16:56:33
175 [auth-rh-rsa.c auth-rsa.c auth.h]
176 split auth_rsa() for better readability and privsep; ok provos@
c390a3c8 177 - itojun@cvs.openbsd.org 2002/03/15 11:00:38
178 [auth.c]
179 fix file type checking (use S_ISREG). ok by markus
bcb68a8f 180 - markus@cvs.openbsd.org 2002/03/16 11:24:53
181 [compress.c]
182 skip inflateEnd if inflate fails; ok provos@
3e65880e 183 - markus@cvs.openbsd.org 2002/03/16 17:22:09
184 [auth-rh-rsa.c auth.h]
185 split auth_rhosts_rsa(), ok provos@
bb15f28b 186 - stevesk@cvs.openbsd.org 2002/03/16 17:41:25
187 [auth-krb5.c]
188 BSD license. from Daniel Kouril via Dug Song. ok markus@
443fa1cd 189 - provos@cvs.openbsd.org 2002/03/17 20:25:56
190 [auth.c auth.h auth1.c auth2.c]
191 getpwnamallow returns struct passwd * only if user valid; okay markus@
1b34c1b3 192 - provos@cvs.openbsd.org 2002/03/18 01:12:14
193 [auth.h auth1.c auth2.c sshd.c]
194 have the authentication functions return the authentication context
195 and then do_authenticated; okay millert@
9d0844e3 196 - dugsong@cvs.openbsd.org 2002/03/18 01:30:10
197 [auth-krb4.c]
198 set client to NULL after xfree(), from Rolf Braun
199 <rbraun+ssh@andrew.cmu.edu>
1836f69f 200 - provos@cvs.openbsd.org 2002/03/18 03:41:08
201 [auth.c session.c]
202 move auth_approval into getpwnamallow with help from millert@
bf8269a9 203 - markus@cvs.openbsd.org 2002/03/18 17:13:15
204 [cipher.c cipher.h]
205 export/import cipher states; needed by ssh-privsep
e050d348 206 - markus@cvs.openbsd.org 2002/03/18 17:16:38
207 [packet.c packet.h]
208 export/import cipher state, iv and ssh2 seqnr; needed by ssh-privsep
d0074658 209 - markus@cvs.openbsd.org 2002/03/18 17:23:31
210 [key.c key.h]
211 add key_demote() for ssh-privsep
b625ad75 212 - provos@cvs.openbsd.org 2002/03/18 17:25:29
213 [bufaux.c bufaux.h]
214 buffer_skip_string and extra sanity checking; needed by ssh-privsep
3d6fc2f8 215 - provos@cvs.openbsd.org 2002/03/18 17:31:54
216 [compress.c]
217 export compression streams for ssh-privsep
1853d1ef 218 - provos@cvs.openbsd.org 2002/03/18 17:50:31
219 [auth-bsdauth.c auth-options.c auth-rh-rsa.c auth-rsa.c auth-skey.c auth.h
220 auth1.c auth2-chall.c auth2.c kex.c kex.h kexdh.c kexgex.c servconf.c
221 session.h servconf.h serverloop.c session.c sshd.c]
222 integrate privilege separated openssh; its turned off by default for now.
223 work done by me and markus@
ce19ff48 224 - provos@cvs.openbsd.org 2002/03/18 17:53:08
225 [sshd.8]
226 credits for privsep
70aa9ff4 227 - provos@cvs.openbsd.org 2002/03/18 17:59:09
228 [sshd.8]
229 document UsePrivilegeSeparation
73fbf637 230 - stevesk@cvs.openbsd.org 2002/03/18 23:52:51
231 [servconf.c]
232 UnprivUser/UnprivGroup usable now--specify numeric user/group; ok
233 provos@
1c352e97 234 - stevesk@cvs.openbsd.org 2002/03/19 03:03:43
235 [pathnames.h servconf.c servconf.h sshd.c]
236 _PATH_PRIVSEP_CHROOT_DIR; ok provos@
fffbaee2 237 - stevesk@cvs.openbsd.org 2002/03/19 05:23:08
238 [sshd.8]
239 Banner has no default.
702b7dd8 240 - mpech@cvs.openbsd.org 2002/03/19 06:32:56
241 [sftp-int.c]
242 use xfree() after xstrdup().
243
244 markus@ ok
51aeb639 245 - markus@cvs.openbsd.org 2002/03/19 10:35:39
246 [auth-options.c auth.h session.c session.h sshd.c]
247 clean up prototypes
762715ce 248 - markus@cvs.openbsd.org 2002/03/19 10:49:35
249 [auth-krb5.c auth-rh-rsa.c auth.c cipher.c key.c misc.h packet.c session.c
250 sftp-client.c sftp-glob.h sftp.c ssh-add.c ssh.c sshconnect2.c sshd.c
251 ttymodes.c]
252 KNF whitespace
5f1f36b5 253 - markus@cvs.openbsd.org 2002/03/19 14:27:39
254 [auth.c auth1.c auth2.c]
255 make getpwnamallow() allways call pwcopy()
06bea668 256 - markus@cvs.openbsd.org 2002/03/19 15:31:47
257 [auth.c]
258 check for NULL; from provos@
2ea6de2b 259 - stevesk@cvs.openbsd.org 2002/03/20 19:12:25
260 [servconf.c servconf.h ssh.h sshd.c]
261 for unprivileged user, group do:
262 pw=getpwnam(SSH_PRIVSEP_USER); do_setusercontext(pw). ok provos@
256debd0 263 - stevesk@cvs.openbsd.org 2002/03/20 21:08:08
264 [sshd.c]
265 strerror() on chdir() fail; ok provos@
edfb66cb 266 - markus@cvs.openbsd.org 2002/03/21 10:21:20
267 [ssh-add.c]
268 ignore errors for nonexisting default keys in ssh-add,
269 fixes http://bugzilla.mindrot.org/show_bug.cgi?id=158
c53c54c2 270 - jakob@cvs.openbsd.org 2002/03/21 15:17:26
271 [clientloop.c ssh.1]
272 add built-in command line for adding new port forwardings on the fly.
273 based on a patch from brian wellington. ok markus@.
7649bbfe 274 - markus@cvs.openbsd.org 2002/03/21 16:38:06
275 [scard.c]
276 make compile w/ openssl 0.9.7
b9f62352 277 - markus@cvs.openbsd.org 2002/03/21 16:54:53
278 [scard.c scard.h ssh-keygen.c]
279 move key upload to scard.[ch]
280 - markus@cvs.openbsd.org 2002/03/21 16:57:15
281 [scard.c]
282 remove const
39ac8430 283 - markus@cvs.openbsd.org 2002/03/21 16:58:13
284 [clientloop.c]
285 remove unused
514b94dc 286 - rees@cvs.openbsd.org 2002/03/21 18:08:15
287 [scard.c]
288 In sc_put_key(), sc_reader_id should be id.
ce1ba33a 289 - markus@cvs.openbsd.org 2002/03/21 20:51:12
290 [sshd_config]
291 add privsep (off)
324bf712 292 - markus@cvs.openbsd.org 2002/03/21 21:23:34
293 [sshd.c]
294 add privsep_preauth() and remove 1 goto; ok provos@
86c4f63d 295 - rees@cvs.openbsd.org 2002/03/21 21:54:34
296 [scard.c scard.h ssh-keygen.c]
297 Add PIN-protection for secret key.
76139bd8 298 - rees@cvs.openbsd.org 2002/03/21 22:44:05
299 [authfd.c authfd.h ssh-add.c ssh-agent.c ssh.c]
300 Add PIN-protection for secret key.
ec9b7086 301 - markus@cvs.openbsd.org 2002/03/21 23:07:37
302 [clientloop.c]
303 remove unused, sync w/ cmdline patch in my tree.
ce1ba33a 304
81dadca3 30520020317
306 - (tim) [configure.ac] Assume path given with --with-pid-dir=PATH is wanted,
307 warn if directory does not exist. Put system directories in front of
308 PATH for finding entorpy commands.
43e41c2c 309 - (tim) [contrib/aix/buildbff.sh contrib/aix/inventory.sh] AIX package
310 build fixes. Patch by Darren Tucker <dtucker@zip.com.au>
311 [contrib/solaris/buildpkg.sh] add missing dirs to SYSTEM_DIR. Have
312 postinstall check for $piddir and add if necessary.
81dadca3 313
e4abf75b 31420020311
315 - (tim) [contrib/solaris/buildpkg.sh, contrib/solaris/README] Updated to
316 build on all platforms that support SVR4 style package tools. Now runs
317 from build dir. Parts are based on patches from Antonio Navarro, and
318 Darren Tucker.
319
fb8f3dc9 32020020308
a068d86f 321 - (djm) Revert bits of Markus' OpenSSL compat patch which was
322 accidentally committed.
323 - (djm) Add Markus' patch for compat wih OpenSSL < 0.9.6.
324 Known issue: Blowfish for SSH1 does not work
dc254471 325 - (stevesk) entropy.c: typo in debug message
633151a3 326 - (djm) ssh-keygen -i needs seeded RNG; report from markus@
fb8f3dc9 327
1854a55e 32820020307
329 - (djm) OpenBSD CVS Sync
330 - markus@cvs.openbsd.org 2002/03/06 00:20:54
331 [compat.c dh.c]
332 compat.c
83a9aa63 333 - markus@cvs.openbsd.org 2002/03/06 00:23:27
334 [compat.c dh.c]
335 undo
dbe426a1 336 - markus@cvs.openbsd.org 2002/03/06 00:24:39
337 [compat.c]
338 compat.c
86044b85 339 - markus@cvs.openbsd.org 2002/03/06 00:25:55
340 [version.h]
341 OpenSSH_3.1
01f8d3ee 342 - (djm) Update RPM spec files with new version number
4ca33cc5 343 - (bal) Updated INSTALL to reflect 0.9.6 OpenSSL requirement
5bbbc661 344 - (bal) Add in check for rpc/types.h since it is needed on
345 some platforms for INADDR_LOOPBACK. We should retest
346 SCO 3 to see if this fixes their problem also.
492a3893 347 - (bal) Test for IRIX JOBS support at runtime. Patch provided
348 by David Kaelbling <drk@sgi.com>
349
a88e3e36 35020020305
351 - stevesk@cvs.openbsd.org 2002/03/02 09:34:42
352 [LICENCE]
353 correct copyright dates for scp license; ok markus@
354
27f30efd 35520020304
356 - OpenBSD CVS Sync
357 - deraadt@cvs.openbsd.org 2002/02/26 18:52:32
358 [sftp.1]
359 Ic cannot have that many arguments; spotted by mouring@etoh.eviladmin.org
dc76d6ce 360 - mouring@cvs.openbsd.org 2002/02/26 19:04:37
361 [sftp.1]
362 > Ic cannot have that many arguments; spotted by mouring@etoh.eviladmin.org
363 Last Ic on the first line should not have a space between it and the final
364 comma.
7e35f994 365 - deraadt@cvs.openbsd.org 2002/02/26 19:06:43
366 [sftp.1]
367 no, look closely. the comma was highlighted. split .Ic even more
3c05447a 368 - stevesk@cvs.openbsd.org 2002/02/26 20:03:51
369 [misc.c]
370 use socklen_t
db518d9b 371 - stevesk@cvs.openbsd.org 2002/02/27 21:23:13
372 [canohost.c channels.c packet.c sshd.c]
373 remove unneeded casts in [gs]etsockopt(); ok markus@
714954dc 374 - markus@cvs.openbsd.org 2002/02/28 15:46:33
375 [authfile.c kex.c kexdh.c kexgex.c key.c ssh-dss.c]
376 add some const EVP_MD for openssl-0.9.7
cd9a7017 377 - stevesk@cvs.openbsd.org 2002/02/28 19:36:28
378 [auth.c match.c match.h]
379 delay hostname lookup until we see a ``@'' in DenyUsers and AllowUsers
380 for sshd -u0; ok markus@
ebb1bf1a 381 - stevesk@cvs.openbsd.org 2002/02/28 20:36:42
382 [sshd.8]
383 DenyUsers allows user@host pattern also
f464aad8 384 - stevesk@cvs.openbsd.org 2002/02/28 20:46:10
385 [sshd.8]
386 -u0 DNS for user@host
b334badd 387 - stevesk@cvs.openbsd.org 2002/02/28 20:56:00
388 [auth.c]
389 log user not allowed details, from dwd@bell-labs.com; ok markus@
6805fc56 390 - markus@cvs.openbsd.org 2002/03/01 13:12:10
391 [auth.c match.c match.h]
392 undo the 'delay hostname lookup' change
393 match.c must not use compress.c (via canonhost.c/packet.c)
394 thanks to wilfried@
fa1eb020 395 - markus@cvs.openbsd.org 2002/03/04 12:43:06
396 [auth-passwd.c auth-rh-rsa.c auth-rhosts.c]
c92ec40b 397 - markus@cvs.openbsd.org 2002/03/04 13:10:46
398 [misc.c]
399 error-> debug, because O_NONBLOCK for /dev/null causes too many different
400 errnos; ok stevesk@, deraadt@
fa1eb020 401 unused include
93c3b6de 402 - stevesk@cvs.openbsd.org 2002/03/04 17:27:39
403 [auth-krb5.c auth-options.h auth.h authfd.h authfile.h bufaux.h buffer.h
404 channels.h cipher.h compat.h compress.h crc32.h deattack.c getput.h
405 groupaccess.c misc.c mpaux.h packet.h readconf.h rsa.h scard.h
406 servconf.h ssh-agent.c ssh.h ssh2.h sshpty.h sshtty.c ttymodes.h
407 uuencode.c xmalloc.h]
408 $OpenBSD$ and RCSID() cleanup: don't use RCSID() in .h files; add
409 missing RCSID() to .c files and remove dup /*$OpenBSD$*/ from .c
410 files. ok markus@
27452401 411 - stevesk@cvs.openbsd.org 2002/03/04 18:30:23
412 [ssh-keyscan.c]
413 handle connection close during read of protocol version string.
414 fixes erroneous "bad greeting". ok markus@
c77d2e56 415 - markus@cvs.openbsd.org 2002/03/04 19:37:58
416 [channels.c]
417 off by one; thanks to joost@pine.nl
ef817d21 418 - (bal) Added contrib/aix/ to support BFF package generation provided
419 by Darren Tucker <dtucker@zip.com.au>
ddceb1c8 42020020226
421 - (tim) Bug 12 [configure.ac] add sys/bitypes.h to int64_t tests
422 based on patch by mooney@dogbert.cc.ndsu.nodak.edu (Tim Mooney)
423 Bug 45 [configure.ac] modify skey test to work around conflict with autoconf
424 reported by nolan@naic.edu (Michael Nolan)
425 patch by Pekka Savola <pekkas@netcore.fi>
426 Bug 74 [configure.ac defines.h] add sig_atomic_t test
427 reported by dwd@bell-labs.com (Dave Dykstra)
428 Bug 102 [defines.h] UNICOS fixes. patch by wendyp@cray.com
429 [configure.ac Makefile.in] link libwrap only with sshd
430 based on patch by Maciej W. Rozycki <macro@ds2.pg.gda.pl>
431 Bug 123 link libpam only with sshd
432 reported by peak@argo.troja.mff.cuni.cz (Pavel Kankovsky)
433 [configure.ac defines.h] modify previous SCO3 fix to not break Solaris 7
434 [acconfig.h] remove unused HAVE_REGCOMP
98f2d9d5 435 [configure.ac] put back in search for prngd-socket
12e8eb8d 436 - (stevesk) openbsd-compat/base64.h: typo in comment
e6164c5e 437 - (bal) Update sshd_config CVSID
c12337d9 438 - (bal) OpenBSD CVS Sync
439 - markus@cvs.openbsd.org 2002/02/15 23:54:10
440 [auth-krb5.c]
441 krb5_get_err_text() does not like context==NULL; he@nordu.net via google;
442 ok provos@
2bae80e9 443 - markus@cvs.openbsd.org 2002/02/22 12:20:34
444 [log.c log.h ssh-keyscan.c]
445 overwrite fatal() in ssh-keyscan.c; fixes pr 2354; ok provos@
b967d870 446 - markus@cvs.openbsd.org 2002/02/23 17:59:02
447 [kex.c kexdh.c kexgex.c]
448 don't allow garbage after payload.
f6b1ba8f 449 - stevesk@cvs.openbsd.org 2002/02/24 16:09:52
450 [sshd.c]
451 use u_char* here; ok markus@
f60ace9f 452 - markus@cvs.openbsd.org 2002/02/24 16:57:19
453 [sftp-client.c]
454 early close(), missing free; ok stevesk@
a318bbf4 455 - markus@cvs.openbsd.org 2002/02/24 16:58:32
456 [packet.c]
457 make 'cp' unsigned and merge with 'ucp'; ok stevesk@
b117a4d3 458 - markus@cvs.openbsd.org 2002/02/24 18:31:09
459 [uuencode.c]
460 typo in comment
c66f9d0e 461 - markus@cvs.openbsd.org 2002/02/24 19:14:59
462 [auth2.c authfd.c authfd.h authfile.c kexdh.c kexgex.c key.c key.h
463 ssh-dss.c ssh-dss.h ssh-keygen.c ssh-rsa.c ssh-rsa.h sshconnect2.c]
464 signed vs. unsigned: make size arguments u_int, ok stevesk@
811a6342 465 - stevesk@cvs.openbsd.org 2002/02/24 19:59:42
466 [channels.c misc.c]
467 disable Nagle in connect_to() and channel_post_port_listener() (port
468 forwarding endpoints). the intention is to preserve the on-the-wire
469 appearance to applications at either end; the applications can then
470 enable TCP_NODELAY according to their requirements. ok markus@
21b30f38 471 - markus@cvs.openbsd.org 2002/02/25 16:33:27
472 [ssh-keygen.c sshconnect2.c uuencode.c uuencode.h]
473 more u_* fixes
bb2fbc98 474 - (bal) Imported missing fatal.c and fixed up Makefile.in
98f2d9d5 475 - (tim) [configure.ac] correction to Bug 123 fix
2d16d9a3 476 [configure.ac] correction to sig_atomic_t test
ddceb1c8 477
da522265 47820020225
479 - (bal) Last AIX patch. Moved aix_usrinfo() outside of do_setuserconext()
480 since we need more session information than provided by that function.
481
2ec3dbf6 48220020224
483 - (bal) Drop Session *s usage in ports-aix.[ch] and pass just what we
484 need to do the jobs (AIX still does not fully compile, but that is
485 coming).
4936fcee 486 - (bal) Part two.. Drop unused AIX header, fix up missing char *cp. All
487 that is left is handling aix_usrinfo().
f3837bc6 488 - (tim) [loginrec.c session.c sshlogin.c sshlogin.h] Bug 84
489 patch by wknox@mitre.org (William Knox).
490 [sshlogin.h] declare record_utmp_only for session.c
2ec3dbf6 491
8001948f 49220020221
2ec3dbf6 493 - (bal) Minor session.c fixup for cygwin. mispelt 'is_winnt' variable.
8001948f 494
241b0041 49520020219
496 - (djm) OpenBSD CVS Sync
497 - mpech@cvs.openbsd.org 2002/02/13 08:33:47
498 [ssh-keyscan.1]
499 When you give command examples and etc., in a manual page prefix them with: $ command
500 or
501 # command
399d1ea6 502 - markus@cvs.openbsd.org 2002/02/14 23:27:59
503 [channels.c]
504 increase the SSH v2 window size to 4 packets. comsumes a little
505 bit more memory for slow receivers but increases througput.
ea9700ba 506 - markus@cvs.openbsd.org 2002/02/14 23:28:00
507 [channels.h session.c ssh.c]
508 increase the SSH v2 window size to 4 packets. comsumes a little
509 bit more memory for slow receivers but increases througput.
3ee832e5 510 - markus@cvs.openbsd.org 2002/02/14 23:41:01
511 [authfile.c cipher.c cipher.h kex.c kex.h packet.c]
512 hide some more implementation details of cipher.[ch] and prepares for move
513 to EVP, ok deraadt@
2a55e100 514 - stevesk@cvs.openbsd.org 2002/02/16 14:53:37
515 [ssh-keygen.1]
516 -t required now for key generation
8d22d775 517 - stevesk@cvs.openbsd.org 2002/02/16 20:40:08
518 [ssh-keygen.c]
519 default to rsa keyfile path for non key generation operations where
520 keyfile not specified. fixes core dump in those cases. ok markus@
ef2839b9 521 - millert@cvs.openbsd.org 2002/02/16 21:27:53
522 [auth.h]
523 Part one of userland __P removal. Done with a simple regexp with
524 some minor hand editing to make comments line up correctly. Another
525 pass is forthcoming that handles the cases that could not be done
526 automatically.
d96be24d 527 - millert@cvs.openbsd.org 2002/02/17 19:42:32
528 [auth.h]
529 Manual cleanup of remaining userland __P use (excluding packages
530 maintained outside the tree)
70fc1609 531 - markus@cvs.openbsd.org 2002/02/18 13:05:32
532 [cipher.c cipher.h]
533 switch to EVP, ok djm@ deraadt@
4e30de66 534 - markus@cvs.openbsd.org 2002/02/18 17:55:20
535 [ssh.1]
536 -q: Fatal errors are _not_ displayed.
d9959c61 537 - deraadt@cvs.openbsd.org 2002/02/19 02:50:59
538 [sshd_config]
539 stategy is not an english word
90e70cfc 540 - (bal) Migrated IRIX jobs/projects/audit/etc code to
2cce09e7 541 openbsd-compat/port-irix.[ch] to improve readiblity of do_child()
90e70cfc 542 - (bal) Migrated AIX getuserattr and usrinfo code to
543 openbsd-compat/port-aix.[c] to improve readilbity of do_child() and
544 simplify our diffs against upstream source.
f7342052 545 - (bal) OpenBSD CVS Sync
546 - markus@cvs.openbsd.org 2002/02/15 23:11:26
547 [session.c]
548 split do_child(), ok mouring@
5dd82c23 549 - markus@cvs.openbsd.org 2002/02/16 00:51:44
550 [session.c]
551 typo
552 - (bal) CVS ID sync since the last two patches were merged mistakenly
241b0041 553
975956bb 55420020218
555 - (tim) newer config.guess from ftp://ftp.gnu.org/gnu/config/config.guess
556
0c43a2e7 55720020213
3b83c722 558 - (djm) Don't use system sys/queue.h on AIX. Report from
559 gert@greenie.muc.de
560 - (djm) Bug #114 - not starting PAM for SSH protocol 1 invalid users
0c43a2e7 561
56220020213
9d726f16 563 - (djm) OpenBSD CVS Sync
564 - markus@cvs.openbsd.org 2002/02/11 16:10:15
565 [kex.c]
566 restore kexinit handler if we reset the dispatcher, this unbreaks
567 rekeying s/kex_clear_dispatch/kex_reset_dispatch/
6b4b5e49 568 - markus@cvs.openbsd.org 2002/02/11 16:15:46
569 [sshconnect1.c]
570 include md5.h, not evp.h
44b1a8e5 571 - markus@cvs.openbsd.org 2002/02/11 16:17:55
572 [sshd.c]
573 do not complain about port > 1024 if rhosts-auth is disabled
436c347c 574 - markus@cvs.openbsd.org 2002/02/11 16:19:39
575 [sshd.c]
576 include md5.h not hmac.h
fa869228 577 - markus@cvs.openbsd.org 2002/02/11 16:21:42
578 [match.c]
579 support up to 40 algorithms per proposal
c25d3df7 580 - djm@cvs.openbsd.org 2002/02/12 12:32:27
581 [sftp.1 sftp.c sftp-client.c sftp-client.h sftp-int.c]
582 Perform multiple overlapping read/write requests in file transfer. Mostly
583 done by Tobias Ringstrom <tori@ringstrom.mine.nu>; ok markus@
b2bab059 584 - djm@cvs.openbsd.org 2002/02/12 12:44:46
585 [sftp-client.c]
586 Let overlapped upload path handle servers which reorder ACKs. This may be
587 permitted by the protocol spec; ok markus@
cb476289 588 - markus@cvs.openbsd.org 2002/02/13 00:28:13
589 [sftp-server.c]
590 handle SSH2_FILEXFER_ATTR_SIZE in SSH2_FXP_(F)SETSTAT; ok djm@
b984f12e 591 - markus@cvs.openbsd.org 2002/02/13 00:39:15
592 [readpass.c]
593 readpass.c is not longer from UCB, since we now use readpassphrase(3)
22e6c827 594 - djm@cvs.openbsd.org 2002/02/13 00:59:23
595 [sftp-client.c sftp-client.h sftp-glob.c sftp-glob.h sftp.h]
596 [sftp-int.c sftp-int.h]
597 API cleanup and backwards compat for filexfer v.0 servers; ok markus@
1656cbed 598 - (djm) Sync openbsd-compat with OpenBSD CVS too
9d6b6505 599 - (djm) Bug #106: Add --without-rpath configure option. Patch from
600 Nicolas.Williams@ubsw.com
f7d5d67f 601 - (tim) [configure.ac, defines.h ] add rpc/rpc.h for INADDR_LOOPBACK
602 on SCO OSR3
9d726f16 603
2a8a6488 60420020210
605 - (djm) OpenBSD CVS Sync
606 - deraadt@cvs.openbsd.org 2002/02/09 17:37:34
607 [pathnames.h session.c ssh.1 sshd.8 sshd_config ssh-keyscan.1]
608 move ssh config files to /etc/ssh
609 - (djm) Adjust portable Makefile.in tnd ssh-rand-helper.c o match
af98ced9 610 - deraadt@cvs.openbsd.org 2002/02/10 01:07:05
611 [readconf.h sshd.8]
612 more /etc/ssh; openbsd@davidkrause.com
2a8a6488 613
980c9344 61420020208
615 - (djm) OpenBSD CVS Sync
616 - markus@cvs.openbsd.org 2002/02/04 12:15:25
617 [sshd.c]
618 add SYSLOG_FACILITY_NOT_SET = -1, SYSLOG_LEVEL_NOT_SET = -1,
619 fixes arm/netbsd; based on patch from bjh21@netbsd.org; ok djm@
4c646df4 620 - stevesk@cvs.openbsd.org 2002/02/04 20:41:16
621 [ssh-agent.1]
622 more sync for default ssh-add identities; ok markus@
375f867e 623 - djm@cvs.openbsd.org 2002/02/05 00:00:46
624 [sftp.1 sftp.c sftp-client.c sftp-client.h sftp-int.c]
625 Add "-B" option to specify copy buffer length (default 32k); ok markus@
06ee33fb 626 - markus@cvs.openbsd.org 2002/02/05 14:32:55
627 [channels.c channels.h ssh.c]
628 merge channel_request() into channel_request_start()
7d5e8c46 629 - markus@cvs.openbsd.org 2002/02/06 14:22:42
630 [sftp.1]
631 sort options; ok mpech@, stevesk@
22be05a5 632 - mpech@cvs.openbsd.org 2002/02/06 14:27:23
633 [sftp.c]
634 sync usage() with manual.
5a4ae906 635 - markus@cvs.openbsd.org 2002/02/06 14:37:22
636 [session.c]
637 minor KNF
3a0d3d54 638 - markus@cvs.openbsd.org 2002/02/06 14:55:16
639 [channels.c clientloop.c serverloop.c ssh.c]
640 channel_new never returns NULL, mouring@; ok djm@
275a87f6 641 - markus@cvs.openbsd.org 2002/02/07 09:35:39
642 [ssh.c]
643 remove bogus comments
980c9344 644
bcc0381e 64520020205
983784a1 646 - (djm) Cleanup after sync:
647 - :%s/reverse_mapping_check/verify_reverse_mapping/g
bcc0381e 648 - (djm) OpenBSD CVS Sync
649 - stevesk@cvs.openbsd.org 2002/01/24 21:09:25
650 [channels.c misc.c misc.h packet.c]
651 add set_nodelay() to set TCP_NODELAY on a socket (prep for nagle tuning).
652 no nagle changes just yet; ok djm@ markus@
2ac91be1 653 - stevesk@cvs.openbsd.org 2002/01/24 21:13:23
654 [packet.c]
655 need misc.h for set_nodelay()
7d30579d 656 - markus@cvs.openbsd.org 2002/01/25 21:00:24
657 [sshconnect2.c]
658 unused include
087dea86 659 - markus@cvs.openbsd.org 2002/01/25 21:42:11
660 [ssh-dss.c ssh-rsa.c]
661 use static EVP_MAX_MD_SIZE buffers for EVP_DigestFinal; ok stevesk@
662 don't use evp_md->md_size, it's not public.
a209a158 663 - markus@cvs.openbsd.org 2002/01/25 22:07:40
664 [kex.c kexdh.c kexgex.c key.c mac.c]
665 use EVP_MD_size(evp_md) and not evp_md->md_size; ok steveks@
f9314d9a 666 - stevesk@cvs.openbsd.org 2002/01/26 16:44:22
667 [includes.h session.c]
668 revert code to add x11 localhost display authorization entry for
669 hostname/unix:d and uts.nodename/unix:d if nodename was different than
670 hostname. just add entry for unix:d instead. ok markus@
e6e573bd 671 - stevesk@cvs.openbsd.org 2002/01/27 14:57:46
672 [channels.c servconf.c servconf.h session.c sshd.8 sshd_config]
673 add X11UseLocalhost; ok markus@
75a624f0 674 - stevesk@cvs.openbsd.org 2002/01/27 18:08:17
675 [ssh.c]
676 handle simple case to identify FamilyLocal display; ok markus@
a2863956 677 - markus@cvs.openbsd.org 2002/01/29 14:27:57
678 [ssh-add.c]
679 exit 2 if no agent, exit 1 if list fails; debian#61078; ok djm@
bf4c5edc 680 - markus@cvs.openbsd.org 2002/01/29 14:32:03
681 [auth2.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c canohost.c]
682 [servconf.c servconf.h session.c sshd.8 sshd_config]
683 s/ReverseMappingCheck/VerifyReverseMapping/ and avoid confusion;
684 ok stevesk@
8875ca97 685 - stevesk@cvs.openbsd.org 2002/01/29 16:29:02
686 [session.c]
687 limit subsystem length in log; ok markus@
8e3ce4dc 688 - markus@cvs.openbsd.org 2002/01/29 16:41:19
689 [ssh-add.1]
690 add DIAGNOSTICS; ok stevesk@
24932ee9 691 - markus@cvs.openbsd.org 2002/01/29 22:46:41
692 [session.c]
693 don't depend on servconf.c; ok djm@
16210ef7 694 - markus@cvs.openbsd.org 2002/01/29 23:50:37
695 [scp.1 ssh.1]
696 mention exit status; ok stevesk@
215ced77 697 - markus@cvs.openbsd.org 2002/01/31 13:35:11
698 [kexdh.c kexgex.c]
699 cross check announced key type and type from key blob
d01c63bb 700 - markus@cvs.openbsd.org 2002/01/31 15:00:05
701 [serverloop.c]
702 no need for WNOHANG; ok stevesk@
7899c98f 703 - markus@cvs.openbsd.org 2002/02/03 17:53:25
704 [auth1.c serverloop.c session.c session.h]
705 don't use channel_input_channel_request and callback
706 use new server_input_channel_req() instead:
707 server_input_channel_req does generic request parsing on server side
708 session_input_channel_req handles just session specific things now
709 ok djm@
8034b5cd 710 - markus@cvs.openbsd.org 2002/02/03 17:55:55
711 [channels.c channels.h]
712 remove unused channel_input_channel_request
05ca0898 713 - markus@cvs.openbsd.org 2002/02/03 17:58:21
714 [channels.c channels.h ssh.c]
715 generic callbacks are not really used, remove and
716 add a callback for msg of type SSH2_MSG_CHANNEL_OPEN_CONFIRMATION
717 ok djm@
0dbdc37c 718 - markus@cvs.openbsd.org 2002/02/03 17:59:23
719 [sshconnect2.c]
720 more cross checking if announced vs. used key type; ok stevesk@
3b5a1b05 721 - stevesk@cvs.openbsd.org 2002/02/03 22:35:57
722 [ssh.1 sshd.8]
723 some KeepAlive cleanup/clarify; ok markus@
49ebf326 724 - stevesk@cvs.openbsd.org 2002/02/03 23:22:59
725 [ssh-agent.1]
726 ssh-add also adds $HOME/.ssh/id_rsa and $HOME/.ssh/id_dsa now.
762f5ea2 727 - stevesk@cvs.openbsd.org 2002/02/04 00:53:39
728 [ssh-agent.c]
729 unneeded includes
67fa09f5 730 - markus@cvs.openbsd.org 2002/02/04 11:58:10
731 [auth2.c]
732 cross checking of announced vs actual pktype in pubkey/hostbaed auth;
733 ok stevesk@
5eaf8578 734 - markus@cvs.openbsd.org 2002/02/04 12:15:25
735 [log.c log.h readconf.c servconf.c]
736 add SYSLOG_FACILITY_NOT_SET = -1, SYSLOG_LEVEL_NOT_SET = -1,
737 fixes arm/netbsd; based on patch from bjh21@netbsd.org; ok djm@
a445d432 738 - stevesk@cvs.openbsd.org 2002/02/04 20:41:16
739 [ssh-add.1]
740 more sync for default ssh-add identities; ok markus@
a96fd7c2 741 - djm@cvs.openbsd.org 2002/02/04 21:53:12
742 [sftp.1 sftp.c]
743 Add "-P" option to directly connect to a local sftp-server. Should be
744 useful for regression testing; ok markus@
86e23f3e 745 - djm@cvs.openbsd.org 2002/02/05 00:00:46
746 [sftp.1 sftp.c sftp-client.c sftp-client.h sftp-int.c]
747 Add "-B" option to specify copy buffer length (default 32k); ok markus@
bcc0381e 748
8d7324af 74920020130
750 - (djm) Delay PRNG seeding until we need it in ssh-keygen, from markus@
70e2f2f3 751 - (tim) [configure.ac] fix logic on when ssh-rand-helper is installed.
752 [sshd_config] put back in line that tells what PATH was compiled into sshd.
8d7324af 753
90bab5a8 75420020125
9b7fcaf0 755 - (djm) Don't grab Xserver or pointer by default. x11-ssh-askpass doesn't
756 and grabbing can cause deadlocks with kinput2.
90bab5a8 757
533845df 75820020124
759 - (stevesk) Makefile.in: bug #61; delete commented line for now.
760
906e811b 76120020123
762 - (djm) Fix non-standard shell syntax in autoconf. Patch from
763 Dave Dykstra <dwd@bell-labs.com>
846f83ab 764 - (stevesk) fix --with-zlib=
eb5d7ff6 765 - (djm) Use case statements in autoconf to clean up some tests
5b6c4ceb 766 - (bal) reverted out of 5/2001 change to atexit(). I assume I
767 did it to handle SonyOS. If that is the case than we will
768 do a special case for them.
906e811b 769
f1b0ecc3 77020020122
771 - (djm) autoconf hacking:
772 - We don't support --without-zlib currently, so don't allow it.
773 - Rework cryptographic random number support detection. We now detect
774 whether OpenSSL seeds itself. If it does, then we don't bother with
775 the ssh-rand-helper program. You can force the use of ssh-rand-helper
776 using the --with-rand-helper configure argument
777 - Simplify and clean up ssh-rand-helper configuration
9780116c 778 - Add OpenSSL sanity check: verify that header version matches version
779 reported by library
49d7ed32 780 - (djm) Fix some bugs I introduced into ssh-rand-helper yesterday
3dc93cd8 781 - OpenBSD CVS Sync
782 - djm@cvs.openbsd.org 2001/12/21 08:52:22
783 [ssh-keygen.1 ssh-keygen.c]
784 Remove default (rsa1) key type; ok markus@
f9654cd7 785 - djm@cvs.openbsd.org 2001/12/21 08:53:45
786 [readpass.c]
787 Avoid interruptable passphrase read; ok markus@
67656ffc 788 - djm@cvs.openbsd.org 2001/12/21 10:06:43
789 [ssh-add.1 ssh-add.c]
790 Try all standard key files (id_rsa, id_dsa, identity) when invoked with
791 no arguments; ok markus@
b0ce9259 792 - markus@cvs.openbsd.org 2001/12/21 12:17:33
793 [serverloop.c]
794 remove ifdef for USE_PIPES since fdin != fdout; ok djm@
0e0bba68 795 - deraadt@cvs.openbsd.org 2001/12/24 07:29:43
796 [ssh-add.c]
797 try all listed keys.. how did this get broken?
e13b4278 798 - markus@cvs.openbsd.org 2001/12/25 18:49:56
799 [key.c]
800 be more careful on allocation
45c49544 801 - markus@cvs.openbsd.org 2001/12/25 18:53:00
802 [auth1.c]
803 be more carefull on allocation
bb28e836 804 - markus@cvs.openbsd.org 2001/12/27 18:10:29
805 [ssh-keygen.c]
806 -t is only needed for key generation (unbreaks -i, -e, etc).
b775c6f2 807 - markus@cvs.openbsd.org 2001/12/27 18:22:16
808 [auth1.c authfile.c auth-rsa.c dh.c kexdh.c kexgex.c key.c rsa.c]
809 [scard.c ssh-agent.c sshconnect1.c sshd.c ssh-dss.c]
810 call fatal() for openssl allocation failures
135113a3 811 - stevesk@cvs.openbsd.org 2001/12/27 18:22:53
812 [sshd.8]
813 clarify -p; ok markus@
cf184a44 814 - markus@cvs.openbsd.org 2001/12/27 18:26:13
815 [authfile.c]
816 missing include
108d362e 817 - markus@cvs.openbsd.org 2001/12/27 19:37:23
818 [dh.c kexdh.c kexgex.c]
819 always use BN_clear_free instead of BN_free
dc421aa3 820 - markus@cvs.openbsd.org 2001/12/27 19:54:53
821 [auth1.c auth.h auth-rh-rsa.c]
822 auth_rhosts_rsa now accept generic keys.
95500969 823 - markus@cvs.openbsd.org 2001/12/27 20:39:58
824 [auth1.c auth-rsa.c channels.c clientloop.c packet.c packet.h]
825 [serverloop.c session.c ssh.c sshconnect1.c sshd.c ttymodes.c]
826 get rid of packet_integrity_check, use packet_done() instead.
3456d3c7 827 - markus@cvs.openbsd.org 2001/12/28 12:14:27
20b279e6 828 [auth1.c auth2.c auth2-chall.c auth-rsa.c channels.c clientloop.c]
829 [kex.c kexdh.c kexgex.c packet.c packet.h serverloop.c session.c]
830 [ssh.c sshconnect1.c sshconnect2.c sshd.c]
3456d3c7 831 s/packet_done/packet_check_eom/ (end-of-message); ok djm@
20b279e6 832 - markus@cvs.openbsd.org 2001/12/28 13:57:33
833 [auth1.c kexdh.c kexgex.c packet.c packet.h sshconnect1.c sshd.c]
834 packet_get_bignum* no longer returns a size
4ef6f649 835 - markus@cvs.openbsd.org 2001/12/28 14:13:13
836 [bufaux.c bufaux.h packet.c]
837 buffer_get_bignum: int -> void
54a5250f 838 - markus@cvs.openbsd.org 2001/12/28 14:50:54
839 [auth1.c auth-rsa.c channels.c dispatch.c kex.c kexdh.c kexgex.c]
840 [packet.c packet.h serverloop.c session.c ssh.c sshconnect1.c]
841 [sshconnect2.c sshd.c]
842 packet_read* no longer return the packet length, since it's not used.
7819b5c3 843 - markus@cvs.openbsd.org 2001/12/28 15:06:00
844 [auth2.c auth2-chall.c channels.c channels.h clientloop.c dispatch.c]
845 [dispatch.h kex.c kex.h serverloop.c ssh.c sshconnect2.c]
846 remove plen from the dispatch fn. it's no longer used.
60015649 847 - stevesk@cvs.openbsd.org 2001/12/28 22:37:48
848 [ssh.1 sshd.8]
849 document LogLevel DEBUG[123]; ok markus@
20905a8e 850 - stevesk@cvs.openbsd.org 2001/12/29 21:56:01
851 [authfile.c channels.c compress.c packet.c sftp-server.c]
852 [ssh-agent.c ssh-keygen.c]
853 remove unneeded casts and some char->u_char cleanup; ok markus@
6c79c353 854 - stevesk@cvs.openbsd.org 2002/01/03 04:11:08
855 [ssh_config]
856 grammar in comment
b4047251 857 - stevesk@cvs.openbsd.org 2002/01/04 17:59:17
858 [readconf.c servconf.c]
859 remove #ifdef _PATH_XAUTH/#endif; ok markus@
0f84fe37 860 - stevesk@cvs.openbsd.org 2002/01/04 18:14:16
861 [servconf.c sshd.8]
862 protocol 2 HostKey code default is now /etc/ssh_host_rsa_key and
863 /etc/ssh_host_dsa_key like we have in sshd_config. ok markus@
8341f420 864 - markus@cvs.openbsd.org 2002/01/05 10:43:40
865 [channels.c]
866 fix hanging x11 channels for rejected cookies (e.g.
867 XAUTHORITY=/dev/null xbiff) bug #36, based on patch from
868 djast@cs.toronto.edu
cb362b5e 869 - stevesk@cvs.openbsd.org 2002/01/05 21:51:56
870 [ssh.1 sshd.8]
871 some missing and misplaced periods
4ccb828d 872 - markus@cvs.openbsd.org 2002/01/09 13:49:27
873 [ssh-keygen.c]
874 append \n only for public keys
0c0738d5 875 - markus@cvs.openbsd.org 2002/01/09 17:16:00
876 [channels.c]
877 merge channel_pre_open_15/channel_pre_open_20; ok provos@
9c50edcf 878 - markus@cvs.openbsd.org 2002/01/09 17:26:35
879 [channels.c nchan.c]
880 replace buffer_consume(b, buffer_len(b)) with buffer_clear(b);
881 ok provos@
99416ceb 882 - markus@cvs.openbsd.org 2002/01/10 11:13:29
883 [serverloop.c]
884 skip client_alive_check until there are channels; ok beck@
3d209bbe 885 - markus@cvs.openbsd.org 2002/01/10 11:24:04
886 [clientloop.c]
887 handle SSH2_MSG_GLOBAL_REQUEST (just reply with failure); ok djm@
3c27606d 888 - markus@cvs.openbsd.org 2002/01/10 12:38:26
889 [nchan.c]
890 remove dead code (skip drain)
6d566d33 891 - markus@cvs.openbsd.org 2002/01/10 12:47:59
892 [nchan.c]
893 more unused code (with channels.c:1.156)
5a5f4c37 894 - markus@cvs.openbsd.org 2002/01/11 10:31:05
895 [packet.c]
896 handle received SSH2_MSG_UNIMPLEMENTED messages; ok djm@
781a02b8 897 - markus@cvs.openbsd.org 2002/01/11 13:36:43
898 [ssh2.h]
899 add defines for msg type ranges
6367063f 900 - markus@cvs.openbsd.org 2002/01/11 13:39:36
901 [auth2.c dispatch.c dispatch.h kex.c]
902 a single dispatch_protocol_error() that sends a message of
903 type 'UNIMPLEMENTED'
904 dispatch_range(): set handler for a ranges message types
905 use dispatch_protocol_ignore() for authentication requests after
906 successful authentication (the drafts requirement).
907 serverloop/clientloop now send a 'UNIMPLEMENTED' message instead
908 of exiting.
70499440 909 - markus@cvs.openbsd.org 2002/01/11 20:14:11
910 [auth2-chall.c auth-skey.c]
911 use strlcpy not strlcat; mouring@
a62ebe1f 912 - markus@cvs.openbsd.org 2002/01/11 23:02:18
913 [readpass.c]
914 use _PATH_TTY
bd2d2ac4 915 - markus@cvs.openbsd.org 2002/01/11 23:02:51
916 [auth2-chall.c]
917 use snprintf; mouring@
7ef24c8c 918 - markus@cvs.openbsd.org 2002/01/11 23:26:30
919 [auth-skey.c]
920 use snprintf; mouring@
68a7e648 921 - markus@cvs.openbsd.org 2002/01/12 13:10:29
922 [auth-skey.c]
923 undo local change
95f0a918 924 - provos@cvs.openbsd.org 2002/01/13 17:27:07
925 [ssh-agent.c]
926 change to use queue.h macros; okay markus@
3469eac4 927 - markus@cvs.openbsd.org 2002/01/13 17:57:37
928 [auth2.c auth2-chall.c compat.c sshconnect2.c sshd.c]
929 use buffer API and avoid static strings of fixed size;
930 ok provos@/mouring@
368e9dfc 931 - markus@cvs.openbsd.org 2002/01/13 21:31:20
932 [channels.h nchan.c]
933 add chan_set_[io]state(), order states, state is now an u_int,
934 simplifies debugging messages; ok provos@
3057c23b 935 - markus@cvs.openbsd.org 2002/01/14 13:22:35
936 [nchan.c]
937 chan_send_oclose1() no longer calls chan_shutdown_write(); ok provos@
938 - markus@cvs.openbsd.org 2002/01/14 13:34:07
939 [nchan.c]
940 merge chan_[io]buf_empty[12]; ok provos@
668a91b7 941 - markus@cvs.openbsd.org 2002/01/14 13:40:10
942 [nchan.c]
943 correct fn names for ssh2, do not switch from closed to closed;
944 ok provos@
3c9f1ecd 945 - markus@cvs.openbsd.org 2002/01/14 13:41:13
946 [nchan.c]
947 remove duplicated code; ok provos@
70bef40e 948 - markus@cvs.openbsd.org 2002/01/14 13:55:55
949 [channels.c channels.h nchan.c]
950 remove function pointers for events, remove chan_init*; ok provos@
8ab5f6b2 951 - markus@cvs.openbsd.org 2002/01/14 13:57:03
952 [channels.h nchan.c]
953 (c) 2002
5641aefa 954 - markus@cvs.openbsd.org 2002/01/16 13:17:51
955 [channels.c channels.h serverloop.c ssh.c]
956 wrapper for channel_setup_fwd_listener
ac10636f 957 - stevesk@cvs.openbsd.org 2002/01/16 17:40:23
958 [sshd_config]
959 The stategy now used for options in the default sshd_config shipped
960 with OpenSSH is to specify options with their default value where
961 possible, but leave them commented. Uncommented options change a
962 default value. Subsystem is currently the only default option
963 changed. ok markus@
cf5a07a8 964 - stevesk@cvs.openbsd.org 2002/01/16 17:42:33
965 [ssh.1]
966 correct defaults for -i/IdentityFile; ok markus@
1bbbc136 967 - stevesk@cvs.openbsd.org 2002/01/16 17:55:33
968 [ssh_config]
969 correct some commented defaults. add Ciphers default. ok markus@
4267abfd 970 - stevesk@cvs.openbsd.org 2002/01/17 04:27:37
971 [log.c]
972 casts to silence enum type warnings for bugzilla bug 37; ok markus@
ba218fbe 973 - stevesk@cvs.openbsd.org 2002/01/18 17:14:16
974 [sshd.8]
975 correct Ciphers default; paola.mannaro@ubs.com
e6207598 976 - stevesk@cvs.openbsd.org 2002/01/18 18:14:17
977 [authfd.c bufaux.c buffer.c cipher.c packet.c ssh-agent.c ssh-keygen.c]
978 unneeded cast cleanup; ok markus@
dfafef8f 979 - stevesk@cvs.openbsd.org 2002/01/18 20:46:34
980 [sshd.8]
981 clarify Allow(Groups|Users) and Deny(Groups|Users); suggestion from
982 allard@oceanpark.com; ok markus@
616a6b93 983 - markus@cvs.openbsd.org 2002/01/21 15:13:51
984 [sshconnect.c]
985 use read_passphrase+ECHO in confirm(), allows use of ssh-askpass
986 for hostkey confirm.
55f9eebd 987 - markus@cvs.openbsd.org 2002/01/21 22:30:12
988 [cipher.c compat.c myproposal.h]
989 remove "rijndael-*", just use "aes-" since this how rijndael is called
990 in the drafts; ok stevesk@
32e7d71f 991 - markus@cvs.openbsd.org 2002/01/21 23:27:10
992 [channels.c nchan.c]
993 cleanup channels faster if the are empty and we are in drain-state;
994 ok deraadt@
3a454b6a 995 - stevesk@cvs.openbsd.org 2002/01/22 02:52:41
996 [servconf.c]
997 typo in error message; from djast@cs.toronto.edu
4ca007b2 998 - (djm) Make auth2-pam.c compile again after dispatch.h and packet.h
999 changes
507c4f2e 1000 - (djm) Recent Glibc includes an incompatible sys/queue.h. Treat it as
1001 bogus in configure
187cd1fa 1002 - (djm) Use local sys/queue.h if necessary in ssh-agent.c
f1b0ecc3 1003
40f64e6f 100420020121
1005 - (djm) Rework ssh-rand-helper:
1006 - Reduce quantity of ifdef code, in preparation for ssh_rand_conf
1007 - Always seed from system calls, even when doing PRNGd seeding
1008 - Tidy and comment #define knobs
1009 - Remove unused facility for multiple runs through command list
1010 - KNF, cleanup, update copyright
1011
088cdc23 101220020114
1013 - (djm) Bug #50 - make autoconf entropy path checks more robust
1014
760b35a6 101520020108
1016 - (djm) Merge Cygwin copy_environment with do_pam_environment, removing
1017 fixed env var size limit in the process. Report from Corinna Vinschen
1018 <vinschen@redhat.com>
5cbceb3f 1019 - (stevesk) defines.h: use "/var/spool/sockets/X11/%u" for HP-UX. does
1020 not depend on transition links. from Lutz Jaenicke.
760b35a6 1021
1d2a4613 102220020106
1023 - (stevesk) defines.h: determine _PATH_UNIX_X; currently "/tmp/.X11-unix/X%u"
1024 for all platforms except HP-UX, which is "/usr/spool/sockets/X11/%u".
1025
d93656c9 102620020105
1027 - (bal) NCR requies use_pipes to operate correctly.
29525240 1028 - (stevesk) fix spurious ; from NCR change.
d93656c9 1029
554e28b2 103020020103
1031 - (djm) Use bigcrypt() on systems with SCO_PROTECTED_PW. Patch from
1032 Roger Cornelius <rac@tenzing.org>
1033
e9571a2c 103420011229
1035 - (djm) Apply Cygwin pointer deref fix from Corinna Vinschen
1036 <vinschen@redhat.com> Could be abused to guess valid usernames
929fb284 1037 - (djm) Typo in contrib/cygwin/README Fix from Corinna Vinschen
1038 <vinschen@redhat.com>
e9571a2c 1039
760edf28 104020011228
1041 - (djm) Remove recommendation to use GNU make, we should support most
1042 make programs.
1043
7bec72bc 104420011225
1045 - (stevesk) [Makefile.in ssh-rand-helper.c]
1046 portable lib and __progname support for ssh-rand-helper; ok djm@
1047
b8291fa0 104820011223
1049 - (bal) Removed contrib/chroot.diff and noted in contrib/README that it
1050 was not being maintained.
1051
46058ce2 105220011222
1053 - (djm) Ignore fix & patchlevel in OpenSSL version check. Patch from
1054 solar@openwall.com
1055 - (djm) Rework entropy code. If the OpenSSL PRNG is has not been
1056 internally seeded, execute a subprogram "ssh-rand-helper" to obtain
1057 some entropy for us. Rewrite the old in-process entropy collecter as
1058 an example ssh-rand-helper.
1059 - (djm) Always perform ssh_prng_cmds path lookups in configure, even if
1060 we don't end up using ssh_prng_cmds (so we always get a valid file)
1061
5fb9865a 106220011221
1063 - (djm) Add option to gnome-ssh-askpass to stop it from grabbing the X
1064 server. I have found this necessary to avoid server hangs with X input
1065 extensions (e.g. kinput2). Enable by setting the environment variable
1066 "GNOME_SSH_ASKPASS_NOGRAB"
805e659f 1067 - OpenBSD CVS Sync
1068 - stevesk@cvs.openbsd.org 2001/12/08 17:49:28
1069 [channels.c pathnames.h]
1070 use only one path to X11 UNIX domain socket vs. an array of paths
1071 to try. report from djast@cs.toronto.edu. ok markus@
2f293d43 1072 - markus@cvs.openbsd.org 2001/12/09 18:45:56
1073 [auth2.c auth2-chall.c auth.h]
1074 add auth2_challenge_stop(), simplifies cleanup of kbd-int sessions,
1075 fixes memleak.
5e8948af 1076 - stevesk@cvs.openbsd.org 2001/12/10 16:45:04
1077 [sshd.c]
1078 possible fd leak on error; ok markus@
cdc95d6e 1079 - markus@cvs.openbsd.org 2001/12/10 20:34:31
1080 [ssh-keyscan.c]
1081 check that server supports v1 for -t rsa1, report from wirth@dfki.de
fb396518 1082 - jakob@cvs.openbsd.org 2001/12/18 10:04:21
1083 [auth.h hostfile.c hostfile.h]
1084 remove auth_rsa_read_key, make hostfile_ready_key non static; ok markus@
306feb91 1085 - jakob@cvs.openbsd.org 2001/12/18 10:05:15
1086 [auth2.c]
1087 log fingerprint on successful public key authentication; ok markus@
46df736f 1088 - jakob@cvs.openbsd.org 2001/12/18 10:06:24
1089 [auth-rsa.c]
1090 log fingerprint on successful public key authentication, simplify
1091 usage of key structs; ok markus@
184eed6a 1092 - deraadt@cvs.openbsd.org 2001/12/19 07:18:56
1093 [auth1.c auth2.c auth2-chall.c auth-bsdauth.c auth.c authfile.c auth.h]
1094 [auth-krb4.c auth-rhosts.c auth-skey.c bufaux.c canohost.c channels.c]
1095 [cipher.c clientloop.c compat.c compress.c deattack.c key.c log.c mac.c]
1096 [match.c misc.c nchan.c packet.c readconf.c rijndael.c rijndael.h scard.c]
1097 [servconf.c servconf.h serverloop.c session.c sftp.c sftp-client.c]
1098 [sftp-glob.c sftp-int.c sftp-server.c ssh-add.c ssh-agent.c ssh.c]
1099 [sshconnect1.c sshconnect2.c sshconnect.c sshd.8 sshd.c sshd_config]
1100 [ssh-keygen.c sshlogin.c sshpty.c sshtty.c ttymodes.c uidswap.c]
1101 basic KNF done while i was looking for something else
a10be357 1102 - markus@cvs.openbsd.org 2001/12/19 16:09:39
1103 [serverloop.c]
1104 fix race between SIGCHLD and select with an additional pipe. writing
1105 to the pipe on SIGCHLD wakes up select(). using pselect() is not
1106 portable and siglongjmp() ugly. W. R. Stevens suggests similar solution.
1107 initial idea by pmenage@ensim.com; ok deraadt@, djm@
6c0fa2b1 1108 - stevesk@cvs.openbsd.org 2001/12/19 17:16:13
1109 [authfile.c bufaux.c bufaux.h buffer.c buffer.h packet.c packet.h ssh.c]
1110 change the buffer/packet interface to use void* vs. char*; ok markus@
ac151b18 1111 - markus@cvs.openbsd.org 2001/12/20 16:37:29
1112 [channels.c channels.h session.c]
1113 setup x11 listen socket for just one connect if the client requests so.
1114 (v2 only, but the openssh client does not support this feature).
24ca6821 1115 - djm@cvs.openbsd.org 2001/12/20 22:50:24
1116 [auth2.c auth2-chall.c channels.c channels.h clientloop.c dispatch.c]
1117 [dispatch.h kex.c kex.h packet.c packet.h serverloop.c ssh.c]
1118 [sshconnect2.c]
1119 Conformance fix: we should send failing packet sequence number when
1120 responding with a SSH_MSG_UNIMPLEMENTED message. Spotted by
1121 yakk@yakk.dot.net; ok markus@
5fb9865a 1122
c9d0ad9b 112320011219
1124 - (stevesk) OpenBSD CVS sync X11 localhost display
1125 - stevesk@cvs.openbsd.org 2001/11/29 14:10:51
1126 [channels.h channels.c session.c]
1127 sshd X11 fake server will now listen on localhost by default:
1128 $ echo $DISPLAY
1129 localhost:12.0
1130 $ netstat -an|grep 6012
1131 tcp 0 0 127.0.0.1.6012 *.* LISTEN
1132 tcp6 0 0 ::1.6012 *.* LISTEN
1133 sshd_config gatewayports=yes can be used to revert back to the old
1134 behavior. will control this with another option later. ok markus@
1135 - stevesk@cvs.openbsd.org 2001/12/19 08:43:11
1136 [includes.h session.c]
1137 handle utsname.nodename case for FamilyLocal X authorization; ok markus@
1138
3f3ac025 113920011207
1140 - (bal) PCRE no longer required. Banished from the source along with
1141 fake-regex.h
c20f63d3 1142 - (bal) OpenBSD CVS Sync
1143 - stevesk@cvs.openbsd.org 2001/12/06 18:02:32
1144 [channels.c sshconnect.c]
1145 shutdown(sock, SHUT_RDWR) not needed here; ok markus@
74860245 1146 - stevesk@cvs.openbsd.org 2001/12/06 18:09:23
1147 [channels.c session.c]
1148 strncpy->strlcpy. remaining strncpy's are necessary. ok markus@
d24631c9 1149 - stevesk@cvs.openbsd.org 2001/12/06 18:20:32
1150 [channels.c]
1151 disable nagle for X11 fake server and client TCPs. from netbsd.
1152 ok markus@
3f3ac025 1153
115420011206
6056eb35 1155 - (bal) OpenBSD CVS Sync
1156 - deraadt@cvs.openbsd.org 2001/11/14 20:45:08
1157 [sshd.c]
1158 errno saving wrapping in a signal handler
0408c978 1159 - markus@cvs.openbsd.org 2001/11/16 12:46:13
1160 [ssh-keyscan.c]
1161 handle empty lines instead of dumping core; report from sha@sha-1.net
17a3011c 1162 - stevesk@cvs.openbsd.org 2001/11/17 19:14:34
1163 [auth2.c auth.c readconf.c servconf.c ssh-agent.c ssh-keygen.c]
1164 enum/int type cleanup where it made sense to do so; ok markus@
7ace8c3b 1165 - markus@cvs.openbsd.org 2001/11/19 11:20:21
1166 [sshd.c]
1167 fd leak on HUP; ok stevesk@
8666316a 1168 - stevesk@cvs.openbsd.org 2001/11/19 18:40:46
1169 [ssh-agent.1]
1170 clarify/state that private keys are not exposed to clients using the
1171 agent; ok markus@
44c2ab73 1172 - mpech@cvs.openbsd.org 2001/11/19 19:02:16
1173 [deattack.c radix.c]
1174 kill more registers
1175 millert@ ok
2f98d223 1176 - markus@cvs.openbsd.org 2001/11/21 15:51:24
1177 [key.c]
1178 mem leak
c840d0ad 1179 - stevesk@cvs.openbsd.org 2001/11/21 18:49:14
1180 [ssh-keygen.1]
1181 more on passphrase construction; ok markus@
f48e63c8 1182 - stevesk@cvs.openbsd.org 2001/11/22 05:27:29
1183 [ssh-keyscan.c]
1184 don't use "\n" in fatal()
7a934d1b 1185 - markus@cvs.openbsd.org 2001/11/22 12:34:22
1186 [clientloop.c serverloop.c sshd.c]
1187 volatile sig_atomic_t
58d94604 1188 - stevesk@cvs.openbsd.org 2001/11/29 19:06:39
1189 [channels.h]
1190 remove dead function prototype; ok markus@
2975f58d 1191 - markus@cvs.openbsd.org 2001/11/29 22:08:48
1192 [auth-rsa.c]
1193 fix protocol error: send 'failed' message instead of a 2nd challenge
1194 (happens if the same key is in authorized_keys twice).
1195 reported Ralf_Meister@genua.de; ok djm@
b48eeb07 1196 - stevesk@cvs.openbsd.org 2001/11/30 20:39:28
1197 [ssh.c]
1198 sscanf() length dependencies are clearer now; can also shrink proto
1199 and data if desired, but i have not done that. ok markus@
2548961d 1200 - markus@cvs.openbsd.org 2001/12/01 21:41:48
1201 [session.c sshd.8]
1202 don't pass user defined variables to /usr/bin/login
947b64c7 1203 - deraadt@cvs.openbsd.org 2001/12/02 02:08:32
1204 [sftp-common.c]
1205 zap };
010f9726 1206 - itojun@cvs.openbsd.org 2001/12/05 03:50:01
1207 [clientloop.c serverloop.c sshd.c]
1208 deal with LP64 printf issue with sig_atomic_t. from thorpej
d5bb9418 1209 - itojun@cvs.openbsd.org 2001/12/05 03:56:39
1210 [auth1.c auth2.c canohost.c channels.c deattack.c packet.c scp.c
1211 sshconnect2.c]
1212 make it compile with more strict prototype checking
6aacefa7 1213 - deraadt@cvs.openbsd.org 2001/12/05 10:06:12
1214 [authfd.c authfile.c bufaux.c channels.c compat.c kex.c kexgex.c
1215 key.c misc.c packet.c servconf.c ssh-agent.c sshconnect2.c
1216 sshconnect.c sshd.c ssh-dss.c ssh-keygen.c ssh-rsa.c]
1217 minor KNF
663ebb32 1218 - markus@cvs.openbsd.org 2001/12/05 15:04:48
1219 [version.h]
1220 post 3.0.2
6a92533a 1221 - markus@cvs.openbsd.org 2001/12/05 16:54:51
1222 [compat.c match.c match.h]
1223 make theo and djm happy: bye bye regexp
2717fa0f 1224 - markus@cvs.openbsd.org 2001/12/06 13:30:06
1225 [servconf.c servconf.h sshd.8 sshd.c]
1226 add -o to sshd, too. ok deraadt@
1227 - (bal) Minor white space fix up in servconf.c
6056eb35 1228
ffb8d130 122920011126
1230 - (tim) [contrib/cygwin/README, openbsd-compat/bsd-cygwin_util.c,
1231 openbsd-compat/bsd-cygwin_util.h, openbsd-compat/daemon.c]
1232 Allow SSHD to install as service under WIndows 9x/Me
1233 [configure.ac] Fix to allow linking against PCRE on Cygwin
1234 Patches by Corinna Vinschen <vinschen@redhat.com>
1235
20716479 123620011115
1237 - (djm) Fix IPv4 default in ssh-keyscan. Spotted by Dan Astoorian
1238 <djast@cs.toronto.edu> Fix from markus@
e41f14ae 1239 - (djm) Release 3.0.1p1
20716479 1240
9aba5a4d 124120011113
1242 - (djm) Fix early (and double) free of remote user when using Kerberos.
1243 Patch from Simon Wilkinson <simon@sxw.org.uk>
19e810f6 1244 - (djm) AIX login{success,failed} changes. Move loginsuccess call to
1245 do_authenticated. Call loginfailed for protocol 2 failures > MAX like
1246 we do for protocol 1. Reports from Ralf Wenk <wera0003@fh-karlsruhe.de>,
1247 K.Wolkersdorfer@fz-juelich.de and others
ede8cea6 1248 - (djm) OpenBSD CVS Sync
1249 - dugsong@cvs.openbsd.org 2001/11/11 18:47:10
1250 [auth-krb5.c]
1251 fix krb5 authorization check. found by <jhawk@MIT.EDU>. from
1252 art@, deraadt@ ok
b0248360 1253 - markus@cvs.openbsd.org 2001/11/12 11:17:07
1254 [servconf.c]
1255 enable authorized_keys2 again. tested by fries@
0bbf2240 1256 - markus@cvs.openbsd.org 2001/11/13 02:03:57
1257 [version.h]
1258 enter 3.0.1
86b164b3 1259 - (djm) Bump RPM package versions
9aba5a4d 1260
3e4e3bc8 126120011112
1262 - (djm) Makefile correctness fix from Mark D. Baushke <mdb@juniper.net>
d36ae718 1263 - (djm) Cygwin config patch from Corinna Vinschen <vinschen@redhat.com>
9ae3f727 1264 - OpenBSD CVS Sync
1265 - markus@cvs.openbsd.org 2001/10/24 08:41:41
1266 [sshd.c]
1267 mention remote port in debug message
f103187f 1268 - markus@cvs.openbsd.org 2001/10/24 08:41:20
1269 [ssh.c]
1270 remove unused
67b75437 1271 - markus@cvs.openbsd.org 2001/10/24 08:51:35
1272 [clientloop.c ssh.c]
1273 ignore SIGPIPE early, makes ssh work if agent dies, netbsd-pr via itojun@
c6940381 1274 - markus@cvs.openbsd.org 2001/10/24 19:57:40
1275 [clientloop.c]
1276 make ~& (backgrounding) work again for proto v1; add support ~& for v2, too
f564d016 1277 - markus@cvs.openbsd.org 2001/10/25 21:14:32
1278 [ssh-keygen.1 ssh-keygen.c]
1279 better docu for fingerprinting, ok deraadt@
e8d59b4d 1280 - markus@cvs.openbsd.org 2001/10/29 19:27:15
1281 [sshconnect2.c]
1282 hostbased: check for client hostkey before building chost
03cf595c 1283 - markus@cvs.openbsd.org 2001/10/30 20:29:09
1284 [ssh.1]
1285 ssh.1
b4b701be 1286 - markus@cvs.openbsd.org 2001/11/07 16:03:17
1287 [packet.c packet.h sshconnect2.c]
1288 pad using the padding field from the ssh2 packet instead of sending
1289 extra ignore messages. tested against several other ssh servers.
10f22cd7 1290 - markus@cvs.openbsd.org 2001/11/07 21:40:21
1291 [ssh-rsa.c]
1292 ssh_rsa_sign/verify: SSH_BUG_SIGBLOB not supported
abc4e9a7 1293 - markus@cvs.openbsd.org 2001/11/07 22:10:28
1294 [ssh-dss.c ssh-rsa.c]
1295 missing free and sync dss/rsa code.
713d61f7 1296 - markus@cvs.openbsd.org 2001/11/07 22:12:01
1297 [sshd.8]
1298 s/Keepalive/KeepAlive/; from openbsd@davidkrause.com
f98585b0 1299 - markus@cvs.openbsd.org 2001/11/07 22:41:51
1300 [auth2.c auth-rh-rsa.c]
1301 unused includes
27c47c0a 1302 - markus@cvs.openbsd.org 2001/11/07 22:53:21
1303 [channels.h]
1304 crank c->path to 256 so they can hold a full hostname; dwd@bell-labs.com
56b551e2 1305 - markus@cvs.openbsd.org 2001/11/08 10:51:08
1306 [readpass.c]
1307 don't strdup too much data; from gotoh@taiyo.co.jp; ok millert.
dd58cb5e 1308 - markus@cvs.openbsd.org 2001/11/08 17:49:53
1309 [ssh.1]
1310 mention setuid root requirements; noted by cnorris@csc.UVic.ca; ok stevesk@
fad3754c 1311 - markus@cvs.openbsd.org 2001/11/08 20:02:24
1312 [auth.c]
1313 don't print ROOT in CAPS for the authentication messages, i.e.
1314 Accepted publickey for ROOT from 127.0.0.1 port 42734 ssh2
1315 becomes
1316 Accepted publickey for root from 127.0.0.1 port 42734 ssh2
b3ad8fe6 1317 - markus@cvs.openbsd.org 2001/11/09 18:59:23
1318 [clientloop.c serverloop.c]
1319 don't memset too much memory, ok millert@
1320 original patch from jlk@kamens.brookline.ma.us via nalin@redhat.com
ac28afd8 1321 - markus@cvs.openbsd.org 2001/11/10 13:19:45
1322 [sshd.c]
e15895cd 1323 cleanup libwrap support (remove bogus comment, bogus close(), add
1324 debug, etc).
5d4446bf 1325 - markus@cvs.openbsd.org 2001/11/10 13:22:42
1326 [ssh-rsa.c]
1327 KNF (unexpand)
ec413a68 1328 - markus@cvs.openbsd.org 2001/11/10 13:37:20
1329 [packet.c]
1330 remove extra debug()
5df83e07 1331 - markus@cvs.openbsd.org 2001/11/11 13:02:31
1332 [servconf.c]
e15895cd 1333 make AuthorizedKeysFile2 fallback to AuthorizedKeysFile if
1334 AuthorizedKeysFile is specified.
1335 - (djm) Reorder portable-specific server options so that they come first.
1336 This should help reduce diff collisions for new server options (as they
1337 will appear at the end)
3e4e3bc8 1338
78afd1dc 133920011109
1340 - (stevesk) auth-pam.c: use do_pam_authenticate(PAM_DISALLOW_NULL_AUTHTOK)
1341 if permit_empty_passwd == 0 so null password check cannot be bypassed.
1342 jayaraj@amritapuri.com OpenBSD bug 2168
30f60c34 1343 - markus@cvs.openbsd.org 2001/11/09 19:08:35
1344 [sshd.c]
1345 remove extra trailing dot from log message; pilot@naughty.monkey.org
1346
7c6d759d 134720011103
1348 - (tim) [ contrib/caldera/openssh.spec contrib/caldera/sshd.init] Updates
1349 from Raymund Will <ray@caldera.de>
1350 [acconfig.h configure.in] Clean up login checks.
1351 Problem reported by Jim Knoble <jmknoble@pobox.com>
1352
135320011101
58389b85 1354 - (djm) Compat define for OpenSSL < 0.9.6 (No OPENSSL_free)
1355
548fd014 135620011031
1357 - (djm) Unsmoke drugs: config files should be noreplace.
1358
b013a983 135920011030
1360 - (djm) Redhat RPM spec: remove noreplace from config files, allow IPv6
1361 by default (can force IPv4 using --define "noipv6 1")
1362
40d0f6b9 136320011029
1364 - (tim) [TODO defines.h loginrec.c] Change the references to configure.in
1365 to configure.ac
1366
9f214051 136720011028
1368 - (djm) Avoid bug in Solaris PAM libs
7eb73cc1 1369 - (djm) Disconnect if no tty and PAM reports password expired
9678565b 1370 - (djm) Fix for PAM password changes being echoed (from stevesk)
840ad55e 1371 - (stevesk) Fix compile problem with PAM password change fix
37a8edf7 1372 - (stevesk) README: zlib location is http://www.gzip.org/zlib/
9f214051 1373
c8c15bcb 137420011027
1375 - (tim) [configure.ac] Fixes for ReliantUNIX (don't use libucb)
1376 Patch by Robert Dahlem <Robert.Dahlem@siemens.com>
1377
9e127e27 137820011026
1379 - (bal) Set the correct current time in login_utmp_only(). Patch by
1380 Wayne Davison <wayned@users.sourceforge.net>
fd96c060 1381 - (tim) [scard/Makefile.in] Fix install: when building outside of source
1382 tree and using --src=/full_path/to/openssh
1383 Patch by Mark D. Baushke <mdb@juniper.net>
9e127e27 1384
d321c94b 138520011025
1386 - (bal) Use VDISABLE if _POSIX_VDISABLE is set in readpassphrase.c. Patch
1387 by todd@
5a162955 1388 - (tim) [configure.ac] Give path given in --with-xxx= for pcre,zlib, and
1389 tcp-wrappers precedence over system libraries and includes.
1390 Report from Dave Dykstra <dwd@bell-labs.com>
d321c94b 1391
95c88805 139220011024
1393 - (bal) Should be 3.0p1 not 3.0p2. Corrected version.h already.
451dab40 1394 - (tim) configure.in -> configure.ac
95c88805 1395
bc86d864 139620011023
1397 - (bal) Updated version to 3.0p1 in preparing for release.
7f0a4ff1 1398 - (bal) Added 'PAM_TTY_KLUDGE' to Solaris platform.
051809f6 1399 - (tim) [configure.in] Fix test for broken dirname. Based on patch from
1400 Dave Dykstra <dwd@bell-labs.com>. Remove un-needed test for zlib.h.
1401 [contrib/caldera/openssh.spec, contrib/redhat/openssh.spec,
1402 contrib/suse/openssh.spec] Update version to match version.h
bc86d864 1403
ce49121d 140420011022
1405 - (djm) Fix fd leak in loginrec.c (ro fd to lastlog was left open).
1406 Report from Michal Zalewski <lcamtuf@coredump.cx>
1407
98a7c37b 140820011021
1409 - (tim) [configure.in] Clean up library testing. Add optional PATH to
1410 --with-pcre, --with-zlib, and --with-tcp-wrappers. Based on
1411 patch by albert chin (china@thewrittenword.com)
1412 Re-arange AC_CHECK_HEADERS and AC_CHECK_FUNCS for eaiser reading
1413 of patches to configure.in. Replace obsolete AC_STRUCT_ST_BLKSIZE
1414 with AC_CHECK_MEMBERS. Add test for broken dirname() on
1415 Solaris 2.5.1 by Dan Astoorian <djast@cs.toronto.edu>
1416 [acconfig.h aclocal.m4 defines.h configure.in] Better socklen_t test.
1417 patch by albert chin (china@thewrittenword.com)
1418 [scp.c] Replace obsolete HAVE_ST_BLKSIZE with
1419 HAVE_STRUCT_STAT_ST_BLKSIZE.
1420 [Makefile.in] When running make in top level, always do make
1421 in openbsd-compat. patch by Dave Dykstra <dwd@bell-labs.com>
1422
09a3bd6d 142320011019
1424 - (bal) Fixed up init.d symlink issue and piddir stuff. Patches by
1425 Zoran Milojevic <Zoran.Milojevic@SS8.com> and j.petersen@msh.de
1426
418e724c 142720011012
1428 - (djm) OpenBSD CVS Sync
1429 - markus@cvs.openbsd.org 2001/10/10 22:18:47
1430 [channels.c channels.h clientloop.c nchan.c serverloop.c]
1431 [session.c session.h]
1432 try to keep channels open until an exit-status message is sent.
1433 don't kill the login shells if the shells stdin/out/err is closed.
1434 this should now work:
1435 ssh -2n localhost 'exec > /dev/null 2>&1; sleep 10; exit 5'; echo ?
efcc9957 1436 - markus@cvs.openbsd.org 2001/10/11 13:45:21
1437 [session.c]
1438 delay detach of session if a channel gets closed but the child is
1439 still alive. however, release pty, since the fd's to the child are
1440 already closed.
fd6cfbaf 1441 - markus@cvs.openbsd.org 2001/10/11 15:24:00
1442 [clientloop.c]
1443 clear select masks if we return before calling select().
b0454d44 1444 - (djm) "make veryclean" fix from Tom Holroyd <tomh@po.crl.go.jp>
aeabbb30 1445 - (djm) Clean some autoconf-2.52 junk when doing "make distclean"
8140f2aa 1446 - (djm) Cleanup sshpty.c a little
6e464960 1447 - (bal) First wave of contrib/solaris/ package upgrades. Still more
1448 work needs to be done, but it is a 190% better then the stuff we
1449 had before!
78c84f13 1450 - (bal) Minor bug fix in contrib/solaris/opensshd.in .. $etcdir was not
1451 set right.
418e724c 1452
c48c32c1 145320011010
1454 - (djm) OpenBSD CVS Sync
1455 - markus@cvs.openbsd.org 2001/10/04 14:34:16
1456 [key.c]
1457 call OPENSSL_free() for memory allocated by openssl; from chombier@mac.com
0c139bd1 1458 - markus@cvs.openbsd.org 2001/10/04 15:05:40
1459 [channels.c serverloop.c]
1460 comment out bogus conditions for selecting on connection_in
72176c0e 1461 - markus@cvs.openbsd.org 2001/10/04 15:12:37
1462 [serverloop.c]
1463 client_alive_check cleanup
a2c92c4a 1464 - markus@cvs.openbsd.org 2001/10/06 00:14:50
1465 [sshconnect.c]
1466 remove unused argument
05fd093c 1467 - markus@cvs.openbsd.org 2001/10/06 00:36:42
1468 [session.c]
1469 fix typo in error message, sync with do_exec_nopty
01e9ef57 1470 - markus@cvs.openbsd.org 2001/10/06 11:18:19
1471 [sshconnect1.c sshconnect2.c sshconnect.c]
1472 unify hostkey check error messages, simplify prompt.
2cdccb44 1473 - markus@cvs.openbsd.org 2001/10/07 10:29:52
1474 [authfile.c]
1475 grammer; Matthew_Clarke@mindlink.bc.ca
639cb8ab 1476 - markus@cvs.openbsd.org 2001/10/07 17:49:40
1477 [channels.c channels.h]
1478 avoid possible FD_ISSET overflow for channels established
1479 during channnel_after_select() (used for dynamic channels).
f3964cb9 1480 - markus@cvs.openbsd.org 2001/10/08 11:48:57
1481 [channels.c]
1482 better debug
32af6a3f 1483 - markus@cvs.openbsd.org 2001/10/08 16:15:47
1484 [sshconnect.c]
1485 use correct family for -b option
dab89049 1486 - markus@cvs.openbsd.org 2001/10/08 19:05:05
1487 [ssh.c sshconnect.c sshconnect.h ssh-keyscan.c]
1488 some more IPv4or6 cleanup
1489 - markus@cvs.openbsd.org 2001/10/09 10:12:08
1490 [session.c]
1491 chdir $HOME after krb_afslog(); from bbense@networking.stanford.edu
01855277 1492 - markus@cvs.openbsd.org 2001/10/09 19:32:49
1493 [session.c]
1494 stat subsystem command before calling do_exec, and return error to client.
9d1b2faa 1495 - markus@cvs.openbsd.org 2001/10/09 19:51:18
1496 [serverloop.c]
1497 close all channels if the connection to the remote host has been closed,
1498 should fix sshd's hanging with WCHAN==wait
d5f24f94 1499 - markus@cvs.openbsd.org 2001/10/09 21:59:41
1500 [channels.c channels.h serverloop.c session.c session.h]
1501 simplify session close: no more delayed session_close, no more
1502 blocking wait() calls.
b6a71cd2 1503 - (bal) removed two unsed headers in openbsd-compat/bsd-misc.c
8782141f 1504 - (bal) seed_init() and seed_rng() required in ssh-keyscan.c
c48c32c1 1505
46dfe5ef 150620011007
1507 - (bal) ssh-copy-id corrected permissions for .ssh/ and authorized_keys.
1508 Prompted by Matthew Vernon <matthew@sel.cam.ac.uk>
1509
822593d4 151020011005
1511 - (bal) AES works under Cray, no more hack.
1512
63fa6b6c 151320011004
1514 - (bal) nchan2.ms resync. BSD License applied.
1515
c8a62153 151620011003
1517 - (bal) CVS ID fix up in version.h
b6350327 1518 - (bal) OpenBSD CVS Sync:
1519 - markus@cvs.openbsd.org 2001/09/27 11:58:16
1520 [compress.c]
1521 mem leak; chombier@mac.com
1522 - markus@cvs.openbsd.org 2001/09/27 11:59:37
1523 [packet.c]
1524 missing called=1; chombier@mac.com
aa8003d6 1525 - markus@cvs.openbsd.org 2001/09/27 15:31:17
1526 [auth2.c auth2-chall.c sshconnect1.c]
1527 typos; from solar
5b263aae 1528 - camield@cvs.openbsd.org 2001/09/27 17:53:24
1529 [sshd.8]
1530 don't talk about compile-time options
1531 ok markus@
e99a518a 1532 - djm@cvs.openbsd.org 2001/09/28 12:07:09
1533 [ssh-keygen.c]
1534 bzero private key after loading to smartcard; ok markus@
f67792f2 1535 - markus@cvs.openbsd.org 2001/09/28 15:46:29
1536 [ssh.c]
1537 bug: read user config first; report kaukasoi@elektroni.ee.tut.fi
5720c10e 1538 - markus@cvs.openbsd.org 2001/10/01 08:06:28
1539 [scp.c]
1540 skip filenames containing \n; report jdamery@chiark.greenend.org.uk
1541 and matthew@debian.org
5e4a7219 1542 - markus@cvs.openbsd.org 2001/10/01 21:38:53
1543 [channels.c channels.h ssh.c sshd.c]
1544 remove ugliness; vp@drexel.edu via angelos
8bbc048a 1545 - markus@cvs.openbsd.org 2001/10/01 21:51:16
1546 [readconf.c readconf.h ssh.1 sshconnect.c]
1547 add NoHostAuthenticationForLocalhost; note that the hostkey is
1548 now check for localhost, too.
e0543e42 1549 - djm@cvs.openbsd.org 2001/10/02 08:38:50
1550 [ssh-add.c]
1551 return non-zero exit code on error; ok markus@
e4d7f734 1552 - stevesk@cvs.openbsd.org 2001/10/02 22:56:09
1553 [sshd.c]
1554 #include "channels.h" for channel_set_af()
76fbdd47 1555 - markus@cvs.openbsd.org 2001/10/03 10:01:20
1556 [auth.c]
1557 use realpath() for homedir, too. from jinmei@isl.rdc.toshiba.co.jp
c8a62153 1558
d9d47a26 155920011001
1560 - (stevesk) loginrec.c: fix type conversion problems exposed when using
1561 64-bit off_t.
1562
d8d6c87e 156320010929
1564 - (bal) move reading 'config.h' up higher. Patch by albert chin
1565 <china@thewrittenword.com)
1566
fc1fc39e 156720010928
1568 - (djm) OpenBSD CVS sync:
1569 - djm@cvs.openbsd.org 2001/09/28 09:49:31
1570 [scard.c]
1571 Fix segv when smartcard communication error occurs during key load.
1572 ok markus@
e3d5570b 1573 - (djm) Update spec files for new x11-askpass
fc1fc39e 1574
8a9ac95d 157520010927
1576 - (stevesk) session.c: declare do_pre_login() before use
1577 wayned@users.sourceforge.net
1578
aa9f6a6e 157920010925
1580 - (djm) Pull in auth-krb5.c from OpenBSD CVS. NB. it is not currently used.
168edd95 1581 - (djm) Sync $sysconfdir/moduli
948fd8b9 1582 - (djm) Add AC_SYS_LARGEFILE configure test
4f9d80ee 1583 - (djm) Avoid bad and unportable sprintf usage in compat code
aa9f6a6e 1584
57dade33 158520010923
1586 - (bal) updated ssh.c to mirror minor getopts 'extern int' formating done
1587 by stevesk@
927c3e15 1588 - (bal) Removed 'extern int optopt;' since it is dead wood.
8ead88d3 1589 - (bal) Updated all *.specs for 2.9.9p1 and updated version.h
57dade33 1590
8ab12eb4 159120010923
1592 - (bal) OpenBSD CVS Sync
1593 - markus@cvs.openbsd.org 2001/09/23 11:09:13
1594 [authfile.c]
1595 relax permission check for private key files.
157fc8e1 1596 - markus@cvs.openbsd.org 2001/09/23 09:58:13
1597 [LICENCE]
1598 new rijndael implementation
8ab12eb4 1599
64bdafe1 160020010920
1601 - (tim) [scard/Makefile.in] Don't strip the Java binary
4a38efad 1602 - (stevesk) sun_len, SUN_LEN() configure stuff no longer required
fc7eca52 1603 - (bal) OpenBSD CVS Sync
1604 - stevesk@cvs.openbsd.org 2001/09/20 00:15:54
1605 [sshd.8]
1606 fix ClientAliveCountMax
ddcfed57 1607 - markus@cvs.openbsd.org 2001/09/20 13:46:48
1608 [auth2.c]
1609 key_read returns now -1 or 1
bcdb96c2 1610 - markus@cvs.openbsd.org 2001/09/20 13:50:40
1611 [compat.c compat.h ssh.c]
1612 bug compat: request a dummy channel for -N (no shell) sessions +
1613 cleanup; vinschen@redhat.com
4a778de1 1614 - mouring@cvs.openbsd.org 2001/09/20 20:57:51
1615 [sshd_config]
1616 CheckMail removed. OKed stevesk@
64bdafe1 1617
4cdbc654 161820010919
35c69348 1619 - (bal) OpenBSD Sync
4cdbc654 1620 - markus@cvs.openbsd.org 2001/09/19 10:08:51
1621 [sshd.8]
1622 command=xxx applies to subsystem now, too
cb8c7bad 1623 - markus@cvs.openbsd.org 2001/09/19 13:23:29
1624 [key.c]
1625 key_read() now returns -1 on type mismatch, too
e1c5bfaf 1626 - stevesk@cvs.openbsd.org 2001/09/19 19:24:19
1627 [readconf.c readconf.h scp.c sftp.c ssh.1]
1628 add ClearAllForwardings ssh option and set it in scp and sftp; ok
1629 markus@
f34f05d5 1630 - stevesk@cvs.openbsd.org 2001/09/19 19:35:30
1631 [authfd.c]
1632 use sizeof addr vs. SUN_LEN(addr) for sockaddr_un. Stevens
1633 blesses this and we do it this way elsewhere. this helps in
1634 portable because not all systems have SUN_LEN() and
1635 sockaddr_un.sun_len. ok markus@
2043936f 1636 - stevesk@cvs.openbsd.org 2001/09/19 21:04:53
1637 [sshd.8]
1638 missing -t in usage
368bae7d 1639 - stevesk@cvs.openbsd.org 2001/09/19 21:41:57
1640 [sshd.8]
1641 don't advertise -V in usage; ok markus@
35c69348 1642 - (bal) openbsd-compat/vis.[ch] is dead wood. Removed.
4cdbc654 1643
d0b19c95 164420010918
46a831dd 1645 - (djm) Configure support for smartcards. Based on Ben's work.
fef4ea6b 1646 - (djm) Revert setgroups call, it causes problems on OS-X
46a831dd 1647 - (djm) Avoid warning on BSDgetopt
93816ec8 1648 - (djm) More makefile infrastructre for smartcard support, also based
1649 on Ben's work
4b255446 1650 - (djm) Specify --datadir in RPM spec files so smartcard applet gets
1651 put somewhere sane. Add Ssh.bin to manifest.
69c94072 1652 - (djm) Make smartcard support conditional in Redhat RPM spec
1a77481c 1653 - (bal) LICENCE update. Has not been done in a while.
f49df8e9 1654 - (stevesk) nchan.c: we use X/Open Sockets on HP-UX now so shutdown(2)
1655 returns ENOTCONN vs. EINVAL for socket not connected; remove EINVAL
1656 check. ok Lutz Jaenicke
35c69348 1657 - (bal) OpenBSD CVS Sync
f1278af7 1658 - stevesk@cvs.openbsd.org 2001/09/17 17:57:57
1659 [scp.1 scp.c sftp.1 sftp.c]
1660 add -Fssh_config option; ok markus@
cf54363d 1661 - stevesk@cvs.openbsd.org 2001/09/17 19:27:15
1662 [kexdh.c kexgex.c key.c key.h ssh-dss.c ssh-keygen.c ssh-rsa.c]
1663 u_char*/char* cleanup; ok markus
4e842b5e 1664 - markus@cvs.openbsd.org 2001/09/17 20:22:14
1665 [scard.c]
1666 never keep a connection to the smartcard open.
1667 allows ssh-keygen -D U while the agent is running; report from
1668 jakob@
e3c1c3e6 1669 - stevesk@cvs.openbsd.org 2001/09/17 20:38:09
1670 [sftp.1 sftp.c]
1671 cleanup and document -1, -s and -S; ok markus@
f7436b8c 1672 - markus@cvs.openbsd.org 2001/09/17 20:50:22
1673 [key.c ssh-keygen.c]
1674 better error handling if you try to export a bad key to ssh.com
a5f82435 1675 - markus@cvs.openbsd.org 2001/09/17 20:52:47
1676 [channels.c channels.h clientloop.c]
1677 try to fix agent-forwarding-backconnection-bug, as seen on HPUX,
1678 for example; with Lutz.Jaenicke@aet.TU-Cottbus.DE,
780a9951 1679 - markus@cvs.openbsd.org 2001/09/17 21:04:02
1680 [channels.c serverloop.c]
1681 don't send fake dummy packets on CR (\r)
1682 bugreport from yyua@cs.sfu.ca via solar@@openwall.com
b6761a3e 1683 - markus@cvs.openbsd.org 2001/09/17 21:09:47
1684 [compat.c]
1685 more versions suffering the SSH_BUG_DEBUG bug;
1686 3.0.x reported by dbutts@maddog.storability.com
edaeb835 1687 - stevesk@cvs.openbsd.org 2001/09/17 23:56:07
1688 [scp.1]
1689 missing -B in usage string
d0b19c95 1690
d31a32a4 169120010917
1692 - (djm) x11-ssh-askpass-1.2.4 in RPM spec, revert workarounds
cb547f98 1693 - (tim) [includes.h openbsd-compat/getopt.c openbsd-compat/getopt.h]
1694 rename getopt() to BSDgetopt() to keep form conflicting with
1695 system getopt().
1696 [Makefile.in configure.in] disable filepriv until I can add
1697 missing procpriv calls.
d31a32a4 1698
95d00a03 169920010916
1700 - (djm) Workaround XFree breakage in RPM spec file
6fcf67f7 1701 - (bal) OpenBSD CVS Sync
1702 - markus@cvs.openbsd.org 2001/09/16 14:46:54
1703 [session.c]
1704 calls krb_afslog() after setting $HOME; mattiasa@e.kth.se; fixes
1705 pr 1943b
95d00a03 1706
0e0144b7 170720010915
1708 - (djm) Make do_pre_login static to avoid prototype #ifdef hell
0fd6c7a9 1709 - (djm) Sync scard/ stuff
23c098ba 1710 - (djm) Redhat spec file cleanups from Pekka Savola <pekkas@netcore.fi> and
1711 Redhat
94a29edc 1712 - (djm) Redhat initscript config sanity checking from Pekka Savola
1713 <pekkas@netcore.fi>
e72ff812 1714 - (djm) Clear supplemental groups at sshd start to prevent them from
1715 being propogated to random PAM modules. Based on patch from Redhat via
1716 Pekka Savola <pekkas@netcore.fi>
a2cb4268 1717 - (djm) Make sure rijndael.c picks config.h
1718 - (djm) Ensure that u_char gets defined
0e0144b7 1719
dcf29cf8 172020010914
1721 - (bal) OpenBSD CVS Sync
1722 - markus@cvs.openbsd.org 2001/09/13
1723 [rijndael.c rijndael.h]
1724 missing $OpenBSD
fd022eed 1725 - markus@cvs.openbsd.org 2001/09/14
1726 [session.c]
1727 command=xxx overwrites subsystems, too
9658ecbc 1728 - markus@cvs.openbsd.org 2001/09/14
1729 [sshd.c]
1730 typo
fd022eed 1731
88c3bfe0 173220010913
1733 - (bal) OpenBSD CVS Sync
1734 - markus@cvs.openbsd.org 2001/08/23 11:31:59
1735 [cipher.c cipher.h]
1736 switch to the optimised AES reference code from
1737 http://www.esat.kuleuven.ac.be/~rijmen/rijndael/rijndael-fst-3.0.zip
1738
5c53a31e 173920010912
1740 - (bal) OpenBSD CVS Sync
1741 - jakob@cvs.openbsd.org 2001/08/16 19:18:34
1742 [servconf.c servconf.h session.c sshd.8]
1743 deprecate CheckMail. ok markus@
54bf768d 1744 - stevesk@cvs.openbsd.org 2001/08/16 20:14:57
1745 [ssh.1 sshd.8]
1746 document case sensitivity for ssh, sshd and key file
1747 options and arguments; ok markus@
6d7b3036 1748 - stevesk@cvs.openbsd.org 2001/08/17 18:59:47
1749 [servconf.h]
1750 typo in comment
ae897d7c 1751 - stevesk@cvs.openbsd.org 2001/08/21 21:47:42
1752 [ssh.1 sshd.8]
1753 minor typos and cleanup
c78e5800 1754 - stevesk@cvs.openbsd.org 2001/08/22 16:21:21
1755 [ssh.1]
1756 hostname not optional; ok markus@
9495bfc5 1757 - stevesk@cvs.openbsd.org 2001/08/22 16:30:02
1758 [sshd.8]
1759 no rexd; ok markus@
29999e54 1760 - stevesk@cvs.openbsd.org 2001/08/22 17:45:16
1761 [ssh.1]
1762 document cipher des for protocol 1; ok deraadt@
8fbc356d 1763 - camield@cvs.openbsd.org 2001/08/23 17:59:31
1764 [sshd.c]
1765 end request with 0, not NULL
1766 ok markus@
d866473d 1767 - stevesk@cvs.openbsd.org 2001/08/23 18:02:48
1768 [ssh-agent.1]
1769 fix usage; ok markus@
75304f85 1770 - stevesk@cvs.openbsd.org 2001/08/23 18:08:59
1771 [ssh-add.1 ssh-keyscan.1]
1772 minor cleanup
b7f79e7a 1773 - danh@cvs.openbsd.org 2001/08/27 22:02:13
1774 [ssh-keyscan.c]
1775 fix memory fault if non-existent filename is given to the -f option
1776 ok markus@
14e4a15f 1777 - markus@cvs.openbsd.org 2001/08/28 09:51:26
1778 [readconf.c]
1779 don't set DynamicForward unless Host matches
e591b98a 1780 - markus@cvs.openbsd.org 2001/08/28 15:39:48
1781 [ssh.1 ssh.c]
1782 allow: ssh -F configfile host
46660a9e 1783 - markus@cvs.openbsd.org 2001/08/29 20:44:03
1784 [scp.c]
1785 clear the malloc'd buffer, otherwise source() will leak malloc'd
1786 memory; ok theo@
e675b851 1787 - stevesk@cvs.openbsd.org 2001/08/29 23:02:21
1788 [sshd.8]
1789 add text about -u0 preventing DNS requests; ok markus@
4c780c2a 1790 - stevesk@cvs.openbsd.org 2001/08/29 23:13:10
1791 [ssh.1 ssh.c]
1792 document -D and DynamicForward; ok markus@
d2e3df16 1793 - stevesk@cvs.openbsd.org 2001/08/29 23:27:23
1794 [ssh.c]
1795 validate ports for -L/-R; ok markus@
70068acc 1796 - stevesk@cvs.openbsd.org 2001/08/29 23:39:40
1797 [ssh.1 sshd.8]
1798 additional documentation for GatewayPorts; ok markus@
ad3e169f 1799 - naddy@cvs.openbsd.org 2001/08/30 15:42:36
1800 [ssh.1]
1801 add -D to synopsis line; ok markus@
3a8aabf0 1802 - stevesk@cvs.openbsd.org 2001/08/30 16:04:35
1803 [readconf.c ssh.1]
1804 validate ports for LocalForward/RemoteForward.
1805 add host/port alternative syntax for IPv6 (like -L/-R).
1806 ok markus@
ed787d14 1807 - stevesk@cvs.openbsd.org 2001/08/30 20:36:34
1808 [auth-options.c sshd.8]
1809 validate ports for permitopen key file option. add host/port
1810 alternative syntax for IPv6. ok markus@
4278ff63 1811 - markus@cvs.openbsd.org 2001/08/30 22:22:32
1812 [ssh-keyscan.c]
1813 do not pass pointers to longjmp; fix from wayne@blorf.net
6b759005 1814 - markus@cvs.openbsd.org 2001/08/31 11:46:39
1815 [sshconnect2.c]
93111dfa 1816 disable kbd-interactive if we don't get SSH2_MSG_USERAUTH_INFO_REQUEST
1817 messages
1818 - stevesk@cvs.openbsd.org 2001/09/03 20:58:33
1819 [readconf.c readconf.h ssh.c]
1820 fatal() for nonexistent -Fssh_config. ok markus@
91789042 1821 - deraadt@cvs.openbsd.org 2001/09/05 06:23:07
1822 [scp.1 sftp.1 ssh.1 ssh-agent.1 sshd.8 ssh-keygen.1 ssh-keyscan.1]
1823 avoid first person in manual pages
3a222388 1824 - stevesk@cvs.openbsd.org 2001/09/12 18:18:25
1825 [scp.c]
1826 don't forward agent for non third-party copies; ok markus@
5c53a31e 1827
c6ed03bd 182820010815
1829 - (bal) Fixed stray code in readconf.c that went in by mistake.
65e683bd 1830 - OpenBSD CVS Sync
1831 - markus@cvs.openbsd.org 2001/08/07 10:37:46
1832 [authfd.c authfd.h]
1833 extended failure messages from galb@vandyke.com
c7f89f1f 1834 - deraadt@cvs.openbsd.org 2001/08/08 07:16:58
1835 [scp.1]
1836 when describing the -o option, give -o Protocol=1 as the specific example
1837 since we are SICK AND TIRED of clueless people who cannot have difficulty
1838 thinking on their own.
f2f1bedd 1839 - markus@cvs.openbsd.org 2001/08/08 18:20:15
1840 [uidswap.c]
1841 permanently_set_uid is a noop if user is not privilegued;
1842 fixes bug on solaris; from sbi@uchicago.edu
58df8789 1843 - markus@cvs.openbsd.org 2001/08/08 21:34:19
1844 [uidswap.c]
1845 undo last change; does not work for sshd
c3abff07 1846 - jakob@cvs.openbsd.org 2001/08/11 22:51:27
1847 [ssh.c tildexpand.c]
1848 fix more paths beginning with "//"; <bradshaw@staff.crosswalk.com>.
1849 ok markus@
4fa5a4db 1850 - stevesk@cvs.openbsd.org 2001/08/13 23:38:54
1851 [scp.c]
1852 don't need main prototype (also sync with rcp); ok markus@
68874d2b 1853 - markus@cvs.openbsd.org 2001/08/14 09:23:02
1854 [sftp.1 sftp-int.c]
1855 "bye"; hk63a@netscape.net
38539909 1856 - stevesk@cvs.openbsd.org 2001/08/14 17:54:29
1857 [scp.1 sftp.1 ssh.1]
1858 consistent documentation and example of ``-o ssh_option'' for sftp and
1859 scp; document keyword=argument for ssh.
41cb4569 1860 - (bal) QNX resync. OK tim@
c6ed03bd 1861
3454ff55 186220010814
1863 - (stevesk) sshpty.c, cray.[ch]: whitespace, formatting and cleanup
1864 for some #ifdef _CRAY code; ok wendyp@cray.com
5bd6962b 1865 - (stevesk) sshpty.c: return 0 on error in cray pty code;
1866 ok wendyp@cray.com
4809bc4c 1867 - (stevesk) bsd-cray.c: utmp strings are not C strings
8280a5ae 1868 - (stevesk) bsd-cray.c: more cleanup; ok wendyp@cray.com
3454ff55 1869
d89a02d4 187020010812
1871 - (djm) Fix detection of long long int support. Based on patch from
1872 Michael Stone <mstone@cs.loyola.edu>. ok stevesk, tim
1873
7ef909d3 187420010808
1875 - (bal) Minor correction to inet_ntop.h. _BSD_RRESVPORT_H should be
1876 _BSD_INET_NTOP_H. Pointed out by Mark Miller <markm@swoon.net>
1877
a704dd54 187820010807
1879 - (tim) [configure.in sshconnect.c openbsd-compat/Makefile.in
1880 openbsd-compat/openbsd-compat.h ] Add inet_ntop.c inet_ntop.h back
1881 in. Needed for sshconnect.c
1882 [sshconnect.c] fix INET6_ADDRSTRLEN for non IPv6 machines
1883 [configure.in] make tests with missing libraries fail
1884 patch by Wendy Palm <wendyp@cray.com>
1885 Added openbsd-compat/bsd-cray.h. Selective patches from
1886 William L. Jones <jones@mail.utexas.edu>
1887
4f7893dc 188820010806
1889 - OpenBSD CVS Sync
1890 - markus@cvs.openbsd.org 2001/07/22 21:32:27
1891 [sshpty.c]
1892 update comment
0aea6c59 1893 - pvalchev@cvs.openbsd.org 2001/07/22 21:32:42
1894 [ssh.1]
1895 There is no option "Compress", point to "Compression" instead; ok
1896 markus
10a2cbef 1897 - markus@cvs.openbsd.org 2001/07/22 22:04:19
1898 [readconf.c ssh.1]
1899 enable challenge-response auth by default; ok millert@
248bad82 1900 - markus@cvs.openbsd.org 2001/07/22 22:24:16
1901 [sshd.8]
1902 Xr login.conf
9f37c0af 1903 - markus@cvs.openbsd.org 2001/07/23 09:06:28
1904 [sshconnect2.c]
1905 reorder default sequence of userauth methods to match ssh behaviour:
1906 hostbased,publickey,keyboard-interactive,password
29c440a0 1907 - markus@cvs.openbsd.org 2001/07/23 12:47:05
1908 [ssh.1]
1909 sync PreferredAuthentications
7fd9477e 1910 - aaron@cvs.openbsd.org 2001/07/23 14:14:18
1911 [ssh-keygen.1]
1912 Fix typo.
1bdee08c 1913 - stevesk@cvs.openbsd.org 2001/07/23 18:14:58
1914 [auth2.c auth-rsa.c]
1915 use %lu; ok markus@
bac2ef55 1916 - stevesk@cvs.openbsd.org 2001/07/23 18:21:46
1917 [xmalloc.c]
1918 no zero size xstrdup() error; ok markus@
55684f0c 1919 - markus@cvs.openbsd.org 2001/07/25 11:59:35
1920 [scard.c]
1921 typo in comment
ce773142 1922 - markus@cvs.openbsd.org 2001/07/25 14:35:18
1923 [readconf.c ssh.1 ssh.c sshconnect.c]
1924 cleanup connect(); connection_attempts 4 -> 1; from
1925 eivind@freebsd.org
f87f09aa 1926 - stevesk@cvs.openbsd.org 2001/07/26 17:18:22
1927 [sshd.8 sshd.c]
1928 add -t option to test configuration file and keys; pekkas@netcore.fi
1929 ok markus@
c42158fe 1930 - rees@cvs.openbsd.org 2001/07/26 20:04:27
1931 [scard.c ssh-keygen.c]
1932 Inquire Cyberflex class for 0xf0 cards
1933 change aid to conform to 7816-5
1934 remove gratuitous fid selects
2e23cde0 1935 - millert@cvs.openbsd.org 2001/07/27 14:50:45
1936 [ssh.c]
1937 If smart card support is compiled in and a smart card is being used
1938 for authentication, make it the first method used. markus@ OK
0b2988ca 1939 - deraadt@cvs.openbsd.org 2001/07/27 17:26:16
1940 [scp.c]
1941 shorten lines
7f19f8bb 1942 - markus@cvs.openbsd.org 2001/07/28 09:21:15
1943 [sshd.8]
1944 cleanup some RSA vs DSA vs SSH1 vs SSH2 notes
79a6cb5c 1945 - mouring@cvs.openbsd.org 2001/07/29 17:02:46
1946 [scp.1]
1947 Clarified -o option in scp.1 OKed by Markus@
0b595937 1948 - jakob@cvs.openbsd.org 2001/07/30 16:06:07
1949 [scard.c scard.h]
1950 better errorcodes from sc_*; ok markus@
d6192346 1951 - stevesk@cvs.openbsd.org 2001/07/30 16:23:30
1952 [rijndael.c rijndael.h]
1953 new BSD-style license:
1954 Brian Gladman <brg@gladman.plus.com>:
1955 >I have updated my code at:
1956 >http://fp.gladman.plus.com/cryptography_technology/rijndael/index.htm
1957 >with a copyright notice as follows:
1958 >[...]
1959 >I am not sure which version of my old code you are using but I am
1960 >happy for the notice above to be substituted for my existing copyright
1961 >intent if this meets your purpose.
71b7a18e 1962 - jakob@cvs.openbsd.org 2001/07/31 08:41:10
1963 [scard.c]
1964 do not complain about missing smartcards. ok markus@
eea098a3 1965 - jakob@cvs.openbsd.org 2001/07/31 09:28:44
1966 [readconf.c readconf.h ssh.1 ssh.c]
1967 add 'SmartcardDevice' client option to specify which smartcard device
1968 is used to access a smartcard used for storing the user's private RSA
1969 key. ok markus@.
88690211 1970 - jakob@cvs.openbsd.org 2001/07/31 12:42:50
1971 [sftp-int.c sftp-server.c]
1972 avoid paths beginning with "//"; <vinschen@redhat.com>
1973 ok markus@
2251e099 1974 - jakob@cvs.openbsd.org 2001/07/31 12:53:34
1975 [scard.c]
1976 close smartcard connection if card is missing
9ff6f66f 1977 - markus@cvs.openbsd.org 2001/08/01 22:03:33
1978 [authfd.c authfd.h readconf.c readconf.h scard.c scard.h ssh-add.c
1979 ssh-agent.c ssh.c]
1980 use strings instead of ints for smartcard reader ids
1930af48 1981 - markus@cvs.openbsd.org 2001/08/01 22:16:45
1982 [ssh.1 sshd.8]
1983 refer to current ietf drafts for protocol v2
4f831fd7 1984 - markus@cvs.openbsd.org 2001/08/01 23:33:09
1985 [ssh-keygen.c]
1986 allow uploading RSA keys for non-default AUT0 (sha1 over passphrase
1987 like sectok).
1a23ac2c 1988 - markus@cvs.openbsd.org 2001/08/01 23:38:45
05b7537a 1989 [scard.c ssh.c]
1990 support finish rsa keys.
1991 free public keys after login -> call finish -> close smartcard.
93a56445 1992 - markus@cvs.openbsd.org 2001/08/02 00:10:17
1993 [ssh-keygen.c]
1994 add -D readerid option (download, i.e. print public RSA key to stdout).
1995 check for card present when uploading keys.
1996 use strings instead of ints for smartcard reader ids, too.
285d2b15 1997 - jakob@cvs.openbsd.org 2001/08/02 08:58:35
1998 [ssh-keygen.c]
1999 change -u (upload smartcard key) to -U. ok markus@
58153e34 2000 - jakob@cvs.openbsd.org 2001/08/02 15:06:52
2001 [ssh-keygen.c]
2002 more verbose usage(). ok markus@
f0d6bdcf 2003 - jakob@cvs.openbsd.org 2001/08/02 15:07:23
2004 [ssh-keygen.1]
2005 document smartcard upload/download. ok markus@
315dfb04 2006 - jakob@cvs.openbsd.org 2001/08/02 15:32:10
2007 [ssh.c]
2008 add smartcard to usage(). ok markus@
3e984472 2009 - jakob@cvs.openbsd.org 2001/08/02 15:43:57
2010 [ssh-agent.c ssh.c ssh-keygen.c]
2011 add /* SMARTCARD */ to #else/#endif. ok markus@
1a23ac2c 2012 - jakob@cvs.openbsd.org 2001/08/02 16:14:05
dd2495cb 2013 [scard.c ssh-agent.c ssh.c ssh-keygen.c]
2014 clean up some /* SMARTCARD */. ok markus@
0f6d5acf 2015 - mpech@cvs.openbsd.org 2001/08/02 18:37:35
2016 [ssh-keyscan.1]
2017 o) .Sh AUTHOR -> .Sh AUTHORS;
2018 o) .Sh EXAMPLE -> .Sh EXAMPLES;
2019 o) Delete .Sh OPTIONS. Text moved to .Sh DESCRIPTION;
2020
2021 millert@ ok
5a26334c 2022 - jakob@cvs.openbsd.org 2001/08/03 10:31:19
2023 [ssh-add.1]
2024 document smartcard options. ok markus@
33e766d2 2025 - jakob@cvs.openbsd.org 2001/08/03 10:31:30
2026 [ssh-add.c ssh-agent.c ssh-keyscan.c]
2027 improve usage(). ok markus@
5061072f 2028 - markus@cvs.openbsd.org 2001/08/05 23:18:20
2029 [ssh-keyscan.1 ssh-keyscan.c]
2030 ssh 2 support; from wayned@users.sourceforge.net
578954b1 2031 - markus@cvs.openbsd.org 2001/08/05 23:29:58
2032 [ssh-keyscan.c]
2033 make -t dsa work with commercial servers, too
cddb9003 2034 - stevesk@cvs.openbsd.org 2001/08/06 19:47:05
2035 [scp.c]
2036 use alarm vs. setitimer for portable; ok markus@
94796c10 2037 - (bal) ssh-keyscan double -lssh hack due to seed_rng().
1a23ac2c 2038 - (bal) Second around of UNICOS patches. A few other things left.
2039 Patches by William L. Jones <jones@mail.utexas.edu>
4f7893dc 2040
29a47408 204120010803
2042 - (djm) Fix interrupted read in entropy gatherer. Spotted by markus@ on
2043 a fast UltraSPARC.
2044
42ad0eec 204520010726
2046 - (stevesk) use mysignal() in protocol 1 loop now that the SIGCHLD
2047 handler has converged.
2048
aa7dbcdd 204920010725
2050 - (bal) Added 'install-nokeys' to Makefile to assist package builders.
2051
0b7d19eb 205220010724
2053 - (bal) 4711 not 04711 for ssh binary.
2054
ca5c7d6a 205520010722
2056 - (bal) Starting the Unicossmk merger. File merged TODO, configure.in,
2057 myproposal.h, ssh_prng_cmds.in, and openbsd-compat/Makefile.in.
2058 Added openbsd-compat/bsd-cray.c. Rest will be merged after
2059 approval. Selective patches from William L. Jones
2060 <jones@mail.utexas.edu>
7458aff1 2061 - OpenBSD CVS Sync
2062 - markus@cvs.openbsd.org 2001/07/18 21:10:43
2063 [sshpty.c]
2064 pr #1946, allow sshd if /dev is readonly
ec9f3450 2065 - stevesk@cvs.openbsd.org 2001/07/18 21:40:40
2066 [ssh-agent.c]
2067 chdir("/") from bbraun@synack.net; ok markus@
5bef3c35 2068 - stevesk@cvs.openbsd.org 2001/07/19 00:41:44
2069 [ssh.1]
2070 escape chars are below now
7efa8482 2071 - markus@cvs.openbsd.org 2001/07/20 14:46:11
2072 [ssh-agent.c]
2073 do not exit() from signal handlers; ok deraadt@
491f5f7b 2074 - stevesk@cvs.openbsd.org 2001/07/20 18:41:51
2075 [ssh.1]
2076 "the" command line
ca5c7d6a 2077
979b0a64 207820010719
2079 - (tim) [configure.in] put inet_aton back in AC_CHECK_FUNCS.
2080 report from Mark Miller <markm@swoon.net>
2081
6e69a45d 208220010718
2083 - OpenBSD CVS Sync
2c5b1791 2084 - stevesk@cvs.openbsd.org 2001/07/14 15:10:17
2085 [readpass.c sftp-client.c sftp-common.c sftp-glob.c]
2086 delete spurious #includes; ok deraadt@ markus@
68fa858a 2087 - markus@cvs.openbsd.org 2001/07/15 16:17:08
2c5b1791 2088 [serverloop.c]
2089 schedule client alive for ssh2 only, greg@cheers.bungi.com
2c71dfc1 2090 - stevesk@cvs.openbsd.org 2001/07/15 16:57:21
2091 [ssh-agent.1]
2092 -d will not fork; ok markus@
d1fc1b88 2093 - stevesk@cvs.openbsd.org 2001/07/15 16:58:29
68fa858a 2094 [ssh-agent.c]
d1fc1b88 2095 typo in usage; ok markus@
68fa858a 2096 - markus@cvs.openbsd.org 2001/07/17 20:48:42
2097 [ssh-agent.c]
e364646f 2098 update maxfd if maxfd is closed; report from jmcelroy@dtgnet.com
68fa858a 2099 - markus@cvs.openbsd.org 2001/07/17 21:04:58
2100 [channels.c channels.h clientloop.c nchan.c serverloop.c]
489aa2e9 2101 keep track of both maxfd and the size of the malloc'ed fdsets.
2102 update maxfd if maxfd gets closed.
c3941fa6 2103 - mouring@cvs.openbsd.org 2001/07/18 16:45:52
2104 [scp.c]
2105 Missing -o in scp usage()
68fa858a 2106 - (bal) Cleaned up trailing spaces in ChangeLog.
31fb6aaf 2107 - (bal) Allow sshd to switch user context without password for Cygwin.
2108 Patch by Corinna Vinschen <vinschen@redhat.com>
41fcc457 2109 - (bal) Updated cygwin README and ssh-host-config. Patch by
ad0cc858 2110 Corinna Vinschen <vinschen@redhat.com>
6e69a45d 2111
39c98ef7 211220010715
2113 - (bal) Set "BROKEN_GETADDRINFO" for darwin platform. Reported by
2114 Josh Larios <jdlarios@cac.washington.edu>
c14e6239 2115 - (tim) put openssh/openbsd-compat/inet_aton.[ch] back in.
2116 needed by openbsd-compat/fake-getaddrinfo.c
68fa858a 2117
6800f427 211820010714
2119 - (stevesk) change getopt() declaration
763a1a18 2120 - (stevesk) configure.in: use ll suffix for long long constant
2121 in snprintf() test
6800f427 2122
453b4bd0 212320010713
68fa858a 2124 - (djm) Enable /etc/nologin check on PAM systems, as some lack the
2125 pam_nologin module. Report from William Yodlowsky
453b4bd0 2126 <bsd@openbsd.rutgers.edu>
9912296f 2127 - (djm) Revert dirname fix, a better one is on its way.
1ee482c5 2128 - OpenBSD CVS Sync
2129 - markus@cvs.openbsd.org 2001/07/04 22:47:19
2130 [ssh-agent.c]
2131 ignore SIGPIPE when debugging, too
878b5225 2132 - markus@cvs.openbsd.org 2001/07/04 23:13:10
2133 [scard.c scard.h ssh-agent.c]
2134 handle card removal more gracefully, add sc_close() to scard.h
77261db4 2135 - markus@cvs.openbsd.org 2001/07/04 23:39:07
2136 [ssh-agent.c]
2137 for smartcards remove both RSA1/2 keys
a0e0f486 2138 - markus@cvs.openbsd.org 2001/07/04 23:49:27
2139 [ssh-agent.c]
2140 handle mutiple adds of the same smartcard key
62bb2c8f 2141 - espie@cvs.openbsd.org 2001/07/05 11:43:33
2142 [sftp-glob.c]
2143 Directly cast to the right type. Ok markus@
2144 - stevesk@cvs.openbsd.org 2001/07/05 20:32:47
2145 [sshconnect1.c]
2146 statement after label; ok dugsong@
97de229c 2147 - stevesk@cvs.openbsd.org 2001/07/08 15:23:38
2148 [servconf.c]
2149 fix ``MaxStartups max''; ok markus@
f5a1a01a 2150 - fgsch@cvs.openbsd.org 2001/07/09 05:58:47
2151 [ssh.c]
2152 Use getopt(3); markus@ ok.
ed916b28 2153 - deraadt@cvs.openbsd.org 2001/07/09 07:04:53
2154 [session.c sftp-int.c]
2155 correct type on last arg to execl(); nordin@cse.ogi.edu
333b5ba7 2156 - markus@cvs.openbsd.org 2001/07/10 21:49:12
2157 [readpass.c]
2158 don't panic if fork or pipe fail (just return an empty passwd).
46d738cd 2159 - itojun@cvs.openbsd.org 2001/07/11 00:24:53
2160 [servconf.c]
68fa858a 2161 make it compilable in all 4 combination of KRB4/KRB5 settings.
46d738cd 2162 dugsong ok
2163 XXX isn't it sensitive to the order of -I/usr/include/kerberosIV and
2164 -I/usr/include/kerberosV?
afd501f9 2165 - markus@cvs.openbsd.org 2001/07/11 16:29:59
2166 [ssh.c]
2167 sort options string, fix -p, add -k
2168 - markus@cvs.openbsd.org 2001/07/11 18:26:15
2169 [auth.c]
2170 no need to call dirname(pw->pw_dir).
2171 note that dirname(3) modifies its argument on some systems.
82d95536 2172 - (djm) Reorder Makefile.in so clean targets work a little better when
2173 run directly from Makefile.in
1812a662 2174 - (djm) Pull in getopt(3) from OpenBSD libc for the optreset extension.
453b4bd0 2175
85b08d98 217620010711
68fa858a 2177 - (djm) dirname(3) may modify its argument on glibc and other systems.
85b08d98 2178 Patch from markus@, spotted by Tom Holroyd <tomh@po.crl.go.jp>
2179
a96070d4 218020010704
2181 - OpenBSD CVS Sync
2182 - markus@cvs.openbsd.org 2001/06/25 08:25:41
68fa858a 2183 [channels.c channels.h cipher.c clientloop.c compat.c compat.h
2184 hostfile.c kex.c kex.h key.c key.h nchan.c packet.c serverloop.c
a96070d4 2185 session.c session.h sftp-server.c ssh-add.c ssh-agent.c uuencode.h]
2186 update copyright for 2001
8a497b11 2187 - markus@cvs.openbsd.org 2001/06/25 17:18:27
2188 [ssh-keygen.1]
68fa858a 2189 sshd(8) will never read the private keys, but ssh(1) does;
8a497b11 2190 hugh@mimosa.com
6978866a 2191 - provos@cvs.openbsd.org 2001/06/25 17:54:47
2192 [auth.c auth.h auth-rsa.c]
68fa858a 2193 terminate secure_filename checking after checking homedir. that way
ffb215be 2194 it works on AFS. okay markus@
2195 - stevesk@cvs.openbsd.org 2001/06/25 20:26:37
2196 [auth2.c sshconnect2.c]
2197 prototype cleanup; ok markus@
2b30154a 2198 - markus@cvs.openbsd.org 2001/06/26 02:47:07
2199 [ssh-keygen.c]
2200 allow loading a private RSA key to a cyberflex card.
ffdb5d70 2201 - markus@cvs.openbsd.org 2001/06/26 04:07:06
2202 [ssh-agent.1 ssh-agent.c]
2203 add debug flag
983def13 2204 - markus@cvs.openbsd.org 2001/06/26 04:59:59
2205 [authfd.c authfd.h ssh-add.c]
2206 initial support for smartcards in the agent
f7e5ac7b 2207 - markus@cvs.openbsd.org 2001/06/26 05:07:43
2208 [ssh-agent.c]
2209 update usage
2b5fe3b8 2210 - markus@cvs.openbsd.org 2001/06/26 05:33:34
2211 [ssh-agent.c]
2212 more smartcard support.
543baeea 2213 - mpech@cvs.openbsd.org 2001/06/26 05:48:07
2214 [sshd.8]
2215 remove unnecessary .Pp between .It;
2216 millert@ ok
0c9664c2 2217 - markus@cvs.openbsd.org 2001/06/26 05:50:11
2218 [auth2.c]
2219 new interface for secure_filename()
2a1e4639 2220 - itojun@cvs.openbsd.org 2001/06/26 06:32:58
68fa858a 2221 [atomicio.h authfd.h authfile.h auth.h auth-options.h bufaux.h
2222 buffer.h canohost.h channels.h cipher.h clientloop.h compat.h
2223 compress.h crc32.h deattack.h dh.h dispatch.h groupaccess.h
2224 hostfile.h kex.h key.h log.h mac.h match.h misc.h mpaux.h packet.h
2a1e4639 2225 radix.h readconf.h readpass.h rsa.h]
2226 prototype pedant. not very creative...
2227 - () -> (void)
2228 - no variable names
1c06a9ca 2229 - itojun@cvs.openbsd.org 2001/06/26 06:33:07
68fa858a 2230 [servconf.h serverloop.h session.h sftp-client.h sftp-common.h
2231 sftp-glob.h sftp-int.h sshconnect.h ssh-dss.h sshlogin.h sshpty.h
1c06a9ca 2232 ssh-rsa.h tildexpand.h uidswap.h uuencode.h xmalloc.h]
2233 prototype pedant. not very creative...
2234 - () -> (void)
2235 - no variable names
ced49be2 2236 - dugsong@cvs.openbsd.org 2001/06/26 16:15:25
68fa858a 2237 [auth1.c auth.h auth-krb4.c auth-passwd.c readconf.c readconf.h
ced49be2 2238 servconf.c servconf.h session.c sshconnect1.c sshd.c]
68fa858a 2239 Kerberos v5 support for SSH1, mostly from Assar Westerlund
ced49be2 2240 <assar@freebsd.org> and Bjorn Gronvall <bg@sics.se>. markus@ ok
3474b2b4 2241 - markus@cvs.openbsd.org 2001/06/26 17:25:34
2242 [ssh.1]
2243 document SSH_ASKPASS; fubob@MIT.EDU
255cabd9 2244 - markus@cvs.openbsd.org 2001/06/26 17:27:25
68fa858a 2245 [authfd.h authfile.h auth.h auth-options.h bufaux.h buffer.h
2246 canohost.h channels.h cipher.h clientloop.h compat.h compress.h
2247 crc32.h deattack.h dh.h dispatch.h groupaccess.c groupaccess.h
2248 hostfile.h kex.h key.h log.c log.h mac.h misc.c misc.h mpaux.h
2249 packet.h radix.h readconf.h readpass.h rsa.h servconf.h serverloop.h
2250 session.h sftp-common.c sftp-common.h sftp-glob.h sftp-int.h
2251 sshconnect.h ssh-dss.h sshlogin.h sshpty.h ssh-rsa.h sshtty.h
255cabd9 2252 tildexpand.h uidswap.h uuencode.h xmalloc.h]
2253 remove comments from .h, since they are cut&paste from the .c files
2254 and out of sync
83f46621 2255 - dugsong@cvs.openbsd.org 2001/06/26 17:41:49
2256 [servconf.c]
2257 #include <kafs.h>
57156994 2258 - markus@cvs.openbsd.org 2001/06/26 20:14:11
2259 [key.c key.h ssh.c sshconnect1.c sshconnect2.c]
2260 add smartcard support to the client, too (now you can use both
2261 the agent and the client).
2262 - markus@cvs.openbsd.org 2001/06/27 02:12:54
2263 [serverloop.c serverloop.h session.c session.h]
2264 quick hack to make ssh2 work again.
80f8f24f 2265 - markus@cvs.openbsd.org 2001/06/27 04:48:53
2266 [auth.c match.c sshd.8]
2267 tridge@samba.org
d0bfe096 2268 - markus@cvs.openbsd.org 2001/06/27 05:35:42
2269 [ssh-keygen.c]
2270 use cyberflex_inq_class to inquire class.
2b63e803 2271 - markus@cvs.openbsd.org 2001/06/27 05:42:25
2272 [rsa.c rsa.h ssh-agent.c ssh-keygen.c]
2273 s/generate_additional_parameters/rsa_generate_additional_parameters/
2274 http://www.humppa.com/
34e02b83 2275 - markus@cvs.openbsd.org 2001/06/27 06:26:36
2276 [ssh-add.c]
2277 convert to getopt(3)
d3260e12 2278 - stevesk@cvs.openbsd.org 2001/06/28 19:57:35
2279 [ssh-keygen.c]
2280 '\0' terminated data[] is ok; ok markus@
49ccba9c 2281 - markus@cvs.openbsd.org 2001/06/29 07:06:34
2282 [ssh-keygen.c]
2283 new error handling for cyberflex_*
542d70b8 2284 - markus@cvs.openbsd.org 2001/06/29 07:11:01
2285 [ssh-keygen.c]
2286 initialize early
eea46d13 2287 - stevesk@cvs.openbsd.org 2001/06/29 18:38:44
2288 [clientloop.c]
2289 sync function definition with declaration; ok markus@
8ab2cb35 2290 - stevesk@cvs.openbsd.org 2001/06/29 18:40:28
2291 [channels.c]
2292 use socklen_t for getsockopt arg #5; ok markus@
b3f8a79c 2293 - stevesk@cvs.openbsd.org 2001/06/30 18:08:40
2294 [channels.c channels.h clientloop.c]
2295 adress -> address; ok markus@
5b5d170c 2296 - markus@cvs.openbsd.org 2001/07/02 13:59:15
2297 [serverloop.c session.c session.h]
68fa858a 2298 wait until !session_have_children(); bugreport from
5b5d170c 2299 Lutz.Jaenicke@aet.TU-Cottbus.DE
613021ac 2300 - markus@cvs.openbsd.org 2001/07/02 22:29:20
2301 [readpass.c]
2302 do not return NULL, use "" instead.
666248da 2303 - markus@cvs.openbsd.org 2001/07/02 22:40:18
2304 [ssh-keygen.c]
2305 update for sectok.h interface changes.
3cf2be58 2306 - markus@cvs.openbsd.org 2001/07/02 22:52:57
2307 [channels.c channels.h serverloop.c]
2308 improve cleanup/exit logic in ssh2:
2309 stop listening to channels, detach channel users (e.g. sessions).
2310 wait for children (i.e. dying sessions), send exit messages,
2311 cleanup all channels.
637b033d 2312 - (bal) forget a few new files in sync up.
06be7c3b 2313 - (bal) Makefile fix up requires scard.c
ac96ca42 2314 - (stevesk) sync misc.h
9c328529 2315 - (stevesk) more sync for session.c
4f1f4d8d 2316 - (stevesk) sync servconf.h (comments)
afb9165e 2317 - (tim) [contrib/caldera/openssh.spec] sync with Caldera
d9e3d19f 2318 - (tim) [openbsd-compat/dirname.h] Remove ^M causing some compilers to
2319 issue warning (line 1: tokens ignored at end of directive line)
2320 - (tim) [sshconnect1.c] give the compiler something to do for success:
2321 if KRB5 and AFS are not defined
2322 (ERROR: "sshconnect1.c", line 1274: Syntax error before or at: })
637b033d 2323
aa8d09da 232420010629
2325 - (bal) Removed net_aton() since we don't use it any more
64c4b8d7 2326 - (bal) Fixed _DISABLE_VPOSIX in readpassphrase.c.
7af3215a 2327 - (bal) Updated zlib's home. Thanks to David Howe <DaveHowe@gmx.co.uk>.
16adf618 2328 - (stevesk) remove _REENTRANT #define
16995a2c 2329 - (stevesk) session.c: use u_int for envsize
6a26f353 2330 - (stevesk) remove cli.[ch]
aa8d09da 2331
f11065cb 233220010628
2333 - (djm) Sync openbsd-compat with -current libc
68fa858a 2334 - (djm) Fix from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE> for my
050df9db 2335 broken makefile
07608451 2336 - (bal) Removed strtok_r() and inet_ntop() since they are no longer used.
2337 - (bal) Remove getusershell() since it's no longer used.
f11065cb 2338
78220944 233920010627
2340 - (djm) Reintroduce pam_session call for non-pty sessions.
68fa858a 2341 - (djm) Remove redundant and incorrect test for max auth attempts in
2342 PAM kbdint code. Based on fix from Matthew Melvin
763dfdf0 2343 <matthewm@webcentral.com.au>
f0194608 2344 - (djm) Rename sysconfdir/primes => sysconfdir/moduli
68fa858a 2345 - (djm) Oops, forgot make logic for primes=>moduli. Also try to rename
ff4955c9 2346 existing primes->moduli if it exists.
0eb1a22d 2347 - (djm) Sync with -current openbsd-compat/readpassphrase.c:
2348 - djm@cvs.openbsd.org 2001/06/27 13:23:30
2349 typo, spotted by Tom Holroyd <tomh@po.crl.go.jp>; ok deraadt@
5ed2bb5b 2350 - (djm) Turn up warnings if gcc or egcs detected
b8fea62d 2351 - (stevesk) for HP-UX 11.X use X/Open socket interface;
2352 pulls in modern socket prototypes and eliminates a number of compiler
2353 warnings. see xopen_networking(7).
fef01705 2354 - (stevesk) fix x11 forwarding from _PATH_XAUTH change
28564873 2355 - (stevesk) use X/Open socket interface for HP-UX 10.X also
78220944 2356
e16f4ac8 235720010625
0cd000dd 2358 - OpenBSD CVS Sync
bc233fdf 2359 - markus@cvs.openbsd.org 2001/06/21 21:08:25
2360 [session.c]
2361 don't reset forced_command (we allow multiple login shells in
2362 ssh2); dwd@bell-labs.com
a5a2da3b 2363 - mpech@cvs.openbsd.org 2001/06/22 10:17:51
2364 [ssh.1 sshd.8 ssh-keyscan.1]
2365 o) .Sh AUTHOR -> .Sh AUTHORS;
2366 o) remove unnecessary .Pp;
2367 o) better -mdoc style;
2368 o) typo;
2369 o) sort SEE ALSO;
a5a2da3b 2370 aaron@ ok
e2854364 2371 - provos@cvs.openbsd.org 2001/06/22 21:27:08
2372 [dh.c pathnames.h]
2373 use /etc/moduli instead of /etc/primes, okay markus@
e2432638 2374 - provos@cvs.openbsd.org 2001/06/22 21:28:53
2375 [sshd.8]
2376 document /etc/moduli
96a7b0cc 2377 - markus@cvs.openbsd.org 2001/06/22 21:55:49
68fa858a 2378 [auth2.c auth-rsa.c pathnames.h ssh.1 sshd.8 sshd_config
96a7b0cc 2379 ssh-keygen.1]
2380 merge authorized_keys2 into authorized_keys.
2381 authorized_keys2 is used for backward compat.
2382 (just append authorized_keys2 to authorized_keys).
826676b3 2383 - provos@cvs.openbsd.org 2001/06/22 21:57:59
2384 [dh.c]
2385 increase linebuffer to deal with larger moduli; use rewind instead of
2386 close/open
bc233fdf 2387 - markus@cvs.openbsd.org 2001/06/22 22:21:20
2388 [sftp-server.c]
2389 allow long usernames/groups in readdir
a599bd06 2390 - markus@cvs.openbsd.org 2001/06/22 23:35:21
2e000c58 2391 [ssh.c]
2392 don't overwrite argv (fixes ssh user@host in 'ps'), report by ericj@
cb220a93 2393 - deraadt@cvs.openbsd.org 2001/06/23 00:16:16
2394 [scp.c]
2395 slightly better care
d0c8ca5c 2396 - markus@cvs.openbsd.org 2001/06/23 00:20:57
2397 [auth2.c auth.c auth.h auth-rh-rsa.c]
2398 *known_hosts2 is obsolete for hostbased authentication and
2399 only used for backward compat. merge ssh1/2 hostkey check
2400 and move it to auth.c
e16f4ac8 2401 - deraadt@cvs.openbsd.org 2001/06/23 02:33:05
2402 [sftp.1 sftp-server.8 ssh-keygen.1]
2403 join .%A entries; most by bk@rt.fm
f49bc4f7 2404 - markus@cvs.openbsd.org 2001/06/23 02:34:33
68fa858a 2405 [kexdh.c kexgex.c kex.h pathnames.h readconf.c servconf.h ssh.1
f49bc4f7 2406 sshconnect1.c sshconnect2.c sshconnect.c sshconnect.h sshd.8]
68fa858a 2407 get rid of known_hosts2, use it for hostkey lookup, but do not
f49bc4f7 2408 modify.
7d747e89 2409 - markus@cvs.openbsd.org 2001/06/23 03:03:59
2410 [sshd.8]
2411 draft-ietf-secsh-dh-group-exchange-01.txt
73473230 2412 - markus@cvs.openbsd.org 2001/06/23 03:04:42
2413 [auth2.c auth-rh-rsa.c]
2414 restore correct ignore_user_known_hosts logic.
c10d042a 2415 - markus@cvs.openbsd.org 2001/06/23 05:26:02
2416 [key.c]
2417 handle sigature of size 0 (some broken clients send this).
7b518233 2418 - deraadt@cvs.openbsd.org 2001/06/23 05:57:09
2419 [sftp.1 sftp-server.8 ssh-keygen.1]
2420 ok, tmac is now fixed
2e0becb6 2421 - markus@cvs.openbsd.org 2001/06/23 06:41:10
2422 [ssh-keygen.c]
2423 try to decode ssh-3.0.0 private rsa keys
2424 (allow migration to openssh, not vice versa), #910
396c147e 2425 - itojun@cvs.openbsd.org 2001/06/23 15:12:20
68fa858a 2426 [auth1.c auth2.c auth2-chall.c authfd.c authfile.c auth-rhosts.c
2427 canohost.c channels.c cipher.c clientloop.c deattack.c dh.c
2428 hostfile.c kex.c kexdh.c kexgex.c key.c nchan.c packet.c radix.c
2429 readpass.c scp.c servconf.c serverloop.c session.c sftp.c
2430 sftp-client.c sftp-glob.c sftp-int.c sftp-server.c ssh-add.c
2431 ssh-agent.c ssh.c sshconnect1.c sshconnect2.c sshconnect.c sshd.c
396c147e 2432 ssh-keygen.c ssh-keyscan.c]
68fa858a 2433 more strict prototypes. raise warning level in Makefile.inc.
396c147e 2434 markus ok'ed
2435 TODO; cleanup headers
a599bd06 2436 - markus@cvs.openbsd.org 2001/06/23 17:05:22
2437 [ssh-keygen.c]
2438 fix import for (broken?) ssh.com/f-secure private keys
2439 (i tested > 1000 RSA keys)
3730bb22 2440 - itojun@cvs.openbsd.org 2001/06/23 17:48:18
2441 [sftp.1 ssh.1 sshd.8 ssh-keyscan.1]
2442 kill whitespace at EOL.
3aca00a3 2443 - markus@cvs.openbsd.org 2001/06/23 19:12:43
2444 [sshd.c]
2445 pidfile/sigterm race; bbraun@synack.net
ce404659 2446 - markus@cvs.openbsd.org 2001/06/23 22:37:46
2447 [sshconnect1.c]
2448 consistent with ssh2: skip key if empty passphrase is entered,
2449 retry num_of_passwd_prompt times if passphrase is wrong. ok fgsch@
2cee8a25 2450 - markus@cvs.openbsd.org 2001/06/24 05:25:10
2451 [auth-options.c match.c match.h]
2452 move ip+hostname check to match.c
1843a425 2453 - markus@cvs.openbsd.org 2001/06/24 05:35:33
2454 [readpass.c readpass.h ssh-add.c sshconnect2.c ssh-keygen.c]
2455 switch to readpassphrase(3)
2456 2.7/8-stable needs readpassphrase.[ch] from libc
80097c54 2457 - markus@cvs.openbsd.org 2001/06/24 05:47:13
2458 [sshconnect2.c]
2459 oops, missing format string
b4e7177c 2460 - markus@cvs.openbsd.org 2001/06/24 17:18:31
2461 [ttymodes.c]
2462 passing modes works fine: debug2->3
ab88181c 2463 - (djm) -Wall fix for session.c
3159d49a 2464 - (djm) Bring in readpassphrase() from OpenBSD libc. Compiles OK on Linux and
2465 Solaris
0cd000dd 2466
7751d4eb 246720010622
2468 - (stevesk) handle systems without pw_expire and pw_change.
2469
e04e7a19 247020010621
2471 - OpenBSD CVS Sync
2472 - markus@cvs.openbsd.org 2001/06/16 08:49:38
2473 [misc.c]
2474 typo; dunlap@apl.washington.edu
c03175c6 2475 - markus@cvs.openbsd.org 2001/06/16 08:50:39
2476 [channels.h]
2477 bad //-style comment; thx to stevev@darkwing.uoregon.edu
08c260ea 2478 - markus@cvs.openbsd.org 2001/06/16 08:57:35
2479 [scp.c]
2480 no stdio or exit() in signal handlers.
c4d49b85 2481 - markus@cvs.openbsd.org 2001/06/16 08:58:34
2482 [misc.c]
2483 copy pw_expire and pw_change, too.
dac6753b 2484 - markus@cvs.openbsd.org 2001/06/19 12:34:09
2485 [session.c]
2486 cleanup forced command handling, from dwd@bell-labs.com
ff027d84 2487 - markus@cvs.openbsd.org 2001/06/19 14:09:45
2488 [session.c sshd.8]
2489 disable x11-fwd if use_login is enabled; from lukem@wasabisystems.com
c95add71 2490 - markus@cvs.openbsd.org 2001/06/19 15:40:45
2491 [session.c]
2492 allocate and free at the same level.
d6746a0b 2493 - markus@cvs.openbsd.org 2001/06/20 13:56:39
2494 [channels.c channels.h clientloop.c packet.c serverloop.c]
2495 move from channel_stop_listening to channel_free_all,
2496 call channel_free_all before calling waitpid() in serverloop.
2497 fixes the utmp handling; report from Lutz.Jaenicke@aet.TU-Cottbus.DE
e04e7a19 2498
5ad9f968 249920010615
2500 - (stevesk) don't set SA_RESTART and set SIGCHLD to SIG_DFL
2501 around grantpt().
f7940aa9 2502 - (stevesk) update TODO: STREAMS pty systems don't call vhangup() now
5ad9f968 2503
eb26141e 250420010614
2505 - OpenBSD CVS Sync
2506 - markus@cvs.openbsd.org 2001/06/13 09:10:31
2507 [session.c]
2508 typo, use pid not s->pid, mstone@cs.loyola.edu
2509
86066315 251020010613
eb26141e 2511 - OpenBSD CVS Sync
86066315 2512 - markus@cvs.openbsd.org 2001/06/12 10:58:29
2513 [session.c]
2514 merge session_free into session_close()
2515 merge pty_cleanup_proc into session_pty_cleanup()
653d5f86 2516 - markus@cvs.openbsd.org 2001/06/12 16:10:38
2517 [session.c]
2518 merge ssh1/ssh2 tty msg parse and alloc code
76735fe3 2519 - markus@cvs.openbsd.org 2001/06/12 16:11:26
2520 [packet.c]
2521 do not log() packet_set_maxsize
b44de2b1 2522 - markus@cvs.openbsd.org 2001/06/12 21:21:29
2523 [session.c]
2524 remove xauth-cookie-in-tmp handling. use default $XAUTHORITY, since
2525 we do already trust $HOME/.ssh
2526 you can use .ssh/sshrc and .ssh/environment if you want to customize
2527 the location of the xauth cookies
7a313633 2528 - markus@cvs.openbsd.org 2001/06/12 21:30:57
2529 [session.c]
2530 unused
86066315 2531
2c9d881a 253220010612
38296b32 2533 - scp.c ID update (upstream synced vfsprintf() from us)
2534 - OpenBSD CVS Sync
2c9d881a 2535 - markus@cvs.openbsd.org 2001/06/10 11:29:20
2536 [dispatch.c]
2537 we support rekeying
2538 protocol errors are fatal.
1500bcdd 2539 - markus@cvs.openbsd.org 2001/06/11 10:18:24
2540 [session.c]
2541 reset pointer to NULL after xfree(); report from solar@openwall.com
f740438e 2542 - markus@cvs.openbsd.org 2001/06/11 16:04:38
2543 [sshd.8]
2544 typo; bdubreuil@crrel.usace.army.mil
2c9d881a 2545
b4d02860 254620010611
68fa858a 2547 - (bal) NeXT/MacOS X lack libgen.h and dirname(). Patch by Mark Miller
2548 <markm@swoon.net>
224cbdcc 2549 - (bal) Handle broken krb4 issues on Solaris with multiple defined u_*_t
68fa858a 2550 types. Patch by Jan IVEN <Jan.Iven@cern.ch>
0bb724ce 2551 - (bal) Fixed Makefile.in so that 'configure; make install' works.
b4d02860 2552
bf093080 255320010610
2554 - (bal) Missed two files in major resync. auth-bsdauth.c and auth-skey.c
2555
e697bda7 255620010609
2557 - OpenBSD CVS Sync
2558 - markus@cvs.openbsd.org 2001/05/30 12:55:13
68fa858a 2559 [auth-options.c auth2.c channels.c channels.h clientloop.c nchan.c
e697bda7 2560 packet.c serverloop.c session.c ssh.c ssh1.h]
2561 channel layer cleanup: merge header files and split .c files
36e1f6a1 2562 - markus@cvs.openbsd.org 2001/05/30 15:20:10
2563 [ssh.c]
2564 merge functions, simplify.
a5efa1bb 2565 - markus@cvs.openbsd.org 2001/05/31 10:30:17
68fa858a 2566 [auth-options.c auth2.c channels.c channels.h clientloop.c nchan.c
a5efa1bb 2567 packet.c serverloop.c session.c ssh.c]
68fa858a 2568 undo the .c file split, just merge the header and keep the cvs
a5efa1bb 2569 history
68fa858a 2570 - (bal) Channels.c and Channels.h -- "Merge Functions, simplify" (draged
8e7895b8 2571 out of ssh Attic)
68fa858a 2572 - (bal) Ooops.. nchan.c (and remove nchan.h) resync from OpenBSD ssh
a98da4aa 2573 Attic.
2574 - OpenBSD CVS Sync
2575 - markus@cvs.openbsd.org 2001/05/31 13:08:04
2576 [sshd_config]
2577 group options and add some more comments
e4f7282d 2578 - markus@cvs.openbsd.org 2001/06/03 14:55:39
2579 [channels.c channels.h session.c]
68fa858a 2580 use fatal_register_cleanup instead of atexit, sync with x11 authdir
e4f7282d 2581 handling
e5b71e99 2582 - markus@cvs.openbsd.org 2001/06/03 19:36:44
2583 [ssh-keygen.1]
2584 1-2 bits of entrophy per character (not per word), ok stevesk@
4fc334a2 2585 - markus@cvs.openbsd.org 2001/06/03 19:38:42
2586 [scp.c]
2587 pass -v to ssh; from slade@shore.net
f5e69c65 2588 - markus@cvs.openbsd.org 2001/06/03 20:06:11
2589 [auth2-chall.c]
68fa858a 2590 the challenge response device decides how to handle non-existing
f5e69c65 2591 users.
2592 -> fake challenges for skey and cryptocard
f0f32b8e 2593 - markus@cvs.openbsd.org 2001/06/04 21:59:43
2594 [channels.c channels.h session.c]
68fa858a 2595 switch uid when cleaning up tmp files and sockets; reported by
f0f32b8e 2596 zen-parse@gmx.net on bugtraq
c9130033 2597 - markus@cvs.openbsd.org 2001/06/04 23:07:21
2598 [clientloop.c serverloop.c sshd.c]
68fa858a 2599 set flags in the signal handlers, do real work in the main loop,
c9130033 2600 ok provos@
8dcd9d5c 2601 - markus@cvs.openbsd.org 2001/06/04 23:16:16
2602 [session.c]
2603 merge ssh1/2 x11-fwd setup, create listener after tmp-dir
aa144206 2604 - pvalchev@cvs.openbsd.org 2001/06/05 05:05:39
2605 [ssh-keyscan.1 ssh-keyscan.c]
2606 License clarification from David Mazieres, ok deraadt@
750c256a 2607 - markus@cvs.openbsd.org 2001/06/05 10:24:32
2608 [channels.c]
2609 don't delete the auth socket in channel_stop_listening()
2610 auth_sock_cleanup_proc() will take care of this.
fc2a1d28 2611 - markus@cvs.openbsd.org 2001/06/05 16:46:19
2612 [session.c]
2613 let session_close() delete the pty. deny x11fwd if xauthfile is set.
d87596b0 2614 - markus@cvs.openbsd.org 2001/06/06 23:13:54
2615 [ssh-dss.c ssh-rsa.c]
2616 cleanup, remove old code
edf9ae81 2617 - markus@cvs.openbsd.org 2001/06/06 23:19:35
2618 [ssh-add.c]
2619 remove debug message; Darren.Moffat@eng.sun.com
2a6a054e 2620 - markus@cvs.openbsd.org 2001/06/07 19:57:53
2621 [auth2.c]
2622 style is used for bsdauth.
2623 disconnect on user/service change (ietf-drafts)
449c5ba5 2624 - markus@cvs.openbsd.org 2001/06/07 20:23:05
68fa858a 2625 [authfd.c authfile.c channels.c kexdh.c kexgex.c packet.c ssh.c
449c5ba5 2626 sshconnect.c sshconnect1.c]
2627 use xxx_put_cstring()
e6abba31 2628 - markus@cvs.openbsd.org 2001/06/07 22:25:02
2629 [session.c]
2630 don't overwrite errno
2631 delay deletion of the xauth cookie
fd9ede94 2632 - markus@cvs.openbsd.org 2001/06/08 15:25:40
2633 [includes.h pathnames.h readconf.c servconf.c]
2634 move the path for xauth to pathnames.h
0abe778b 2635 - (bal) configure.in fix for Tru64 (forgeting to reset $LIB)
83c17f20 2636 - (bal) ANSIify strmode()
68fa858a 2637 - (bal) --with-catman should be --with-mantype patch by Dave
2638 Dykstra <dwd@bell-labs.com>
fd9ede94 2639
4869a96f 264020010606
e697bda7 2641 - OpenBSD CVS Sync
68fa858a 2642 - markus@cvs.openbsd.org 2001/05/17 21:34:15
e697bda7 2643 [ssh.1]
68fa858a 2644 no spaces in PreferredAuthentications;
5ba55ada 2645 meixner@rbg.informatik.tu-darmstadt.de
2646 - markus@cvs.openbsd.org 2001/05/18 14:13:29
68fa858a 2647 [auth-chall.c auth.h auth1.c auth2-chall.c auth2.c readconf.c
5ba55ada 2648 readconf.h servconf.c servconf.h sshconnect1.c sshconnect2.c sshd.c]
2649 improved kbd-interactive support. work by per@appgate.com and me
bc03d5aa 2650 - djm@cvs.openbsd.org 2001/05/19 00:36:40
2651 [session.c]
2652 Disable X11 forwarding if xauth binary is not found. Patch from Nalin
2653 Dahyabhai <nalin@redhat.com>; ok markus@
68fa858a 2654 - markus@cvs.openbsd.org 2001/05/19 16:05:41
2655 [scp.c]
3e4fc5f9 2656 ftruncate() instead of open()+O_TRUNC like rcp.c does
68fa858a 2657 allows scp /path/to/file localhost:/path/to/file
2658 - markus@cvs.openbsd.org 2001/05/19 16:08:43
2659 [sshd.8]
a18395da 2660 sort options; Matthew.Stier@fnc.fujitsu.com
68fa858a 2661 - markus@cvs.openbsd.org 2001/05/19 16:32:16
2662 [ssh.1 sshconnect2.c]
2663 change preferredauthentication order to
2664 publickey,hostbased,password,keyboard-interactive
3398dda9 2665 document that hostbased defaults to no, document order
47bf6266 2666 - markus@cvs.openbsd.org 2001/05/19 16:46:19
68fa858a 2667 [ssh.1 sshd.8]
2668 document MACs defaults with .Dq
2669 - stevesk@cvs.openbsd.org 2001/05/19 19:43:57
2670 [misc.c misc.h servconf.c sshd.8 sshd.c]
2671 sshd command-line arguments and configuration file options that
2672 specify time may be expressed using a sequence of the form:
e2b1fb42 2673 time[qualifier], where time is a positive integer value and qualifier
68fa858a 2674 is one of the following:
2675 <none>,s,m,h,d,w
2676 Examples:
2677 600 600 seconds (10 minutes)
2678 10m 10 minutes
2679 1h30m 1 hour 30 minutes (90 minutes)
2680 ok markus@
7e8c18e9 2681 - stevesk@cvs.openbsd.org 2001/05/19 19:57:09
68fa858a 2682 [channels.c]
2683 typo in error message
e697bda7 2684 - markus@cvs.openbsd.org 2001/05/20 17:20:36
c8445989 2685 [auth-rsa.c auth.c auth.h auth2.c servconf.c servconf.h sshd.8
2686 sshd_config]
68fa858a 2687 configurable authorized_keys{,2} location; originally from peter@;
2688 ok djm@
1ddf764b 2689 - markus@cvs.openbsd.org 2001/05/24 11:12:42
68fa858a 2690 [auth.c]
2691 fix comment; from jakob@
2692 - stevesk@cvs.openbsd.org 2001/05/24 18:57:53
2693 [clientloop.c readconf.c ssh.c ssh.h]
4bf9c10e 2694 don't perform escape processing when ``EscapeChar none''; ok markus@
abe0fb9f 2695 - markus@cvs.openbsd.org 2001/05/25 14:37:32
68fa858a 2696 [ssh-keygen.c]
2697 use -P for -e and -y, too.
63cd7dd0 2698 - markus@cvs.openbsd.org 2001/05/28 08:04:39
68fa858a 2699 [ssh.c]
2700 fix usage()
2701 - markus@cvs.openbsd.org 2001/05/28 10:08:55
2702 [authfile.c]
eb2e1595 2703 key_load_private: set comment to filename for PEM keys
2cf27bc4 2704 - markus@cvs.openbsd.org 2001/05/28 22:51:11
68fa858a 2705 [cipher.c cipher.h]
2706 simpler 3des for ssh1
2707 - markus@cvs.openbsd.org 2001/05/28 23:14:49
2708 [channels.c channels.h nchan.c]
6fd8622b 2709 undo broken channel fix and try a different one. there
68fa858a 2710 should be still some select errors...
2711 - markus@cvs.openbsd.org 2001/05/28 23:25:24
2712 [channels.c]
2713 cleanup, typo
08dcb5d7 2714 - markus@cvs.openbsd.org 2001/05/28 23:58:35
68fa858a 2715 [packet.c packet.h sshconnect.c sshd.c]
2716 remove some lines, simplify.
a10bdd7c 2717 - markus@cvs.openbsd.org 2001/05/29 12:31:27
68fa858a 2718 [authfile.c]
2719 typo
5ba55ada 2720
5cde8062 272120010528
2722 - (tim) [conifgure.in] add setvbuf test needed for sftp-int.c
2723 Patch by Corinna Vinschen <vinschen@redhat.com>
2724
362df52e 272520010517
2726 - OpenBSD CVS Sync
2727 - markus@cvs.openbsd.org 2001/05/12 19:53:13
2728 [sftp-server.c]
2729 readlink does not NULL-terminate; mhe@home.se
6efa3d14 2730 - deraadt@cvs.openbsd.org 2001/05/15 22:04:01
2731 [ssh.1]
2732 X11 forwarding details improved
70ea8327 2733 - markus@cvs.openbsd.org 2001/05/16 20:51:57
2734 [authfile.c]
2735 return comments for private pem files, too; report from nolan@naic.edu
24b6b45f 2736 - markus@cvs.openbsd.org 2001/05/16 21:53:53
2737 [clientloop.c]
2738 check for open sessions before we call select(); fixes the x11 client
2739 bug reported by bowman@math.ualberta.ca
7231bd47 2740 - markus@cvs.openbsd.org 2001/05/16 22:09:21
2741 [channels.c nchan.c]
2742 more select() error fixes (don't set rfd/wfd to -1).
7043a38d 2743 - (bal) Enabled USE_PIPES for Cygwin on Corinna Vinschen <vinschen@redhat.com>
68fa858a 2744 - (bal) Corrected on_exit() emulation via atexit().
362df52e 2745
89aa792b 274620010512
2747 - OpenBSD CVS Sync
2748 - markus@cvs.openbsd.org 2001/05/11 14:59:56
2749 [clientloop.c misc.c misc.h]
2750 add unset_nonblock for stdout/err flushing in client_loop().
286e38f7 2751 - (bal) Patch to partial sync up contrib/solaris/ packaging software.
2752 Patch by pete <ninjaz@webexpress.com>
89aa792b 2753
97430469 275420010511
2755 - OpenBSD CVS Sync
2756 - markus@cvs.openbsd.org 2001/05/09 22:51:57
2757 [channels.c]
2758 fix -R for protocol 2, noticed by greg@nest.cx.
2759 bug was introduced with experimental dynamic forwarding.
a16092bb 2760 - markus@cvs.openbsd.org 2001/05/09 23:01:31
2761 [rijndael.h]
2762 fix prototype; J.S.Peatfield@damtp.cam.ac.uk
97430469 2763
588f4ed0 276420010509
2765 - OpenBSD CVS Sync
2766 - markus@cvs.openbsd.org 2001/05/06 21:23:31
2767 [cli.c]
2768 cli_read() fails to catch SIGINT + overflow; from obdb@zzlevo.net
d18e0850 2769 - markus@cvs.openbsd.org 2001/05/08 19:17:31
a01a10dd 2770 [channels.c serverloop.c clientloop.c]
d18e0850 2771 adds correct error reporting to async connect()s
68fa858a 2772 fixes the server-discards-data-before-connected-bug found by
d18e0850 2773 onoe@sm.sony.co.jp
8a624ebf 2774 - mouring@cvs.openbsd.org 2001/05/08 19:45:25
2775 [misc.c misc.h scp.c sftp.c]
2776 Use addargs() in sftp plus some clean up of addargs(). OK Markus
1b02d786 2777 - markus@cvs.openbsd.org 2001/05/06 21:45:14
2778 [clientloop.c]
68fa858a 2779 use atomicio for flushing stdout/stderr bufs. thanks to
1b02d786 2780 jbw@izanami.cee.hw.ac.uk
010980f6 2781 - markus@cvs.openbsd.org 2001/05/08 22:48:07
2782 [atomicio.c]
2783 no need for xmalloc.h, thanks to espie@
68fa858a 2784 - (bal) UseLogin patch for Solaris/UNICOS. Patch by Wayne Davison
7e2d5fa4 2785 <wayne@blorf.net>
99c8ddac 2786 - (bal) ./configure support to disable SIA on OSF1. Patch by
2787 Chris Adams <cmadams@hiwaay.net>
68fa858a 2788 - (bal) Updates from the Sony NEWS-OS platform by NAKAJI Hiroyuki
b81c369b 2789 <nakaji@tutrp.tut.ac.jp>
588f4ed0 2790
7b22534a 279120010508
68fa858a 2792 - (bal) Fixed configure test for USE_SIA.
7b22534a 2793
94539b2a 279420010506
2795 - (djm) Update config.guess and config.sub with latest versions (from
2796 ftp://ftp.gnu.org/gnu/config/) to allow configure on ia64-hpux.
2797 Suggested by Jason Mader <jason@ncac.gwu.edu>
96c63318 2798 - (bal) White Space and #ifdef sync with OpenBSD
044b0662 2799 - (bal) Add 'seed_rng()' to ssh-add.c
9e9bd8c0 2800 - (bal) CVS ID updates for readpass.c, readpass.h, cli.c, and cli.h
cf7ff074 2801 - OpenBSD CVS Sync
2802 - stevesk@cvs.openbsd.org 2001/05/05 13:42:52
2803 [sftp.1 ssh-add.1 ssh-keygen.1]
2804 typos, grammar
94539b2a 2805
98143cfc 280620010505
2807 - OpenBSD CVS Sync
2808 - stevesk@cvs.openbsd.org 2001/05/04 14:21:56
2809 [ssh.1 sshd.8]
2810 typos
5b9601c8 2811 - markus@cvs.openbsd.org 2001/05/04 14:34:34
2812 [channels.c]
94539b2a 2813 channel_new() reallocs channels[], we cannot use Channel *c after
2814 calling channel_new(), XXX fix this in the future...
719fc62f 2815 - markus@cvs.openbsd.org 2001/05/04 23:47:34
2816 [channels.c channels.h clientloop.c nchan.c nchan.h serverloop.c ssh.c]
68fa858a 2817 move to Channel **channels (instead of Channel *channels), fixes realloc
2818 problems. channel_new now returns a Channel *, favour Channel * over
719fc62f 2819 channel id. remove old channel_allocate interface.
98143cfc 2820
f92fee1f 282120010504
2822 - OpenBSD CVS Sync
2823 - stevesk@cvs.openbsd.org 2001/05/03 15:07:39
2824 [channels.c]
2825 typo in debug() string
503e7e5b 2826 - markus@cvs.openbsd.org 2001/05/03 15:45:15
2827 [session.c]
2828 exec shell -c /bin/sh .ssh/sshrc, from abartlet@pcug.org.au
c98cab9b 2829 - stevesk@cvs.openbsd.org 2001/05/03 21:43:01
2830 [servconf.c]
2831 remove "\n" from fatal()
1fcde3fe 2832 - mouring@cvs.openbsd.org 2001/05/03 23:09:53
2833 [misc.c misc.h scp.c sftp.c]
2834 Move colon() and cleanhost() to misc.c where I should I have put it in
2835 the first place
044aa419 2836 - (bal) Updated Cygwin README by Corinna Vinschen <vinschen@redhat.com>
c7ccfd39 2837 - (bal) Avoid socket file security issues in ssh-agent for Cygwin.
2838 Patch by Egor Duda <deo@logos-m.ru>
f92fee1f 2839
065604bb 284020010503
2841 - OpenBSD CVS Sync
2842 - markus@cvs.openbsd.org 2001/05/02 16:41:20
2843 [ssh-add.c]
2844 fix prompt for ssh-add.
2845
742ee8f2 284620010502
2847 - OpenBSD CVS Sync
2848 - mouring@cvs.openbsd.org 2001/05/02 01:25:39
2849 [readpass.c]
2850 Put the 'const' back into ssh_askpass() function. Pointed out
2851 by Mark Miller <markm@swoon.net>. OK Markus
2852
3435f5a6 285320010501
2854 - OpenBSD CVS Sync
2855 - markus@cvs.openbsd.org 2001/04/30 11:18:52
2856 [readconf.c readconf.h ssh.1 ssh.c sshconnect.c]
2857 implement 'ssh -b bind_address' like 'telnet -b'
eef7adcb 2858 - markus@cvs.openbsd.org 2001/04/30 15:50:46
2859 [compat.c compat.h kex.c]
2860 allow interop with weaker key generation used by ssh-2.0.x, x < 10
ec430473 2861 - markus@cvs.openbsd.org 2001/04/30 16:02:49
2862 [compat.c]
2863 ssh-2.0.10 has the weak-key-bug, too.
3ca6cc45 2864 - (tim) [contrib/caldera/openssh.spec] add Requires line for Caldera 3.1
3435f5a6 2865
e8171bff 286620010430
39aefe7b 2867 - OpenBSD CVS Sync
2868 - markus@cvs.openbsd.org 2001/04/29 18:32:52
2869 [serverloop.c]
2870 fix whitespace
fbe90f7b 2871 - markus@cvs.openbsd.org 2001/04/29 19:16:52
2872 [channels.c clientloop.c compat.c compat.h serverloop.c]
2873 more ssh.com-2.0.x bug-compat; from per@appgate.com
e8171bff 2874 - (tim) New version of mdoc2man.pl from Mark D. Roth <roth+openssh@feep.net>
0b47e48f 2875 - (djm) Add .cvsignore files, suggested by Wayne Davison <wayne@blorf.net>
39aefe7b 2876
baf8c81a 287720010429
2878 - (bal) Updated INSTALL. PCRE moved to a new place.
e878ffe1 2879 - (djm) Release OpenSSH-2.9p1
baf8c81a 2880
0096ac62 288120010427
2882 - (bal) Fixed uidswap.c so it should work on non-posix complient systems.
2883 patch based on 2.5.2 version by djm.
95595a77 2884 - (bal) Build manpages and config files once unless changed. Patch by
2885 Carson Gaspar <carson@taltos.org>
68fa858a 2886 - (bal) arpa/nameser.h does not exist on Cygwin. Patch by Corinna
4a2df58f 2887 Vinschen <vinschen@redhat.com>
5ef815d7 2888 - (bal) Add /etc/sysconfig/sshd support to redhat's sshd.init. Patch by
2889 Pekka Savola <pekkas@netcore.fi>
68fa858a 2890 - (bal) Cygwin lacks setgroups() API. Patch by Corinna Vinschen
229be2df 2891 <vinschen@redhat.com>
cc3ccfdc 2892 - (bal) version.h synced, RPM specs updated for 2.9
b1e2a48c 2893 - (tim) update contrib/caldera files with what Caldera is using.
2894 <sps@caldera.de>
0096ac62 2895
b587c165 289620010425
2897 - OpenBSD CVS Sync
2898 - markus@cvs.openbsd.org 2001/04/23 21:57:07
2899 [ssh-keygen.1 ssh-keygen.c]
2900 allow public key for -e, too
012bc0e1 2901 - markus@cvs.openbsd.org 2001/04/23 22:14:13
2902 [ssh-keygen.c]
2903 remove debug
f8252c48 2904 - (bal) Whitespace resync w/ OpenBSD for uidswap.c
10f72868 2905 - (djm) Add new server configuration directive 'PAMAuthenticationViaKbdInt'
68fa858a 2906 (default: off), implies KbdInteractiveAuthentication. Suggestion from
10f72868 2907 markus@
c2d059b5 2908 - (djm) Include crypt.h if available in auth-passwd.c
533875af 2909 - tim@mindrot.org 2001/04/25 21:38:01 [configure.in]
2910 man page detection fixes for SCO
b587c165 2911
da89cf4d 291220010424
2913 - OpenBSD CVS Sync
2914 - markus@cvs.openbsd.org 2001/04/22 23:58:36
2915 [ssh-keygen.1 ssh.1 sshd.8]
2916 document hostbased and other cleanup
5e29aeaf 2917 - (stevesk) start_pam() doesn't use DNS now for sshd -u0.
3cc990d7 2918 - (stevesk) auth-pam.c: use PERMIT_NO_PASSWD
68fa858a 2919 - (bal) sys/queue.h is bogus for NCR platform. Patch by Daniel Carroll
d8e76a0a 2920 <dan@mesastate.edu>
3644dc25 2921 - (bal) Fixed contrib/postinstall.in. Patch by wsanders@wsanders.net
da89cf4d 2922
a3626e12 292320010422
2924 - OpenBSD CVS Sync
2925 - markus@cvs.openbsd.org 2001/04/20 16:32:22
2926 [uidswap.c]
2927 set non-privileged gid before uid; tholo@ and deraadt@
1a726b04 2928 - mouring@cvs.openbsd.org 2001/04/21 00:55:57
2929 [sftp.1]
2930 Spelling
67b964a1 2931 - djm@cvs.openbsd.org 2001/04/22 08:13:30
2932 [ssh.1]
2933 typos spotted by stevesk@; ok deraadt@
ba917921 2934 - markus@cvs.openbsd.org 2001/04/22 12:34:05
2935 [scp.c]
2936 scp > 2GB; niles@scyld.com; ok deraadt@, djm@
5deceabb 2937 - markus@cvs.openbsd.org 2001/04/22 13:25:37
2938 [ssh-keygen.1 ssh-keygen.c]
2939 rename arguments -x -> -e (export key), -X -> -i (import key)
2940 xref draft-ietf-secsh-publickeyfile-01.txt
2cad6cef 2941 - markus@cvs.openbsd.org 2001/04/22 13:32:27
2942 [sftp-server.8 sftp.1 ssh.1 sshd.8]
2943 xref draft-ietf-secsh-*
bcaa828e 2944 - markus@cvs.openbsd.org 2001/04/22 13:41:02
2945 [ssh-keygen.1 ssh-keygen.c]
2946 style, noted by stevesk; sort flags in usage
a3626e12 2947
df841692 294820010421
2949 - OpenBSD CVS Sync
2950 - djm@cvs.openbsd.org 2001/04/20 07:17:51
2951 [clientloop.c ssh.1]
2952 Split out and improve escape character documentation, mention ~R in
2953 ~? help text; ok markus@
0e7e0abe 2954 - Update RPM spec files for CVS version.h
1ddee76b 2955 - (stevesk) set the default PAM service name to __progname instead
2956 of the hard-coded value "sshd"; from Mark D. Roth <roth@feep.net>
4b28be2c 2957 - (stevesk) document PAM service name change in INSTALL
13dd877b 2958 - tim@mindrot.org 2001/04/21 14:25:57 [Makefile.in configure.in]
2959 fix perl test, fix nroff test, fix Makefile to build outside source tree
df841692 2960
05cc0c99 296120010420
68fa858a 2962 - OpenBSD CVS Sync
05cc0c99 2963 - ian@cvs.openbsd.org 2001/04/18 16:21:05
68fa858a 2964 [ssh-keyscan.1]
2965 Fix typo reported in PR/1779
2966 - markus@cvs.openbsd.org 2001/04/18 21:57:42
2967 [readpass.c ssh-add.c]
561e5254 2968 call askpass from ssh, too, based on work by roth@feep.net, ok deraadt
68fa858a 2969 - markus@cvs.openbsd.org 2001/04/18 22:03:45
2970 [auth2.c sshconnect2.c]
f98c3421 2971 use FDQN with trailing dot in the hostbased auth packets, ok deraadt@
57a5edd8 2972 - markus@cvs.openbsd.org 2001/04/18 22:48:26
68fa858a 2973 [auth2.c]
2974 no longer const
2975 - markus@cvs.openbsd.org 2001/04/18 23:43:26
2976 [auth2.c compat.c sshconnect2.c]
2977 more ssh v2 hostbased-auth interop: ssh.com >= 2.1.0 works now
8dddf799 2978 (however the 2.1.0 server seems to work only if debug is enabled...)
ae88ea7e 2979 - markus@cvs.openbsd.org 2001/04/18 23:44:51
68fa858a 2980 [authfile.c]
2981 error->debug; noted by fries@
2982 - markus@cvs.openbsd.org 2001/04/19 00:05:11
2983 [auth2.c]
2984 use local variable, no function call needed.
5cf13595 2985 (btw, hostbased works now with ssh.com >= 2.0.13)
431a2493 2986 - (bal) Put scp-common.h back into scp.c (it exists in the upstream
2987 tree) pointed out by Tom Holroyd <tomh@po.crl.go.jp>
05cc0c99 2988
e78e738a 298920010418
68fa858a 2990 - OpenBSD CVS Sync
e78e738a 2991 - markus@cvs.openbsd.org 2001/04/17 19:34:25
3a83b819 2992 [session.c]
2993 move auth_approval to do_authenticated().
2994 do_child(): nuke hostkeys from memory
2995 don't source .ssh/rc for subsystems.
2996 - markus@cvs.openbsd.org 2001/04/18 14:15:00
2997 [canohost.c]
2998 debug->debug3
ce2af031 2999 - (bal) renabled 'catman-do:' and fixed it. So now catman pages should
3000 be working again.
e0c4d3ac 3001 - (bal) Makfile day... Cleaned up multiple mantype support (Patch by
3002 Mark D. Roth <roth+openssh@feep.net>), and fixed PIDDIR support.
3a83b819 3003
8c6b78e4 300420010417
3005 - (bal) Add perl5 check for HP/UX, Removed GNUness from Makefile.in
6d165a89 3006 and temporary commented out 'catman-do:' since it is broken. Patches
8c6b78e4 3007 for the first two by Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
a88b7b57 3008 - OpenBSD CVS Sync
53b8fe68 3009 - deraadt@cvs.openbsd.org 2001/04/16 08:26:04
3010 [key.c]
3011 better safe than sorry in later mods; yongari@kt-is.co.kr
3012 - markus@cvs.openbsd.org 2001/04/17 08:14:01
3013 [sshconnect1.c]
3014 check for key!=NULL, thanks to costa
3015 - markus@cvs.openbsd.org 2001/04/17 09:52:48
3016 [clientloop.c]
cf6bc93c 3017 handle EINTR/EAGAIN on read; ok deraadt@
53b8fe68 3018 - markus@cvs.openbsd.org 2001/04/17 10:53:26
3019 [key.c key.h readconf.c readconf.h ssh.1 sshconnect2.c]
e961a8f9 3020 add HostKeyAlgorithms; based on patch from res@shore.net; ok provos@
53b8fe68 3021 - markus@cvs.openbsd.org 2001/04/17 12:55:04
3022 [channels.c ssh.c]
3023 undo socks5 and https support since they are not really used and
3024 only bloat ssh. remove -D from usage(), since '-D' is experimental.
3025
e4664c3e 302620010416
3027 - OpenBSD CVS Sync
3028 - stevesk@cvs.openbsd.org 2001/04/15 01:35:22
3029 [ttymodes.c]
3030 fix comments
ec1f12d3 3031 - markus@cvs.openbsd.org 2001/04/15 08:43:47
3032 [dh.c sftp-glob.c sftp-glob.h sftp-int.c sshconnect2.c sshd.c]
3033 some unused variable and typos; from tomh@po.crl.go.jp
58cfa257 3034 - markus@cvs.openbsd.org 2001/04/15 16:58:03
3035 [authfile.c ssh-keygen.c sshd.c]
3036 don't use errno for key_{load,save}_private; discussion w/ solar@openwall
e968270c 3037 - markus@cvs.openbsd.org 2001/04/15 17:16:00
3038 [clientloop.c]
3039 set stdin/out/err to nonblocking in SSH proto 1, too. suggested by ho@
3040 should fix some of the blocking problems for rsync over SSH-1
84fc17bf 3041 - stevesk@cvs.openbsd.org 2001/04/15 19:41:21
3042 [sshd.8]
3043 some ClientAlive cleanup; ok markus@
b7c70970 3044 - stevesk@cvs.openbsd.org 2001/04/15 21:28:35
3045 [readconf.c servconf.c]
3046 use fatal() or error() vs. fprintf(); ok markus@
5d97cfbf 3047 - (djm) Convert mandoc manpages to man automatically. Patch from Mark D.
3048 Roth <roth+openssh@feep.net>
6023325e 3049 - (bal) CVS ID fix up and slight manpage fix from OpenBSD tree.
47b53518 3050 - (djm) OpenBSD CVS Sync
3051 - mouring@cvs.openbsd.org 2001/04/16 02:31:44
3052 [scp.c sftp.c]
3053 IPv6 support for sftp (which I bungled in my last patch) which is
3054 borrowed from scp.c. Thanks to Markus@ for pointing it out.
764291b3 3055 - deraadt@cvs.openbsd.org 2001/04/16 08:05:34
3056 [xmalloc.c]
3057 xrealloc dealing with ptr == nULL; mouring
f2c2fd71 3058 - djm@cvs.openbsd.org 2001/04/16 08:19:31
3059 [session.c]
68fa858a 3060 Split motd and hushlogin checks into seperate functions, helps for
f2c2fd71 3061 portable. From Chris Adams <cmadams@hiwaay.net>; ok markus@
68fa858a 3062 - Fix OSF SIA support displaying too much information for quiet
3063 logins and logins where access was denied by SIA. Patch from Chris Adams
c96a4aaf 3064 <cmadams@hiwaay.net>
e4664c3e 3065
f03228b1 306620010415
3067 - OpenBSD CVS Sync
3068 - deraadt@cvs.openbsd.org 2001/04/14 04:31:01
3069 [ssh-add.c]
3070 do not double free
9cf972fa 3071 - markus@cvs.openbsd.org 2001/04/14 16:17:14
3072 [channels.c]
3073 remove some channels that are not appropriate for keepalive.
eae942e2 3074 - markus@cvs.openbsd.org 2001/04/14 16:27:57
3075 [ssh-add.c]
3076 use clear_pass instead of xfree()
30dcc918 3077 - stevesk@cvs.openbsd.org 2001/04/14 16:33:20
3078 [clientloop.c packet.h session.c ssh.c ttymodes.c ttymodes.h]
3079 protocol 2 tty modes support; ok markus@
36967a16 3080 - stevesk@cvs.openbsd.org 2001/04/14 17:04:42
3081 [scp.c]
3082 'T' handling rcp/scp sync; ok markus@
e4664c3e 3083 - Missed sshtty.[ch] in Sync.
f03228b1 3084
e400a640 308520010414
3086 - Sync with OpenBSD glob.c, strlcat.c and vis.c changes
68fa858a 3087 - Cygwin sftp/sftp-server binary mode patch from Corinna Vinschen
fe56c12b 3088 <vinschen@redhat.com>
3ffc6336 3089 - OpenBSD CVS Sync
3090 - beck@cvs.openbsd.org 2001/04/13 22:46:54
3091 [channels.c channels.h servconf.c servconf.h serverloop.c sshd.8]
3092 Add options ClientAliveInterval and ClientAliveCountMax to sshd.
3093 This gives the ability to do a "keepalive" via the encrypted channel
3094 which can't be spoofed (unlike TCP keepalives). Useful for when you want
3095 to use ssh connections to authenticate people for something, and know
3096 relatively quickly when they are no longer authenticated. Disabled
3097 by default (of course). ok markus@
e400a640 3098
cc44f691 309920010413
68fa858a 3100 - OpenBSD CVS Sync
3101 - markus@cvs.openbsd.org 2001/04/12 14:29:09
3102 [ssh.c]
3103 show debug output during option processing, report from
cc44f691 3104 pekkas@netcore.fi
8002af61 3105 - markus@cvs.openbsd.org 2001/04/12 19:15:26
68fa858a 3106 [auth-rhosts.c auth.h auth2.c buffer.c canohost.c canohost.h
3107 compat.c compat.h hostfile.c pathnames.h readconf.c readconf.h
3108 servconf.c servconf.h ssh.c sshconnect.c sshconnect.h sshconnect1.c
8002af61 3109 sshconnect2.c sshd_config]
3110 implement HostbasedAuthentication (= RhostRSAAuthentication for ssh v2)
3111 similar to RhostRSAAuthentication unless you enable (the experimental)
3112 HostbasedUsesNameFromPacketOnly option. please test. :)
0140e66a 3113 - markus@cvs.openbsd.org 2001/04/12 19:39:27
3114 [readconf.c]
3115 typo
2d2a2c65 3116 - stevesk@cvs.openbsd.org 2001/04/12 20:09:38
3117 [misc.c misc.h readconf.c servconf.c ssh.c sshd.c]
3118 robust port validation; ok markus@ jakob@
edeeab1e 3119 - mouring@cvs.openbsd.org 2001/04/12 23:17:54
3120 [sftp-int.c sftp-int.h sftp.1 sftp.c]
3121 Add support for:
3122 sftp [user@]host[:file [file]] - Fetch remote file(s)
3123 sftp [user@]host[:dir[/]] - Start in remote dir/
3124 OK deraadt@
57aa8961 3125 - stevesk@cvs.openbsd.org 2001/04/13 01:26:17
3126 [ssh.c]
3127 missing \n in error message
96f8b59f 3128 - (bal) Added openbsd-compat/inet_ntop.[ch] since HP/UX (and others)
3129 lack it.
cc44f691 3130
28b9cb4d 313120010412
68fa858a 3132 - OpenBSD CVS Sync
28b9cb4d 3133 - markus@cvs.openbsd.org 2001/04/10 07:46:58
68fa858a 3134 [channels.c]
3135 cleanup socks4 handling
3136 - itojun@cvs.openbsd.org 2001/04/10 09:13:22
c0ecc314 3137 [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
68fa858a 3138 document id_rsa{.pub,}. markus ok
070adba2 3139 - markus@cvs.openbsd.org 2001/04/10 12:15:23
68fa858a 3140 [channels.c]
3141 debug cleanup
45a2e669 3142 - djm@cvs.openbsd.org 2001/04/11 07:06:22
3143 [sftp-int.c]
3144 'mget' and 'mput' aliases; ok markus@
6031af8d 3145 - markus@cvs.openbsd.org 2001/04/11 10:59:01
3146 [ssh.c]
3147 use strtol() for ports, thanks jakob@
6683b40f 3148 - markus@cvs.openbsd.org 2001/04/11 13:56:13
3149 [channels.c ssh.c]
3150 https-connect and socks5 support. i feel so bad.
ff14faf1 3151 - lebel@cvs.openbsd.org 2001/04/11 16:25:30
3152 [sshd.8 sshd.c]
3153 implement the -e option into sshd:
3154 -e When this option is specified, sshd will send the output to the
3155 standard error instead of the system log.
3156 markus@ OK.
28b9cb4d 3157
0a85ab61 315820010410
3159 - OpenBSD CVS Sync
3160 - deraadt@cvs.openbsd.org 2001/04/08 20:52:55
3161 [sftp.c]
3162 do not modify an actual argv[] entry
b2ae83b8 3163 - stevesk@cvs.openbsd.org 2001/04/08 23:28:27
3164 [sshd.8]
3165 spelling
317611b5 3166 - stevesk@cvs.openbsd.org 2001/04/09 00:42:05
3167 [sftp.1]
3168 spelling
a8666d84 3169 - markus@cvs.openbsd.org 2001/04/09 15:12:23
3170 [ssh-add.c]
3171 passphrase caching: ssh-add tries last passphrase, clears passphrase if
3172 not successful and after last try.
3173 based on discussions with espie@, jakob@, ... and code from jakob@ and
3174 wolfgang@wsrcc.com
49ae4185 3175 - markus@cvs.openbsd.org 2001/04/09 15:19:49
3176 [ssh-add.1]
3177 ssh-add retries the last passphrase...
b8a297f1 3178 - stevesk@cvs.openbsd.org 2001/04/09 18:00:15
3179 [sshd.8]
3180 ListenAddress mandoc from aaron@
0a85ab61 3181
6e9944b8 318220010409
febd3f8e 3183 - (stevesk) use setresgid() for setegid() if needed
26de7942 3184 - (stevesk) configure.in: typo
6e9944b8 3185 - OpenBSD CVS Sync
3186 - stevesk@cvs.openbsd.org 2001/04/08 16:01:36
3187 [sshd.8]
3188 document ListenAddress addr:port
d64050ef 3189 - markus@cvs.openbsd.org 2001/04/08 13:03:00
3190 [ssh-add.c]
3191 init pointers with NULL, thanks to danimal@danimal.org
d0a4c20b 3192 - markus@cvs.openbsd.org 2001/04/08 11:27:33
3193 [clientloop.c]
3194 leave_raw_mode if ssh2 "session" is closed
63bd8c36 3195 - markus@cvs.openbsd.org 2001/04/06 21:00:17
3196 [auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth2.c channels.c session.c
3197 ssh.c sshconnect.c sshconnect.h uidswap.c uidswap.h]
3198 do gid/groups-swap in addition to uid-swap, should help if /home/group
3199 is chmod 750 + chgrp grp /home/group/, work be deraadt and me, thanks
3200 to olar@openwall.com is comments. we had many requests for this.
0490e609 3201 - markus@cvs.openbsd.org 2001/04/07 08:55:18
3202 [buffer.c channels.c channels.h readconf.c ssh.c]
68fa858a 3203 allow the ssh client act as a SOCKS4 proxy (dynamic local
3204 portforwarding). work by Dan Kaminsky <dankamin@cisco.com> and me.
3205 thanks to Dan for this great patch: use 'ssh -D 1080 host' and make
0490e609 3206 netscape use localhost:1080 as a socks proxy.
d98d029a 3207 - markus@cvs.openbsd.org 2001/04/08 11:24:33
3208 [uidswap.c]
3209 KNF
6e9944b8 3210
d9d49fdb 321120010408
3212 - OpenBSD CVS Sync
3213 - stevesk@cvs.openbsd.org 2001/04/06 22:12:47
3214 [hostfile.c]
3215 unused; typo in comment
d11c1288 3216 - stevesk@cvs.openbsd.org 2001/04/06 22:25:25
3217 [servconf.c]
3218 in addition to:
3219 ListenAddress host|ipv4_addr|ipv6_addr
3220 permit:
3221 ListenAddress [host|ipv4_addr|ipv6_addr]:port
3222 ListenAddress host|ipv4_addr:port
3223 sshd.8 updates coming. ok markus@
d9d49fdb 3224
613fc910 322520010407
3226 - (bal) CVS ID Resync of version.h
cc94bd38 3227 - OpenBSD CVS Sync
3228 - markus@cvs.openbsd.org 2001/04/05 23:39:20
3229 [serverloop.c]
3230 keep the ssh session even if there is no active channel.
3231 this is more in line with the protocol spec and makes
3232 ssh -N -L 1234:server:110 host
3233 more useful.
3234 based on discussion with <mats@mindbright.se> long time ago
3235 and recent mail from <res@shore.net>
0fc791ba 3236 - deraadt@cvs.openbsd.org 2001/04/06 16:46:59
3237 [scp.c]
3238 remove trailing / from source paths; fixes pr#1756
68fa858a 3239
63f7e231 324020010406
3241 - (stevesk) logintest.c: fix for systems without __progname
72170131 3242 - (stevesk) Makefile.in: log.o is in libssh.a
d8a2f554 3243 - OpenBSD CVS Sync
3244 - markus@cvs.openbsd.org 2001/04/05 10:00:06
3245 [compat.c]
3246 2.3.x does old GEX, too; report jakob@
6ba22c93 3247 - markus@cvs.openbsd.org 2001/04/05 10:39:03
3248 [compress.c compress.h packet.c]
3249 reset compress state per direction when rekeying.
3667ba79 3250 - markus@cvs.openbsd.org 2001/04/05 10:39:48
3251 [version.h]
3252 temporary version 2.5.4 (supports rekeying).
3253 this is not an official release.
cd332296 3254 - markus@cvs.openbsd.org 2001/04/05 10:42:57
68fa858a 3255 [auth-chall.c authfd.c channels.c clientloop.c kex.c kexgex.c key.c
3256 mac.c packet.c serverloop.c sftp-client.c sftp-client.h sftp-glob.c
3257 sftp-glob.h sftp-int.c sftp-server.c sftp.c ssh-keygen.c sshconnect.c
cd332296 3258 sshconnect2.c sshd.c]
3259 fix whitespace: unexpand + trailing spaces.
255cfda1 3260 - markus@cvs.openbsd.org 2001/04/05 11:09:17
3261 [clientloop.c compat.c compat.h]
3262 add SSH_BUG_NOREKEY and detect broken (=all old) openssh versions.
b4a19d21 3263 - markus@cvs.openbsd.org 2001/04/05 15:45:43
3264 [ssh.1]
3265 ssh defaults to protocol v2; from quisar@quisar.ambre.net
46e3af7f 3266 - stevesk@cvs.openbsd.org 2001/04/05 15:48:18
3267 [canohost.c canohost.h session.c]
3268 move get_remote_name_or_ip() to canohost.[ch]; for portable. ok markus@
54506d2e 3269 - markus@cvs.openbsd.org 2001/04/05 20:01:10
3270 [clientloop.c]
3271 for ~R print message if server does not support rekeying. (and fix ~R).
b37caf1a 3272 - markus@cvs.openbsd.org 2001/04/05 21:02:46
3273 [buffer.c]
3274 better error message
eb0dd41f 3275 - markus@cvs.openbsd.org 2001/04/05 21:05:24
3276 [clientloop.c ssh.c]
3277 don't request a session for 'ssh -N', pointed out slade@shore.net
63f7e231 3278
d8ee838b 327920010405
68fa858a 3280 - OpenBSD CVS Sync
3281 - markus@cvs.openbsd.org 2001/04/04 09:48:35
d8ee838b 3282 [kex.c kex.h kexdh.c kexgex.c packet.c sshconnect2.c sshd.c]
68fa858a 3283 don't sent multiple kexinit-requests.
3284 send newkeys, block while waiting for newkeys.
3285 fix comments.
3286 - markus@cvs.openbsd.org 2001/04/04 14:34:58
3287 [clientloop.c kex.c kex.h serverloop.c sshconnect2.c sshd.c]
3288 enable server side rekeying + some rekey related clientup.
7a37c112 3289 todo: we should not send any non-KEX messages after we send KEXINIT
5adb303f 3290 - markus@cvs.openbsd.org 2001/04/04 15:50:55
3291 [compat.c]
3292 f-secure 1.3.2 does not handle IGNORE; from milliondl@ornl.gov
c422989b 3293 - markus@cvs.openbsd.org 2001/04/04 20:25:38
68fa858a 3294 [channels.c channels.h clientloop.c kex.c kex.h serverloop.c
c422989b 3295 sshconnect2.c sshd.c]
3296 more robust rekeying
3297 don't send channel data after rekeying is started.
0715ec6c 3298 - markus@cvs.openbsd.org 2001/04/04 20:32:56
3299 [auth2.c]
3300 we don't care about missing bannerfiles; from tsoome@ut.ee, ok deraadt@
bbb4cc1b 3301 - markus@cvs.openbsd.org 2001/04/04 22:04:35
3302 [kex.c kexgex.c serverloop.c]
3303 parse full kexinit packet.
3304 make server-side more robust, too.
a7ca6275 3305 - markus@cvs.openbsd.org 2001/04/04 23:09:18
3306 [dh.c kex.c packet.c]
3307 clear+free keys,iv for rekeying.
3308 + fix DH mem leaks. ok niels@
86c9e193 3309 - (stevesk) don't use vhangup() if defined(HAVE_DEV_PTMX); also removes
3310 BROKEN_VHANGUP
d8ee838b 3311
9d451c5a 331220010404
3313 - OpenBSD CVS Sync
3314 - deraadt@cvs.openbsd.org 2001/04/02 17:32:23
3315 [ssh-agent.1]
3316 grammar; slade@shore.net
894c5fa6 3317 - stevesk@cvs.openbsd.org 2001/04/03 13:56:11
3318 [sftp-glob.c ssh-agent.c ssh-keygen.c]
3319 free() -> xfree()
a5c9ffdb 3320 - markus@cvs.openbsd.org 2001/04/03 19:53:29
3321 [dh.c dh.h kex.c kex.h sshconnect2.c sshd.c]
3322 move kex to kex*.c, used dispatch_set() callbacks for kex. should
3323 make rekeying easier.
3463ff28 3324 - todd@cvs.openbsd.org 2001/04/03 21:19:38
3325 [ssh_config]
3326 id_rsa1/2 -> id_rsa; ok markus@
d1ac6175 3327 - markus@cvs.openbsd.org 2001/04/03 23:32:12
3328 [kex.c kex.h packet.c sshconnect2.c sshd.c]
3329 undo parts of recent my changes: main part of keyexchange does not
3330 need dispatch-callbacks, since application data is delayed until
3331 the keyexchange completes (if i understand the drafts correctly).
3332 add some infrastructure for re-keying.
e092ce67 3333 - markus@cvs.openbsd.org 2001/04/04 00:06:54
3334 [clientloop.c sshconnect2.c]
3335 enable client rekeying
3336 (1) force rekeying with ~R, or
3337 (2) if the server requests rekeying.
3338 works against ssh-2.0.12/2.0.13/2.1.0/2.2.0/2.3.0/2.3.1/2.4.0
0bc35151 3339 - (bal) Oops.. Missed including kexdh.c and kexgex.c in OpenBSD sync.
9d451c5a 3340
672f212f 334120010403
3342 - OpenBSD CVS Sync
3343 - stevesk@cvs.openbsd.org 2001/04/02 14:15:31
3344 [sshd.8]
3345 typo; ok markus@
6be9a5e8 3346 - stevesk@cvs.openbsd.org 2001/04/02 14:20:23
3347 [readconf.c servconf.c]
3348 correct comment; ok markus@
fe39c3df 3349 - (stevesk) nchan.c: remove ostate checks and add EINVAL to
3350 shutdown(SHUT_RD) error() bypass for HP-UX.
672f212f 3351
0be033ea 335220010402
3353 - (stevesk) log.c openbsd sync; missing newlines
5d9e4c8d 3354 - (stevesk) sshpty.h openbsd sync; PTY_H -> SSHPTY_H
0be033ea 3355
b7a2a476 335620010330
3357 - (djm) Another openbsd-compat/glob.c sync
4047d868 3358 - (djm) OpenBSD CVS Sync
3359 - provos@cvs.openbsd.org 2001/03/28 21:59:41
3360 [kex.c kex.h sshconnect2.c sshd.c]
3361 forgot to include min and max params in hash, okay markus@
c8682232 3362 - provos@cvs.openbsd.org 2001/03/28 22:04:57
3363 [dh.c]
3364 more sanity checking on primes file
d9cd3575 3365 - markus@cvs.openbsd.org 2001/03/28 22:43:31
3366 [auth.h auth2.c auth2-chall.c]
3367 check auth_root_allowed for kbd-int auth, too.
86b878d5 3368 - provos@cvs.openbsd.org 2001/03/29 14:24:59
3369 [sshconnect2.c]
3370 use recommended defaults
1ad64a93 3371 - stevesk@cvs.openbsd.org 2001/03/29 21:06:21
3372 [sshconnect2.c sshd.c]
3373 need to set both STOC and CTOS for SSH_BUG_BIGENDIANAES; ok markus@
03b8f8be 3374 - markus@cvs.openbsd.org 2001/03/29 21:17:40
3375 [dh.c dh.h kex.c kex.h]
3376 prepare for rekeying: move DH code to dh.c
76ca7b01 3377 - djm@cvs.openbsd.org 2001/03/29 23:42:01
3378 [sshd.c]
3379 Protocol 1 key regeneration log => verbose, some KNF; ok markus@
b7a2a476 3380
01ce749f 338120010329
3382 - OpenBSD CVS Sync
3383 - stevesk@cvs.openbsd.org 2001/03/26 15:47:59
3384 [ssh.1]
3385 document more defaults; misc. cleanup. ok markus@
569807fb 3386 - markus@cvs.openbsd.org 2001/03/26 23:12:42
3387 [authfile.c]
3388 KNF
457fc0c6 3389 - markus@cvs.openbsd.org 2001/03/26 23:23:24
3390 [rsa.c rsa.h ssh-agent.c ssh-keygen.c]
3391 try to read private f-secure ssh v2 rsa keys.
1a92bd7e 3392 - markus@cvs.openbsd.org 2001/03/27 10:34:08
3393 [ssh-rsa.c sshd.c]
3394 use EVP_get_digestbynid, reorder some calls and fix missing free.
a4da628b 3395 - markus@cvs.openbsd.org 2001/03/27 10:57:00
3396 [compat.c compat.h ssh-rsa.c]
3397 some older systems use NID_md5 instead of NID_sha1 for RSASSA-PKCS1-v1_5
3398 signatures in SSH protocol 2, ok djm@
db1cd2f3 3399 - provos@cvs.openbsd.org 2001/03/27 17:46:50
3400 [compat.c compat.h dh.c dh.h ssh2.h sshconnect2.c sshd.c version.h]
3401 make dh group exchange more flexible, allow min and max group size,
3402 okay markus@, deraadt@
e5ff6ecf 3403 - stevesk@cvs.openbsd.org 2001/03/28 19:56:23
3404 [scp.c]
3405 start to sync scp closer to rcp; ok markus@
03cb2621 3406 - stevesk@cvs.openbsd.org 2001/03/28 20:04:38
3407 [scp.c]
3408 usage more like rcp and add missing -B to usage; ok markus@
563834bb 3409 - markus@cvs.openbsd.org 2001/03/28 20:50:45
3410 [sshd.c]
3411 call refuse() before close(); from olemx@ans.pl
01ce749f 3412
b5b68128 341320010328
68fa858a 3414 - (djm) Reorder tests and library inclusion for Krb4/AFS to try to
3415 resolve linking conflicts with libcrypto. Report and suggested fix
b5b68128 3416 from Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
edbe6722 3417 - (djm) Work around Solaris' broken struct dirent. Diagnosis and suggested
3418 fix from Philippe Levan <levan@epix.net>
cccfea16 3419 - (djm) Rework krbIV tests to get us closer to building on Redhat. Still
3420 doesn't work because of conflicts between krbIV's and OpenSSL's des.h
8d0cc79b 3421 - (djm) Sync openbsd-compat/glob.c
b5b68128 3422
0c90b590 342320010327
3424 - Attempt sync with sshlogin.c w/ OpenBSD (mainly CVS ID)
68fa858a 3425 - Fix pointer issues in waitpid() and wait() replaces. Patch by Lutz
60a8683f 3426 Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
690d0d7f 3427 - OpenBSD CVS Sync
3428 - djm@cvs.openbsd.org 2001/03/25 00:01:34
3429 [session.c]
3430 shorten; ok markus@
4f4648f9 3431 - stevesk@cvs.openbsd.org 2001/03/25 13:16:11
3432 [servconf.c servconf.h session.c sshd.8 sshd_config]
3433 PrintLastLog option; from chip@valinux.com with some minor
3434 changes by me. ok markus@
9afbfcfa 3435 - markus@cvs.openbsd.org 2001/03/26 08:07:09
68fa858a 3436 [authfile.c authfile.h ssh-add.c ssh-keygen.c ssh.c sshconnect.c
9afbfcfa 3437 sshconnect.h sshconnect1.c sshconnect2.c sshd.c]
3438 simpler key load/save interface, see authfile.h
68fa858a 3439 - (djm) Reestablish PAM credentials (which can be supplemental group
9afbfcfa 3440 memberships) after initgroups() blows them away. Report and suggested
3441 fix from Nalin Dahyabhai <nalin@redhat.com>
0c90b590 3442
b567a40c 344320010324
3444 - Fixed permissions ssh-keyscan. Thanks to Christopher Linn <celinn@mtu.edu>.
80cd07ae 3445 - OpenBSD CVS Sync
3446 - djm@cvs.openbsd.org 2001/03/23 11:04:07
3447 [compat.c compat.h sshconnect2.c sshd.c]
3448 Compat for OpenSSH with broken Rijndael/AES. ok markus@
7af9f7f8 3449 - markus@cvs.openbsd.org 2001/03/23 12:02:49
3450 [auth1.c]
3451 authctxt is now passed to do_authenticated
e285053e 3452 - markus@cvs.openbsd.org 2001/03/23 13:10:57
3453 [sftp-int.c]
3454 fix put, upload to _absolute_ path, ok djm@
1d3c30db 3455 - markus@cvs.openbsd.org 2001/03/23 14:28:32
3456 [session.c sshd.c]
3457 ignore SIGPIPE, restore in child, fixes x11-fwd crashes; with djm@
8ca3f6dc 3458 - (djm) Pull out our own SIGPIPE hacks
b567a40c 3459
8a169574 346020010323
68fa858a 3461 - OpenBSD CVS Sync
8a169574 3462 - deraadt@cvs.openbsd.org 2001/03/22 20:22:55
68fa858a 3463 [sshd.c]
3464 do not place linefeeds in buffer
8a169574 3465
ee110bfb 346620010322
3467 - (djm) Better AIX no tty fix, spotted by Gert Doering <gert@greenie.muc.de>
289ba62e 3468 - (bal) version.c CVS ID resync
a5b09902 3469 - (bal) auth-chall.c auth-passwd.c auth.h auth1.c auth2.c session.c CVS ID
3470 resync
ae7242ef 3471 - (bal) scp.c CVS ID resync
3e587cc3 3472 - OpenBSD CVS Sync
3473 - markus@cvs.openbsd.org 2001/03/20 19:10:16
3474 [readconf.c]
3475 default to SSH protocol version 2
e5d7a405 3476 - markus@cvs.openbsd.org 2001/03/20 19:21:21
3477 [session.c]
3478 remove unused arg
39f7530f 3479 - markus@cvs.openbsd.org 2001/03/20 19:21:21
3480 [session.c]
3481 remove unused arg
bb5639fe 3482 - markus@cvs.openbsd.org 2001/03/21 11:43:45
3483 [auth1.c auth2.c session.c session.h]
3484 merge common ssh v1/2 code
5e7cb456 3485 - jakob@cvs.openbsd.org 2001/03/21 14:20:45
3486 [ssh-keygen.c]
3487 add -B flag to usage
ca4df544 3488 - markus@cvs.openbsd.org 2001/03/21 21:06:30
3489 [session.c]
3490 missing init; from mib@unimelb.edu.au
ee110bfb 3491
f5f6020e 349220010321
68fa858a 3493 - (djm) Fix ttyname breakage for AIX and Tru64. Patch from Steve
f5f6020e 3494 VanDevender <stevev@darkwing.uoregon.edu>
37eadb90 3495 - (djm) Make sure pam_retval is initialised on call to pam_end. Patch
3496 from Solar Designer <solar@openwall.com>
0a3700ee 3497 - (djm) Don't loop forever when changing password via PAM. Patch
3498 from Solar Designer <solar@openwall.com>
0c13ffa2 3499 - (djm) Generate config files before build
7a7101ec 3500 - (djm) Correctly handle SIA and AIX when no tty present. Spotted and
3501 suggested fix from Mike Battersby <mib@unimelb.edu.au>
f5f6020e 3502
8d539493 350320010320
01022caf 3504 - (bal) glob.c update to added GLOB_LIMITS (OpenBSD CVS).
3505 - (bal) glob.c update to set gl_pathv to NULL (OpenBSD CVS).
1620233b 3506 - (bal) Oops. Missed globc.h change (OpenBSD CVS).
614dee3a 3507 - (djm) OpenBSD CVS Sync
3508 - markus@cvs.openbsd.org 2001/03/19 17:07:23
3509 [auth.c readconf.c]
3510 undo /etc/shell and proto 2,1 change for openssh-2.5.2
3dd16786 3511 - markus@cvs.openbsd.org 2001/03/19 17:12:10
3512 [version.h]
3513 version 2.5.2
ea44783f 3514 - (djm) Update RPM spec version
3515 - (djm) Release 2.5.2p1
3743cc2f 3516- tim@mindrot.org 2001/03/19 18:33:47 [defines.h]
3517 change S_ISLNK macro to work for UnixWare 2.03
9887f269 3518- tim@mindrot.org 2001/03/19 20:45:11 [openbsd-compat/glob.c]
3519 add get_arg_max(). Use sysconf() if ARG_MAX is not defined
8d539493 3520
e339aa53 352120010319
68fa858a 3522 - (djm) Seed PRNG at startup, rather than waiting for arc4random calls to
e339aa53 3523 do it implicitly.
7cdb79d4 3524 - (djm) Add getusershell() functions from OpenBSD CVS
b1ed8313 3525 - OpenBSD CVS Sync
3526 - markus@cvs.openbsd.org 2001/03/18 12:07:52
3527 [auth-options.c]
3528 ignore permitopen="host:port" if AllowTcpForwarding==no
f8f230bf 3529 - (djm) Make scp work on systems without 64-bit ints
2538ecf1 3530 - tim@mindrot.org 2001/03/18 18:28:39 [defines.h]
3531 move HAVE_LONG_LONG_INT where it works
d1581d5f 3532 - (bal) Use 'NGROUPS' for NeXT Since 'MAX_NGROUPS' is wrapped up in -lposix
107628c0 3533 stuff. Change suggested by Mark Miller <markm@swoon.net>
d1581d5f 3534 - (bal) Small fix to scp. %lu vs %ld
68fa858a 3535 - (bal) NeXTStep lacks S_ISLNK. Plus split up S_IS*
bb6da70f 3536 - (djm) OpenBSD CVS Sync
3537 - djm@cvs.openbsd.org 2001/03/19 03:52:51
3538 [sftp-client.c]
3539 Report ssh connection closing correctly; ok deraadt@
3a1c54d4 3540 - deraadt@cvs.openbsd.org 2001/03/18 23:30:55
3541 [compat.c compat.h sshd.c]
68fa858a 3542 specifically version match on ssh scanners. do not log scan
3a1c54d4 3543 information to the console
dc504afd 3544 - djm@cvs.openbsd.org 2001/03/19 12:10:17
db4d3098 3545 [sshd.8]
dc504afd 3546 Document permitopen authorized_keys option; ok markus@
babd91d4 3547 - djm@cvs.openbsd.org 2001/03/19 05:49:52
3548 [ssh.1]
3549 document PreferredAuthentications option; ok markus@
05c64611 3550 - (bal) Minor NeXT fixed. Forgot to #undef NGROUPS_MAX
e339aa53 3551
ec0ad9c2 355220010318
68fa858a 3553 - (bal) Fixed scp type casing issue which causes "scp: protocol error:
ec0ad9c2 3554 size not delimited" fatal errors when tranfering.
5cc8d4ad 3555 - OpenBSD CVS Sync
3556 - markus@cvs.openbsd.org 2001/03/17 17:27:59
3557 [auth.c]
3558 check /etc/shells, too
7411201c 3559 - tim@mindrot.org 2001/03/17 18:45:25 [compat.c]
3560 openbsd-compat/fake-regex.h
ec0ad9c2 3561
8a968c25 356220010317
68fa858a 3563 - Support usrinfo() on AIX. Based on patch from Gert Doering
8a968c25 3564 <gert@greenie.muc.de>
bf1d27bd 3565 - OpenBSD CVS Sync
3566 - markus@cvs.openbsd.org 2001/03/15 15:05:59
3567 [scp.c]
3568 use %lld in printf, ok millert@/deraadt@; report from ssh@client.fi
56b3e9ce 3569 - markus@cvs.openbsd.org 2001/03/15 22:07:08
3570 [session.c]
3571 pass Session to do_child + KNF
d50d9b63 3572 - djm@cvs.openbsd.org 2001/03/16 08:16:18
3573 [sftp-client.c sftp-client.h sftp-glob.c sftp-int.c]
3574 Revise globbing for get/put to be more shell-like. In particular,
3575 "get/put file* directory/" now works. ok markus@
f55d1b5f 3576 - markus@cvs.openbsd.org 2001/03/16 09:55:53
3577 [sftp-int.c]
3578 fix memset and whitespace
6a8496e4 3579 - markus@cvs.openbsd.org 2001/03/16 13:44:24
3580 [sftp-int.c]
3581 discourage strcat/strcpy
01794848 3582 - markus@cvs.openbsd.org 2001/03/16 19:06:30
3583 [auth-options.c channels.c channels.h serverloop.c session.c]
3584 implement "permitopen" key option, restricts -L style forwarding to
3585 to specified host:port pairs. based on work by harlan@genua.de
68fa858a 3586 - Check for gl_matchc support in glob_t and fall back to the
40849fdb 3587 openbsd-compat/glob.[ch] support if it does not exist.
8a968c25 3588
4cb5d598 358920010315
3590 - OpenBSD CVS Sync
3591 - markus@cvs.openbsd.org 2001/03/14 08:57:14
3592 [sftp-client.c]
3593 Wall
85cf5827 3594 - markus@cvs.openbsd.org 2001/03/14 15:15:58
3595 [sftp-int.c]
3596 add version command
61b3a2bc 3597 - deraadt@cvs.openbsd.org 2001/03/14 22:50:25
3598 [sftp-server.c]
3599 note no getopt()
51e2fc8f 3600 - (stevesk) ssh-keyscan.c: specify "openbsd-compat/fake-queue.h"
68fa858a 3601 - (bal) Cygwin README change by Corinna Vinschen <vinschen@redhat.com>
4cb5d598 3602
acc9d6d7 360320010314
3604 - OpenBSD CVS Sync
85cf5827 3605 - markus@cvs.openbsd.org 2001/03/13 17:34:42
3606 [auth-options.c]
3607 missing xfree, deny key on parse error; ok stevesk@
3608 - djm@cvs.openbsd.org 2001/03/13 22:42:54
3609 [sftp-client.c sftp-client.h sftp-glob.c sftp-glob.h sftp-int.c]
3610 sftp client filename globbing for get, put, ch{mod,grp,own}. ok markus@
84ceda19 3611 - (bal) Fix strerror() in bsd-misc.c
3612 - (djm) Add replacement glob() from OpenBSD libc if the system glob is
3613 missing or lacks the GLOB_ALTDIRFUNC extension
68fa858a 3614 - (djm) Remove -I$(srcdir)/openbsd-compat from CFLAGS, refer to headers
84ceda19 3615 relatively. Avoids conflict between glob.h and /usr/include/glob.h
acc9d6d7 3616
22138a36 361720010313
3618 - OpenBSD CVS Sync
3619 - markus@cvs.openbsd.org 2001/03/12 22:02:02
3620 [key.c key.h ssh-add.c ssh-keygen.c sshconnect.c sshconnect2.c]
3621 remove old key_fingerprint interface, s/_ex//
3622
539af7f5 362320010312
3624 - OpenBSD CVS Sync
3625 - markus@cvs.openbsd.org 2001/03/11 13:25:36
3626 [auth2.c key.c]
3627 debug
301e8e5b 3628 - jakob@cvs.openbsd.org 2001/03/11 15:03:16
3629 [key.c key.h]
3630 add improved fingerprint functions. based on work by Carsten
3631 Raskgaard <cara@int.tele.dk> and modified by me. ok markus@.
954f0550 3632 - jakob@cvs.openbsd.org 2001/03/11 15:04:16
3633 [ssh-keygen.1 ssh-keygen.c]
3634 print both md5, sha1 and bubblebabble fingerprints when using
3635 ssh-keygen -l -v. ok markus@.
08345971 3636 - jakob@cvs.openbsd.org 2001/03/11 15:13:09
3637 [key.c]
3638 cleanup & shorten some var names key_fingerprint_bubblebabble.
64b1aa3b 3639 - deraadt@cvs.openbsd.org 2001/03/11 16:39:03
3640 [ssh-keygen.c]
3641 KNF, and SHA1 binary output is just creeping featurism
733cf7f4 3642 - tim@mindrot.org 2001/03/11 17:29:32 [configure.in]
3643 test if snprintf() supports %ll
3644 add /dev to search path for PRNGD/EGD socket
3645 fix my mistake in USER_PATH test program
79c9ac1b 3646 - OpenBSD CVS Sync
3647 - markus@cvs.openbsd.org 2001/03/11 18:29:51
3648 [key.c]
3649 style+cleanup
aaf45d87 3650 - markus@cvs.openbsd.org 2001/03/11 22:33:24
3651 [ssh-keygen.1 ssh-keygen.c]
3652 remove -v again. use -B instead for bubblebabble. make -B consistent
3653 with -l and make -B work with /path/to/known_hosts. ok deraadt@
a0322342 3654 - (djm) Bump portable version number for generating test RPMs
94dd09e3 3655 - (djm) Add "static_openssl" RPM build option, remove rsh build dependency
68fa858a 3656 - (bal) Reorder includes in Makefile.
539af7f5 3657
d156519a 365820010311
3659 - OpenBSD CVS Sync
3660 - markus@cvs.openbsd.org 2001/03/10 12:48:27
3661 [sshconnect2.c]
3662 ignore nonexisting private keys; report rjmooney@mediaone.net
5e36d59c 3663 - deraadt@cvs.openbsd.org 2001/03/10 12:53:51
3664 [readconf.c ssh_config]
3665 default to SSH2, now that m68k runs fast
2f778758 3666 - stevesk@cvs.openbsd.org 2001/03/10 15:02:05
3667 [ttymodes.c ttymodes.h]
3668 remove unused sgtty macros; ok markus@
99c415db 3669 - deraadt@cvs.openbsd.org 2001/03/10 15:31:00
3670 [compat.c compat.h sshconnect.c]
3671 all known netscreen ssh versions, and older versions of OSU ssh cannot
3672 handle password padding (newer OSU is fixed)
456fce50 3673 - tim@mindrot.org 2001/03/10 16:33:42 [configure.in Makefile.in sshd_config]
3674 make sure $bindir is in USER_PATH so scp will work
cab80f75 3675 - OpenBSD CVS Sync
3676 - markus@cvs.openbsd.org 2001/03/10 17:51:04
3677 [kex.c match.c match.h readconf.c readconf.h sshconnect2.c]
3678 add PreferredAuthentications
d156519a 3679
1c9a907f 368020010310
3681 - OpenBSD CVS Sync
3682 - deraadt@cvs.openbsd.org 2001/03/09 03:14:39
3683 [ssh-keygen.c]
68fa858a 3684 create *.pub files with umask 0644, so that you can mv them to
1c9a907f 3685 authorized_keys
cb7bd922 3686 - deraadt@cvs.openbsd.org 2001/03/09 12:30:29
3687 [sshd.c]
3688 typo; slade@shore.net
61cf0e38 3689 - Removed log.o from sftp client. Not needed.
1c9a907f 3690
385590e4 369120010309
3692 - OpenBSD CVS Sync
3693 - stevesk@cvs.openbsd.org 2001/03/08 18:47:12
3694 [auth1.c]
3695 unused; ok markus@
acf06a60 3696 - stevesk@cvs.openbsd.org 2001/03/08 20:44:48
3697 [sftp.1]
3698 spelling, cleanup; ok deraadt@
fee56204 3699 - markus@cvs.openbsd.org 2001/03/08 21:42:33
3700 [compat.c compat.h readconf.h ssh.c sshconnect1.c sshconnect2.c]
3701 implement client side of SSH2_MSG_USERAUTH_PK_OK (test public key ->
3702 no need to do enter passphrase or do expensive sign operations if the
3703 server does not accept key).
385590e4 3704
3a7fe5ba 370520010308
3706 - OpenBSD CVS Sync
d5ebca2b 3707 - djm@cvs.openbsd.org 2001/03/07 10:11:23
3708 [sftp-client.c sftp-client.h sftp-int.c sftp-server.c sftp.1 sftp.c sftp.h]
3709 Support for new draft (draft-ietf-secsh-filexfer-01). New symlink handling
3710 functions and small protocol change.
3711 - markus@cvs.openbsd.org 2001/03/08 00:15:48
3712 [readconf.c ssh.1]
3713 turn off useprivilegedports by default. only rhost-auth needs
3714 this. older sshd's may need this, too.
097ca118 3715 - (stevesk) Reliant Unix (SNI) needs HAVE_BOGUS_SYS_QUEUE_H;
3716 Dirk Markwardt <D.Markwardt@tu-bs.de>
3a7fe5ba 3717
3251b439 371820010307
3719 - (bal) OpenBSD CVS Sync
3720 - deraadt@cvs.openbsd.org 2001/03/06 06:11:18
3721 [ssh-keyscan.c]
3722 appease gcc
a5ec8a3d 3723 - deraadt@cvs.openbsd.org 2001/03/06 06:11:44
3724 [sftp-int.c sftp.1 sftp.c]
3725 sftp -b batchfile; mouring@etoh.eviladmin.org
17910dce 3726 - deraadt@cvs.openbsd.org 2001/03/06 15:10:42
3727 [sftp.1]
3728 order things
2c86906e 3729 - deraadt@cvs.openbsd.org 2001/03/07 01:19:06
3730 [ssh.1 sshd.8]
3731 the name "secure shell" is boring, noone ever uses it
7daf8515 3732 - deraadt@cvs.openbsd.org 2001/03/07 04:05:58
3733 [ssh.1]
3734 removed dated comment
f52798a4 3735 - Cygwin contrib improvements from Corinna Vinschen <vinschen@redhat.com>
3251b439 3736
657297ff 373720010306
3738 - (bal) OpenBSD CVS Sync
3739 - deraadt@cvs.openbsd.org 2001/03/05 14:28:47
3740 [sshd.8]
3741 alpha order; jcs@rt.fm
7c8f2a26 3742 - stevesk@cvs.openbsd.org 2001/03/05 15:44:51
3743 [servconf.c]
3744 sync error message; ok markus@
f2ba0775 3745 - deraadt@cvs.openbsd.org 2001/03/05 15:56:16
3746 [myproposal.h ssh.1]
3747 switch to aes128-cbc/hmac-md5 by default in SSH2 -- faster;
3748 provos & markus ok
7a6c39a3 3749 - deraadt@cvs.openbsd.org 2001/03/05 16:07:15
3750 [sshd.8]
3751 detail default hmac setup too
7de5b06b 3752 - markus@cvs.openbsd.org 2001/03/05 17:17:21
3753 [kex.c kex.h sshconnect2.c sshd.c]
3754 generate a 2*need size (~300 instead of 1024/2048) random private
3755 exponent during the DH key agreement. according to Niels (the great
3756 german advisor) this is safe since /etc/primes contains strong
3757 primes only.
3758
3759 References:
3760 P. C. van Oorschot and M. J. Wiener, On Diffie-Hellman key
3761 agreement with short exponents, In Advances in Cryptology
3762 - EUROCRYPT'96, LNCS 1070, Springer-Verlag, 1996, pp.332-343.
a5df12e9 3763 - stevesk@cvs.openbsd.org 2001/03/05 17:40:48
3764 [ssh.1]
3765 more ssh_known_hosts2 documentation; ok markus@
0b2190ee 3766 - stevesk@cvs.openbsd.org 2001/03/05 17:58:22
3767 [dh.c]
3768 spelling
bbc62e59 3769 - deraadt@cvs.openbsd.org 2001/03/06 00:33:04
3770 [authfd.c cli.c ssh-agent.c]
3771 EINTR/EAGAIN handling is required in more cases
c16c7f20 3772 - millert@cvs.openbsd.org 2001/03/06 01:06:03
3773 [ssh-keyscan.c]
3774 Don't assume we wil get the version string all in one read().
3775 deraadt@ OK'd
09cb311c 3776 - millert@cvs.openbsd.org 2001/03/06 01:08:27
3777 [clientloop.c]
3778 If read() fails with EINTR deal with it the same way we treat EAGAIN
657297ff 3779
1a2936c4 378020010305
3781 - (bal) CVS ID touch up on sshpty.[ch] and sshlogin.[ch]
68fa858a 3782 - (bal) CVS ID touch up on sftp-int.c
e77df335 3783 - (bal) CVS ID touch up on uuencode.c
6cca9fde 3784 - (bal) CVS ID touch up on auth2.c, serverloop.c, session.c & sshd.c
778f6940 3785 - (bal) OpenBSD CVS Sync
dcb971e1 3786 - deraadt@cvs.openbsd.org 2001/02/17 23:48:48
3787 [sshd.8]
3788 it's the OpenSSH one
778f6940 3789 - deraadt@cvs.openbsd.org 2001/02/21 07:37:04
3790 [ssh-keyscan.c]
3791 inline -> __inline__, and some indent
81333640 3792 - deraadt@cvs.openbsd.org 2001/02/21 09:05:54
3793 [authfile.c]
3794 improve fd handling
79ddf6db 3795 - deraadt@cvs.openbsd.org 2001/02/21 09:12:56
3796 [sftp-server.c]
3797 careful with & and &&; markus ok
96ee8386 3798 - stevesk@cvs.openbsd.org 2001/02/21 21:14:04
3799 [ssh.c]
3800 -i supports DSA identities now; ok markus@
0c126dc9 3801 - deraadt@cvs.openbsd.org 2001/02/22 04:29:37
3802 [servconf.c]
3803 grammar; slade@shore.net
ed2166d8 3804 - deraadt@cvs.openbsd.org 2001/02/22 06:43:55
3805 [ssh-keygen.1 ssh-keygen.c]
3806 document -d, and -t defaults to rsa1
b07ae1e9 3807 - deraadt@cvs.openbsd.org 2001/02/22 08:03:51
3808 [ssh-keygen.1 ssh-keygen.c]
3809 bye bye -d
e2fccec3 3810 - deraadt@cvs.openbsd.org 2001/02/22 18:09:06
3811 [sshd_config]
3812 activate RSA 2 key
e91c60f2 3813 - markus@cvs.openbsd.org 2001/02/22 21:57:27
3814 [ssh.1 sshd.8]
3815 typos/grammar from matt@anzen.com
3b1a83df 3816 - markus@cvs.openbsd.org 2001/02/22 21:59:44
3817 [auth.c auth.h auth1.c auth2.c misc.c misc.h ssh.c]
3818 use pwcopy in ssh.c, too
19d57054 3819 - markus@cvs.openbsd.org 2001/02/23 15:34:53
3820 [serverloop.c]
3821 debug2->3
00be5382 3822 - markus@cvs.openbsd.org 2001/02/23 18:15:13
3823 [sshd.c]
3824 the random session key depends now on the session_key_int
3825 sent by the 'attacker'
3826 dig1 = md5(cookie|session_key_int);
3827 dig2 = md5(dig1|cookie|session_key_int);
3828 fake_session_key = dig1|dig2;
3829 this change is caused by a mail from anakin@pobox.com
3830 patch based on discussions with my german advisor niels@openbsd.org
ec63b02d 3831 - deraadt@cvs.openbsd.org 2001/02/24 10:37:55
3832 [readconf.c]
3833 look for id_rsa by default, before id_dsa
582038fb 3834 - deraadt@cvs.openbsd.org 2001/02/24 10:37:26
3835 [sshd_config]
3836 ssh2 rsa key before dsa key
6e18cb71 3837 - markus@cvs.openbsd.org 2001/02/27 10:35:27
3838 [packet.c]
3839 fix random padding
1b5dfeb2 3840 - markus@cvs.openbsd.org 2001/02/27 11:00:11
3841 [compat.c]
3842 support SSH-2.0-2.1 ; from Christophe_Moret@hp.com
4ab21f86 3843 - deraadt@cvs.openbsd.org 2001/02/28 05:34:28
3844 [misc.c]
3845 pull in protos
167b3512 3846 - deraadt@cvs.openbsd.org 2001/02/28 05:36:28
3847 [sftp.c]
3848 do not kill the subprocess on termination (we will see if this helps
3849 things or hurts things)
7e8911cd 3850 - markus@cvs.openbsd.org 2001/02/28 08:45:39
3851 [clientloop.c]
3852 fix byte counts for ssh protocol v1
ee55dacf 3853 - markus@cvs.openbsd.org 2001/02/28 08:54:55
3854 [channels.c nchan.c nchan.h]
3855 make sure remote stderr does not get truncated.
3856 remove closed fd's from the select mask.
a6215e53 3857 - markus@cvs.openbsd.org 2001/02/28 09:57:07
3858 [packet.c packet.h sshconnect2.c]
3859 in ssh protocol v2 use ignore messages for padding (instead of
3860 trailing \0).
94dfb550 3861 - markus@cvs.openbsd.org 2001/02/28 12:55:07
3862 [channels.c]
3863 unify debug messages
5649fbbe 3864 - deraadt@cvs.openbsd.org 2001/02/28 17:52:54
3865 [misc.c]
3866 for completeness, copy pw_gecos too
0572fe75 3867 - markus@cvs.openbsd.org 2001/02/28 21:21:41
3868 [sshd.c]
3869 generate a fake session id, too
95ce5599 3870 - markus@cvs.openbsd.org 2001/02/28 21:27:48
3871 [channels.c packet.c packet.h serverloop.c]
3872 use ignore message to simulate a SSH2_MSG_CHANNEL_DATA message
3873 use random content in ignore messages.
355724fc 3874 - markus@cvs.openbsd.org 2001/02/28 21:31:32
3875 [channels.c]
3876 typo
c3f7d267 3877 - deraadt@cvs.openbsd.org 2001/03/01 02:11:25
3878 [authfd.c]
3879 split line so that p will have an easier time next time around
a01a5f30 3880 - deraadt@cvs.openbsd.org 2001/03/01 02:29:04
3881 [ssh.c]
3882 shorten usage by a line
12bf85ed 3883 - deraadt@cvs.openbsd.org 2001/03/01 02:45:10
3884 [auth-rsa.c auth2.c deattack.c packet.c]
3885 KNF
4371658c 3886 - deraadt@cvs.openbsd.org 2001/03/01 03:38:33
3887 [cli.c cli.h rijndael.h ssh-keyscan.1]
3888 copyright notices on all source files
ce91d6f8 3889 - markus@cvs.openbsd.org 2001/03/01 22:46:37
3890 [ssh.c]
3891 don't truncate remote ssh-2 commands; from mkubita@securities.cz
3892 use min, not max for logging, fixes overflow.
409edaba 3893 - deraadt@cvs.openbsd.org 2001/03/02 06:21:01
3894 [sshd.8]
3895 explain SIGHUP better
b8dc87d3 3896 - deraadt@cvs.openbsd.org 2001/03/02 09:42:49
3897 [sshd.8]
3898 doc the dsa/rsa key pair files
f3c7c613 3899 - deraadt@cvs.openbsd.org 2001/03/02 18:54:31
3900 [atomicio.c atomicio.h auth-chall.c auth.c auth2-chall.c crc32.h
3901 scp.c serverloop.c session.c sftp-server.8 sftp.1 ssh-add.1 ssh-add.c
3902 ssh-agent.1 ssh-agent.c ssh-keygen.1 ssh.1 sshd.8]
3903 make copyright lines the same format
2671b47f 3904 - deraadt@cvs.openbsd.org 2001/03/03 06:53:12
3905 [ssh-keyscan.c]
3906 standard theo sweep
ff7fee59 3907 - millert@cvs.openbsd.org 2001/03/03 21:19:41
3908 [ssh-keyscan.c]
3909 Dynamically allocate read_wait and its copies. Since maxfd is
3910 based on resource limits it is often (usually?) larger than FD_SETSIZE.
c8d75031 3911 - millert@cvs.openbsd.org 2001/03/03 21:40:30
3912 [sftp-server.c]
3913 Dynamically allocate fd_set; deraadt@ OK
20e04e90 3914 - millert@cvs.openbsd.org 2001/03/03 21:41:07
3915 [packet.c]
3916 Dynamically allocate fd_set; deraadt@ OK
dce9bac5 3917 - deraadt@cvs.openbsd.org 2001/03/03 22:07:50
3918 [sftp-server.c]
3919 KNF
c630ce76 3920 - markus@cvs.openbsd.org 2001/03/03 23:52:22
3921 [sftp.c]
3922 clean up arg processing. based on work by Christophe_Moret@hp.com
20244695 3923 - markus@cvs.openbsd.org 2001/03/03 23:59:34
3924 [log.c ssh.c]
3925 log*.c -> log.c
61f8a1d1 3926 - markus@cvs.openbsd.org 2001/03/04 00:03:59
3927 [channels.c]
3928 debug1->2
38967add 3929 - stevesk@cvs.openbsd.org 2001/03/04 10:57:53
3930 [ssh.c]
3931 add -m to usage; ok markus@
46f23b8d 3932 - stevesk@cvs.openbsd.org 2001/03/04 11:04:41
3933 [sshd.8]
3934 small cleanup and clarify for PermitRootLogin; ok markus@
9c81df4c 3935 - stevesk@cvs.openbsd.org 2001/03/04 11:16:06
3936 [servconf.c sshd.8]
3937 kill obsolete RandomSeed; ok markus@ deraadt@
f5429434 3938 - stevesk@cvs.openbsd.org 2001/03/04 12:54:04
3939 [sshd.8]
3940 spelling
54b974dc 3941 - millert@cvs.openbsd.org 2001/03/04 17:42:28
3942 [authfd.c channels.c dh.c log.c readconf.c servconf.c sftp-int.c
3943 ssh.c sshconnect.c sshd.c]
3944 log functions should not be passed strings that end in newline as they
3945 get passed on to syslog() and when logging to stderr, do_log() appends
3946 its own newline.
51c251f0 3947 - deraadt@cvs.openbsd.org 2001/03/04 18:21:28
3948 [sshd.8]
3949 list SSH2 ciphers
2605addd 3950 - (bal) Put HAVE_PW_CLASS_IN_PASSWD back into pwcopy()
164c80dc 3951 - (bal) Fix up logging since it changed. removed log-*.c
cc3067d6 3952 - (djm) Fix up LOG_AUTHPRIV for systems that have it
70a052c7 3953 - (stevesk) OpenBSD sync:
3954 - deraadt@cvs.openbsd.org 2001/03/05 08:37:27
3955 [ssh-keyscan.c]
3956 skip inlining, why bother
5152d46f 3957 - (stevesk) sftp.c: handle __progname
1a2936c4 3958
40edd7ef 395920010304
3960 - (bal) Remove make-ssh-known-hosts.1 since it's no longer valid.
889fbcd3 3961 - (bal) Updated contrib/README to remove 'make-ssh-known-hosts' and
3962 give Mark Roth credit for mdoc2man.pl
40edd7ef 3963
9817de5f 396420010303
40edd7ef 3965 - (djm) Remove make-ssh-known-hosts.pl, ssh-keyscan is better.
3966 - (djm) Document PAM ChallengeResponseAuthentication in sshd.8
3967 - (djm) Disable and comment ChallengeResponseAuthentication in sshd_config
3968 - (djm) Allow PRNGd entropy collection from localhost TCP socket. Replace
68fa858a 3969 "--with-egd-pool" configure option with "--with-prngd-socket" and
9bdd5929 3970 "--with-prngd-port" options. Debugged and improved by Lutz Jaenicke
3971 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
9817de5f 3972
20cad736 397320010301
68fa858a 3974 - (djm) Properly add -lcrypt if needed.
5f404be3 3975 - (djm) Force standard PAM conversation function in a few more places.
68fa858a 3976 Patch from Redhat 2.5.1p1-2 RPM, probably Nalin Dahyabhai
5f404be3 3977 <nalin@redhat.com>
68fa858a 3978 - (djm) Cygwin needs pw->pw_gecos copied too. Patch from Corinna Vinschen
480eb294 3979 <vinschen@redhat.com>
ad1f4a20 3980 - (djm) Released 2.5.1p2
20cad736 3981
cf0c5df5 398220010228
3983 - (djm) Detect endianness in configure and use it in rijndael.c. Fixes
3984 "Bad packet length" bugs.
68fa858a 3985 - (djm) Fully revert PAM session patch (again). All PAM session init is
403f5a8e 3986 now done before the final fork().
065ef9b1 3987 - (djm) EGD detection patch from Tim Rice <tim@multitalents.net>
d9b1f19a 3988 - (djm) Remove /tmp from EGD socket search list
cf0c5df5 3989
86b416a7 399020010227
68fa858a 3991 - (bal) Applied shutdown() patch for sftp.c by Corinna Vinschen
51fb577a 3992 <vinschen@redhat.com>
2af09193 3993 - (bal) OpenBSD Sync
3994 - markus@cvs.openbsd.org 2001/02/23 15:37:45
3995 [session.c]
3996 handle SSH_PROTOFLAG_SCREEN_NUMBER for buggy clients
68fa858a 3997 - (bal) sshd.init support for all Redhat release. Patch by Jim Knoble
a892c46e 3998 <jmknoble@jmknoble.cx>
68fa858a 3999 - (djm) Fix up POSIX saved uid support. Report from Mark Miller
f4e9a0e1 4000 <markm@swoon.net>
4001 - (djm) Search for -lcrypt on FreeBSD too
c7c72446 4002 - (djm) fatal() on OpenSSL version mismatch
27cf96de 4003 - (djm) Move PAM init to after fork for non-Solaris derived PAMs
d5c4c52e 4004 - (djm) Warning fix on entropy.c saved uid stuff. Patch from Mark Miller
4005 <markm@swoon.net>
4bc6dd70 4006 - (djm) Fix PAM fix
4236bde4 4007 - (djm) Remove 'noreplace' flag from sshd_config in RPM spec files. This
4008 change is being made as 2.5.x configfiles are not back-compatible with
64e0e67e 4009 2.3.x.
4010 - (djm) Avoid warnings for missing broken IP_TOS. Patch from Mark Miller
4011 <markm@swoon.net>
68fa858a 4012 - (djm) Open Server 5 doesn't need BROKEN_SAVED_UIDS. Patch from Tim Rice
a29d3f1c 4013 <tim@multitalents.net>
68fa858a 4014 - (djm) Avoid multiple definition of _PATH_LS. Patch from Tim Rice
a29d3f1c 4015 <tim@multitalents.net>
51fb577a 4016
4925395f 401720010226
4018 - (bal) Fixed bsd-snprinf.c so it now honors 'BROKEN_SNPRINTF' again.
68fa858a 4019 - (djm) Some systems (SCO3, NeXT) have weird saved uid semantics.
e9a13ac1 4020 Based on patch from Tim Rice <tim@multitalents.net>
4925395f 4021
1eb4ec64 402220010225
4023 - (djm) Use %{_libexecdir} rather than hardcoded path in RPM specfile
4024 Patch from Adrian Ho <lexfiend@usa.net>
490cad94 4025 - (bal) Replace 'unsigned long long' to 'u_int64_t' since not every
4026 platform defines u_int64_t as being that.
1eb4ec64 4027
a738c3b0 402820010224
68fa858a 4029 - (bal) Missed part of the UNIX sockets patch. Patch by Corinna
a738c3b0 4030 Vinschen <vinschen@redhat.com>
4031 - (bal) Reorder where 'strftime' is detected to resolve linking
4032 issues on SCO. Patch by Tim Rice <tim@multitalents.net>
4033
8fd97cc4 403420010224
4035 - (bal) pam_stack fix to correctly detect between RH7 and older RHs.
4036 Patch by Pekka Savola <pekkas@netcore.fi>
8f0b3553 4037 - (bal) Renamed sigaction.[ch] to sigact.[ch]. Causes problems with
4038 some platforms.
3d114925 4039 - (bal) Generalize lack of UNIX sockets since this also effects Cray
4040 not just Cygwin. Based on patch by Wendy Palm <wendyp@cray.com>
8fd97cc4 4041
14a49e44 404220010223
4043 - (bal) Fix --define rh7 in openssh.spec file. Patch by Steve Tell
4044 <tell@telltronics.org>
cb291102 4045 - (bal) Patch to force OpenSSH rpm to require the same version of OpenSSL
4046 that it was compiled against. Patch by Pekka Savola <pekkas@netcore.fi>
68fa858a 4047 - (bal) Double -I for OpenSSL on SCO. Patch by Tim Rice
5a67331c 4048 <tim@multitalents.net>
14a49e44 4049
68fa858a 405020010222
73d6d7fa 4051 - (bal) Corrected SCO luid patch by svaughan <svaughan@asterion.com>
ca742b3b 4052 - (bal) Added mdoc2man.pl from Mark Roth <roth@feep.net>
4053 - (bal) Removed reference to liblogin from contrib/README. It was
4054 integrated into OpenSSH a long while ago.
2a81eb9f 4055 - (stevesk) remove erroneous #ifdef sgi code.
4056 Michael Stone <mstone@cs.loyola.edu>
73d6d7fa 4057
fbf305f1 405820010221
4059 - (bal) Removed -L/usr/ucblib -R/usr/ucblib for Solaris platform.
68fa858a 4060 - (bal) Fixed OpenSSL rework to use $saved_*. Patch by Tim Rice
9dd3bc84 4061 <tim@multitalents.net>
1fe61b2e 4062 - (bal) Reverted out of 2001/02/15 patch by djm below because it
4063 breaks Solaris.
4064 - (djm) Move PAM session setup back to before setuid to user.
4065 fixes problems on Solaris-drived PAMs.
266140a8 4066 - (stevesk) session.c: back out to where we were before:
68fa858a 4067 - (djm) Move PAM session initialisation until after fork in sshd. Patch
266140a8 4068 from Nalin Dahyabhai <nalin@redhat.com>
9dd3bc84 4069
8b3319f4 407020010220
4071 - (bal) Fix mixed up params to memmove() from Jan 5th in setenv.c and
4072 getcwd.c.
c2b544a5 4073 - (bal) OpenBSD CVS Sync:
4074 - deraadt@cvs.openbsd.org 2001/02/19 23:09:05
4075 [sshd.c]
4076 clarify message to make it not mention "ident"
8b3319f4 4077
1729c161 407820010219
4079 - (bal) Markus' blessing to rename login.[ch] -> sshlogin.[ch] and
4080 pty.[ch] -> sshpty.[ch]
d6f13fbb 4081 - (djm) Rework search for OpenSSL location. Skip directories which don't
4082 exist, don't add -L$ssldir/lib if it doesn't exist. Should help SCO
4083 with its limit of 6 -L options.
0476625f 4084 - OpenBSD CVS Sync:
4085 - reinhard@cvs.openbsd.org 2001/02/17 08:24:40
4086 [sftp.1]
4087 typo
4088 - deraadt@cvs.openbsd.org 2001/02/17 16:28:58
4089 [ssh.c]
4090 cleanup -V output; noted by millert
4091 - deraadt@cvs.openbsd.org 2001/02/17 16:48:48
4092 [sshd.8]
4093 it's the OpenSSH one
4094 - markus@cvs.openbsd.org 2001/02/18 11:33:54
4095 [dispatch.c]
4096 typo, SSH2_MSG_KEXINIT, from aspa@kronodoc.fi
4097 - markus@cvs.openbsd.org 2001/02/19 02:53:32
4098 [compat.c compat.h serverloop.c]
4099 ssh-1.2.{18-22} has broken handling of ignore messages; report from
4100 itojun@
4101 - markus@cvs.openbsd.org 2001/02/19 03:35:23
4102 [version.h]
4103 OpenSSH_2.5.1 adds bug compat with 1.2.{18-22}
4104 - deraadt@cvs.openbsd.org 2001/02/19 03:36:25
4105 [scp.c]
4106 np is changed by recursion; vinschen@redhat.com
4107 - Update versions in RPM spec files
4108 - Release 2.5.1p1
1729c161 4109
663fd560 411020010218
68fa858a 4111 - (bal) Patch for fix FCHMOD reference in ftp-client.c by Tim Rice
4112 <tim@multitalents.net>
25cd3375 4113 - (Bal) Patch for lack of RA_RESTART in misc.c for mysignal by
4114 stevesk
68fa858a 4115 - (djm) Fix my breaking of cygwin builds, Patch from Corinna Vinschen
58e7f038 4116 <vinschen@redhat.com> and myself.
32ced054 4117 - (djm) Close listen_sock on bind() failures. Patch from Arkadiusz
4118 Miskiewicz <misiek@pld.ORG.PL>
6a951840 4119 - (djm) Robustify EGD/PRNGd code in face of socket closures. Patch from
4120 Todd C. Miller <Todd.Miller@courtesan.com>
68fa858a 4121 - (djm) Use ttyname() to determine name of tty returned by openpty()
4122 rather then risking overflow. Patch from Marek Michalkiewicz
b82f1310 4123 <marekm@amelek.gda.pl>
68fa858a 4124 - (djm) Swapped tests for no_libsocket and no_libnsl in configure.in.
bdf80b2c 4125 Patch from Marek Michalkiewicz <marekm@amelek.gda.pl>
af8fda37 4126 - (djm) Doc fixes from Pekka Savola <pekkas@netcore.fi>
68fa858a 4127 - (djm) Use SA_INTERRUPT along SA_RESTART if present (equivalent for
df538d55 4128 SunOS)
68fa858a 4129 - (djm) SCO needs librpc for libwrap. Patch from Tim Rice
f61d6b17 4130 <tim@multitalents.net>
dfef7e7e 4131 - (stevesk) misc.c: cpp rework of SA_(INTERRUPT|RESTART) handling.
36a358ca 4132 - (stevesk) scp.c: use mysignal() for updateprogressmeter() handler.
68fa858a 4133 - (djm) SA_INTERRUPT is the converse of SA_RESTART, apply it only for
d54d99a3 4134 SIGALRM.
e1a023df 4135 - (djm) Move entropy.c over to mysignal()
68fa858a 4136 - (djm) SunOS 4.x also needs to define HAVE_BOGUS_SYS_QUEUE_H as it has
4137 a <sys/queue.h> that lacks the TAILQ_* macros. Patch from Todd C.
667beaa9 4138 Miller <Todd.Miller@courtesan.com>
ecdde3d8 4139 - (djm) Update RPM spec files for 2.5.0p1
51ee9048 4140 - (djm) Merge BSD_AUTH support from Markus Friedl and David J. MacKenzie
4141 enable with --with-bsd-auth.
2adddc78 4142 - (stevesk) entropy.c: typo; should be SIGPIPE
663fd560 4143
0b1728c5 414420010217
4145 - (bal) OpenBSD Sync:
4146 - markus@cvs.openbsd.org 2001/02/16 13:38:18
68fa858a 4147 [channel.c]
4148 remove debug
c8b058b4 4149 - markus@cvs.openbsd.org 2001/02/16 14:03:43
4150 [session.c]
4151 proper payload-length check for x11 w/o screen-number
0b1728c5 4152
b41d8d4d 415320010216
4154 - (bal) added '--with-prce' to allow overriding of system regex when
4155 required (tested by David Dulek <ddulek@fastenal.com>)
d6fdb079 4156 - (bal) Added DG/UX case and set that they have a broken IPTOS.
278588d8 4157 - (djm) Mini-configure reorder patch from Tim Rice <tim@multitalents.net>
4158 Fixes linking on SCO.
68fa858a 4159 - (djm) Make gnome-ssh-askpass handle multi-line prompts. Patch from
0ceb21d6 4160 Nalin Dahyabhai <nalin@redhat.com>
4161 - (djm) BSD license for gnome-ssh-askpass (was X11)
4162 - (djm) KNF on gnome-ssh-askpass
ed6553e2 4163 - (djm) USE_PIPES for a few more sysv platforms
4164 - (djm) Cleanup configure.in a little
4165 - (djm) Ask users to check config.log when we can't find necessary libs
aca75d94 4166 - (djm) Set "login ID" on systems with setluid. Only enabled for SCO
4167 OpenServer for now. Based on patch from svaughan <svaughan@asterion.com>
0ae4fe1d 4168 - (djm) OpenBSD CVS:
4169 - markus@cvs.openbsd.org 2001/02/15 16:19:59
4170 [channels.c channels.h serverloop.c sshconnect.c sshconnect.h]
4171 [sshconnect1.c sshconnect2.c]
4172 genericize password padding function for SSH1 and SSH2.
4173 add stylized echo to 2, too.
4174 - (djm) Add roundup() macro to defines.h
9535dddf 4175 - (stevesk) set SA_RESTART flag in mysignal() for SIGCHLD;
4176 needed on Unixware 2.x.
b41d8d4d 4177
0086bfaf 417820010215
68fa858a 4179 - (djm) Move PAM session setup back to before setuid to user. Fixes
0086bfaf 4180 problems on Solaris-derived PAMs.
e11aab29 4181 - (djm) Clean up PAM namespace. Suggested by Darren Moffat
4182 <Darren.Moffat@eng.sun.com>
9e3c31f7 4183 - (bal) Sync w/ OpenSSH for new release
4184 - markus@cvs.openbsd.org 2001/02/12 12:45:06
4185 [sshconnect1.c]
4186 fix xmalloc(0), ok dugsong@
b2552997 4187 - markus@cvs.openbsd.org 2001/02/11 12:59:25
4188 [Makefile.in sshd.8 sshconnect2.c readconf.h readconf.c packet.c
4189 sshd.c ssh.c ssh.1 servconf.h servconf.c myproposal.h kex.h kex.c]
4190 1) clean up the MAC support for SSH-2
4191 2) allow you to specify the MAC with 'ssh -m'
4192 3) or the 'MACs' keyword in ssh(d)_config
4193 4) add hmac-{md5,sha1}-96
4194 ok stevesk@, provos@
15853e93 4195 - markus@cvs.openbsd.org 2001/02/12 16:16:23
4196 [auth-passwd.c auth.c auth.h auth1.c auth2.c servconf.c servconf.h
4197 ssh-keygen.c sshd.8]
4198 PermitRootLogin={yes,without-password,forced-commands-only,no}
4199 (before this change, root could login even if PermitRootLogin==no)
7cc4cf0a 4200 - deraadt@cvs.openbsd.org 2001/02/12 22:56:09
fd193ca4 4201 [clientloop.c packet.c ssh-keyscan.c]
4202 deal with EAGAIN/EINTR selects which were skipped
7cc4cf0a 4203 - markus@cvs.openssh.org 2001/02/13 22:49:40
4204 [auth1.c auth2.c]
4205 setproctitle(user) only if getpwnam succeeds
4206 - markus@cvs.openbsd.org 2001/02/12 23:26:20
4207 [sshd.c]
4208 missing memset; from solar@openwall.com
4209 - stevesk@cvs.openbsd.org 2001/02/12 20:53:33
4210 [sftp-int.c]
4211 lumask now works with 1 numeric arg; ok markus@, djm@
4212 - djm@cvs.openbsd.org 2001/02/14 9:46:03
4213 [sftp-client.c sftp-int.c sftp.1]
4214 Fix and document 'preserve modes & times' option ('-p' flag in sftp);
4215 ok markus@
0b16bb01 4216 - (bal) replaced PATH_MAX in sftp-int.c w/ MAXPATHLEN.
4217 - (djm) Move to Jim's 1.2.0 X11 askpass program
62da27dd 4218 - (stevesk) OpenBSD sync:
4219 - deraadt@cvs.openbsd.org 2001/02/15 01:38:04
4220 [serverloop.c]
4221 indent
0b16bb01 4222
1c2d0a13 422320010214
4224 - (djm) Don't try to close PAM session or delete credentials if the
68fa858a 4225 session has not been open or credentials not set. Based on patch from
1c2d0a13 4226 Andrew Bartlett <abartlet@pcug.org.au>
68fa858a 4227 - (djm) Move PAM session initialisation until after fork in sshd. Patch
0ab1bcba 4228 from Nalin Dahyabhai <nalin@redhat.com>
958e5ae4 4229 - (bal) Missing function prototype in bsd-snprintf.c patch by
4230 Mark Miller <markm@swoon.net>
b7ccb051 4231 - (djm) Split out and improve OSF SIA auth code. Patch from Chris Adams
4232 <cmadams@hiwaay.net> with a little modification and KNF.
815800e1 4233 - (stevesk) fix for SIA patch, misplaced session_setup_sia()
1c2d0a13 4234
0610439b 423520010213
84eb157c 4236 - (djm) Only test -S potential EGD sockets if they exist and are readable.
f1312c76 4237 - (bal) Cleaned out bsd-snprintf.c. VARARGS have been banished and
4238 I did a base KNF over the whe whole file to make it more acceptable.
4239 (backed out of original patch and removed it from ChangeLog)
01f13020 4240 - (bal) Use chown() if fchown() does not exist in ftp-server.c patch by
4241 Tim Rice <tim@multitalents.net>
8d60e965 4242 - (stevesk) auth1.c: fix PAM passwordless check.
0610439b 4243
894a4851 424420010212
68fa858a 4245 - (djm) Update Redhat specfile to allow --define "skip_x11_askpass 1",
4246 --define "skip_gnome_askpass 1", --define "rh7 1" and make the
4247 implicit rpm-3.0.5 dependancy explicit. Patch and suggestions from
894a4851 4248 Pekka Savola <pekkas@netcore.fi>
782d6a0d 4249 - (djm) Clean up PCRE text in INSTALL
68fa858a 4250 - (djm) Fix OSF SIA auth NULL pointer deref. Report from Mike Battersby
77db6c3f 4251 <mib@unimelb.edu.au>
6f68f28a 4252 - (bal) NCR SVR4 compatiblity provide by Don Bragg <thewizarddon@yahoo.com>
01a7bc9a 4253 - (stevesk) session.c: remove debugging code.
894a4851 4254
abf1f107 425520010211
4256 - (bal) OpenBSD Sync
4257 - markus@cvs.openbsd.org 2001/02/07 22:35:46
4258 [auth1.c auth2.c sshd.c]
4259 move k_setpag() to a central place; ok dugsong@
c845316f 4260 - markus@cvs.openbsd.org 2001/02/10 12:52:02
4261 [auth2.c]
4262 offer passwd before s/key
e6fa162e 4263 - markus@cvs.openbsd.org 2001/02/8 22:37:10
4264 [canohost.c]
4265 remove last call to sprintf; ok deraadt@
0ab4b0f0 4266 - markus@cvs.openbsd.org 2001/02/10 1:33:32
4267 [canohost.c]
4268 add debug message, since sshd blocks here if DNS is not available
7f8ea238 4269 - markus@cvs.openbsd.org 2001/02/10 12:44:02
4270 [cli.c]
4271 don't call vis() for \r
5c470997 4272 - danh@cvs.openbsd.org 2001/02/10 0:12:43
4273 [scp.c]
4274 revert a small change to allow -r option to work again; ok deraadt@
4275 - danh@cvs.openbsd.org 2001/02/10 15:14:11
4276 [scp.c]
4277 fix memory leak; ok markus@
a0e6fead 4278 - djm@cvs.openbsd.org 2001/02/10 0:45:52
4279 [scp.1]
4280 Mention that you can quote pathnames with spaces in them
b3106440 4281 - markus@cvs.openbsd.org 2001/02/10 1:46:28
4282 [ssh.c]
4283 remove mapping of argv[0] -> hostname
f72e01a5 4284 - markus@cvs.openbsd.org 2001/02/06 22:26:17
4285 [sshconnect2.c]
4286 do not ask for passphrase in batch mode; report from ejb@ql.org
4287 - itojun@cvs.opebsd.org 2001/02/08 10:47:05
5d1d11d1 4288 [sshconnect.c sshconnect1.c sshconnect2.c]
68fa858a 4289 %.30s is too short for IPv6 numeric address. use %.128s for now.
f72e01a5 4290 markus ok
4291 - markus@cvs.openbsd.org 2001/02/09 12:28:35
4292 [sshconnect2.c]
4293 do not free twice, thanks to /etc/malloc.conf
4294 - markus@cvs.openbsd.org 2001/02/09 17:10:53
4295 [sshconnect2.c]
4296 partial success: debug->log; "Permission denied" if no more auth methods
4297 - markus@cvs.openbsd.org 2001/02/10 12:09:21
4298 [sshconnect2.c]
4299 remove some lines
e0b2cf6b 4300 - markus@cvs.openbsd.org 2001/02/09 13:38:07
4301 [auth-options.c]
4302 reset options if no option is given; from han.holl@prismant.nl
ca910e13 4303 - markus@cvs.openbsd.org 2001/02/08 21:58:28
4304 [channels.c]
4305 nuke sprintf, ok deraadt@
4306 - markus@cvs.openbsd.org 2001/02/08 21:58:28
4307 [channels.c]
4308 nuke sprintf, ok deraadt@
affa8be4 4309 - markus@cvs.openbsd.org 2001/02/06 22:43:02
4310 [clientloop.h]
4311 remove confusing callback code
d2c46e77 4312 - deraadt@cvs.openbsd.org 2001/02/08 14:39:36
4313 [readconf.c]
4314 snprintf
cc8aca8a 4315 - itojun@cvs.openbsd.org 2001/02/08 19:30:52
4316 sync with netbsd tree changes.
4317 - more strict prototypes, include necessary headers
4318 - use paths.h/pathnames.h decls
4319 - size_t typecase to int -> u_long
5be2ec5e 4320 - itojun@cvs.openbsd.org 2001/02/07 18:04:50
4321 [ssh-keyscan.c]
4322 fix size_t -> int cast (use u_long). markus ok
4323 - markus@cvs.openbsd.org 2001/02/07 22:43:16
4324 [ssh-keyscan.c]
4325 s/getline/Linebuf_getline/; from roumen.petrov@skalasoft.com
4326 - itojun@cvs.openbsd.org 2001/02/09 9:04:59
4327 [ssh-keyscan.c]
68fa858a 4328 do not assume malloc() returns zero-filled region. found by
5be2ec5e 4329 malloc.conf=AJ.
f21032a6 4330 - markus@cvs.openbsd.org 2001/02/08 22:35:30
4331 [sshconnect.c]
68fa858a 4332 don't connect if batch_mode is true and stricthostkeychecking set to
f21032a6 4333 'ask'
7bbcc167 4334 - djm@cvs.openbsd.org 2001/02/04 21:26:07
4335 [sshd_config]
4336 type: ok markus@
4337 - deraadt@cvs.openbsd.org 2001/02/06 22:07:50
4338 [sshd_config]
4339 enable sftp-server by default
a2e6d17d 4340 - deraadt 2001/02/07 8:57:26
4341 [xmalloc.c]
4342 deal with new ANSI malloc stuff
4343 - markus@cvs.openbsd.org 2001/02/07 16:46:08
4344 [xmalloc.c]
4345 typo in fatal()
4346 - itojun@cvs.openbsd.org 2001/02/07 18:04:50
4347 [xmalloc.c]
4348 fix size_t -> int cast (use u_long). markus ok
4ef922e3 4349 - 1.47 Thu Feb 8 23:11:42 GMT 2001 by dugsong
4350 [serverloop.c sshconnect1.c]
68fa858a 4351 mitigate SSH1 traffic analysis - from Solar Designer
4ef922e3 4352 <solar@openwall.com>, ok provos@
68fa858a 4353 - (bal) fixed sftp-client.c. Return 'status' instead of '0'
ca910e13 4354 (from the OpenBSD tree)
6b442913 4355 - (bal) Synced ssh.1, ssh-add.1 and sshd.8 w/ OpenBSD
27df9d4a 4356 - (bal) sftp-sever.c '%8lld' to '%8llu' (OpenBSD Sync)
17321afe 4357 - (bal) uuencode.c resync w/ OpenBSD tree, plus whitespace.
f98d56f0 4358 - (bal) A bit more whitespace cleanup
68fa858a 4359 - (djm) Set PAM_RHOST earlier, patch from Andrew Bartlett
e275684f 4360 <abartlet@pcug.org.au>
b27e97b1 4361 - (stevesk) misc.c: ssh.h not needed.
38a316c0 4362 - (stevesk) compat.c: more friendly cpp error
94f38e16 4363 - (stevesk) OpenBSD sync:
4364 - stevesk@cvs.openbsd.org 2001/02/11 06:15:57
4365 [LICENSE]
4366 typos and small cleanup; ok deraadt@
abf1f107 4367
0426a3b4 436820010210
4369 - (djm) Sync sftp and scp stuff from OpenBSD:
4370 - djm@cvs.openbsd.org 2001/02/07 03:55:13
4371 [sftp-client.c]
4372 Don't free handles before we are done with them. Based on work from
4373 Corinna Vinschen <vinschen@redhat.com>. ok markus@
4374 - djm@cvs.openbsd.org 2001/02/06 22:32:53
4375 [sftp.1]
4376 Punctuation fix from Pekka Savola <pekkas@netcore.fi>
4377 - deraadt@cvs.openbsd.org 2001/02/07 04:07:29
4378 [sftp.1]
4379 pretty up significantly
4380 - itojun@cvs.openbsd.org 2001/02/07 06:49:42
4381 [sftp.1]
4382 .Bl-.El mismatch. markus ok
4383 - djm@cvs.openbsd.org 2001/02/07 06:12:30
4384 [sftp-int.c]
4385 Check that target is a directory before doing ls; ok markus@
4386 - itojun@cvs.openbsd.org 2001/02/07 11:01:18
4387 [scp.c sftp-client.c sftp-server.c]
4388 unsigned long long -> %llu, not %qu. markus ok
4389 - stevesk@cvs.openbsd.org 2001/02/07 11:10:39
4390 [sftp.1 sftp-int.c]
4391 more man page cleanup and sync of help text with man page; ok markus@
4392 - markus@cvs.openbsd.org 2001/02/07 14:58:34
4393 [sftp-client.c]
4394 older servers reply with SSH2_FXP_NAME + count==0 instead of EOF
4395 - djm@cvs.openbsd.org 2001/02/07 15:27:19
4396 [sftp.c]
4397 Don't forward agent and X11 in sftp. Suggestion from Roumen Petrov
4398 <roumen.petrov@skalasoft.com>
4399 - stevesk@cvs.openbsd.org 2001/02/07 15:36:04
4400 [sftp-int.c]
4401 portable; ok markus@
4402 - stevesk@cvs.openbsd.org 2001/02/07 15:55:47
4403 [sftp-int.c]
4404 lowercase cmds[].c also; ok markus@
4405 - markus@cvs.openbsd.org 2001/02/07 17:04:52
4406 [pathnames.h sftp.c]
4407 allow sftp over ssh protocol 1; ok djm@
4408 - deraadt@cvs.openbsd.org 2001/02/08 07:38:55
4409 [scp.c]
4410 memory leak fix, and snprintf throughout
4411 - deraadt@cvs.openbsd.org 2001/02/08 08:02:02
4412 [sftp-int.c]
4413 plug a memory leak
4414 - stevesk@cvs.openbsd.org 2001/02/08 10:11:23
4415 [session.c sftp-client.c]
4416 %i -> %d
4417 - stevesk@cvs.openbsd.org 2001/02/08 10:57:59
4418 [sftp-int.c]
4419 typo
4420 - stevesk@cvs.openbsd.org 2001/02/08 15:28:07
4421 [sftp-int.c pathnames.h]
4422 _PATH_LS; ok markus@
4423 - djm@cvs.openbsd.org 2001/02/09 04:46:25
4424 [sftp-int.c]
4425 Check for NULL attribs for chown, chmod & chgrp operations, only send
4426 relevant attribs back to server; ok markus@
96b64eb0 4427 - djm@cvs.openbsd.org 2001/02/06 15:05:25
4428 [sftp.c]
4429 Use getopt to process commandline arguments
4430 - djm@cvs.openbsd.org 2001/02/06 15:06:21
4431 [sftp.c ]
4432 Wait for ssh subprocess at exit
4433 - djm@cvs.openbsd.org 2001/02/06 15:18:16
4434 [sftp-int.c]
4435 stat target for remote chdir before doing chdir
4436 - djm@cvs.openbsd.org 2001/02/06 15:32:54
4437 [sftp.1]
4438 Punctuation fix from Pekka Savola <pekkas@netcore.fi>
4439 - provos@cvs.openbsd.org 2001/02/05 22:22:02
4440 [sftp-int.c]
4441 cleanup get_pathname, fix pwd after failed cd. okay djm@
0426a3b4 4442 - (djm) Update makefile.in for _PATH_SFTP_SERVER
c9f5e42e 4443 - (bal) sftp-client.c replace NULL w/ 0 in do_ls() (pending in OpenBSD tree)
0426a3b4 4444
6d1e1d2b 444520010209
68fa858a 4446 - (bal) patch to vis.c to deal with HAVE_VIS right by Robert Mooney
6d1e1d2b 4447 <rjmooney@mediaone.net>
bb0c1991 4448 - (bal) .c.o rule in openbsd-compat/Makefile.in did not make it to the
68fa858a 4449 main tree while porting forward. Pointed out by Lutz Jaenicke
bb0c1991 4450 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
f902d909 4451 - (bal) double entry in configure.in. Pointed out by Lutz Jaenicke
4452 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
25f4c264 4453 - (stevesk) OpenBSD sync:
4454 - markus@cvs.openbsd.org 2001/02/08 11:20:01
4455 [auth2.c]
4456 strict checking
4457 - markus@cvs.openbsd.org 2001/02/08 11:15:22
4458 [version.h]
4459 update to 2.3.2
4460 - markus@cvs.openbsd.org 2001/02/08 11:12:30
4461 [auth2.c]
4462 fix typo
72b3f75d 4463 - (djm) Update spec files
0ed28836 4464 - (bal) OpenBSD sync:
4465 - deraadt@cvs.openbsd.org 2001/02/08 14:38:54
4466 [scp.c]
4467 memory leak fix, and snprintf throughout
1fc8ccdf 4468 - markus@cvs.openbsd.org 2001/02/06 22:43:02
4469 [clientloop.c]
4470 remove confusing callback code
0b202697 4471 - (djm) Add CVS Id's to files that we have missed
5ca51e19 4472 - (bal) OpenBSD Sync (more):
4473 - itojun@cvs.openbsd.org 2001/02/08 19:30:52
4474 sync with netbsd tree changes.
4475 - more strict prototypes, include necessary headers
4476 - use paths.h/pathnames.h decls
4477 - size_t typecase to int -> u_long
1f3bf5aa 4478 - markus@cvs.openbsd.org 2001/02/06 22:07:42
4479 [ssh.c]
4480 fatal() if subsystem fails
4481 - markus@cvs.openbsd.org 2001/02/06 22:43:02
4482 [ssh.c]
4483 remove confusing callback code
4484 - jakob@cvs.openbsd.org 2001/02/06 23:03:24
4485 [ssh.c]
4486 add -1 option (force protocol version 1). ok markus@
4487 - jakob@cvs.openbsd.org 2001/02/06 23:06:21
4488 [ssh.c]
4489 reorder -{1,2,4,6} options. ok markus@
e6aa01b4 4490 - (bal) Missing 'const' in readpass.h
9c5a8165 4491 - (bal) OpenBSD Sync (so at least the thing compiles for 2.3.2 =)
4492 - djm@cvs.openbsd.org 2001/02/06 23:30:28
4493 [sftp-client.c]
4494 replace arc4random with counter for request ids; ok markus@
68fa858a 4495 - (djm) Define _PATH_TTY for systems that don't. Report from Lutz
bc79ed5c 4496 Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
6d1e1d2b 4497
6a25c04c 449820010208
4499 - (djm) Don't delete external askpass program in make uninstall target.
4500 Report and fix from Roumen Petrov <roumen.petrov@skalasoft.com>
6958bd37 4501 - (djm) Fix linking of sftp, don't need arc4random any more.
4502 - (djm) Try to use shell that supports "test -S" for EGD socket search.
4503 Based on patch from Tim Rice <tim@multitalents.net>
6a25c04c 4504
547519f0 450520010207
bee0a37e 4506 - (bal) Save the whole path to AR in configure. Some Solaris 2.7 installs
4507 seem lose track of it while in openbsd-compat/ (two confirmed reports)
5c377b3b 4508 - (djm) Much KNF on PAM code
547519f0 4509 - (djm) Revise auth-pam.c conversation function to be a little more
4510 readable.
5c377b3b 4511 - (djm) Revise kbd-int PAM conversation function to fold all text messages
4512 to before first prompt. Fixes hangs if last pam_message did not require
4513 a reply.
4514 - (djm) Fix password changing when using PAM kbd-int authentication
bee0a37e 4515
547519f0 451620010205
2b87da3b 4517 - (bal) Disable groupaccess by setting NGROUPS_MAX to 0 for platforms
99286dc8 4518 that don't have NGROUPS_MAX.
57559587 4519 - (bal) AIX patch for auth1.c by William L. Jones <jones@hpc.utexas.edu>
2b87da3b 4520 - (stevesk) OpenBSD sync:
4521 - stevesk@cvs.openbsd.org 2001/02/04 08:32:27
4522 [many files; did this manually to our top-level source dir]
4523 unexpand and remove end-of-line whitespace; ok markus@
408ba72f 4524 - stevesk@cvs.openbsd.org 2001/02/04 15:21:19
4525 [sftp-server.c]
4526 SSH2_FILEXFER_ATTR_UIDGID support; ok markus@
ec2a033a 4527 - deraadt@cvs.openbsd.org 2001/02/04 17:02:32
4528 [sftp-int.c]
4529 ? == help
4530 - deraadt@cvs.openbsd.org 2001/02/04 16:47:46
4531 [sftp-int.c]
4532 sort commands, so that abbreviations work as expected
4533 - stevesk@cvs.openbsd.org 2001/02/04 15:17:52
4534 [sftp-int.c]
4535 debugging sftp: precedence and missing break. chmod, chown, chgrp
4536 seem to be working now.
4537 - markus@cvs.openbsd.org 2001/02/04 14:41:21
4538 [sftp-int.c]
4539 use base 8 for umask/chmod
4540 - markus@cvs.openbsd.org 2001/02/04 11:11:54
4541 [sftp-int.c]
4542 fix LCD
c44559d2 4543 - markus@cvs.openbsd.org 2001/02/04 08:10:44
4544 [ssh.1]
4545 typo; dpo@club-internet.fr
a5930351 4546 - stevesk@cvs.openbsd.org 2001/02/04 06:30:12
4547 [auth2.c authfd.c packet.c]
4548 remove duplicate #include's; ok markus@
6a416424 4549 - deraadt@cvs.openbsd.org 2001/02/04 16:56:23
4550 [scp.c sshd.c]
4551 alpha happiness
4552 - stevesk@cvs.openbsd.org 2001/02/04 15:12:17
4553 [sshd.c]
4554 precedence; ok markus@
02a024dd 4555 - deraadt@cvs.openbsd.org 2001/02/04 08:14:15
6a416424 4556 [ssh.c sshd.c]
4557 make the alpha happy
02a024dd 4558 - markus@cvs.openbsd.org 2001/01/31 13:37:24
4559 [channels.c channels.h serverloop.c ssh.c]
68fa858a 4560 do not disconnect if local port forwarding fails, e.g. if port is
547519f0 4561 already in use
02a024dd 4562 - markus@cvs.openbsd.org 2001/02/01 14:58:09
4563 [channels.c]
4564 use ipaddr in channel messages, ietf-secsh wants this
4565 - markus@cvs.openbsd.org 2001/01/31 12:26:20
4566 [channels.c]
68fa858a 4567 ssh.com-2.0.1x does not send additional info in CHANNEL_OPEN_FAILURE
547519f0 4568 messages; bug report from edmundo@rano.org
a741554f 4569 - markus@cvs.openbsd.org 2001/01/31 13:48:09
4570 [sshconnect2.c]
4571 unused
9378f292 4572 - deraadt@cvs.openbsd.org 2001/02/04 08:23:08
4573 [sftp-client.c sftp-server.c]
4574 make gcc on the alpha even happier
1fc243d1 4575
547519f0 457620010204
781a0585 4577 - (bal) I think this is the last of the bsd-*.h that don't belong.
634e0b53 4578 - (bal) Minor Makefile fix
f0f14bea 4579 - (bal) openbsd-compat/Makefile minor fix. Ensure dependancies are done
61e96248 4580 right.
78987b57 4581 - (bal) Changed order of LIB="" in -with-skey due to library resolving.
166e4f2a 4582 - (bal) next-posix.h changed to bsd-nextstep.h
61e96248 4583 - (djm) OpenBSD CVS sync:
4584 - markus@cvs.openbsd.org 2001/02/03 03:08:38
4585 [auth-options.c auth-rh-rsa.c auth-rhosts.c auth.c canohost.c]
4586 [canohost.h servconf.c servconf.h session.c sshconnect1.c sshd.8]
4587 [sshd_config]
4588 make ReverseMappingCheck optional in sshd_config; ok djm@,dugsong@
4589 - markus@cvs.openbsd.org 2001/02/03 03:19:51
4590 [ssh.1 sshd.8 sshd_config]
4591 Skey is now called ChallengeResponse
4592 - markus@cvs.openbsd.org 2001/02/03 03:43:09
4593 [sshd.8]
4594 use no-pty option in .ssh/authorized_keys* if you need a 8-bit clean
4595 channel. note from Erik.Anggard@cygate.se (pr/1659)
4596 - stevesk@cvs.openbsd.org 2001/02/03 10:03:06
4597 [ssh.1]
4598 typos; ok markus@
4599 - djm@cvs.openbsd.org 2001/02/04 04:11:56
4600 [scp.1 sftp-server.c ssh.1 sshd.8 sftp-client.c sftp-client.h]
4601 [sftp-common.c sftp-common.h sftp-int.c sftp-int.h sftp.1 sftp.c]
4602 Basic interactive sftp client; ok theo@
4603 - (djm) Update RPM specs for new sftp binary
68fa858a 4604 - (djm) Update several bits for new optional reverse lookup stuff. I
61e96248 4605 think I got them all.
8b061486 4606 - (djm) Makefile.in fixes
1aa00dcb 4607 - (stevesk) add mysignal() wrapper and use it for the protocol 2
4608 SIGCHLD handler.
408ba72f 4609 - (djm) Use setvbuf() instead of setlinebuf(). Suggest from stevesk@
781a0585 4610
547519f0 461120010203
63fe0529 4612 - (bal) Cygwin clean up by Corinna Vinschen <vinschen@redhat.com>
bf3db92d 4613 - (bal) renamed queue.h to fake-queue.h (even if it's an OpenBSD
4614 based file) to ensure #include space does not get confused.
f78888c7 4615 - (bal) Minor Makefile.in tweak. dirname may not exist on some
4616 platforms so builds fail. (NeXT being a well known one)
63fe0529 4617
547519f0 461820010202
61e96248 4619 - (bal) Makefile fix where sourcedir != builddir by Corinna Vinschen
c85a87f2 4620 <vinschen@redhat.com>
71301416 4621 - (bal) Makefile fix to use $(MAKE) instead of 'make' for platforms
4622 that use 'gmake'. Patch by Tim Rice <tim@multitalents.net>
c85a87f2 4623
547519f0 462420010201
ad5075bd 4625 - (bal) Minor fix to Makefile to stop rebuilding executables if no
4626 changes have occured to any of the supporting code. Patch by
4627 Roumen Petrov <roumen.petrov@skalasoft.com>
4628
9c8dbb1b 462920010131
37845585 4630 - (djm) OpenBSD CVS Sync:
4631 - djm@cvs.openbsd.org 2001/01/30 15:48:53
4632 [sshconnect.c]
4633 Make warning message a little more consistent. ok markus@
8c89dd2b 4634 - (djm) Fix autoconf logic for --with-lastlog=no Report and diagnosis from
4635 Philipp Buehler <lists@fips.de> and Kevin Steves <stevesk@sweden.hp.com>
4636 respectively.
c59dc6bd 4637 - (djm) Don't log SSH2 PAM KbdInt responses to debug, they may contain
4638 passwords.
9c8dbb1b 4639 - (bal) Reorder. Move all bsd-*, fake-*, next-*, and cygwin* stuff to
4640 openbsd-compat/. And resolve all ./configure and Makefile.in issues
4641 assocated.
37845585 4642
9c8dbb1b 464320010130
39929cdb 4644 - (djm) OpenBSD CVS Sync:
4645 - markus@cvs.openbsd.org 2001/01/29 09:55:37
4646 [channels.c channels.h clientloop.c serverloop.c]
4647 fix select overflow; ok deraadt@ and stevesk@
865ac82e 4648 - markus@cvs.openbsd.org 2001/01/29 12:42:35
4649 [canohost.c canohost.h channels.c clientloop.c]
4650 add get_peer_ipaddr(socket), x11-fwd in ssh2 requires ipaddr, not DNS
46aa2d1f 4651 - markus@cvs.openbsd.org 2001/01/29 12:47:32
4652 [rsa.c rsa.h ssh-agent.c sshconnect1.c sshd.c]
4653 handle rsa_private_decrypt failures; helps against the Bleichenbacher
4654 pkcs#1 attack
ae810de7 4655 - djm@cvs.openbsd.org 2001/01/29 05:36:11
4656 [ssh.1 ssh.c]
4657 Allow invocation of sybsystem by commandline (-s); ok markus@
83bc57f9 4658 - (stevesk) configure.in: remove duplicate PROG_LS
39929cdb 4659
9c8dbb1b 466020010129
f29ef605 4661 - (stevesk) sftp-server.c: use %lld vs. %qd
4662
cb9da0fc 466320010128
4664 - (bal) Put USE_PIPES back into sco3.2v5
23c2a7a5 4665 - (bal) OpenBSD Sync
9bd5b720 4666 - markus@cvs.openbsd.org 2001/01/28 10:15:34
4667 [dispatch.c]
4668 re-keying is not supported; ok deraadt@
5fb622e4 4669 - markus@cvs.openbsd.org 2001/01/28 10:24:04
7f5c4295 4670 [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
5fb622e4 4671 cleanup AUTHORS sections
9bd5b720 4672 - markus@cvs.openbsd.org 2001/01/28 10:37:26
ab60252b 4673 [sshd.c sshd.8]
9bd5b720 4674 remove -Q, no longer needed
4675 - stevesk@cvs.openbsd.org 2001/01/28 20:36:16
a877488a 4676 [readconf.c ssh.1]
9bd5b720 4677 ``StrictHostKeyChecking ask'' documentation and small cleanup.
4678 ok markus@
6f37606e 4679 - stevesk@cvs.openbsd.org 2001/01/28 20:43:25
61e96248 4680 [sshd.8]
6f37606e 4681 spelling. ok markus@
95f4ccfb 4682 - stevesk@cvs.openbsd.org 2001/01/28 20:53:21
4683 [xmalloc.c]
4684 use size_t for strlen() return. ok markus@
6f37606e 4685 - stevesk@cvs.openbsd.org 2001/01/28 22:27:05
4686 [authfile.c]
4687 spelling. use sizeof vs. strlen(). ok markus@
9bd5b720 4688 - niklas@cvs.openbsd.org 2001/01/29 1:59:14
23c2a7a5 4689 [atomicio.h canohost.h clientloop.h deattack.h dh.h dispatch.h
4690 groupaccess.c groupaccess.h hmac.h hostfile.h includes.h kex.h
4691 key.h log.h login.h match.h misc.h myproposal.h nchan.ms pathnames.h
4692 radix.h readpass.h rijndael.h serverloop.h session.h sftp.h ssh-add.1
4693 ssh-dss.h ssh-keygen.1 ssh-keyscan.1 ssh-rsa.h ssh1.h ssh_config
4694 sshconnect.h sshd_config tildexpand.h uidswap.h uuencode.h]
4695 $OpenBSD$
b0e305c9 4696 - (bal) Minor auth2.c resync. Whitespace and moving of an #include.
cb9da0fc 4697
c9606e03 469820010126
61e96248 4699 - (bal) SSH_PROGRAM vs _PATH_SSH_PROGRAM fix pointed out by Roumen
c9606e03 4700 Petrov <roumen.petrov@skalasoft.com>
2f4b2e38 4701 - (bal) OpenBSD Sync
4702 - deraadt@cvs.openbsd.org 2001/01/25 8:06:33
4703 [ssh-agent.c]
4704 call _exit() in signal handler
c9606e03 4705
d7d5f0b2 470620010125
4707 - (djm) Sync bsd-* support files:
4708 - deraadt@cvs.openbsd.org 2000/01/26 03:43:20
4709 [rresvport.c bindresvport.c]
61e96248 4710 new bindresvport() semantics that itojun, shin, jean-luc and i have
d7d5f0b2 4711 agreed on, which will be happy for the future. bindresvport_sa() for
4712 sockaddr *, too. docs later..
4713 - deraadt@cvs.openbsd.org 2000/01/24 02:24:21
4714 [bindresvport.c]
61e96248 4715 in bindresvport(), if sin is non-NULL, example sin->sin_family for
d7d5f0b2 4716 the actual family being processed
e1dd3a7a 4717 - (djm) Mention PRNGd in documentation, it is nicer than EGD
4718 - (djm) Automatically search for "well-known" EGD/PRNGd sockets in autoconf
8080699b 4719 - (bal) AC_FUNC_STRFTIME added to autoconf
4ccb01d6 4720 - (bal) OpenBSD Resync
4721 - stevesk@cvs.openbsd.org 2001/01/24 21:03:50
4722 [channels.c]
4723 missing freeaddrinfo(); ok markus@
d7d5f0b2 4724
556eb464 472520010124
4726 - (bal) OpenBSD Resync
4727 - markus@cvs.openbsd.org 2001/01/23 10:45:10
4728 [ssh.h]
61e96248 4729 nuke comment
1aecda34 4730 - (bal) no 64bit support patch from Tim Rice <tim@multitalents.net>
4731 - (bal) #ifdef around S_IFSOCK if platform does not support it.
4732 patch by Tim Rice <tim@multitalents.net>
4733 - (bal) fake-regex.h cleanup based on Tim Rice's patch.
c33f0b36 4734 - (stevesk) sftp-server.c: fix chmod() mode mask
556eb464 4735
effa6591 473620010123
4737 - (bal) regexp.h typo in configure.in. Should have been regex.h
4738 - (bal) SSH_USER_DIR to _PATH_SSH_USER_DIR patch by stevesk@
61e96248 4739 - (bal) SSH_ASKPASS_DEFAULT to _PATH_SSH_ASKPASS_DEFAULT
53a24016 4740 - (bal) OpenBSD Resync
4741 - markus@cvs.openbsd.org 2001/01/22 8:15:00
4742 [auth-krb4.c sshconnect1.c]
4743 only AFS needs radix.[ch]
4744 - markus@cvs.openbsd.org 2001/01/22 8:32:53
4745 [auth2.c]
4746 no need to include; from mouring@etoh.eviladmin.org
4747 - stevesk@cvs.openbsd.org 2001/01/22 16:55:21
4748 [key.c]
4749 free() -> xfree(); ok markus@
4750 - stevesk@cvs.openbsd.org 2001/01/22 17:22:28
4751 [sshconnect2.c sshd.c]
4752 fix memory leaks in SSH2 key exchange; ok markus@
d464095c 4753 - markus@cvs.openbsd.org 2001/01/22 23:06:39
4754 [auth1.c auth2.c readconf.c readconf.h servconf.c servconf.h
4755 sshconnect1.c sshconnect2.c sshd.c]
4756 rename skey -> challenge response.
4757 auto-enable kbd-interactive for ssh2 if challenge-reponse is enabled.
53a24016 4758
effa6591 4759
42f11eb2 476020010122
4761 - (bal) OpenBSD Resync
4762 - markus@cvs.openbsd.org 2001/01/19 12:45:26 GMT 2001 by markus
4763 [servconf.c ssh.h sshd.c]
4764 only auth-chall.c needs #ifdef SKEY
4765 - markus@cvs.openbsd.org 2001/01/19 15:55:10 GMT 2001 by markus
4766 [auth-krb4.c auth-options.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c
4767 auth1.c auth2.c channels.c clientloop.c dh.c dispatch.c nchan.c
4768 packet.c pathname.h readconf.c scp.c servconf.c serverloop.c
4769 session.c ssh-add.c ssh-keygen.c ssh-keyscan.c ssh.c ssh.h
4770 ssh1.h sshconnect1.c sshd.c ttymodes.c]
4771 move ssh1 definitions to ssh1.h, pathnames to pathnames.h
4772 - markus@cvs.openbsd.org 2001/01/19 16:48:14
4773 [sshd.8]
4774 fix typo; from stevesk@
4775 - markus@cvs.openbsd.org 2001/01/19 16:50:58
4776 [ssh-dss.c]
61e96248 4777 clear and free digest, make consistent with other code (use dlen); from
42f11eb2 4778 stevesk@
4779 - markus@cvs.openbsd.org 2001/01/20 15:55:20 GMT 2001 by markus
4780 [auth-options.c auth-options.h auth-rsa.c auth2.c]
4781 pass the filename to auth_parse_options()
61e96248 4782 - markus@cvs.openbsd.org 2001/01/20 17:59:40 GMT 2001
42f11eb2 4783 [readconf.c]
4784 fix SIGSEGV from -o ""; problem noted by jehsom@togetherweb.com
4785 - stevesk@cvs.openbsd.org 2001/01/20 18:20:29
4786 [sshconnect2.c]
4787 dh_new_group() does not return NULL. ok markus@
4788 - markus@cvs.openbsd.org 2001/01/20 21:33:42
4789 [ssh-add.c]
61e96248 4790 do not loop forever if askpass does not exist; from
42f11eb2 4791 andrew@pimlott.ne.mediaone.net
4792 - djm@cvs.openbsd.org 2001/01/20 23:00:56
4793 [servconf.c]
4794 Check for NULL return from strdelim; ok markus
4795 - djm@cvs.openbsd.org 2001/01/20 23:02:07
4796 [readconf.c]
4797 KNF; ok markus
4798 - jakob@cvs.openbsd.org 2001/01/21 9:00:33
4799 [ssh-keygen.1]
4800 remove -R flag; ok markus@
4801 - markus@cvs.openbsd.org 2001/01/21 19:05:40
4802 [atomicio.c automicio.h auth-chall.c auth-krb4.c auth-options.c
4803 auth-options.h auth-passwd.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c
4804 auth.c auth.h auth1.c auth2-chall.c auth2.c authfd.c authfile.c
4805 bufaux.c bufaux.h buffer.c canahost.c canahost.h channels.c
4806 cipher.c cli.c clientloop.c clientloop.h compat.c compress.c
4807 deattack.c dh.c dispatch.c groupaccess.c hmac.c hostfile.c kex.c
4808 key.c key.h log-client.c log-server.c log.c log.h login.c login.h
4809 match.c misc.c misc.h nchan.c packet.c pty.c radix.h readconf.c
4810 readpass.c readpass.h rsa.c scp.c servconf.c serverloop.c serverloop.h
4811 session.c sftp-server.c ssh-add.c ssh-agent.c ssh-dss.c ssh-keygen.c
61e96248 4812 ssh-keyscan.c ssh-rsa.c ssh.c ssh.h sshconnect.c sshconnect.h
42f11eb2 4813 sshconnect1.c sshconnect2.c sshd.c tildexpand.c tildexpand.h
4814 ttysmodes.c uidswap.c xmalloc.c]
61e96248 4815 split ssh.h and try to cleanup the #include mess. remove unnecessary
42f11eb2 4816 #includes. rename util.[ch] -> misc.[ch]
4817 - (bal) renamed 'PIDDIR' to '_PATH_SSH_PIDDIR' to match OpenBSD tree
61e96248 4818 - (bal) Moved #ifdef KRB4 in auth-krb4.c above the #include to resolve
42f11eb2 4819 conflict when compiling for non-kerb install
4820 - (bal) removed the #ifdef SKEY in auth1.c to match Markus' changes
4821 on 1/19.
4822
6005a40c 482320010120
4824 - (bal) OpenBSD Resync
4825 - markus@cvs.openbsd.org 2001/01/19 12:45:26
4826 [ssh-chall.c servconf.c servconf.h ssh.h sshd.c]
4827 only auth-chall.c needs #ifdef SKEY
47af6577 4828 - (bal) Slight auth2-pam.c clean up.
4829 - (bal) Includes a fake-regexp.h to be only used if regcomp() is found,
4830 but no 'regexp.h' found (SCO OpenServer 3 lacks the header).
6005a40c 4831
922e6493 483220010119
4833 - (djm) Update versions in RPM specfiles
59c97189 4834 - (bal) OpenBSD Resync
4835 - markus@cvs.openbsd.org 2001/01/18 16:20:21
4836 [log-client.c log-server.c log.c readconf.c servconf.c ssh.1 ssh.h
4837 sshd.8 sshd.c]
61e96248 4838 log() is at pri=LOG_INFO, since LOG_NOTICE goes to /dev/console on many
59c97189 4839 systems
4840 - markus@cvs.openbsd.org 2001/01/18 16:59:59
4841 [auth-passwd.c auth.c auth.h auth1.c auth2.c serverloop.c session.c
4842 session.h sshconnect1.c]
4843 1) removes fake skey from sshd, since this will be much
4844 harder with /usr/libexec/auth/login_XXX
4845 2) share/unify code used in ssh-1 and ssh-2 authentication (server side)
4846 3) make addition of BSD_AUTH and other challenge reponse methods
4847 easier.
4848 - markus@cvs.openbsd.org 2001/01/18 17:12:43
4849 [auth-chall.c auth2-chall.c]
4850 rename *-skey.c *-chall.c since the files are not skey specific
04fc7a67 4851 - (djm) Merge patch from Tim Waugh (via Nalin Dahyabhai <nalin@redhat.com>)
4852 to fix NULL pointer deref and fake authloop breakage in PAM code.
f4ebf0e8 4853 - (bal) Updated contrib/cygwin/ by Corinna Vinschen <vinschen@redhat.com>
3c418020 4854 - (bal) Minor cygwin patch to auth1.c. Suggested by djm.
61e96248 4855
b5c334cc 485620010118
4857 - (bal) Super Sized OpenBSD Resync
4858 - markus@cvs.openbsd.org 2001/01/11 22:14:20 GMT 2001 by markus
4859 [sshd.c]
4860 maxfd+1
4861 - markus@cvs.openbsd.org 2001/01/13 17:59:18
4862 [ssh-keygen.1]
4863 small ssh-keygen manpage cleanup; stevesk@pobox.com
4864 - markus@cvs.openbsd.org 2001/01/13 18:03:07
4865 [scp.c ssh-keygen.c sshd.c]
4866 getopt() returns -1 not EOF; stevesk@pobox.com
4867 - markus@cvs.openbsd.org 2001/01/13 18:06:54
4868 [ssh-keyscan.c]
4869 use SSH_DEFAULT_PORT; from stevesk@pobox.com
4870 - markus@cvs.openbsd.org 2001/01/13 18:12:47
4871 [ssh-keyscan.c]
4872 free() -> xfree(); fix memory leak; from stevesk@pobox.com
4873 - markus@cvs.openbsd.org 2001/01/13 18:14:13
4874 [ssh-add.c]
4875 typo, from stevesk@sweden.hp.com
4876 - markus@cvs.openbsd.org 2001/01/13 18:32:50
61e96248 4877 [packet.c session.c ssh.c sshconnect.c sshd.c]
b5c334cc 4878 split out keepalive from packet_interactive (from dale@accentre.com)
4879 set IPTOS_LOWDELAY TCP_NODELAY IPTOS_THROUGHPUT for ssh2, too.
4880 - markus@cvs.openbsd.org 2001/01/13 18:36:45
4881 [packet.c packet.h]
4882 reorder, typo
4883 - markus@cvs.openbsd.org 2001/01/13 18:38:00
4884 [auth-options.c]
4885 fix comment
4886 - markus@cvs.openbsd.org 2001/01/13 18:43:31
4887 [session.c]
4888 Wall
61e96248 4889 - markus@cvs.openbsd.org 2001/01/13 19:14:08
b5c334cc 4890 [clientloop.h clientloop.c ssh.c]
4891 move callback to headerfile
4892 - markus@cvs.openbsd.org 2001/01/15 21:40:10
4893 [ssh.c]
4894 use log() instead of stderr
4895 - markus@cvs.openbsd.org 2001/01/15 21:43:51
4896 [dh.c]
4897 use error() not stderr!
4898 - markus@cvs.openbsd.org 2001/01/15 21:45:29
4899 [sftp-server.c]
4900 rename must fail if newpath exists, debug off by default
4901 - markus@cvs.openbsd.org 2001/01/15 21:46:38
4902 [sftp-server.c]
4903 readable long listing for sftp-server, ok deraadt@
4904 - markus@cvs.openbsd.org 2001/01/16 19:20:06
4905 [key.c ssh-rsa.c]
61e96248 4906 make "ssh-rsa" key format for ssh2 confirm to the ietf-drafts; from
4907 galb@vandyke.com. note that you have to delete older ssh2-rsa keys,
4908 since they are in the wrong format, too. they must be removed from
b5c334cc 4909 .ssh/authorized_keys2 and .ssh/known_hosts2, etc.
61e96248 4910 (cd; grep -v ssh-rsa .ssh/authorized_keys2 > TMP && mv TMP
4911 .ssh/authorized_keys2) additionally, we now check that
b5c334cc 4912 BN_num_bits(rsa->n) >= 768.
4913 - markus@cvs.openbsd.org 2001/01/16 20:54:27
4914 [sftp-server.c]
4915 remove some statics. simpler handles; idea from nisse@lysator.liu.se
4916 - deraadt@cvs.openbsd.org 2001/01/16 23:58:08
4917 [bufaux.c radix.c sshconnect.h sshconnect1.c]
4918 indent
4919 - (bal) Added bsd-strmode.[ch] since some non-OpenBSD platforms may
4920 be missing such feature.
4921
61e96248 4922
52ce34a2 492320010117
4924 - (djm) Only write random seed file at exit
717057b6 4925 - (djm) Make PAM support optional, enable with --with-pam
61e96248 4926 - (djm) Try to use libcrypt on Linux, but link it after OpenSSL (which
717057b6 4927 provides a crypt() of its own)
4928 - (djm) Avoid a warning in bsd-bindresvport.c
4929 - (djm) Try to avoid adding -I/usr/include to CPPFLAGS during SSL tests. This
61e96248 4930 can cause weird segfaults errors on Solaris
8694a1ce 4931 - (djm) Avoid warning in PAM code by making read_passphrase arguments const
d748039d 4932 - (djm) Add --with-pam to RPM spec files
52ce34a2 4933
2fd3c144 493420010115
4935 - (bal) sftp-server.c change to use chmod() if fchmod() does not exist.
89c7e31c 4936 - (bal) utimes() support via utime() interface on machine that lack utimes().
2fd3c144 4937
63b68889 493820010114
4939 - (stevesk) initial work for OpenBSD "support supplementary group in
4940 {Allow,Deny}Groups" patch:
4941 - import getgrouplist.c from OpenBSD (bsd-getgrouplist.c)
4942 - add bsd-getgrouplist.h
4943 - new files groupaccess.[ch]
4944 - build but don't use yet (need to merge auth.c changes)
c6a69271 4945 - (stevesk) complete:
4946 - markus@cvs.openbsd.org 2001/01/13 11:56:48
4947 [auth.c sshd.8]
4948 support supplementary group in {Allow,Deny}Groups
4949 from stevesk@pobox.com
61e96248 4950
f546c780 495120010112
4952 - (bal) OpenBSD Sync
4953 - markus@cvs.openbsd.org 2001/01/10 22:56:22
4954 [bufaux.h bufaux.c sftp-server.c sftp.h getput.h]
4955 cleanup sftp-server implementation:
547519f0 4956 add buffer_get_int64, buffer_put_int64, GET_64BIT, PUT_64BIT
4957 parse SSH2_FILEXFER_ATTR_EXTENDED
4958 send SSH2_FX_EOF if readdir returns no more entries
4959 reply to SSH2_FXP_EXTENDED message
4960 use #defines from the draft
4961 move #definations to sftp.h
f546c780 4962 more info:
61e96248 4963 http://www.ietf.org/internet-drafts/draft-ietf-secsh-filexfer-00.txt
f546c780 4964 - markus@cvs.openbsd.org 2001/01/10 19:43:20
4965 [sshd.c]
4966 XXX - generate_empheral_server_key() is not safe against races,
61e96248 4967 because it calls log()
f546c780 4968 - markus@cvs.openbsd.org 2001/01/09 21:19:50
4969 [packet.c]
4970 allow TCP_NDELAY for ipv6; from netbsd via itojun@
4971
9548d6c8 497220010110
4973 - (djm) SNI/Reliant Unix needs USE_PIPES and $DISPLAY hack. Report from
4974 Bladt Norbert <Norbert.Bladt@adi.ch>
4975
af972861 497620010109
4977 - (bal) Resync CVS ID of cli.c
4b80e97b 4978 - (stevesk) auth1.c: free should be after WITH_AIXAUTHENTICATE
4979 code.
eea39c02 4980 - (bal) OpenBSD Sync
4981 - markus@cvs.openbsd.org 2001/01/08 22:29:05
4982 [auth2.c compat.c compat.h servconf.c servconf.h sshd.8
4983 sshd_config version.h]
4984 implement option 'Banner /etc/issue.net' for ssh2, move version to
4985 2.3.1 (needed for bugcompat detection, 2.3.0 would fail if Banner
4986 is enabled).
4987 - markus@cvs.openbsd.org 2001/01/08 22:03:23
4988 [channels.c ssh-keyscan.c]
4989 O_NDELAY -> O_NONBLOCK; thanks stevesk@pobox.com
4990 - markus@cvs.openbsd.org 2001/01/08 21:55:41
4991 [sshconnect1.c]
4992 more cleanups and fixes from stevesk@pobox.com:
4993 1) try_agent_authentication() for loop will overwrite key just
4994 allocated with key_new(); don't alloc
4995 2) call ssh_close_authentication_connection() before exit
4996 try_agent_authentication()
4997 3) free mem on bad passphrase in try_rsa_authentication()
4998 - markus@cvs.openbsd.org 2001/01/08 21:48:17
4999 [kex.c]
5000 missing free; thanks stevesk@pobox.com
f1c4659d 5001 - (bal) Detect if clock_t structure exists, if not define it.
5002 - (bal) Detect if O_NONBLOCK exists, if not define it.
5003 - (bal) removed news4-posix.h (now empty)
5004 - (bal) changed bsd-bindresvport.c and bsd-rresvport.c to use 'socklen_t'
5005 instead of 'int'
adc83ebf 5006 - (stevesk) sshd_config: sync
4f771a33 5007 - (stevesk) defines.h: remove spurious ``;''
af972861 5008
bbcf899f 500920010108
5010 - (bal) Fixed another typo in cli.c
5011 - (bal) OpenBSD Sync
5012 - markus@cvs.openbsd.org 2001/01/07 21:26:55
5013 [cli.c]
5014 typo
5015 - markus@cvs.openbsd.org 2001/01/07 21:26:55
5016 [cli.c]
5017 missing free, stevesk@pobox.com
5018 - markus@cvs.openbsd.org 2001/01/07 19:06:25
5019 [auth1.c]
5020 missing free, stevesk@pobox.com
5021 - markus@cvs.openbsd.org 2001/01/07 11:28:04
5022 [log-client.c log-server.c log.c readconf.c servconf.c ssh.1
5023 ssh.h sshd.8 sshd.c]
5024 rename SYSLOG_LEVEL_INFO->SYSLOG_LEVEL_NOTICE
5025 syslog priority changes:
5026 fatal() LOG_ERR -> LOG_CRIT
5027 log() LOG_INFO -> LOG_NOTICE
b8c37305 5028 - Updated TODO
bbcf899f 5029
9616313f 503020010107
5031 - (bal) OpenBSD Sync
5032 - markus@cvs.openbsd.org 2001/01/06 11:23:27
5033 [ssh-rsa.c]
5034 remove unused
5035 - itojun@cvs.openbsd.org 2001/01/05 08:23:29
5036 [ssh-keyscan.1]
5037 missing .El
5038 - markus@cvs.openbsd.org 2001/01/04 22:41:03
5039 [session.c sshconnect.c]
5040 consistent use of _PATH_BSHELL; from stevesk@pobox.com
5041 - djm@cvs.openbsd.org 2001/01/04 22:35:32
5042 [ssh.1 sshd.8]
5043 Mention AES as available SSH2 Cipher; ok markus
5044 - markus@cvs.openbsd.org 2001/01/04 22:25:58
5045 [sshd.c]
5046 sync usage()/man with defaults; from stevesk@pobox.com
5047 - markus@cvs.openbsd.org 2001/01/04 22:21:26
5048 [sshconnect2.c]
5049 handle SSH2_MSG_USERAUTH_BANNER; fixes bug when connecting to a server
5050 that prints a banner (e.g. /etc/issue.net)
61e96248 5051
1877dc0c 505220010105
5053 - (bal) contrib/caldera/ provided by Tim Rice <tim@multitalents.net>
5a64a938 5054 - (bal) bsd-getcwd.c and bsd-setenv.c changed from bcopy() to memmove()
1877dc0c 5055
488c06c8 505620010104
5057 - (djm) Fix memory leak on systems with BROKEN_GETADDRINFO. Based on
5058 work by Chris Vaughan <vaughan99@yahoo.com>
5059
7c49df64 506020010103
5061 - (bal) fixed up sshconnect.c so it was closer inline with the OpenBSD
5062 tree (mainly positioning)
5063 - (bal) OpenSSH CVS Update
5064 - markus@cvs.openbsd.org 2001/01/02 20:41:02
5065 [packet.c]
5066 log remote ip on disconnect; PR 1600 from jcs@rt.fm
5067 - markus@cvs.openbsd.org 2001/01/02 20:50:56
5068 [sshconnect.c]
61e96248 5069 strict_host_key_checking for host_status != HOST_CHANGED &&
7c49df64 5070 ip_status == HOST_CHANGED
61e96248 5071 - (bal) authfile.c: Synced CVS ID tag
2c523de9 5072 - (bal) UnixWare 2.0 fixes by Tim Rice <tim@multitalents.net>
5073 - (bal) Disable sftp-server if no 64bit int support exists. Based on
5074 patch by Tim Rice <tim@multitalents.net>
5075 - (bal) Makefile.in changes to uninstall: target to remove sftp-server
5076 and sftp-server.8 manpage.
7c49df64 5077
a421e945 507820010102
5079 - (bal) OpenBSD CVS Update
5080 - markus@cvs.openbsd.org 2001/01/01 14:52:49
5081 [scp.c]
5082 use shared fatal(); from stevesk@pobox.com
5083
0efc80a7 508420001231
5085 - (bal) Reverted out of MAXHOSTNAMELEN. This should be set per OS.
5086 for multiple reasons.
b1335fdf 5087 - (bal) Reverted out of a partial NeXT patch.
0efc80a7 5088
efcae5b1 508920001230
5090 - (bal) OpenBSD CVS Update
5091 - markus@cvs.openbsd.org 2000/12/28 18:58:30
5092 [ssh-keygen.c]
5093 enable 'ssh-keygen -l -f ~/.ssh/{authorized_keys,known_hosts}{,2}
b148018f 5094 - markus@cvs.openbsd.org 2000/12/29 22:19:13
5095 [channels.c]
5096 missing xfree; from vaughan99@yahoo.com
efcae5b1 5097 - (bal) Resynced CVS ID with OpenBSD for channel.c and uidswap.c
03a14cc9 5098 - (bal) if no MAXHOSTNAMELEN is defined. Default to 64 character defination.
34665bf7 5099 Suggested by Christian Kurz <shorty@debian.org>
cb6dabf4 5100 - (bal) Add in '.c.o' section to Makefile.in to address make programs that
61e96248 5101 don't honor CPPFLAGS by default. Suggested by Lutz Jaenicke
cb6dabf4 5102 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
0dd78cd8 5103
510420001229
61e96248 5105 - (bal) Fixed spelling of 'authorized_keys' in ssh-copy-id.1 by Christian
34665bf7 5106 Kurz <shorty@debian.org>
8abcdba4 5107 - (bal) OpenBSD CVS Update
5108 - markus@cvs.openbsd.org 2000/12/28 14:25:51
5109 [auth.h auth2.c]
5110 count authentication failures only
5111 - markus@cvs.openbsd.org 2000/12/28 14:25:03
5112 [sshconnect.c]
5113 fingerprint for MITM attacks, too.
5114 - markus@cvs.openbsd.org 2000/12/28 12:03:57
5115 [sshd.8 sshd.c]
5116 document -D
5117 - markus@cvs.openbsd.org 2000/12/27 14:19:21
5118 [serverloop.c]
5119 less chatty
5120 - markus@cvs.openbsd.org 2000/12/27 12:34
5121 [auth1.c sshconnect2.c sshd.c]
5122 typo
5123 - markus@cvs.openbsd.org 2000/12/27 12:30:19
5124 [readconf.c readconf.h ssh.1 sshconnect.c]
5125 new option: HostKeyAlias: allow the user to record the host key
5126 under a different name. This is useful for ssh tunneling over
5127 forwarded connections or if you run multiple sshd's on different
5128 ports on the same machine.
5129 - markus@cvs.openbsd.org 2000/12/27 11:51:53
5130 [ssh.1 ssh.c]
5131 multiple -t force pty allocation, document ORIGINAL_COMMAND
5132 - markus@cvs.openbsd.org 2000/12/27 11:41:31
5133 [sshd.8]
5134 update for ssh-2
c52c7082 5135 - (stevesk) compress.[ch] sync with openbsd; missed in prototype
5136 fix merge.
0dd78cd8 5137
8f523d67 513820001228
5139 - (bal) Patch to add libutil.h to loginrec.c only if the platform has
5140 libutil.h. Suggested by Pekka Savola <pekka@netcore.fi>
9fb76616 5141 - (djm) Update to new x11-askpass in RPM spec
0dd78cd8 5142 - (bal) SCO patch to not include <sys/queue.h> since it's unrelated
5143 header. Patch by Tim Rice <tim@multitalents.net>
5144 - Updated TODO w/ known HP/UX issue
5145 - (bal) removed extra <netdb.h> noticed by Kevin Steves and removed the
5146 bad reference to 'NeXT including it else were' on the #ifdef version.
8f523d67 5147
b03bd394 514820001227
61e96248 5149 - (bal) Typo in configure.in: entut?ent should be endut?ent. Suggested by
b03bd394 5150 Takumi Yamane <yamtak@b-session.com>
5151 - (bal) Checks for getrlimit(), sysconf(), and setdtablesize(). Patch
8f523d67 5152 by Corinna Vinschen <vinschen@redhat.com>
5153 - (djm) Fix catman-do target for non-bash
61e96248 5154 - (bal) Typo in configure.in: entut?ent should be endut?ent. Suggested by
8f523d67 5155 Takumi Yamane <yamtak@b-session.com>
5156 - (bal) Checks for getrlimit(), sysconf(), and setdtablesize(). Patch
b03bd394 5157 by Corinna Vinschen <vinschen@redhat.com>
13991f8e 5158 - (djm) Fix catman-do target for non-bash
61e96248 5159 - (bal) Fixed NeXT's lack of CPPFLAGS honoring.
5160 - (bal) ssh-keyscan.c: NeXT (and older BSDs) don't support getrlimit() w/
f318b98b 5161 'RLIMIT_NOFILE'
61e96248 5162 - (djm) Remove *.Ylonen files. They are no longer in the OpenBSD tree,
5163 the info in COPYING.Ylonen has been moved to the start of each
3bdf55b1 5164 SSH1-derived file and README.Ylonen is well out of date.
b03bd394 5165
8d88011e 516620001223
5167 - (bal) Fixed Makefile.in to support recompile of all ssh and sshd objects
5168 if a change to config.h has occurred. Suggested by Gert Doering
5169 <gert@greenie.muc.de>
5170 - (bal) OpenBSD CVS Update:
5171 - markus@cvs.openbsd.org 2000/12/22 16:49:40
5172 [ssh-keygen.c]
5173 fix ssh-keygen -x -t type > file; from Roumen.Petrov@skalasoft.com
5174
1e3b8b07 517520001222
5176 - Updated RCSID for pty.c
5177 - (bal) OpenBSD CVS Updates:
5178 - markus@cvs.openbsd.org 2000/12/21 15:10:16
5179 [auth-rh-rsa.c hostfile.c hostfile.h sshconnect.c]
5180 print keyfile:line for changed hostkeys, for deraadt@, ok deraadt@
5181 - markus@cvs.openbsd.org 2000/12/20 19:26:56
5182 [authfile.c]
5183 allow ssh -i userkey for root
5184 - markus@cvs.openbsd.org 2000/12/20 19:37:21
5185 [authfd.c authfd.h kex.c sshconnect2.c sshd.c uidswap.c uidswap.h]
5186 fix prototypes; from stevesk@pobox.com
5187 - markus@cvs.openbsd.org 2000/12/20 19:32:08
5188 [sshd.c]
5189 init pointer to NULL; report from Jan.Ivan@cern.ch
5190 - markus@cvs.openbsd.org 2000/12/19 23:17:54
5191 [auth-krb4.c auth-options.c auth-options.h auth-rhosts.c auth-rsa.c
5192 auth1.c auth2-skey.c auth2.c authfd.c authfd.h authfile.c bufaux.c
5193 bufaux.h buffer.c canohost.c channels.c clientloop.c compress.c
5194 crc32.c deattack.c getput.h hmac.c hmac.h hostfile.c kex.c kex.h
5195 key.c key.h log.c login.c match.c match.h mpaux.c mpaux.h packet.c
5196 packet.h radix.c readconf.c rsa.c scp.c servconf.c servconf.h
5197 serverloop.c session.c sftp-server.c ssh-agent.c ssh-dss.c ssh-dss.h
5198 ssh-keygen.c ssh-keyscan.c ssh-rsa.c ssh-rsa.h ssh.c ssh.h uuencode.c
5199 uuencode.h sshconnect1.c sshconnect2.c sshd.c tildexpand.c]
5200 replace 'unsigned bla' with 'u_bla' everywhere. also replace 'char
5201 unsigned' with u_char.
5202
67b0facb 520320001221
5204 - (stevesk) OpenBSD CVS updates:
5205 - markus@cvs.openbsd.org 2000/12/19 15:43:45
5206 [authfile.c channels.c sftp-server.c ssh-agent.c]
5207 remove() -> unlink() for consistency
5208 - markus@cvs.openbsd.org 2000/12/19 15:48:09
5209 [ssh-keyscan.c]
5210 replace <ssl/x.h> with <openssl/x.h>
5211 - markus@cvs.openbsd.org 2000/12/17 02:33:40
5212 [uidswap.c]
5213 typo; from wsanchez@apple.com
61e96248 5214
adeebd37 521520001220
61e96248 5216 - (djm) Workaround PAM inconsistencies between Solaris derived PAM code
adeebd37 5217 and Linux-PAM. Based on report and fix from Andrew Morgan
5218 <morgan@transmeta.com>
5219
f072c47a 522020001218
5221 - (stevesk) rsa.c: entropy.h not needed.
0c2fb82f 5222 - (bal) split CFLAGS into CFLAGS and CPPFLAGS in configure.in and Makefile.
5223 Suggested by Wilfredo Sanchez <wsanchez@apple.com>
f072c47a 5224
731c1541 522520001216
5226 - (stevesk) OpenBSD CVS updates:
5227 - markus@cvs.openbsd.org 2000/12/16 02:53:57
5228 [scp.c]
5229 allow + in usernames; request from Florian.Weimer@RUS.Uni-Stuttgart.DE
5230 - markus@cvs.openbsd.org 2000/12/16 02:39:57
5231 [scp.c]
5232 unused; from stevesk@pobox.com
5233
227e8e86 523420001215
9853409f 5235 - (stevesk) Old OpenBSD patch wasn't completely applied:
5236 - markus@cvs.openbsd.org 2000/01/24 22:11:20
5237 [scp.c]
5238 allow '.' in usernames; from jedgar@fxp.org
227e8e86 5239 - (stevesk) OpenBSD CVS updates:
5240 - markus@cvs.openbsd.org 2000/12/13 16:26:53
5241 [ssh-keyscan.c]
5242 fatal already adds \n; from stevesk@pobox.com
5243 - markus@cvs.openbsd.org 2000/12/13 16:25:44
5244 [ssh-agent.c]
5245 remove redundant spaces; from stevesk@pobox.com
5246 - ho@cvs.openbsd.org 2000/12/12 15:50:21
5247 [pty.c]
5248 When failing to set tty owner and mode on a read-only filesystem, don't
5249 abort if the tty already has correct owner and reasonably sane modes.
5250 Example; permit 'root' to login to a firewall with read-only root fs.
5251 (markus@ ok)
5252 - deraadt@cvs.openbsd.org 2000/12/13 06:36:05
5253 [pty.c]
5254 KNF
6ffc9c88 5255 - markus@cvs.openbsd.org 2000/12/12 14:45:21
5256 [sshd.c]
5257 source port < 1024 is no longer required for rhosts-rsa since it
5258 adds no additional security.
5259 - markus@cvs.openbsd.org 2000/12/12 16:11:49
5260 [ssh.1 ssh.c]
5261 rhosts-rsa is no longer automagically disabled if ssh is not privileged.
5262 UsePrivilegedPort=no disables rhosts-rsa _only_ for old servers.
5263 these changes should not change the visible default behaviour of the ssh client.
71c0d06a 5264 - deraadt@cvs.openbsd.org 2000/12/11 10:27:33
5265 [scp.c]
5266 when copying 0-sized files, do not re-print ETA time at completion
3e1caa83 5267 - provos@cvs.openbsd.org 2000/12/15 10:30:15
5268 [kex.c kex.h sshconnect2.c sshd.c]
5269 compute diffie-hellman in parallel between server and client. okay markus@
227e8e86 5270
6c935fbd 527120001213
5272 - (djm) Make sure we reset the SIGPIPE disposition after we fork. Report
5273 from Andreas M. Kirchwitz <amk@krell.zikzak.de>
227e8e86 5274 - (stevesk) OpenBSD CVS update:
1fe6a48f 5275 - markus@cvs.openbsd.org 2000/12/12 15:30:02
5276 [ssh-keyscan.c ssh.c sshd.c]
61e96248 5277 consistently use __progname; from stevesk@pobox.com
6c935fbd 5278
367d1840 527920001211
5280 - (bal) Applied patch to include ssh-keyscan into Redhat's package, and
5281 patch to install ssh-keyscan manpage. Patch by Pekka Savola
5282 <pekka@netcore.fi>
e3a70753 5283 - (bal) OpenbSD CVS update
5284 - markus@cvs.openbsd.org 2000/12/10 17:01:53
5285 [sshconnect1.c]
5286 always request new challenge for skey/tis-auth, fixes interop with
5287 other implementations; report from roth@feep.net
367d1840 5288
6b523bae 528920001210
5290 - (bal) OpenBSD CVS updates
61e96248 5291 - markus@cvs.openbsd.org 2000/12/09 13:41:51
6b523bae 5292 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
5293 undo rijndael changes
61e96248 5294 - markus@cvs.openbsd.org 2000/12/09 13:48:31
6b523bae 5295 [rijndael.c]
5296 fix byte order bug w/o introducing new implementation
61e96248 5297 - markus@cvs.openbsd.org 2000/12/09 14:08:27
6b523bae 5298 [sftp-server.c]
5299 "" -> "." for realpath; from vinschen@redhat.com
61e96248 5300 - markus@cvs.openbsd.org 2000/12/09 14:06:54
6b523bae 5301 [ssh-agent.c]
5302 extern int optind; from stevesk@sweden.hp.com
13af0aa2 5303 - provos@cvs.openbsd.org 2000/12/09 23:51:11
5304 [compat.c]
5305 remove unnecessary '\n'
6b523bae 5306
ce9c0b75 530720001209
6b523bae 5308 - (bal) OpenBSD CVS updates:
61e96248 5309 - djm@cvs.openbsd.org 2000/12/07 4:24:59
ce9c0b75 5310 [ssh.1]
5311 Typo fix from Wilfredo Sanchez <wsanchez@apple.com>; ok theo
5312
f72fc97f 531320001207
6b523bae 5314 - (bal) OpenBSD CVS updates:
61e96248 5315 - markus@cvs.openbsd.org 2000/12/06 22:58:14
f72fc97f 5316 [compat.c compat.h packet.c]
5317 disable debug messages for ssh.com/f-secure 2.0.1x, 2.1.0
dfe89252 5318 - markus@cvs.openbsd.org 2000/12/06 23:10:39
5319 [rijndael.c]
5320 unexpand(1)
61e96248 5321 - markus@cvs.openbsd.org 2000/12/06 23:05:43
dfe89252 5322 [cipher.c cipher.h rijndael.c rijndael.h rijndael_boxes.h]
5323 new rijndael implementation. fixes endian bugs
f72fc97f 5324
97fb6912 532520001206
6b523bae 5326 - (bal) OpenBSD CVS updates:
97fb6912 5327 - markus@cvs.openbsd.org 2000/12/05 20:34:09
5328 [channels.c channels.h clientloop.c serverloop.c]
5329 async connects for -R/-L; ok deraadt@
5330 - todd@cvs.openssh.org 2000/12/05 16:47:28
5331 [sshd.c]
5332 tweak comment to reflect real location of pid file; ok provos@
bf5f69f7 5333 - (stevesk) Import <sys/queue.h> from OpenBSD for systems that don't
5334 have it (used in ssh-keyscan).
227e8e86 5335 - (stevesk) OpenBSD CVS update:
f20255cb 5336 - markus@cvs.openbsd.org 2000/12/06 19:57:48
5337 [ssh-keyscan.c]
5338 err(3) -> internal error(), from stevesk@sweden.hp.com
97fb6912 5339
f6fdbddf 534020001205
6b523bae 5341 - (bal) OpenBSD CVS updates:
f6fdbddf 5342 - markus@cvs.openbsd.org 2000/12/04 19:24:02
5343 [ssh-keyscan.c ssh-keyscan.1]
5344 David Maziere's ssh-keyscan, ok niels@
5345 - (bal) Updated Makefile.in to include ssh-keyscan that was just added
5346 to the recent OpenBSD source tree.
835d2104 5347 - (stevesk) fix typos in contrib/hpux/README
f6fdbddf 5348
cbc5abf9 534920001204
5350 - (bal) More C functions defined in NeXT that are unaccessable without
61e96248 5351 defining -POSIX.
5352 - (bal) OpenBSD CVS updates:
5353 - markus@cvs.openbsd.org 2000/12/03 11:29:04
cbc5abf9 5354 [compat.c]
5355 remove fallback to SSH_BUG_HMAC now that the drafts are updated
5356 - markus@cvs.openbsd.org 2000/12/03 11:27:55
5357 [compat.c]
61e96248 5358 correctly match "2.1.0.pl2 SSH" etc; from
97fb6912 5359 pekkas@netcore.fi/bugzilla.redhat
cbc5abf9 5360 - markus@cvs.openbsd.org 2000/12/03 11:15:03
5361 [auth2.c compat.c compat.h sshconnect2.c]
5362 support f-secure/ssh.com 2.0.12; ok niels@
5363
0b6fbf03 536420001203
cbc5abf9 5365 - (bal) OpenBSD CVS updates:
0b6fbf03 5366 - markus@cvs.openbsd.org 2000/11/30 22:54:31
5367 [channels.c]
61e96248 5368 debug->warn if tried to do -R style fwd w/o client requesting this;
0b6fbf03 5369 ok neils@
5370 - markus@cvs.openbsd.org 2000/11/29 20:39:17
5371 [cipher.c]
5372 des_cbc_encrypt -> des_ncbc_encrypt since it already updates the IV
5373 - markus@cvs.openbsd.org 2000/11/30 18:33:05
5374 [ssh-agent.c]
5375 agents must not dump core, ok niels@
61e96248 5376 - markus@cvs.openbsd.org 2000/11/30 07:04:02
0b6fbf03 5377 [ssh.1]
5378 T is for both protocols
5379 - markus@cvs.openbsd.org 2000/12/01 00:00:51
5380 [ssh.1]
5381 typo; from green@FreeBSD.org
5382 - markus@cvs.openbsd.org 2000/11/30 07:02:35
5383 [ssh.c]
5384 check -T before isatty()
5385 - provos@cvs.openbsd.org 2000/11/29 13:51:27
5386 [sshconnect.c]
61e96248 5387 show IP address and hostname when new key is encountered. okay markus@
0b6fbf03 5388 - markus@cvs.openbsd.org 2000/11/30 22:53:35
5389 [sshconnect.c]
5390 disable agent/x11/port fwding if hostkey has changed; ok niels@
5391 - marksu@cvs.openbsd.org 2000/11/29 21:11:59
5392 [sshd.c]
5393 sshd -D, startup w/o deamon(), for monitoring scripts or inittab;
5394 from handler@sub-rosa.com and eric@urbanrange.com; ok niels@
8c9fe09e 5395 - (djm) Added patch from Nalin Dahyabhai <nalin@redhat.com> to enable
5396 PAM authentication using KbdInteractive.
5397 - (djm) Added another TODO
0b6fbf03 5398
90f4078a 539920001202
5400 - (bal) Backed out of part of Alain St-Denis' loginrec.c patch.
61e96248 5401 - (bal) Irix need some sort of mansubdir, patch by Michael Stone
90f4078a 5402 <mstone@cs.loyola.edu>
5403
dcef6523 540420001129
7062c40f 5405 - (djm) Back out all the serverloop.c hacks. sshd will now hang again
5406 if there are background children with open fds.
c193d002 5407 - (djm) bsd-rresvport.c bzero -> memset
61e96248 5408 - (djm) Don't fail in defines.h on absence of 64 bit types (we will
c193d002 5409 still fail during compilation of sftp-server).
5410 - (djm) Fail if ar is not found during configure
c523303b 5411 - (djm) OpenBSD CVS updates:
5412 - provos@cvs.openbsd.org 2000/11/22 08:38:31
5413 [sshd.8]
5414 talk about /etc/primes, okay markus@
5415 - markus@cvs.openbsd.org 2000/11/23 14:03:48
5416 [ssh.c sshconnect1.c sshconnect2.c]
5417 complain about invalid ciphers for ssh1/ssh2, fall back to reasonable
5418 defaults
5419 - markus@cvs.openbsd.org 2000/11/25 09:42:53
5420 [sshconnect1.c]
5421 reorder check for illegal ciphers, bugreport from espie@
5422 - markus@cvs.openbsd.org 2000/11/25 10:19:34
5423 [ssh-keygen.c ssh.h]
5424 print keytype when generating a key.
5425 reasonable defaults for RSA1/RSA/DSA keys.
b3ec54b4 5426 - (djm) Patch from Pekka Savola <Pekka.Savola@netcore.fi> to include a few
5427 more manpage paths in fixpaths calls
5428 - (djm) Also add xauth path at Pekka's suggestion.
57ce3f00 5429 - (djm) Add Redhat RPM patch for AUTHPRIV SyslogFacility
dcef6523 5430
e879a080 543120001125
5432 - (djm) Give up privs when reading seed file
5433
d343d900 543420001123
5435 - (bal) Merge OpenBSD changes:
5436 - markus@cvs.openbsd.org 2000/11/15 22:31:36
5437 [auth-options.c]
61e96248 5438 case insensitive key options; from stevesk@sweeden.hp.com
d343d900 5439 - markus@cvs.openbsd.org 2000/11/16 17:55:43
5440 [dh.c]
5441 do not use perror() in sshd, after child is forked()
5442 - markus@cvs.openbsd.org 2000/11/14 23:42:40
5443 [auth-rsa.c]
5444 parse option only if key matches; fix some confusing seen by the client
5445 - markus@cvs.openbsd.org 2000/11/14 23:44:19
5446 [session.c]
5447 check no_agent_forward_flag for ssh-2, too
5448 - markus@cvs.openbsd.org 2000/11/15
5449 [ssh-agent.1]
5450 reorder SYNOPSIS; typo, use .It
5451 - markus@cvs.openbsd.org 2000/11/14 23:48:55
5452 [ssh-agent.c]
5453 do not reorder keys if a key is removed
5454 - markus@cvs.openbsd.org 2000/11/15 19:58:08
5455 [ssh.c]
61e96248 5456 just ignore non existing user keys
d343d900 5457 - millert@cvs.openbsd.org 200/11/15 20:24:43
5458 [ssh-keygen.c]
5459 Add missing \n at end of error message.
5460
0b49a754 546120001122
5462 - (bal) Minor patch to ensure platforms lacking IRIX job limit supports
5463 are compilable.
5464 - (bal) Updated TODO as of 11/18/2000 with known things to resolve.
5465
fab2e5d3 546620001117
5467 - (bal) Changed from 'primes' to 'primes.out' for consistancy sake. It
5468 has no affect the output. Patch by Corinna Vinschen <vinschen@redhat.com>
61e96248 5469 - (stevesk) Reworked progname support.
260d427b 5470 - (bal) Misplaced #include "includes.h" in bsd-setproctitle.c. Patch by
5471 Shinichi Maruyama <marya@st.jip.co.jp>
fab2e5d3 5472
c2207f11 547320001116
5474 - (bal) Added in MAXSYMLINK test in bsd-realpath.c. Required for some SCO
5475 releases.
5476 - (bal) Make builds work outside of source tree. Patch by Mark D. Roth
5477 <roth@feep.net>
5478
3d398e04 547920001113
61e96248 5480 - (djm) Add pointer to http://www.imasy.or.jp/~gotoh/connect.c to
3d398e04 5481 contrib/README
fa08c86b 5482 - (djm) Merge OpenBSD changes:
5483 - markus@cvs.openbsd.org 2000/11/06 16:04:56
5484 [channels.c channels.h clientloop.c nchan.c serverloop.c]
5485 [session.c ssh.c]
5486 agent forwarding and -R for ssh2, based on work from
5487 jhuuskon@messi.uku.fi
5488 - markus@cvs.openbsd.org 2000/11/06 16:13:27
5489 [ssh.c sshconnect.c sshd.c]
5490 do not disabled rhosts(rsa) if server port > 1024; from
5491 pekkas@netcore.fi
5492 - markus@cvs.openbsd.org 2000/11/06 16:16:35
5493 [sshconnect.c]
5494 downgrade client to 1.3 if server is 1.4; help from mdb@juniper.net
5495 - markus@cvs.openbsd.org 2000/11/09 18:04:40
5496 [auth1.c]
5497 typo; from mouring@pconline.com
5498 - markus@cvs.openbsd.org 2000/11/12 12:03:28
5499 [ssh-agent.c]
5500 off-by-one when removing a key from the agent
5501 - markus@cvs.openbsd.org 2000/11/12 12:50:39
5502 [auth-rh-rsa.c auth2.c authfd.c authfd.h]
5503 [authfile.c hostfile.c kex.c kex.h key.c key.h myproposal.h]
5504 [readconf.c readconf.h rsa.c rsa.h servconf.c servconf.h ssh-add.c]
5505 [ssh-agent.c ssh-keygen.1 ssh-keygen.c ssh.1 ssh.c ssh_config]
5506 [sshconnect1.c sshconnect2.c sshd.8 sshd.c sshd_config ssh-dss.c]
61e96248 5507 [ssh-dss.h ssh-rsa.c ssh-rsa.h dsa.c dsa.h]
fa08c86b 5508 add support for RSA to SSH2. please test.
5509 there are now 3 types of keys: RSA1 is used by ssh-1 only,
5510 RSA and DSA are used by SSH2.
5511 you can use 'ssh-keygen -t rsa -f ssh2_rsa_file' to generate RSA
5512 keys for SSH2 and use the RSA keys for hostkeys or for user keys.
5513 SSH2 RSA or DSA keys are added to .ssh/authorised_keys2 as before.
5514 - (djm) Fix up Makefile and Redhat init script to create RSA host keys
f001465f 5515 - (djm) Change to interim version
5733a41a 5516 - (djm) Fix RPM spec file stupidity
6fff1ac4 5517 - (djm) fixpaths to DSA and RSA keys too
3d398e04 5518
d287c664 551920001112
5520 - (bal) SCO Patch to add needed libraries for configure.in. Patch by
5521 Phillips Porch <root@theporch.com>
3d398e04 5522 - (bal) IRIX patch to adding Job Limits. Patch by Denis Parker
5523 <dcp@sgi.com>
a3bf38d0 5524 - (stevesk) pty.c: HP-UX 10 and 11 don't define TIOCSCTTY. Add error() to
5525 failed ioctl(TIOCSCTTY) call.
d287c664 5526
3c4d4fef 552720001111
5528 - (djm) Added /etc/primes for kex DH group neg, fixup Makefile.in and
5529 packaging files
35325fd4 5530 - (djm) Fix new Makefile.in warnings
61e96248 5531 - (djm) Fix vsprintf("%h") in bsd-snprintf.c, short int va_args are
5532 promoted to type int. Report and fix from Dan Astoorian
027bf205 5533 <djast@cs.toronto.edu>
61e96248 5534 - (djm) Hardwire sysconfdir in RPM spec files as some RPM versions get
e3291159 5535 it wrong. Report from Bennett Todd <bet@rahul.net>
3c4d4fef 5536
3e366738 553720001110
5538 - (bal) Fixed dropped answer from skey_keyinfo() in auth1.c
5539 - (bal) Changed from --with-skey to --with-skey=PATH in configure.in
5540 - (bal) Added in check to verify S/Key library is being detected in
5541 configure.in
61e96248 5542 - (bal) next-posix.h - added another prototype wrapped in POSIX ifdef/endif.
3e366738 5543 Patch by Mark Miller <markm@swoon.net>
5544 - (bal) Added 'util.h' header to loginrec.c only if HAVE_UTIL_H is defined
61e96248 5545 to remove warnings under MacOS X. Patch by Mark Miller <markm@swoon.net>
3e366738 5546 - (bal) Fixed LDFLAG mispelling in configure.in for --with-afs
5547
373998a4 554820001107
e506ee73 5549 - (bal) acconfig.in - removed the double "USE_PIPES" entry. Patch by
5550 Mark Miller <markm@swoon.net>
373998a4 5551 - (bal) sshd.init files corrected to assign $? to RETVAL. Patch by
5552 Jarno Huuskonen <jhuuskon@messi.uku.fi>
e506ee73 5553 - (bal) fixpaths fixed to stop it from quitely failing. Patch by
5554 Mark D. Roth <roth@feep.net>
373998a4 5555
ac89998a 555620001106
5557 - (djm) Use Jim's new 1.0.3 askpass in Redhat RPMs
6c09e23c 5558 - (djm) Manually fix up missed diff hunks (mainly RCS idents)
61e96248 5559 - (djm) Remove UPGRADING document in favour of a link to the better
d6846e6a 5560 maintained FAQ on www.openssh.com
73bd30fe 5561 - (djm) Fix multiple dependancy on gnome-libs from Pekka Savola
5562 <pekkas@netcore.fi>
5563 - (djm) Don't need X11-askpass in RPM spec file if building without it
5564 from Pekka Savola <pekkas@netcore.fi>
c215ba3b 5565 - (djm) Release 2.3.0p1
97b378bf 5566 - (bal) typo in configure.in in regards to --with-ldflags from Marko
5567 Asplund <aspa@kronodoc.fi>
5568 - (bal) fixed next-posix.h. Forgot prototype of getppid().
68f189a9 5569
b850ecd9 557020001105
5571 - (bal) Sync with OpenBSD:
5572 - markus@cvs.openbsd.org 2000/10/31 9:31:58
5573 [compat.c]
5574 handle all old openssh versions
5575 - markus@cvs.openbsd.org 2000/10/31 13:1853
5576 [deattack.c]
5577 so that large packets do not wrap "n"; from netbsd
5578 - (bal) rijndel.c - fix up RCSID to match OpenBSD tree
a30ce26d 5579 - (bal) auth2-skey.c - Checked in. Missing from portable tree.
5580 - (bal) Reworked NEWS-OS and NeXT ports to extract waitpid() and
5581 setsid() into more common files
96054e6f 5582 - (stevesk) pty.c: use __hpux to identify HP-UX.
d0127657 5583 - (bal) Missed auth-skey.o in Makefile.in and minor correction to
5584 bsd-waitpid.c
b850ecd9 5585
75b90ced 558620001029
5587 - (stevesk) Fix typo in auth.c: USE_PAM not PAM
95273555 5588 - (stevesk) Create contrib/cygwin/ directory; patch from
5589 Corinna Vinschen <vinschen@redhat.com>
e9e4a1c7 5590 - (bal) Resolved more $xno and $xyes issues in configure.in
fd5f0295 5591 - (bal) next-posix.h - spelling and forgot a prototype
75b90ced 5592
344f2b94 559320001028
61e96248 5594 - (djm) fix select hack in serverloop.c from Philippe WILLEM
344f2b94 5595 <Philippe.WILLEM@urssaf.fr>
240ae474 5596 - (djm) Fix mangled AIXAUTHENTICATE code
61e96248 5597 - (djm) authctxt->pw may be NULL. Fix from Markus Friedl
606ea390 5598 <markus.friedl@informatik.uni-erlangen.de>
a22aff1f 5599 - (djm) Sync with OpenBSD:
5600 - markus@cvs.openbsd.org 2000/10/16 15:46:32
5601 [ssh.1]
5602 fixes from pekkas@netcore.fi
5603 - markus@cvs.openbsd.org 2000/10/17 14:28:11
5604 [atomicio.c]
5605 return number of characters processed; ok deraadt@
5606 - markus@cvs.openbsd.org 2000/10/18 12:04:02
5607 [atomicio.c]
5608 undo
5609 - markus@cvs.openbsd.org 2000/10/18 12:23:02
5610 [scp.c]
5611 replace atomicio(read,...) with read(); ok deraadt@
5612 - markus@cvs.openbsd.org 2000/10/18 12:42:00
5613 [session.c]
5614 restore old record login behaviour
5615 - deraadt@cvs.openbsd.org 2000/10/19 10:41:13
5616 [auth-skey.c]
5617 fmt string problem in unused code
5618 - provos@cvs.openbsd.org 2000/10/19 10:45:16
5619 [sshconnect2.c]
5620 don't reference freed memory. okay deraadt@
5621 - markus@cvs.openbsd.org 2000/10/21 11:04:23
5622 [canohost.c]
5623 typo, eramore@era-t.ericsson.se; ok niels@
5624 - markus@cvs.openbsd.org 2000/10/23 13:31:55
5625 [cipher.c]
5626 non-alignment dependent swap_bytes(); from
5627 simonb@wasabisystems.com/netbsd
5628 - markus@cvs.openbsd.org 2000/10/26 12:38:28
5629 [compat.c]
5630 add older vandyke products
5631 - markus@cvs.openbsd.org 2000/10/27 01:32:19
5632 [channels.c channels.h clientloop.c serverloop.c session.c]
5633 [ssh.c util.c]
61e96248 5634 enable non-blocking IO on channels, and tty's (except for the
a22aff1f 5635 client ttys).
344f2b94 5636
ddc49b5c 563720001027
5638 - (djm) Increase REKEY_BYTES to 2^24 for arc4random
5639
48e7916f 564020001025
5641 - (djm) Added WARNING.RNG file and modified configure to ask users of the
5642 builtin entropy code to read it.
5643 - (djm) Prefer builtin regex to PCRE.
00937921 5644 - (bal) Added USE_PIPS defined to NeXT configure.in since scp hangs randomly.
5645 - (bal) Apply fixes to configure.in pointed out by Pavel Roskin
5646 <proski@gnu.org>
48e7916f 5647
8dcda1e3 564820001020
5649 - (djm) Don't define _REENTRANT for SNI/Reliant Unix
07bee9a7 5650 - (bal) Imported NEWS-OS waitpid() macros into NeXT. Since implementation
5651 is more correct then current version.
8dcda1e3 5652
f5af5cd5 565320001018
5654 - (stevesk) Add initial support for setproctitle(). Current
5655 support is for the HP-UX pstat(PSTAT_SETCMD, ...) method.
134fd7f6 5656 - (stevesk) Add egd startup scripts to contrib/hpux/
f5af5cd5 5657
2f31bdd6 565820001017
5659 - (djm) Add -lregex to cywin libs from Corinna Vinschen
5660 <vinschen@cygnus.com>
ba7a3f40 5661 - (djm) Don't rely on atomicio's retval to determine length of askpass
5662 supplied passphrase. Problem report from Lutz Jaenicke
5663 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
66d6c27e 5664 - (bal) Changed from GNU rx to PCRE on suggestion from djm.
61e96248 5665 - (bal) Integrated Sony NEWS-OS patches from NAKAJI Hirouyuki
66d6c27e 5666 <nakaji@tutrp.tut.ac.jp>
2f31bdd6 5667
33de75a3 566820001016
5669 - (djm) Sync with OpenBSD:
5670 - markus@cvs.openbsd.org 2000/10/14 04:01:15
5671 [cipher.c]
5672 debug3
5673 - markus@cvs.openbsd.org 2000/10/14 04:07:23
5674 [scp.c]
5675 remove spaces from arguments; from djm@mindrot.org
5676 - markus@cvs.openbsd.org 2000/10/14 06:09:46
5677 [ssh.1]
5678 Cipher is for SSH-1 only
5679 - markus@cvs.openbsd.org 2000/10/14 06:12:09
5680 [servconf.c servconf.h serverloop.c session.c sshd.8]
5681 AllowTcpForwarding; from naddy@
5682 - markus@cvs.openbsd.org 2000/10/14 06:16:56
5683 [auth2.c compat.c compat.h sshconnect2.c version.h]
61e96248 5684 OpenSSH_2.3; note that is is not complete, but the version number
33de75a3 5685 needs to be changed for interoperability reasons
5686 - markus@cvs.openbsd.org 2000/10/14 06:19:45
5687 [auth-rsa.c]
5688 do not send RSA challenge if key is not allowed by key-options; from
5689 eivind@ThinkSec.com
5690 - markus@cvs.openbsd.org 2000/10/15 08:14:01
5691 [rijndael.c session.c]
5692 typos; from stevesk@sweden.hp.com
5693 - markus@cvs.openbsd.org 2000/10/15 08:18:31
5694 [rijndael.c]
5695 typo
61e96248 5696 - (djm) Copy manpages back over from OpenBSD - too tedious to wade
30d8b039 5697 through diffs
61e96248 5698 - (djm) Added condrestart to Redhat init script. Patch from Pekka Savola
30d8b039 5699 <pekkas@netcore.fi>
aa0289fe 5700 - (djm) Update version in Redhat spec file
61e96248 5701 - (djm) Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
aa0289fe 5702 Redhat 7.0 spec file
5b2d4b75 5703 - (djm) Make inability to read/write PRNG seedfile non-fatal
5704
33de75a3 5705
4d670c24 570620001015
5707 - (djm) Fix ssh2 hang on background processes at logout.
5708
71dfaf1c 570920001014
443172c4 5710 - (bal) Add support for realpath and getcwd for platforms with broken
5711 or missing realpath implementations for sftp-server.
5712 - (bal) Corrected mistake in INSTALL in regards to GNU rx library
61e96248 5713 - (bal) Add support for GNU rx library for those lacking regexp support
71dfaf1c 5714 - (djm) Don't accept PAM_PROMPT_ECHO_ON messages during initial auth
02323c45 5715 - (djm) Revert SSH2 serverloop hack, will find a better way.
4ee81249 5716 - (djm) Add workaround for Linux 2.4's gratuitious errno change. Patch
5717 from Martin Johansson <fatbob@acc.umu.se>
94ec8c6b 5718 - (djm) Big OpenBSD sync:
5719 - markus@cvs.openbsd.org 2000/09/30 10:27:44
5720 [log.c]
5721 allow loglevel debug
5722 - markus@cvs.openbsd.org 2000/10/03 11:59:57
5723 [packet.c]
5724 hmac->mac
5725 - markus@cvs.openbsd.org 2000/10/03 12:03:03
5726 [auth-krb4.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth1.c]
5727 move fake-auth from auth1.c to individual auth methods, disables s/key in
5728 debug-msg
5729 - markus@cvs.openbsd.org 2000/10/03 12:16:48
5730 ssh.c
5731 do not resolve canonname, i have no idea why this was added oin ossh
5732 - markus@cvs.openbsd.org 2000/10/09 15:30:44
5733 ssh-keygen.1 ssh-keygen.c
5734 -X now reads private ssh.com DSA keys, too.
5735 - markus@cvs.openbsd.org 2000/10/09 15:32:34
5736 auth-options.c
5737 clear options on every call.
5738 - markus@cvs.openbsd.org 2000/10/09 15:51:00
5739 authfd.c authfd.h
5740 interop with ssh-agent2, from <res@shore.net>
5741 - markus@cvs.openbsd.org 2000/10/10 14:20:45
5742 compat.c
5743 use rexexp for version string matching
5744 - provos@cvs.openbsd.org 2000/10/10 22:02:18
5745 [kex.c kex.h myproposal.h ssh.h ssh2.h sshconnect2.c sshd.c dh.c dh.h]
5746 First rough implementation of the diffie-hellman group exchange. The
5747 client can ask the server for bigger groups to perform the diffie-hellman
5748 in, thus increasing the attack complexity when using ciphers with longer
5749 keys. University of Windsor provided network, T the company.
5750 - markus@cvs.openbsd.org 2000/10/11 13:59:52
5751 [auth-rsa.c auth2.c]
5752 clear auth options unless auth sucessfull
5753 - markus@cvs.openbsd.org 2000/10/11 14:00:27
5754 [auth-options.h]
5755 clear auth options unless auth sucessfull
5756 - markus@cvs.openbsd.org 2000/10/11 14:03:27
5757 [scp.1 scp.c]
5758 support 'scp -o' with help from mouring@pconline.com
5759 - markus@cvs.openbsd.org 2000/10/11 14:11:35
5760 [dh.c]
5761 Wall
5762 - markus@cvs.openbsd.org 2000/10/11 14:14:40
5763 [auth.h auth2.c readconf.c readconf.h readpass.c servconf.c servconf.h]
5764 [ssh.h sshconnect2.c sshd_config auth2-skey.c cli.c cli.h]
5765 add support for s/key (kbd-interactive) to ssh2, based on work by
5766 mkiernan@avantgo.com and me
5767 - markus@cvs.openbsd.org 2000/10/11 14:27:24
5768 [auth.c auth1.c auth2.c authfile.c cipher.c cipher.h kex.c kex.h]
5769 [myproposal.h packet.c readconf.c session.c ssh.c ssh.h sshconnect1.c]
5770 [sshconnect2.c sshd.c]
5771 new cipher framework
5772 - markus@cvs.openbsd.org 2000/10/11 14:45:21
5773 [cipher.c]
5774 remove DES
5775 - markus@cvs.openbsd.org 2000/10/12 03:59:20
5776 [cipher.c cipher.h sshconnect1.c sshconnect2.c sshd.c]
5777 enable DES in SSH-1 clients only
5778 - markus@cvs.openbsd.org 2000/10/12 08:21:13
5779 [kex.h packet.c]
5780 remove unused
5781 - markus@cvs.openbsd.org 2000/10/13 12:34:46
5782 [sshd.c]
5783 Kludge for F-Secure Macintosh < 1.0.2; appro@fy.chalmers.se
5784 - markus@cvs.openbsd.org 2000/10/13 12:59:15
5785 [cipher.c cipher.h myproposal.h rijndael.c rijndael.h]
5786 rijndael/aes support
5787 - markus@cvs.openbsd.org 2000/10/13 13:10:54
5788 [sshd.8]
5789 more info about -V
5790 - markus@cvs.openbsd.org 2000/10/13 13:12:02
5791 [myproposal.h]
5792 prefer no compression
3ed32516 5793 - (djm) Fix scp user@host handling
5794 - (djm) Don't clobber ssh_prng_cmds on install
6bcf7caa 5795 - (stevesk) Include config.h in rijndael.c so we define intXX_t and
5796 u_intXX_t types on all platforms.
9ea53ba5 5797 - (stevesk) rijndael.c: cleanup missing declaration warnings.
2919e060 5798 - (stevesk) ~/.hushlogin shouldn't cause required password change to
5799 be bypassed.
f5665f6f 5800 - (stevesk) Display correct path to ssh-askpass in configure output.
5801 Report from Lutz Jaenicke.
71dfaf1c 5802
ebd782f7 580320001007
5804 - (stevesk) Print PAM return value in PAM log messages to aid
5805 with debugging.
97994d32 5806 - (stevesk) Fix detection of pw_class struct member in configure;
5807 patch from KAMAHARA Junzo <kamahara@cc.kshosen.ac.jp>
5808
47a134c1 580920001002
5810 - (djm) Fix USER_PATH, report from Kevin Steves <stevesk@sweden.hp.com>
5811 - (djm) Add host system and CC to end-of-configure report. Suggested by
5812 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
5813
7322ef0e 581420000931
5815 - (djm) Cygwin fixes from Corinna Vinschen <vinschen@cygnus.com>
5816
6ac7829a 581720000930
b6490dcb 5818 - (djm) Irix ssh_prng_cmds path fix from Pekka Savola <pekkas@netcore.fi>
61e96248 5819 - (djm) Support in bsd-snprintf.c for long long conversions from
772bd898 5820 Ben Lindstrom <mouring@pconline.com>
5821 - (djm) Cleanup NeXT support from Ben Lindstrom <mouring@pconline.com>
857040fb 5822 - (djm) Ignore SIGPIPEs from serverloop to child. Fixes crashes with
61e96248 5823 very short lived X connections. Bug report from Tobias Oetiker
857040fb 5824 <oetiker@ee.ethz.ch>. Fix from Markus Friedl <markus@cvs.openbsd.org>
bd2d7f6a 5825 - (djm) Add recent InitScripts as a RPM dependancy for openssh-server
5826 patch from Pekka Savola <pekkas@netcore.fi>
58665035 5827 - (djm) Forgot to cvs add LICENSE file
dc2901a0 5828 - (djm) Add LICENSE to RPM spec files
de273eef 5829 - (djm) CVS OpenBSD sync:
5830 - markus@cvs.openbsd.org 2000/09/26 13:59:59
5831 [clientloop.c]
5832 use debug2
5833 - markus@cvs.openbsd.org 2000/09/27 15:41:34
5834 [auth2.c sshconnect2.c]
5835 use key_type()
5836 - markus@cvs.openbsd.org 2000/09/28 12:03:18
5837 [channels.c]
5838 debug -> debug2 cleanup
61e96248 5839 - (djm) Irix strips "/dev/tty" from [uw]tmp entries (other systems only
2a7d529a 5840 strip "/dev/"). Fix loginrec.c based on patch from Alain St-Denis
5841 <Alain.St-Denis@ec.gc.ca>
61e96248 5842 - (djm) Fix 9 character passphrase failure with gnome-ssh-askpass.
5843 Problem was caused by interrupted read in ssh-add. Report from Donald
2a7d529a 5844 J. Barry <don@astro.cornell.edu>
6ac7829a 5845
c5d85828 584620000929
5847 - (djm) Fix SSH2 not terminating until all background tasks done problem.
61e96248 5848 - (djm) Another off-by-one fix from Pavel Kankovsky
5849 <peak@argo.troja.mff.cuni.cz>
22d89d24 5850 - (djm) Clean up. Strip some unnecessary differences with OpenBSD's code,
5851 tidy necessary differences. Use Markus' new debugN() in entropy.c
61e96248 5852 - (djm) Merged big SCO portability patch from Tim Rice
77bb0bca 5853 <tim@multitalents.net>
c5d85828 5854
6fd7f731 585520000926
5856 - (djm) Update X11-askpass to 1.0.2 in RPM spec file
c5ae7384 5857 - (djm) Define _REENTRANT to pickup strtok_r() on HP/UX
61e96248 5858 - (djm) Security: fix off-by-one buffer overrun in fake-getnameinfo.c.
5859 Report and fix from Pavel Kankovsky <peak@argo.troja.mff.cuni.cz>
6fd7f731 5860
2f125ca1 586120000924
5862 - (djm) Merged cleanup patch from Mark Miller <markm@swoon.net>
5863 - (djm) A bit more cleanup - created cygwin_util.h
bcdaaeab 5864 - (djm) Include strtok_r() from OpenBSD libc. Fixes report from Mark Miller
5865 <markm@swoon.net>
2f125ca1 5866
764d4113 586720000923
61e96248 5868 - (djm) Fix address logging in utmp from Kevin Steves
764d4113 5869 <stevesk@sweden.hp.com>
777319db 5870 - (djm) Redhat spec and manpage fixes from Pekka Savola <pekkas@netcore.fi>
bd590612 5871 - (djm) Seperate tests for int64_t and u_int64_t types
61e96248 5872 - (djm) Tweak password expiry checking at suggestion of Kevin Steves
37c1c46d 5873 <stevesk@sweden.hp.com>
e79b44e1 5874 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
61e96248 5875 - (djm) Use printf %lld instead of %qd in sftp-server.c. Fix from
e2144f11 5876 Michael Stone <mstone@cs.loyola.edu>
188adeb2 5877 - (djm) OpenBSD CVS sync:
5878 - markus@cvs.openbsd.org 2000/09/17 09:38:59
5879 [sshconnect2.c sshd.c]
5880 fix DEBUG_KEXDH
5881 - markus@cvs.openbsd.org 2000/09/17 09:52:51
5882 [sshconnect.c]
5883 yes no; ok niels@
5884 - markus@cvs.openbsd.org 2000/09/21 04:55:11
5885 [sshd.8]
5886 typo
5887 - markus@cvs.openbsd.org 2000/09/21 05:03:54
5888 [serverloop.c]
5889 typo
5890 - markus@cvs.openbsd.org 2000/09/21 05:11:42
5891 scp.c
5892 utime() to utimes(); mouring@pconline.com
5893 - markus@cvs.openbsd.org 2000/09/21 05:25:08
5894 sshconnect2.c
5895 change login logic in ssh2, allows plugin of other auth methods
5896 - markus@cvs.openbsd.org 2000/09/21 05:25:35
5897 [auth2.c channels.c channels.h clientloop.c dispatch.c dispatch.h]
5898 [serverloop.c]
5899 add context to dispatch_run
5900 - markus@cvs.openbsd.org 2000/09/21 05:07:52
5901 authfd.c authfd.h ssh-agent.c
5902 bug compat for old ssh.com software
764d4113 5903
7f377177 590420000920
5905 - (djm) Fix bad path substitution. Report from Andrew Miner
5906 <asminer@cs.iastate.edu>
5907
bcbf86ec 590820000916
61e96248 5909 - (djm) Fix SSL search order from Lutz Jaenicke
7950bf97 5910 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
19ece6d2 5911 - (djm) New SuSE spec from Corinna Vinschen <corinna@vinschen.de>
9cd45ea4 5912 - (djm) Update CygWin support from Corinna Vinschen <vinschen@cygnus.com>
995edaac 5913 - (djm) Use a real struct sockaddr inside the fake struct sockaddr_storage.
5914 Patch from Larry Jones <larry.jones@sdrc.com>
61e96248 5915 - (djm) Add Steve VanDevender's <stevev@darkwing.uoregon.edu> PAM
ad55cd03 5916 password change patch.
5917 - (djm) Bring licenses on my stuff in line with OpenBSD's
0bbfbdeb 5918 - (djm) Cleanup auth-passwd.c and unify HP/UX authentication. Patch from
5919 Kevin Steves <stevesk@sweden.hp.com>
7f8f5e00 5920 - (djm) Shadow expiry check fix from Pavel Troller <patrol@omni.sinus.cz>
5921 - (djm) Re-enable int64_t types - we need them for sftp
5922 - (djm) Use libexecdir from configure , rather than libexecdir/ssh
5923 - (djm) Update Redhat SPEC file accordingly
5924 - (djm) Add Kevin Steves <stevesk@sweden.hp.com> HP/UX contrib files
5925 - (djm) Add Charles Levert <charles@comm.polymtl.ca> getpgrp patch
61e96248 5926 - (djm) Fix password auth on HP/UX 10.20. Patch from Dirk De Wachter
7f8f5e00 5927 <Dirk.DeWachter@rug.ac.be>
61e96248 5928 - (djm) Fixprogs and entropy list fixes from Larry Jones
7f8f5e00 5929 <larry.jones@sdrc.com>
5930 - (djm) Fix for SuSE spec file from Takashi YOSHIDA
5931 <tyoshida@gemini.rc.kyushu-u.ac.jp>
bcbf86ec 5932 - (djm) Merge OpenBSD changes:
5933 - markus@cvs.openbsd.org 2000/09/05 02:59:57
5934 [session.c]
5935 print hostname (not hushlogin)
5936 - markus@cvs.openbsd.org 2000/09/05 13:18:48
5937 [authfile.c ssh-add.c]
5938 enable ssh-add -d for DSA keys
5939 - markus@cvs.openbsd.org 2000/09/05 13:20:49
5940 [sftp-server.c]
5941 cleanup
5942 - markus@cvs.openbsd.org 2000/09/06 03:46:41
5943 [authfile.h]
5944 prototype
5945 - deraadt@cvs.openbsd.org 2000/09/07 14:27:56
5946 [ALL]
61e96248 5947 cleanup copyright notices on all files. I have attempted to be
5948 accurate with the details. everything is now under Tatu's licence
5949 (which I copied from his readme), and/or the core-sdi bsd-ish thing
5950 for deattack, or various openbsd developers under a 2-term bsd
bcbf86ec 5951 licence. We're not changing any rules, just being accurate.
5952 - markus@cvs.openbsd.org 2000/09/07 14:40:30
5953 [channels.c channels.h clientloop.c serverloop.c ssh.c]
5954 cleanup window and packet sizes for ssh2 flow control; ok niels
5955 - markus@cvs.openbsd.org 2000/09/07 14:53:00
5956 [scp.c]
5957 typo
5958 - markus@cvs.openbsd.org 2000/09/07 15:13:37
5959 [auth-options.c auth-options.h auth-rh-rsa.c auth-rsa.c auth.c]
5960 [authfile.h canohost.c channels.h compat.c hostfile.h log.c match.h]
5961 [pty.c readconf.c]
5962 some more Copyright fixes
5963 - markus@cvs.openbsd.org 2000/09/08 03:02:51
5964 [README.openssh2]
5965 bye bye
5966 - deraadt@cvs.openbsd.org 2000/09/11 18:38:33
5967 [LICENCE cipher.c]
5968 a few more comments about it being ARC4 not RC4
5969 - markus@cvs.openbsd.org 2000/09/12 14:53:11
5970 [log-client.c log-server.c log.c ssh.1 ssh.c ssh.h sshd.8 sshd.c]
5971 multiple debug levels
5972 - markus@cvs.openbsd.org 2000/09/14 14:25:15
5973 [clientloop.c]
5974 typo
5975 - deraadt@cvs.openbsd.org 2000/09/15 01:13:51
5976 [ssh-agent.c]
5977 check return value for setenv(3) for failure, and deal appropriately
5978
deb8d717 597920000913
5980 - (djm) Fix server not exiting with jobs in background.
5981
b5e300c2 598220000905
5983 - (djm) Import OpenBSD CVS changes
5984 - markus@cvs.openbsd.org 2000/08/31 15:52:24
5985 [Makefile sshd.8 sshd_config sftp-server.8 sftp-server.c]
5986 implement a SFTP server. interops with sftp2, scp2 and the windows
5987 client from ssh.com
5988 - markus@cvs.openbsd.org 2000/08/31 15:56:03
5989 [README.openssh2]
5990 sync
5991 - markus@cvs.openbsd.org 2000/08/31 16:05:42
5992 [session.c]
5993 Wall
5994 - markus@cvs.openbsd.org 2000/08/31 16:09:34
5995 [authfd.c ssh-agent.c]
5996 add a flag to SSH2_AGENTC_SIGN_REQUEST for future extensions
5997 - deraadt@cvs.openbsd.org 2000/09/01 09:25:13
5998 [scp.1 scp.c]
5999 cleanup and fix -S support; stevesk@sweden.hp.com
6000 - markus@cvs.openbsd.org 2000/09/01 16:29:32
6001 [sftp-server.c]
6002 portability fixes
6003 - markus@cvs.openbsd.org 2000/09/01 16:32:41
6004 [sftp-server.c]
6005 fix cast; mouring@pconline.com
6006 - itojun@cvs.openbsd.org 2000/09/03 09:23:28
6007 [ssh-add.1 ssh.1]
6008 add missing .El against .Bl.
6009 - markus@cvs.openbsd.org 2000/09/04 13:03:41
6010 [session.c]
6011 missing close; ok theo
6012 - markus@cvs.openbsd.org 2000/09/04 13:07:21
6013 [session.c]
6014 fix get_last_login_time order; from andre@van-veen.de
6015 - markus@cvs.openbsd.org 2000/09/04 13:10:09
6016 [sftp-server.c]
6017 more cast fixes; from mouring@pconline.com
6018 - markus@cvs.openbsd.org 2000/09/04 13:06:04
6019 [session.c]
6020 set SSH_ORIGINAL_COMMAND; from Leakin@dfw.nostrum.com, bet@rahul.net
6021 - (djm) Cleanup after import. Fix sftp-server compilation, Makefile
3c62e7eb 6022 - (djm) Merge cygwin support from Corinna Vinschen <vinschen@cygnus.com>
6023
1e61f54a 602420000903
6025 - (djm) Fix Redhat init script
6026
c80876b4 602720000901
6028 - (djm) Pick up Jim's new X11-askpass
6029 - (djm) Release 2.2.0p1
6030
8b4a0d08 603120000831
bcbf86ec 6032 - (djm) Workaround SIGPIPE problems on SCO. Fix from Aran Cox
8b4a0d08 6033 <acox@cv.telegroup.com>
b817711d 6034 - (djm) Pick up new version (2.2.0) from OpenBSD CVS
8b4a0d08 6035
0b65b628 603620000830
6037 - (djm) Compile warning fixes from Mark Miller <markm@swoon.net>
10fa00c8 6038 - (djm) Periodically rekey arc4random
6039 - (djm) Clean up diff against OpenBSD.
bcbf86ec 6040 - (djm) HPUX 11 needs USE_PIPES as well: Kevin Steves
2b10f47a 6041 <stevesk@sweden.hp.com>
b33a2e6e 6042 - (djm) Quieten the pam delete credentials error message
44839801 6043 - (djm) Fix printing of $DISPLAY hack if set by system type. Report from
6044 Kevin Steves <stevesk@sweden.hp.com>
84a770d1 6045 - (djm) NeXT patch from Ben Lindstrom <mouring@pconline.com>
7efa2776 6046 - (djm) Fix doh in bsd-arc4random.c
0b65b628 6047
9aaf9be4 604820000829
bcbf86ec 6049 - (djm) Fix ^C ignored issue on Solaris. Diagnosis from Gert
6050 Doering <gert@greenie.muc.de>, John Horne <J.Horne@plymouth.ac.uk> and
9aaf9be4 6051 Garrick James <garrick@james.net>
b5f90139 6052 - (djm) Check for SCO pty naming style (ptyp%d/ttyp%d). Based on fix from
6053 Bastian Trompetter <btrompetter@firemail.de>
698d107e 6054 - (djm) NeXT tweaks from Ben Lindstrom <mouring@pconline.com>
14a9a859 6055 - More OpenBSD updates:
6056 - deraadt@cvs.openbsd.org 2000/08/24 15:46:59
6057 [scp.c]
6058 off_t in sink, to fix files > 2GB, i think, test is still running ;-)
6059 - deraadt@cvs.openbsd.org 2000/08/25 10:10:06
6060 [session.c]
6061 Wall
6062 - markus@cvs.openbsd.org 2000/08/26 04:33:43
6063 [compat.c]
6064 ssh.com-2.3.0
6065 - markus@cvs.openbsd.org 2000/08/27 12:18:05
6066 [compat.c]
6067 compatibility with future ssh.com versions
6068 - deraadt@cvs.openbsd.org 2000/08/27 21:50:55
6069 [auth-krb4.c session.c ssh-add.c sshconnect.c uidswap.c]
6070 print uid/gid as unsigned
6071 - markus@cvs.openbsd.org 2000/08/28 13:51:00
6072 [ssh.c]
6073 enable -n and -f for ssh2
6074 - markus@cvs.openbsd.org 2000/08/28 14:19:53
6075 [ssh.c]
6076 allow combination of -N and -f
6077 - markus@cvs.openbsd.org 2000/08/28 14:20:56
6078 [util.c]
6079 util.c
6080 - markus@cvs.openbsd.org 2000/08/28 14:22:02
6081 [util.c]
6082 undo
6083 - markus@cvs.openbsd.org 2000/08/28 14:23:38
6084 [util.c]
6085 don't complain if setting NONBLOCK fails with ENODEV
9aaf9be4 6086
137d7b6c 608720000823
6088 - (djm) Define USE_PIPES to avoid socketpair problems on HPUX 10 and SunOS 4
bcbf86ec 6089 Avoids "scp never exits" problem. Reports from Lutz Jaenicke
6090 <Lutz.Jaenicke@aet.TU-Cottbus.DE> and Tamito KAJIYAMA
137d7b6c 6091 <kajiyama@grad.sccs.chukyo-u.ac.jp>
2e73a022 6092 - (djm) Pick up LOGIN_PROGRAM from environment or PATH if not set by headers
da40ab4d 6093 - (djm) Add local version to version.h
ea788c22 6094 - (djm) Don't reseed arc4random everytime it is used
2e73a022 6095 - (djm) OpenBSD CVS updates:
6096 - deraadt@cvs.openbsd.org 2000/08/18 20:07:23
6097 [ssh.c]
6098 accept remsh as a valid name as well; roman@buildpoint.com
6099 - deraadt@cvs.openbsd.org 2000/08/18 20:17:13
6100 [deattack.c crc32.c packet.c]
6101 rename crc32() to ssh_crc32() to avoid zlib name clash. do not move to
6102 libz crc32 function yet, because it has ugly "long"'s in it;
6103 oneill@cs.sfu.ca
6104 - deraadt@cvs.openbsd.org 2000/08/18 20:26:08
6105 [scp.1 scp.c]
6106 -S prog support; tv@debian.org
6107 - deraadt@cvs.openbsd.org 2000/08/18 20:50:07
6108 [scp.c]
6109 knf
6110 - deraadt@cvs.openbsd.org 2000/08/18 20:57:33
6111 [log-client.c]
6112 shorten
6113 - markus@cvs.openbsd.org 2000/08/19 12:48:11
6114 [channels.c channels.h clientloop.c ssh.c ssh.h]
6115 support for ~. in ssh2
6116 - deraadt@cvs.openbsd.org 2000/08/19 15:29:40
6117 [crc32.h]
6118 proper prototype
6119 - markus@cvs.openbsd.org 2000/08/19 15:34:44
bcbf86ec 6120 [authfd.c authfd.h key.c key.h ssh-add.1 ssh-add.c ssh-agent.1]
6121 [ssh-agent.c ssh-keygen.c sshconnect1.c sshconnect2.c Makefile]
2e73a022 6122 [fingerprint.c fingerprint.h]
6123 add SSH2/DSA support to the agent and some other DSA related cleanups.
6124 (note that we cannot talk to ssh.com's ssh2 agents)
6125 - markus@cvs.openbsd.org 2000/08/19 15:55:52
6126 [channels.c channels.h clientloop.c]
6127 more ~ support for ssh2
6128 - markus@cvs.openbsd.org 2000/08/19 16:21:19
6129 [clientloop.c]
6130 oops
6131 - millert@cvs.openbsd.org 2000/08/20 12:25:53
6132 [session.c]
6133 We have to stash the result of get_remote_name_or_ip() before we
6134 close our socket or getpeername() will get EBADF and the process
6135 will exit. Only a problem for "UseLogin yes".
6136 - millert@cvs.openbsd.org 2000/08/20 12:30:59
6137 [session.c]
6138 Only check /etc/nologin if "UseLogin no" since login(1) may have its
6139 own policy on determining who is allowed to login when /etc/nologin
6140 is present. Also use the _PATH_NOLOGIN define.
6141 - millert@cvs.openbsd.org 2000/08/20 12:42:43
6142 [auth1.c auth2.c session.c ssh.c]
6143 Add calls to setusercontext() and login_get*(). We basically call
6144 setusercontext() in most places where previously we did a setlogin().
6145 Add default login.conf file and put root in the "daemon" login class.
6146 - millert@cvs.openbsd.org 2000/08/21 10:23:31
6147 [session.c]
6148 Fix incorrect PATH setting; noted by Markus.
137d7b6c 6149
c345cf9d 615020000818
6151 - (djm) OpenBSD CVS changes:
6152 - markus@cvs.openbsd.org 2000/07/22 03:14:37
6153 [servconf.c servconf.h sshd.8 sshd.c sshd_config]
6154 random early drop; ok theo, niels
6155 - deraadt@cvs.openbsd.org 2000/07/26 11:46:51
6156 [ssh.1]
6157 typo
6158 - deraadt@cvs.openbsd.org 2000/08/01 11:46:11
6159 [sshd.8]
6160 many fixes from pepper@mail.reppep.com
6161 - provos@cvs.openbsd.org 2000/08/01 13:01:42
6162 [Makefile.in util.c aux.c]
6163 rename aux.c to util.c to help with cygwin port
6164 - deraadt@cvs.openbsd.org 2000/08/02 00:23:31
6165 [authfd.c]
6166 correct sun_len; Alexander@Leidinger.net
6167 - provos@cvs.openbsd.org 2000/08/02 10:27:17
6168 [readconf.c sshd.8]
6169 disable kerberos authentication by default
6170 - provos@cvs.openbsd.org 2000/08/02 11:27:05
6171 [sshd.8 readconf.c auth-krb4.c]
6172 disallow kerberos authentication if we can't verify the TGT; from
6173 dugsong@
6174 kerberos authentication is on by default only if you have a srvtab.
6175 - markus@cvs.openbsd.org 2000/08/04 14:30:07
6176 [auth.c]
6177 unused
6178 - markus@cvs.openbsd.org 2000/08/04 14:30:35
6179 [sshd_config]
6180 MaxStartups
6181 - markus@cvs.openbsd.org 2000/08/15 13:20:46
6182 [authfd.c]
6183 cleanup; ok niels@
6184 - markus@cvs.openbsd.org 2000/08/17 14:05:10
6185 [session.c]
6186 cleanup login(1)-like jobs, no duplicate utmp entries
6187 - markus@cvs.openbsd.org 2000/08/17 14:06:34
6188 [session.c sshd.8 sshd.c]
6189 sshd -u len, similar to telnetd
1a022229 6190 - (djm) Lastlog was not getting closed after writing login entry
39987cc0 6191 - (djm) Add Solaris package support from Rip Loomis <loomisg@cist.saic.com>
c345cf9d 6192
416ed5a7 619320000816
6194 - (djm) Replacement for inet_ntoa for Irix (which breaks on gcc)
bcbf86ec 6195 - (djm) Fix strerror replacement for old SunOS. Based on patch from
416ed5a7 6196 Charles Levert <charles@comm.polymtl.ca>
bcbf86ec 6197 - (djm) Seperate arc4random into seperate file and use OpenSSL's RC4
416ed5a7 6198 implementation.
ba606eb2 6199 - (djm) SUN_LEN macro for systems which lack it
416ed5a7 6200
dbaa2e87 620120000815
6202 - (djm) More SunOS 4.1.x fixes from Nate Itkin <nitkin@europa.com>
cd352c82 6203 - (djm) Avoid failures on Irix when ssh is not setuid. Fix from
6204 Michael Stone <mstone@cs.loyola.edu>
d93a7e5a 6205 - (djm) Don't seek in directory based lastlogs
bcbf86ec 6206 - (djm) Fix --with-ipaddr-display configure option test. Patch from
d93a7e5a 6207 Jarno Huuskonen <jhuuskon@messi.uku.fi>
2a2cb9e7 6208 - (djm) Fix AIX limits from Alexandre Oliva <oliva@lsd.ic.unicamp.br>
dbaa2e87 6209
6c33bf70 621020000813
6211 - (djm) Add $(srcdir) to includes when compiling (for VPATH). Report from
6212 Fabrice bacchella <fabrice.bacchella@marchfirst.fr>
6213
3fcce26c 621420000809
bcbf86ec 6215 - (djm) Define AIX hard limits if headers don't. Report from
3fcce26c 6216 Bill Painter <william.t.painter@lmco.com>
bcbf86ec 6217 - (djm) utmp direct write & SunOS 4 patch from Charles Levert
32eec038 6218 <charles@comm.polymtl.ca>
3fcce26c 6219
71d43804 622020000808
6221 - (djm) Cleanup Redhat RPMs. Generate keys at runtime rather than install
6222 time, spec file cleanup.
6223
f9bcea07 622420000807
378f2232 6225 - (djm) Set 0755 on binaries during install. Report from Lutz Jaenicke
47670e77 6226 - (djm) Suppress error messages on channel close shutdown() failurs
6227 works around Linux bug. Patch from Zack Weinberg <zack@wolery.cumb.org>
378f2232 6228 - (djm) Add some more entropy collection commands from Lutz Jaenicke
f9bcea07 6229
bcf89935 623020000725
6231 - (djm) Fix autoconf typo: HAVE_BINRESVPORT_AF -> HAVE_BINDRESVPORT_AF
6232
4c8722d9 623320000721
6234 - (djm) OpenBSD CVS updates:
6235 - markus@cvs.openbsd.org 2000/07/16 02:27:22
6236 [authfd.c authfd.h channels.c clientloop.c ssh-add.c ssh-agent.c ssh.c]
6237 [sshconnect1.c sshconnect2.c]
6238 make ssh-add accept dsa keys (the agent does not)
6239 - djm@cvs.openbsd.org 2000/07/17 19:25:02
6240 [sshd.c]
6241 Another closing of stdin; ok deraadt
6242 - markus@cvs.openbsd.org 2000/07/19 18:33:12
6243 [dsa.c]
6244 missing free, reorder
6245 - markus@cvs.openbsd.org 2000/07/20 16:23:14
6246 [ssh-keygen.1]
6247 document input and output files
6248
240777b8 624920000720
4c8722d9 6250 - (djm) Spec file fix from Petr Novotny <Petr.Novotny@antek.cz>
240777b8 6251
3c7def32 625220000716
4c8722d9 6253 - (djm) Release 2.1.1p4
3c7def32 6254
819b676f 625520000715
704b1659 6256 - (djm) OpenBSD CVS updates
6257 - provos@cvs.openbsd.org 2000/07/13 16:53:22
6258 [aux.c readconf.c servconf.c ssh.h]
6259 allow multiple whitespace but only one '=' between tokens, bug report from
6260 Ralf S. Engelschall <rse@engelschall.com> but different fix. okay deraadt@
6261 - provos@cvs.openbsd.org 2000/07/13 17:14:09
6262 [clientloop.c]
6263 typo; todd@fries.net
6264 - provos@cvs.openbsd.org 2000/07/13 17:19:31
6265 [scp.c]
6266 close can fail on AFS, report error; from Greg Hudson <ghudson@mit.edu>
6267 - markus@cvs.openbsd.org 2000/07/14 16:59:46
6268 [readconf.c servconf.c]
6269 allow leading whitespace. ok niels
6270 - djm@cvs.openbsd.org 2000/07/14 22:01:38
6271 [ssh-keygen.c ssh.c]
6272 Always create ~/.ssh with mode 700; ok Markus
819b676f 6273 - Fixes for SunOS 4.1.4 from Gordon Atwood <gordon@cs.ualberta.ca>
6274 - Include floatingpoint.h for entropy.c
6275 - strerror replacement
704b1659 6276
3f7a7e4a 627720000712
c37fb3c1 6278 - (djm) Remove -lresolve for Reliant Unix
3f7a7e4a 6279 - (djm) OpenBSD CVS Updates:
6280 - deraadt@cvs.openbsd.org 2000/07/11 02:11:34
6281 [session.c sshd.c ]
6282 make MaxStartups code still work with -d; djm
6283 - deraadt@cvs.openbsd.org 2000/07/11 13:17:45
6284 [readconf.c ssh_config]
6285 disable FallBackToRsh by default
c37fb3c1 6286 - (djm) Replace in_addr_t with u_int32_t in bsd-inet_aton.c. Report from
6287 Ben Lindstrom <mouring@pconline.com>
1e970014 6288 - (djm) Make building of X11-Askpass and GNOME-Askpass optional in RPM
6289 spec file.
dcb36e5d 6290 - (djm) Released 2.1.1p3
3f7a7e4a 6291
56118702 629220000711
6293 - (djm) Fixup for AIX getuserattr() support from Tom Bertelson
6294 <tbert@abac.com>
132dd316 6295 - (djm) ReliantUNIX support from Udo Schweigert <ust@cert.siemens.de>
bcbf86ec 6296 - (djm) NeXT: dirent structures to get scp working from Ben Lindstrom
c99e5056 6297 <mouring@pconline.com>
bcbf86ec 6298 - (djm) Fix broken inet_ntoa check and ut_user/ut_name confusion, report
dc2a6d09 6299 from Jim Watt <jimw@peisj.pebio.com>
2d9a148e 6300 - (djm) Replaced bsd-snprintf.c with one from Mutt source tree, it is known
6301 to compile on more platforms (incl NeXT).
cc6f2c4c 6302 - (djm) Added bsd-inet_aton and configure support for NeXT
aae19451 6303 - (djm) Misc NeXT fixes from Ben Lindstrom <mouring@pconline.com>
089fbbd2 6304 - (djm) OpenBSD CVS updates:
6305 - markus@cvs.openbsd.org 2000/06/26 03:22:29
6306 [authfd.c]
6307 cleanup, less cut&paste
6308 - markus@cvs.openbsd.org 2000/06/26 15:59:19
6309 [servconf.c servconf.h session.c sshd.8 sshd.c]
bcbf86ec 6310 MaxStartups: limit number of unauthenticated connections, work by
089fbbd2 6311 theo and me
6312 - deraadt@cvs.openbsd.org 2000/07/05 14:18:07
6313 [session.c]
6314 use no_x11_forwarding_flag correctly; provos ok
6315 - provos@cvs.openbsd.org 2000/07/05 15:35:57
6316 [sshd.c]
6317 typo
6318 - aaron@cvs.openbsd.org 2000/07/05 22:06:58
6319 [scp.1 ssh-agent.1 ssh-keygen.1 sshd.8]
bcbf86ec 6320 Insert more missing .El directives. Our troff really should identify
089fbbd2 6321 these and spit out a warning.
6322 - todd@cvs.openbsd.org 2000/07/06 21:55:04
6323 [auth-rsa.c auth2.c ssh-keygen.c]
6324 clean code is good code
6325 - deraadt@cvs.openbsd.org 2000/07/07 02:14:29
6326 [serverloop.c]
6327 sense of port forwarding flag test was backwards
6328 - provos@cvs.openbsd.org 2000/07/08 17:17:31
6329 [compat.c readconf.c]
6330 replace strtok with strsep; from David Young <dyoung@onthejob.net>
6331 - deraadt@cvs.openbsd.org 2000/07/08 19:21:15
6332 [auth.h]
6333 KNF
6334 - ho@cvs.openbsd.org 2000/07/08 19:27:33
6335 [compat.c readconf.c]
6336 Better conditions for strsep() ending.
6337 - ho@cvs.openbsd.org 2000/07/10 10:27:05
6338 [readconf.c]
6339 Get the correct message on errors. (niels@ ok)
6340 - ho@cvs.openbsd.org 2000/07/10 10:30:25
6341 [cipher.c kex.c servconf.c]
6342 strtok() --> strsep(). (niels@ ok)
5540ea9b 6343 - (djm) Fix problem with debug mode and MaxStartups
eb37534b 6344 - (djm) Don't generate host keys when $(DESTDIR) is set (e.g. during RPM
6345 builds)
229f64ee 6346 - (djm) Add strsep function from OpenBSD libc for systems that lack it
56118702 6347
a8545c6c 634820000709
6349 - (djm) Only enable PAM_TTY kludge for Linux. Problem report from
6350 Kevin Steves <stevesk@sweden.hp.com>
ec90a7d6 6351 - (djm) Match prototype and function declaration for rresvport_af.
6352 Problem report from Niklas Edmundsson <nikke@ing.umu.se>
bcbf86ec 6353 - (djm) Missing $(DESTDIR) on host-key target causing problems with RPM
732e8ac5 6354 builds. Problem report from Gregory Leblanc <GLeblanc@cu-portland.edu>
37f1df94 6355 - (djm) Replace ut_name with ut_user. Patch from Jim Watt
6356 <jimw@peisj.pebio.com>
264dce47 6357 - (djm) Fix pam sprintf fix
6358 - (djm) Cleanup entropy collection code a little more. Split initialisation
6359 from seeding, perform intialisation immediatly at start, be careful with
6360 uids. Based on problem report from Jim Watt <jimw@peisj.pebio.com>
5bf9cfe9 6361 - (djm) More NeXT compatibility from Ben Lindstrom <mouring@pconline.com>
6362 Including sigaction() et al. replacements
bcbf86ec 6363 - (djm) AIX getuserattr() session initialisation from Tom Bertelson
eeec075f 6364 <tbert@abac.com>
a8545c6c 6365
e2902a5b 636620000708
bcbf86ec 6367 - (djm) Fix bad fprintf format handling in auth-pam.c. Patch from
e2902a5b 6368 Aaron Hopkins <aaron@die.net>
7a33f831 6369 - (djm) Fix incorrect configure handling of --with-rsh-path option. Fix from
6370 Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 6371 - (djm) Fixed undefined variables for OSF SIA. Report from
b3f162ba 6372 Baars, Henk <Hendrik.Baars@nl.origin-it.com>
bcbf86ec 6373 - (djm) Handle EWOULDBLOCK returns from read() and write() in atomicio.c
b28e4a3b 6374 Fix from Marquess, Steve Mr JMLFDC <Steve.Marquess@DET.AMEDD.ARMY.MIL>
bcbf86ec 6375 - (djm) Don't use inet_addr.
e2902a5b 6376
5637650d 637720000702
6378 - (djm) Fix brace mismatch from Corinna Vinschen <vinschen@cygnus.com>
27494968 6379 - (djm) Stop shadow expiry checking from preventing logins with NIS. Based
6380 on fix from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
a4070484 6381 - (djm) Use standard OpenSSL functions in auth-skey.c. Patch from
6382 Chris, the Young One <cky@pobox.com>
bcbf86ec 6383 - (djm) Fix scp progress meter on really wide terminals. Based on patch
88726b31 6384 from James H. Cloos Jr. <cloos@jhcloos.com>
5637650d 6385
388e9f9f 638620000701
6387 - (djm) Fix Tru64 SIA problems reported by John P Speno <speno@isc.upenn.edu>
daaff4d5 6388 - (djm) Login fixes from Tom Bertelson <tbert@abac.com>
82258d68 6389 - (djm) Replace "/bin/sh" with _PATH_BSHELL. Report from Corinna Vinschen
6390 <vinschen@cygnus.com>
30228d7c 6391 - (djm) Replace "/usr/bin/login" with LOGIN_PROGRAM
2647ae26 6392 - (djm) Added check for broken snprintf() functions which do not correctly
6393 terminate output string and attempt to use replacement.
46158300 6394 - (djm) Released 2.1.1p2
388e9f9f 6395
9f32ceb4 639620000628
6397 - (djm) Fixes to lastlog code for Irix
6398 - (djm) Use atomicio in loginrec
3206bb3b 6399 - (djm) Patch from Michael Stone <mstone@cs.loyola.edu> to add support for
6400 Irix 6.x array sessions, project id's, and system audit trail id.
9e0c3e1f 6401 - (djm) Added 'distprep' make target to simplify packaging
bcbf86ec 6402 - (djm) Added patch from Chris Adams <cmadams@hiwaay.net> to add OSF SIA
4d33e531 6403 support. Enable using "USE_SIA=1 ./configure [options]"
61e96248 6404
d8caae24 640520000627
6406 - (djm) Fixes to login code - not setting li->uid, cleanups
a05a70ab 6407 - (djm) Formatting
d8caae24 6408
fe30cc2e 640920000626
3e98362e 6410 - (djm) Better fix to aclocal tests from Garrick James <garrick@james.net>
4cb5ffa0 6411 - (djm) Account expiry support from Andreas Steinmetz <ast@domdv.de>
6412 - (djm) Added password expiry checking (no password change support)
be0b9bb7 6413 - (djm) Make EGD failures non-fatal if OpenSSL's entropy pool is still OK
6414 based on patch from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
b5b3f75d 6415 - (djm) Fix fixed EGD code.
3e98362e 6416 - OpenBSD CVS update
6417 - provos@cvs.openbsd.org 2000/06/25 14:17:58
6418 [channels.c]
6419 correct check for bad channel ids; from Wei Dai <weidai@eskimo.com>
6420
1c04b088 642120000623
bcbf86ec 6422 - (djm) Use sa_family_t in prototype for rresvport_af. Patch from
1c04b088 6423 Svante Signell <svante.signell@telia.com>
6424 - (djm) Autoconf logic to define sa_family_t if it is missing
e5a0294f 6425 - OpenBSD CVS Updates:
6426 - markus@cvs.openbsd.org 2000/06/22 10:32:27
6427 [sshd.c]
6428 missing atomicio; report from Steve.Marquess@DET.AMEDD.ARMY.MIL
6429 - djm@cvs.openbsd.org 2000/06/22 17:55:00
6430 [auth-krb4.c key.c radix.c uuencode.c]
6431 Missing CVS idents; ok markus
1c04b088 6432
f528fdf2 643320000622
6434 - (djm) Automatically generate host key during "make install". Suggested
6435 by Gary E. Miller <gem@rellim.com>
6436 - (djm) Paranoia before kill() system call
74fc9186 6437 - OpenBSD CVS Updates:
6438 - markus@cvs.openbsd.org 2000/06/18 18:50:11
6439 [auth2.c compat.c compat.h sshconnect2.c]
6440 make userauth+pubkey interop with ssh.com-2.2.0
6441 - markus@cvs.openbsd.org 2000/06/18 20:56:17
6442 [dsa.c]
6443 mem leak + be more paranoid in dsa_verify.
6444 - markus@cvs.openbsd.org 2000/06/18 21:29:50
6445 [key.c]
6446 cleanup fingerprinting, less hardcoded sizes
6447 - markus@cvs.openbsd.org 2000/06/19 19:39:45
6448 [atomicio.c auth-options.c auth-passwd.c auth-rh-rsa.c auth-rhosts.c]
6449 [auth-rsa.c auth-skey.c authfd.c authfd.h authfile.c bufaux.c bufaux.h]
bcbf86ec 6450 [buffer.c buffer.h canohost.c channels.c channels.h cipher.c cipher.h]
74fc9186 6451 [clientloop.c compat.c compat.h compress.c compress.h crc32.c crc32.h]
6452 [deattack.c dispatch.c dsa.c fingerprint.c fingerprint.h getput.h hmac.c]
bcbf86ec 6453 [kex.c log-client.c log-server.c login.c match.c mpaux.c mpaux.h nchan.c]
6454 [nchan.h packet.c packet.h pty.c pty.h readconf.c readconf.h readpass.c]
74fc9186 6455 [rsa.c rsa.h scp.c servconf.c servconf.h ssh-add.c ssh-keygen.c ssh.c]
6456 [ssh.h tildexpand.c ttymodes.c ttymodes.h uidswap.c xmalloc.c xmalloc.h]
6457 OpenBSD tag
6458 - markus@cvs.openbsd.org 2000/06/21 10:46:10
6459 sshconnect2.c missing free; nuke old comment
f528fdf2 6460
e5fe9a1f 646120000620
6462 - (djm) Replace use of '-o' and '-a' logical operators in configure tests
986a22ec 6463 with '||' and '&&'. As suggested by Jim Knoble <jmknoble@jmknoble.cx>
e5fe9a1f 6464 to fix SCO Unixware problem reported by Gary E. Miller <gem@rellim.com>
c03aced4 6465 - (djm) Typo in loginrec.c
e5fe9a1f 6466
cbd7492e 646720000618
6468 - (djm) Add summary of configure options to end of ./configure run
bcbf86ec 6469 - (djm) Not all systems define RUSAGE_SELF & RUSAGE_CHILDREN. Report from
cbd7492e 6470 Michael Stone <mstone@cs.loyola.edu>
bcbf86ec 6471 - (djm) rusage is a privileged operation on some Unices (incl.
cbd7492e 6472 Solaris 2.5.1). Report from Paul D. Smith <pausmith@nortelnetworks.com>
bcbf86ec 6473 - (djm) Avoid PAM failures when running without a TTY. Report from
cbd7492e 6474 Martin Petrak <petrak@spsknm.schools.sk>
6475 - (djm) Include sys/types.h when including netinet/in.h in configure tests.
6476 Patch from Jun-ichiro itojun Hagino <itojun@iijlab.net>
729bfe59 6477 - (djm) Started merge of Ben Lindstrom's <mouring@pconline.com> NeXT support
38c295d6 6478 - OpenBSD CVS updates:
6479 - deraadt@cvs.openbsd.org 2000/06/17 09:58:46
6480 [channels.c]
6481 everyone says "nix it" (remove protocol 2 debugging message)
6482 - markus@cvs.openbsd.org 2000/06/17 13:24:34
6483 [sshconnect.c]
6484 allow extended server banners
6485 - markus@cvs.openbsd.org 2000/06/17 14:30:10
6486 [sshconnect.c]
6487 missing atomicio, typo
6488 - jakob@cvs.openbsd.org 2000/06/17 16:52:34
6489 [servconf.c servconf.h session.c sshd.8 sshd_config]
6490 add support for ssh v2 subsystems. ok markus@.
6491 - deraadt@cvs.openbsd.org 2000/06/17 18:57:48
6492 [readconf.c servconf.c]
6493 include = in WHITESPACE; markus ok
6494 - markus@cvs.openbsd.org 2000/06/17 19:09:10
6495 [auth2.c]
6496 implement bug compatibility with ssh-2.0.13 pubkey, server side
6497 - markus@cvs.openbsd.org 2000/06/17 21:00:28
6498 [compat.c]
6499 initial support for ssh.com's 2.2.0
6500 - markus@cvs.openbsd.org 2000/06/17 21:16:09
6501 [scp.c]
6502 typo
6503 - markus@cvs.openbsd.org 2000/06/17 22:05:02
6504 [auth-rsa.c auth2.c serverloop.c session.c auth-options.c auth-options.h]
6505 split auth-rsa option parsing into auth-options
6506 add options support to authorized_keys2
6507 - markus@cvs.openbsd.org 2000/06/17 22:42:54
6508 [session.c]
6509 typo
cbd7492e 6510
509b1f88 651120000613
6512 - (djm) Fixes from Andrew McGill <andrewm@datrix.co.za>:
6513 - Platform define for SCO 3.x which breaks on /dev/ptmx
6514 - Detect and try to fix missing MAXPATHLEN
a4d05724 6515 - (djm) Fix short copy in loginrec.c (based on patch from Phill Camp
6516 <P.S.S.Camp@ukc.ac.uk>
509b1f88 6517
09564242 651820000612
6519 - (djm) Glob manpages in RPM spec files to catch compressed files
6520 - (djm) Full license in auth-pam.c
08ae384f 6521 - (djm) Configure fixes from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
383207f7 6522 - (andre) AIX, lastlog, configure fixes from Tom Bertelson <tbert@abac.com>:
6523 - Don't try to retrieve lastlog from wtmp/wtmpx if DISABLE_LASTLOG is
6524 def'd
6525 - Set AIX to use preformatted manpages
61e96248 6526
74b224a0 652720000610
6528 - (djm) Minor doc tweaks
217ab55e 6529 - (djm) Fix for configure on bash2 from Jim Knoble <jmknoble@jmknoble.cx>
74b224a0 6530
32c80420 653120000609
6532 - (djm) Patch from Kenji Miyake <kenji@miyake.org> to disable utmp usage
6533 (in favour of utmpx) on Solaris 8
6534
fa649821 653520000606
48c99b2c 6536 - (djm) Cleanup of entropy.c. Reorganised code, removed second pass through
6537 list of commands (by default). Removed verbose debugging (by default).
bcbf86ec 6538 - (djm) Increased command entropy estimates and default entropy collection
48c99b2c 6539 timeout
f988dce5 6540 - (djm) Remove duplicate headers from loginrec.c
c5fa2eb0 6541 - (djm) Don't add /usr/local/lib to library search path on Irix
bcbf86ec 6542 - (djm) Fix rsh path in RPMs. Report from Jason L Tibbitts III
fa649821 6543 <tibbs@math.uh.edu>
1e83f2a2 6544 - (djm) Warn user if grabs fail in GNOME askpass. Patch from Zack Weinberg
6545 <zack@wolery.cumb.org>
fa649821 6546 - (djm) OpenBSD CVS updates:
6547 - todd@cvs.openbsd.org
6548 [sshconnect2.c]
6549 teach protocol v2 to count login failures properly and also enable an
6550 explanation of why the password prompt comes up again like v1; this is NOT
6551 crypto
61e96248 6552 - markus@cvs.openbsd.org
fa649821 6553 [readconf.c readconf.h servconf.c servconf.h session.c ssh.1 ssh.c sshd.8]
6554 xauth_location support; pr 1234
6555 [readconf.c sshconnect2.c]
6556 typo, unused
6557 [session.c]
6558 allow use_login only for login sessions, otherwise remote commands are
6559 execed with uid==0
6560 [sshd.8]
6561 document UseLogin better
6562 [version.h]
6563 OpenSSH 2.1.1
6564 [auth-rsa.c]
bcbf86ec 6565 fix match_hostname() logic for auth-rsa: deny access if we have a
fa649821 6566 negative match or no match at all
6567 [channels.c hostfile.c match.c]
bcbf86ec 6568 don't panic if mkdtemp fails for authfwd; jkb@yahoo-inc.com via
fa649821 6569 kris@FreeBSD.org
6570
8e7b16f8 657120000606
bcbf86ec 6572 - (djm) Added --with-cflags, --with-ldflags and --with-libs options to
8e7b16f8 6573 configure.
6574
d7c0f3d5 657520000604
6576 - Configure tweaking for new login code on Irix 5.3
2d6c411f 6577 - (andre) login code changes based on djm feedback
d7c0f3d5 6578
2d6c411f 657920000603
6580 - (andre) New login code
6581 - Remove bsd-login.[ch] and all the OpenBSD-derived code in login.c
6582 - Add loginrec.[ch], logintest.c and autoconf code
61e96248 6583
5daf7064 658420000531
6585 - Cleanup of auth.c, login.c and fake-*
6586 - Cleanup of auth-pam.c, save and print "account expired" error messages
e5662474 6587 - Fix EGD read bug by IWAMURO Motonori <iwa@mmp.fujitsu.co.jp>
69134b9b 6588 - Rewrote bsd-login to use proper utmp API if available. Major cleanup
6589 of fallback DIY code.
5daf7064 6590
b9f446d1 659120000530
6592 - Define atexit for old Solaris
b02ebca1 6593 - Fix buffer overrun in login.c for systems which use syslen in utmpx.
6594 patch from YOSHIFUJI Hideaki <yoshfuji@cerberus.nemoto.ecei.tohoku.ac.jp>
71276795 6595 - OpenBSD CVS updates:
6596 - markus@cvs.openbsd.org
6597 [session.c]
6598 make x11-fwd work w/ localhost (xauth add host/unix:11)
6599 [cipher.c compat.c readconf.c servconf.c]
6600 check strtok() != NULL; ok niels@
6601 [key.c]
6602 fix key_read() for uuencoded keys w/o '='
6603 [serverloop.c]
6604 group ssh1 vs. ssh2 in serverloop
6605 [kex.c kex.h myproposal.h sshconnect2.c sshd.c]
6606 split kexinit/kexdh, factor out common code
6607 [readconf.c ssh.1 ssh.c]
6608 forwardagent defaults to no, add ssh -A
6609 - theo@cvs.openbsd.org
6610 [session.c]
6611 just some line shortening
60688ef9 6612 - Released 2.1.0p3
b9f446d1 6613
29611d9c 661420000520
6615 - Xauth fix from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
25422c70 6616 - Don't touch utmp if USE_UTMPX defined
a423beaf 6617 - SunOS 4.x support from Todd C. Miller <Todd.Miller@courtesan.com>
fc1e8bf4 6618 - SIGCHLD fix for AIX and HPUX from Tom Bertelson <tbert@abac.com>
bcbf86ec 6619 - HPUX and Configure fixes from Lutz Jaenicke
fc1e8bf4 6620 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
bcbf86ec 6621 - Use mkinstalldirs script to make directories instead of non-portable
fc1e8bf4 6622 "install -d". Suggested by Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
a905808d 6623 - Doc cleanup
29611d9c 6624
301e9b01 662520000518
6626 - Include Andre Lucas' fixprogs script. Forgot to "cvs add" it yesterday
6627 - OpenBSD CVS updates:
6628 - markus@cvs.openbsd.org
6629 [sshconnect.c]
6630 copy only ai_addrlen bytes; misiek@pld.org.pl
6631 [auth.c]
bcbf86ec 6632 accept an empty shell in authentication; bug reported by
301e9b01 6633 chris@tinker.ucr.edu
6634 [serverloop.c]
6635 we don't have stderr for interactive terminal sessions (fcntl errors)
6636
ad85db64 663720000517
6638 - Fix from Andre Lucas <andre.lucas@dial.pipex.com>
6639 - Fixes command line printing segfaults (spotter: Bladt Norbert)
6640 - Fixes erroneous printing of debug messages to syslog
6641 - Fixes utmp for MacOS X (spotter: Aristedes Maniatis)
6642 - Gives useful error message if PRNG initialisation fails
6643 - Reduced ssh startup delay
6644 - Measures cumulative command time rather than the time between reads
704b1659 6645 after select()
ad85db64 6646 - 'fixprogs' perl script to eliminate non-working entropy commands, and
704b1659 6647 optionally run 'ent' to measure command entropy
c1ef8333 6648 - Applied Tom Bertelson's <tbert@abac.com> AIX authentication fix
a64009ad 6649 - Avoid WCOREDUMP complation errors for systems that lack it
bcbf86ec 6650 - Avoid SIGCHLD warnings from entropy commands
28c1d5ce 6651 - Fix HAVE_PAM_GETENVLIST setting from Simon Wilkinson <sxw@dcs.ed.ac.uk>
0e73cc53 6652 - OpenBSD CVS update:
bcbf86ec 6653 - markus@cvs.openbsd.org
0e73cc53 6654 [ssh.c]
6655 fix usage()
6656 [ssh2.h]
6657 draft-ietf-secsh-architecture-05.txt
6658 [ssh.1]
6659 document ssh -T -N (ssh2 only)
6660 [channels.c serverloop.c ssh.h sshconnect.c sshd.c aux.c]
6661 enable nonblocking IO for sshd w/ proto 1, too; split out common code
6662 [aux.c]
6663 missing include
c04f75f1 6664 - Several patches from SAKAI Kiyotaka <ksakai@kso.netwk.ntt-at.co.jp>
6665 - INSTALL typo and URL fix
6666 - Makefile fix
6667 - Solaris fixes
bcbf86ec 6668 - Checking for ssize_t and memmove. Based on patch from SAKAI Kiyotaka
c04f75f1 6669 <ksakai@kso.netwk.ntt-at.co.jp>
afa5ee68 6670 - RSAless operation patch from kevin_oconnor@standardandpoors.com
d45e3d76 6671 - Detect OpenSSL seperatly from RSA
bcbf86ec 6672 - Better test for RSA (more compatible with RSAref). Based on work by
d45e3d76 6673 Ed Eden <ede370@stl.rural.usda.gov>
ad85db64 6674
3d1a1654 667520000513
bcbf86ec 6676 - Fix for non-recognised DSA keys from Arkadiusz Miskiewicz
3d1a1654 6677 <misiek@pld.org.pl>
6678
d02a3a00 667920000511
bcbf86ec 6680 - Fix for prng_seed permissions checking from Lutz Jaenicke
d02a3a00 6681 <Lutz.Jaenicke@aet.TU-Cottbus.DE>
3d1a1654 6682 - "make host-key" fix for Irix
d02a3a00 6683
d0c832f3 668420000509
6685 - OpenBSD CVS update
6686 - markus@cvs.openbsd.org
6687 [cipher.h myproposal.h readconf.c readconf.h servconf.c ssh.1 ssh.c]
6688 [ssh.h sshconnect1.c sshconnect2.c sshd.8]
6689 - complain about invalid ciphers in SSH1 (e.g. arcfour is SSH2 only)
6690 - hugh@cvs.openbsd.org
6691 [ssh.1]
6692 - zap typo
6693 [ssh-keygen.1]
6694 - One last nit fix. (markus approved)
6695 [sshd.8]
6696 - some markus certified spelling adjustments
6697 - markus@cvs.openbsd.org
6698 [auth2.c channels.c clientloop.c compat compat.h dsa.c kex.c]
6699 [sshconnect2.c ]
6700 - bug compat w/ ssh-2.0.13 x11, split out bugs
6701 [nchan.c]
6702 - no drain if ibuf_empty, fixes x11fwd problems; tests by fries@
6703 [ssh-keygen.c]
6704 - handle escapes in real and original key format, ok millert@
6705 [version.h]
6706 - OpenSSH-2.1
3dc1102e 6707 - Moved all the bsd-* and fake-* stuff into new libopenbsd-compat.a
e93ee87a 6708 - Doc updates
bcbf86ec 6709 - Cleanup of bsd-base64 headers, bugfix definitions of __b64_*. Reported
21e5304a 6710 by Andre Lucas <andre.lucas@dial.pipex.com>
d0c832f3 6711
ebdeb9a8 671220000508
6713 - Makefile and RPM spec fixes
6714 - Generate DSA host keys during "make key" or RPM installs
f6cde515 6715 - OpenBSD CVS update
6716 - markus@cvs.openbsd.org
6717 [clientloop.c sshconnect2.c]
6718 - make x11-fwd interop w/ ssh-2.0.13
6719 [README.openssh2]
6720 - interop w/ SecureFX
6721 - Release 2.0.0beta2
ebdeb9a8 6722
bcbf86ec 6723 - Configure caching and cleanup patch from Andre Lucas'
58d100bf 6724 <andre.lucas@dial.pipex.com>
6725
1d1ffb87 672620000507
6727 - Remove references to SSLeay.
6728 - Big OpenBSD CVS update
6729 - markus@cvs.openbsd.org
6730 [clientloop.c]
6731 - typo
6732 [session.c]
6733 - update proctitle on pty alloc/dealloc, e.g. w/ windows client
6734 [session.c]
6735 - update proctitle for proto 1, too
6736 [channels.h nchan.c serverloop.c session.c sshd.c]
6737 - use c-style comments
6738 - deraadt@cvs.openbsd.org
6739 [scp.c]
6740 - more atomicio
bcbf86ec 6741 - markus@cvs.openbsd.org
1d1ffb87 6742 [channels.c]
6743 - set O_NONBLOCK
6744 [ssh.1]
6745 - update AUTHOR
6746 [readconf.c ssh-keygen.c ssh.h]
6747 - default DSA key file ~/.ssh/id_dsa
6748 [clientloop.c]
6749 - typo, rm verbose debug
6750 - deraadt@cvs.openbsd.org
6751 [ssh-keygen.1]
6752 - document DSA use of ssh-keygen
6753 [sshd.8]
6754 - a start at describing what i understand of the DSA side
6755 [ssh-keygen.1]
6756 - document -X and -x
6757 [ssh-keygen.c]
6758 - simplify usage
bcbf86ec 6759 - markus@cvs.openbsd.org
1d1ffb87 6760 [sshd.8]
6761 - there is no rhosts_dsa
6762 [ssh-keygen.1]
6763 - document -y, update -X,-x
6764 [nchan.c]
6765 - fix close for non-open ssh1 channels
6766 [servconf.c servconf.h ssh.h sshd.8 sshd.c ]
6767 - s/DsaKey/HostDSAKey/, document option
6768 [sshconnect2.c]
6769 - respect number_of_password_prompts
6770 [channels.c channels.h servconf.c servconf.h session.c sshd.8]
6771 - GatewayPorts for sshd, ok deraadt@
6772 [ssh-add.1 ssh-agent.1 ssh.1]
6773 - more doc on: DSA, id_dsa, known_hosts2, authorized_keys2
6774 [ssh.1]
6775 - more info on proto 2
6776 [sshd.8]
6777 - sync AUTHOR w/ ssh.1
6778 [key.c key.h sshconnect.c]
6779 - print key type when talking about host keys
6780 [packet.c]
6781 - clear padding in ssh2
6782 [dsa.c key.c radix.c ssh.h sshconnect1.c uuencode.c uuencode.h]
6783 - replace broken uuencode w/ libc b64_ntop
6784 [auth2.c]
6785 - log failure before sending the reply
6786 [key.c radix.c uuencode.c]
6787 - remote trailing comments before calling __b64_pton
6788 [auth2.c readconf.c readconf.h servconf.c servconf.h ssh.1]
6789 [sshconnect2.c sshd.8]
6790 - add DSAAuthetication option to ssh/sshd, document SSH2 in sshd.8
6791 - Bring in b64_ntop and b64_pton from OpenBSD libc (bsd-base64.[ch])
6792
1a11e1ae 679320000502
0fbe8c74 6794 - OpenBSD CVS update
6795 [channels.c]
6796 - init all fds, close all fds.
6797 [sshconnect2.c]
6798 - check whether file exists before asking for passphrase
6799 [servconf.c servconf.h sshd.8 sshd.c]
6800 - PidFile, pr 1210
6801 [channels.c]
6802 - EINTR
6803 [channels.c]
6804 - unbreak, ok niels@
6805 [sshd.c]
6806 - unlink pid file, ok niels@
6807 [auth2.c]
6808 - Add missing #ifdefs; ok - markus
bcbf86ec 6809 - Add Andre Lucas' <andre.lucas@dial.pipex.com> patch to read entropy
d3083fbd 6810 gathering commands from a text file
1a11e1ae 6811 - Release 2.0.0beta1
6812
c4bc58eb 681320000501
6814 - OpenBSD CVS update
6815 [packet.c]
6816 - send debug messages in SSH2 format
3189621b 6817 [scp.c]
6818 - fix very rare EAGAIN/EINTR issues; based on work by djm
6819 [packet.c]
6820 - less debug, rm unused
6821 [auth2.c]
6822 - disable kerb,s/key in ssh2
6823 [sshd.8]
6824 - Minor tweaks and typo fixes.
6825 [ssh-keygen.c]
6826 - Put -d into usage and reorder. markus ok.
bcbf86ec 6827 - Include missing headers for OpenSSL tests. Fix from Phil Karn
44fb55e9 6828 <karn@ka9q.ampr.org>
bcbf86ec 6829 - Fixed __progname symbol collisions reported by Andre Lucas
3fd95d9a 6830 <andre.lucas@dial.pipex.com>
0d5f7abc 6831 - Merged bsd-login ttyslot and AIX utmp patch from Gert Doering
6832 <gd@hilb1.medat.de>
8cb940db 6833 - Add some missing ifdefs to auth2.c
8af50c98 6834 - Deprecate perl-tk askpass.
52bcc044 6835 - Irix portability fixes - don't include netinet headers more than once
6836 - Make sure we don't save PRNG seed more than once
c4bc58eb 6837
2b763e31 683820000430
6839 - Merge HP-UX fixes and TCB support from Ged Lodder <lodder@yacc.com.au>
b7a87eea 6840 - Integrate Andre Lucas' <andre.lucas@dial.pipex.com> entropy collection
6841 patch.
6842 - Adds timeout to entropy collection
6843 - Disables slow entropy sources
6844 - Load and save seed file
bcbf86ec 6845 - Changed entropy seed code to user per-user seeds only (server seed is
b7a87eea 6846 saved in root's .ssh directory)
6847 - Use atexit() and fatal cleanups to save seed on exit
0b242b12 6848 - More OpenBSD updates:
6849 [session.c]
6850 - don't call chan_write_failed() if we are not writing
6851 [auth-rsa.c auth1.c authfd.c hostfile.c ssh-agent.c]
6852 - keysize warnings error() -> log()
2b763e31 6853
a306f2dd 685420000429
6855 - Merge big update to OpenSSH-2.0 from OpenBSD CVS
6856 [README.openssh2]
6857 - interop w/ F-secure windows client
6858 - sync documentation
6859 - ssh_host_dsa_key not ssh_dsa_key
6860 [auth-rsa.c]
6861 - missing fclose
6862 [auth.c authfile.c compat.c dsa.c dsa.h hostfile.c key.c key.h radix.c]
6863 [readconf.c readconf.h ssh-add.c ssh-keygen.c ssh.c ssh.h sshconnect.c]
6864 [sshd.c uuencode.c uuencode.h authfile.h]
6865 - add DSA pubkey auth and other SSH2 fixes. use ssh-keygen -[xX]
6866 for trading keys with the real and the original SSH, directly from the
6867 people who invented the SSH protocol.
6868 [auth.c auth.h authfile.c sshconnect.c auth1.c auth2.c sshconnect.h]
6869 [sshconnect1.c sshconnect2.c]
6870 - split auth/sshconnect in one file per protocol version
6871 [sshconnect2.c]
6872 - remove debug
6873 [uuencode.c]
6874 - add trailing =
6875 [version.h]
6876 - OpenSSH-2.0
6877 [ssh-keygen.1 ssh-keygen.c]
6878 - add -R flag: exit code indicates if RSA is alive
6879 [sshd.c]
6880 - remove unused
6881 silent if -Q is specified
6882 [ssh.h]
6883 - host key becomes /etc/ssh_host_dsa_key
6884 [readconf.c servconf.c ]
6885 - ssh/sshd default to proto 1 and 2
6886 [uuencode.c]
6887 - remove debug
6888 [auth2.c ssh-keygen.c sshconnect2.c sshd.c]
6889 - xfree DSA blobs
6890 [auth2.c serverloop.c session.c]
6891 - cleanup logging for sshd/2, respect PasswordAuth no
6892 [sshconnect2.c]
6893 - less debug, respect .ssh/config
6894 [README.openssh2 channels.c channels.h]
bcbf86ec 6895 - clientloop.c session.c ssh.c
a306f2dd 6896 - support for x11-fwding, client+server
6897
0ac7199f 689820000421
6899 - Merge fix from OpenBSD CVS
6900 [ssh-agent.c]
6901 - Fix memory leak per connection. Report from Andy Spiegl <Andy@Spiegl.de>
6902 via Debian bug #59926
18ba2aab 6903 - Define __progname in session.c if libc doesn't
6904 - Remove indentation on autoconf #include statements to avoid bug in
bcbf86ec 6905 DEC Tru64 compiler. Report and fix from David Del Piero
18ba2aab 6906 <David.DelPiero@qed.qld.gov.au>
0ac7199f 6907
e1b37056 690820000420
bcbf86ec 6909 - Make fixpaths work with perl4, patch from Andre Lucas
e1b37056 6910 <andre.lucas@dial.pipex.com>
9da5c3c9 6911 - Sync with OpenBSD CVS:
6912 [clientloop.c login.c serverloop.c ssh-agent.c ssh.h sshconnect.c sshd.c]
6913 - pid_t
6914 [session.c]
6915 - remove bogus chan_read_failed. this could cause data
6916 corruption (missing data) at end of a SSH2 session.
4e577b89 6917 - Merge fixes from Debian patch from Phil Hands <phil@hands.com>
6918 - Allow setting of PAM service name through CFLAGS (SSHD_PAM_SERVICE)
6919 - Use vhangup to clean up Linux ttys
6920 - Force posix getopt processing on GNU libc systems
371ecff9 6921 - Debian bug #55910 - remove references to ssl(8) manpages
247f1a89 6922 - Debian bug #58031 - ssh_config lies about default cipher
e1b37056 6923
d6f24e45 692420000419
6925 - OpenBSD CVS updates
6926 [channels.c]
6927 - fix pr 1196, listen_port and port_to_connect interchanged
6928 [scp.c]
bcbf86ec 6929 - after completion, replace the progress bar ETA counter with a final
d6f24e45 6930 elapsed time; my idea, aaron wrote the patch
6931 [ssh_config sshd_config]
6932 - show 'Protocol' as an example, ok markus@
6933 [sshd.c]
6934 - missing xfree()
6935 - Add missing header to bsd-misc.c
6936
35484284 693720000416
6938 - Reduce diff against OpenBSD source
bcbf86ec 6939 - All OpenSSL includes are now unconditionally referenced as
35484284 6940 openssl/foo.h
6941 - Pick up formatting changes
6942 - Other minor changed (typecasts, etc) that I missed
6943
6ae2364d 694420000415
6945 - OpenBSD CVS updates.
6946 [ssh.1 ssh.c]
6947 - ssh -2
6948 [auth.c channels.c clientloop.c packet.c packet.h serverloop.c]
6949 [session.c sshconnect.c]
6950 - check payload for (illegal) extra data
6951 [ALL]
6952 whitespace cleanup
6953
c323ac76 695420000413
6955 - INSTALL doc updates
f54651ce 6956 - Merged OpenBSD updates to include paths.
bcbf86ec 6957
a8be9f80 695820000412
6959 - OpenBSD CVS updates:
6960 - [channels.c]
6961 repair x11-fwd
6962 - [sshconnect.c]
6963 fix passwd prompt for ssh2, less debugging output.
6964 - [clientloop.c compat.c dsa.c kex.c sshd.c]
6965 less debugging output
6966 - [kex.c kex.h sshconnect.c sshd.c]
6967 check for reasonable public DH values
6968 - [README.openssh2 cipher.c cipher.h compat.c compat.h readconf.c]
6969 [readconf.h servconf.c servconf.h ssh.c ssh.h sshconnect.c sshd.c]
6970 add Cipher and Protocol options to ssh/sshd, e.g.:
6971 ssh -o 'Protocol 1,2' if you prefer proto 1, ssh -o 'Ciphers
6972 arcfour,3des-cbc'
6973 - [sshd.c]
6974 print 1.99 only if server supports both
6975
18e92801 697620000408
6977 - Avoid some compiler warnings in fake-get*.c
6978 - Add IPTOS macros for systems which lack them
9d98aaf6 6979 - Only set define entropy collection macros if they are found
e78a59f5 6980 - More large OpenBSD CVS updates:
6981 - [auth.c auth.h servconf.c servconf.h serverloop.c session.c]
6982 [session.h ssh.h sshd.c README.openssh2]
6983 ssh2 server side, see README.openssh2; enable with 'sshd -2'
6984 - [channels.c]
6985 no adjust after close
6986 - [sshd.c compat.c ]
6987 interop w/ latest ssh.com windows client.
61e96248 6988
8ce64345 698920000406
6990 - OpenBSD CVS update:
6991 - [channels.c]
6992 close efd on eof
6993 - [clientloop.c compat.c ssh.c sshconnect.c myproposal.h]
6994 ssh2 client implementation, interops w/ ssh.com and lsh servers.
6995 - [sshconnect.c]
6996 missing free.
6997 - [authfile.c cipher.c cipher.h packet.c sshconnect.c sshd.c]
6998 remove unused argument, split cipher_mask()
6999 - [clientloop.c]
7000 re-order: group ssh1 vs. ssh2
7001 - Make Redhat spec require openssl >= 0.9.5a
7002
e7627112 700320000404
7004 - Add tests for RAND_add function when searching for OpenSSL
7e7327a1 7005 - OpenBSD CVS update:
7006 - [packet.h packet.c]
7007 ssh2 packet format
7008 - [packet.h packet.c nchan2.ms nchan.h compat.h compat.c]
7009 [channels.h channels.c]
7010 channel layer support for ssh2
7011 - [kex.h kex.c hmac.h hmac.c dsa.c dsa.h]
7012 DSA, keyexchange, algorithm agreement for ssh2
6c081128 7013 - Generate manpages before make install not at the end of make all
7014 - Don't seed the rng quite so often
7015 - Always reseed rng when requested
e7627112 7016
bfc9a610 701720000403
7018 - Wrote entropy collection routines for systems that lack /dev/random
7019 and EGD
837c30b8 7020 - Disable tests and typedefs for 64 bit types. They are currently unused.
bfc9a610 7021
7368a6c8 702220000401
7023 - Big OpenBSD CVS update (mainly beginnings of SSH2 infrastructure)
7024 - [auth.c session.c sshd.c auth.h]
7025 split sshd.c -> auth.c session.c sshd.c plus cleanup and goto-removal
7026 - [bufaux.c bufaux.h]
7027 support ssh2 bignums
7028 - [channels.c channels.h clientloop.c sshd.c nchan.c nchan.h packet.c]
7029 [readconf.c ssh.c ssh.h serverloop.c]
7030 replace big switch() with function tables (prepare for ssh2)
7031 - [ssh2.h]
7032 ssh2 message type codes
7033 - [sshd.8]
7034 reorder Xr to avoid cutting
7035 - [serverloop.c]
7036 close(fdin) if fdin != fdout, shutdown otherwise, ok theo@
7037 - [channels.c]
7038 missing close
7039 allow bigger packets
7040 - [cipher.c cipher.h]
7041 support ssh2 ciphers
7042 - [compress.c]
7043 cleanup, less code
7044 - [dispatch.c dispatch.h]
7045 function tables for different message types
7046 - [log-server.c]
7047 do not log() if debuggin to stderr
7048 rename a cpp symbol, to avoid param.h collision
7049 - [mpaux.c]
7050 KNF
7051 - [nchan.c]
7052 sync w/ channels.c
7053
f5238bee 705420000326
7055 - Better tests for OpenSSL w/ RSAref
bcbf86ec 7056 - Added replacement setenv() function from OpenBSD libc. Suggested by
f5238bee 7057 Ben Lindstrom <mouring@pconline.com>
4fe2af09 7058 - OpenBSD CVS update
7059 - [auth-krb4.c]
7060 -Wall
7061 - [auth-rh-rsa.c auth-rsa.c hostfile.c hostfile.h key.c key.h match.c]
7062 [match.h ssh.c ssh.h sshconnect.c sshd.c]
7063 initial support for DSA keys. ok deraadt@, niels@
7064 - [cipher.c cipher.h]
7065 remove unused cipher_attack_detected code
7066 - [scp.1 ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
7067 Fix some formatting problems I missed before.
7068 - [ssh.1 sshd.8]
7069 fix spelling errors, From: FreeBSD
7070 - [ssh.c]
7071 switch to raw mode only if he _get_ a pty (not if we _want_ a pty).
f5238bee 7072
0024a081 707320000324
7074 - Released 1.2.3
7075
bd499f9e 707620000317
7077 - Clarified --with-default-path option.
7078 - Added -blibpath handling for AIX to work around stupid runtime linking.
7079 Problem elucidated by gshapiro@SENDMAIL.ORG by way of Jim Knoble
986a22ec 7080 <jmknoble@jmknoble.cx>
474b5fef 7081 - Checks for 64 bit int types. Problem report from Mats Fredholm
7082 <matsf@init.se>
610cd5c6 7083 - OpenBSD CVS updates:
bcbf86ec 7084 - [atomicio.c auth-krb4.c bufaux.c channels.c compress.c fingerprint.c]
610cd5c6 7085 [packet.h radix.c rsa.c scp.c ssh-agent.c ssh-keygen.c sshconnect.c]
7086 [sshd.c]
7087 pedantic: signed vs. unsigned, void*-arithm, etc
7088 - [ssh.1 sshd.8]
7089 Various cleanups and standardizations.
bcbf86ec 7090 - Runtime error fix for HPUX from Otmar Stahl
be48d23c 7091 <O.Stahl@lsw.uni-heidelberg.de>
bd499f9e 7092
4696775a 709320000316
bcbf86ec 7094 - Fixed configure not passing LDFLAGS to Solaris. Report from David G.
4696775a 7095 Hesprich <dghespri@sprintparanet.com>
d423d822 7096 - Propogate LD through to Makefile
b7a9ce47 7097 - Doc cleanups
2ba2a610 7098 - Added blurb about "scp: command not found" errors to UPGRADING
4696775a 7099
cb0b7ea4 710020000315
7101 - Fix broken CFLAGS handling during search for OpenSSL. Fixes va_list
7102 problems with gcc/Solaris.
bcbf86ec 7103 - Don't free argument to putenv() after use (in setenv() replacement).
db55a3ea 7104 Report from Seigo Tanimura <tanimura@r.dl.itc.u-tokyo.ac.jp>
bcbf86ec 7105 - Created contrib/ subdirectory. Included helpers from Phil Hands'
13652e52 7106 Debian package, README file and chroot patch from Ricardo Cerqueira
7107 <rmcc@clix.pt>
bcbf86ec 7108 - Moved gnome-ssh-askpass.c to contrib directory and removed config
13652e52 7109 option.
7110 - Slight cleanup to doc files
b14b2ae7 7111 - Configure fix from Bratislav ILICH <bilic@zepter.ru>
cb0b7ea4 7112
a8ed9fd9 711320000314
bcbf86ec 7114 - Include macro for IN6_IS_ADDR_V4MAPPED. Report from
a8ed9fd9 7115 peter@frontierflying.com
84afc958 7116 - Include /usr/local/include and /usr/local/lib for systems that don't
7117 do it themselves
7118 - -R/usr/local/lib for Solaris
7119 - Fix RSAref detection
7120 - Fix IN6_IS_ADDR_V4MAPPED macro
a8ed9fd9 7121
bcf36c78 712220000311
7123 - Detect RSAref
43e48848 7124 - OpenBSD CVS change
7125 [sshd.c]
7126 - disallow guessing of root password
867dbf40 7127 - More configure fixes
80faa19f 7128 - IPv6 workarounds from Hideaki YOSHIFUJI <yoshfuji@ecei.tohoku.ac.jp>
bcf36c78 7129
c8d54615 713020000309
7131 - OpenBSD CVS updates to v1.2.3
704b1659 7132 [ssh.h atomicio.c]
7133 - int atomicio -> ssize_t (for alpha). ok deraadt@
7134 [auth-rsa.c]
7135 - delay MD5 computation until client sends response, free() early, cleanup.
7136 [cipher.c]
7137 - void* -> unsigned char*, ok niels@
7138 [hostfile.c]
7139 - remove unused variable 'len'. fix comments.
7140 - remove unused variable
7141 [log-client.c log-server.c]
7142 - rename a cpp symbol, to avoid param.h collision
7143 [packet.c]
7144 - missing xfree()
7145 - getsockname() requires initialized tolen; andy@guildsoftware.com
7146 - use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
7147 from Holger.Trapp@Informatik.TU-Chemnitz.DE
7148 [pty.c pty.h]
bcbf86ec 7149 - register cleanup for pty earlier. move code for pty-owner handling to
c8d54615 7150 pty.c ok provos@, dugsong@
704b1659 7151 [readconf.c]
7152 - turn off x11-fwd for the client, too.
7153 [rsa.c]
7154 - PKCS#1 padding
7155 [scp.c]
7156 - allow '.' in usernames; from jedgar@fxp.org
7157 [servconf.c]
7158 - typo: ignore_user_known_hosts int->flag; naddy@mips.rhein-neckar.de
7159 - sync with sshd_config
7160 [ssh-keygen.c]
7161 - enable ssh-keygen -l -f ~/.ssh/known_hosts, ok deraadt@
7162 [ssh.1]
7163 - Change invalid 'CHAT' loglevel to 'VERBOSE'
7164 [ssh.c]
7165 - suppress AAAA query host when '-4' is used; from shin@nd.net.fujitsu.co.jp
7166 - turn off x11-fwd for the client, too.
7167 [sshconnect.c]
7168 - missing xfree()
7169 - retry rresvport_af(), too. from sumikawa@ebina.hitachi.co.jp.
7170 - read error vs. "Connection closed by remote host"
7171 [sshd.8]
7172 - ie. -> i.e.,
7173 - do not link to a commercial page..
7174 - sync with sshd_config
7175 [sshd.c]
7176 - no need for poll.h; from bright@wintelcom.net
7177 - log with level log() not fatal() if peer behaves badly.
7178 - don't panic if client behaves strange. ok deraadt@
7179 - make no-port-forwarding for RSA keys deny both -L and -R style fwding
7180 - delay close() of pty until the pty has been chowned back to root
7181 - oops, fix comment, too.
7182 - missing xfree()
7183 - move XAUTHORITY to subdir. ok dugsong@. fixes debian bug #57907, too.
7184 (http://cgi.debian.org/cgi-bin/bugreport.cgi?archive=no&bug=57907)
bcbf86ec 7185 - register cleanup for pty earlier. move code for pty-owner handling to
704b1659 7186 pty.c ok provos@, dugsong@
7187 - create x11 cookie file
7188 - fix pr 1113, fclose() -> pclose(), todo: remote popen()
7189 - version 1.2.3
c8d54615 7190 - Cleaned up
bcbf86ec 7191 - Removed warning workaround for Linux and devpts filesystems (no longer
d8223847 7192 required after OpenBSD updates)
c8d54615 7193
07055445 719420000308
7195 - Configure fix from Hiroshi Takekawa <takekawa@sr3.t.u-tokyo.ac.jp>
7196
719720000307
7198 - Released 1.2.2p1
7199
9c8c3fc6 720020000305
7201 - Fix DEC compile fix
54096dcc 7202 - Explicitly seed OpenSSL's PRNG before checking rsa_alive()
aa6bd60a 7203 - Check for getpagesize in libucb.a if not found in libc. Fix for old
7204 Solaris from Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 7205 - Check for libwrap if --with-tcp-wrappers option specified. Suggestion
9fc7867e 7206 Mate Wierdl <mw@moni.msci.memphis.edu>
9c8c3fc6 7207
6bf4d066 720820000303
7209 - Added "make host-key" target, Suggestion from Dominik Brettnacher
7210 <domi@saargate.de>
bcbf86ec 7211 - Don't permanently fail on bind() if getaddrinfo has more choices left for
16218745 7212 us. Needed to work around messy IPv6 on Linux. Patch from Arkadiusz
7213 Miskiewicz <misiek@pld.org.pl>
22fa590f 7214 - DEC Unix compile fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
7215 - Manpage fix from David Del Piero <David.DelPiero@qed.qld.gov.au>
6bf4d066 7216
a0391976 721720000302
7218 - Big cleanup of autoconf code
7219 - Rearranged to be a little more logical
7220 - Added -R option for Solaris
7221 - Rewrote OpenSSL detection code. Now uses AC_TRY_RUN with a test program
7222 to detect library and header location _and_ ensure library has proper
7223 RSA support built in (this is a problem with OpenSSL 0.9.5).
817175bc 7224 - Applied pty cleanup patch from markus.friedl@informatik.uni-erlangen.de
0a1718dc 7225 - Avoid warning message with Unix98 ptys
bcbf86ec 7226 - Warning was valid - possible race condition on PTYs. Avoided using
3276571c 7227 platform-specific code.
7228 - Document some common problems
bcbf86ec 7229 - Allow root access to any key. Patch from
81eef326 7230 markus.friedl@informatik.uni-erlangen.de
a0391976 7231
f55afe71 723220000207
7233 - Removed SOCKS code. Will support through a ProxyCommand.
7234
d07d1c58 723520000203
7236 - Fixed SEGVs in authloop, fix from vbzoli@hbrt.hu
d581b7ae 7237 - Add --with-ssl-dir option
d07d1c58 7238
9d5f374b 723920000202
bcbf86ec 7240 - Fix lastlog code for directory based lastlogs. Fix from Josh Durham
9d5f374b 7241 <jmd@aoe.vt.edu>
6b1f3fdb 7242 - Documentation fixes from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 7243 - Added URLs to Japanese translations of documents by HARUYAMA Seigo
6b1f3fdb 7244 <haruyama@nt.phys.s.u-tokyo.ac.jp>
9d5f374b 7245
bc8c2601 724620000201
7247 - Use socket pairs by default (instead of pipes). Prevents race condition
7248 on several (buggy) OSs. Report and fix from tridge@linuxcare.com
7249
69c76614 725020000127
7251 - Seed OpenSSL's random number generator before generating RSA keypairs
7252 - Split random collector into seperate file
aaf2abd7 7253 - Compile fix from Andre Lucas <andre.lucas@dial.pipex.com>
69c76614 7254
f9507c24 725520000126
7256 - Released 1.2.2 stable
7257
bcbf86ec 7258 - NeXT keeps it lastlog in /usr/adm. Report from
f9507c24 7259 mouring@newton.pconline.com
bcbf86ec 7260 - Added note in UPGRADING re interop with commercial SSH using idea.
986a22ec 7261 Report from Jim Knoble <jmknoble@jmknoble.cx>
587120ad 7262 - Fix linking order for Kerberos/AFS. Fix from Holget Trapp
7263 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
f9507c24 7264
bfae20ad 726520000125
bcbf86ec 7266 - Fix NULL pointer dereference in login.c. Fix from Andre Lucas
bfae20ad 7267 <andre.lucas@dial.pipex.com>
07b0cb78 7268 - Reorder PAM initialisation so it does not mess up lastlog. Reported
7269 by Andre Lucas <andre.lucas@dial.pipex.com>
bcbf86ec 7270 - Use preformatted manpages on SCO, report from Gary E. Miller
9755cbdb 7271 <gem@rellim.com>
7272 - New URL for x11-ssh-askpass.
bcbf86ec 7273 - Fixpaths was missing /etc/ssh_known_hosts. Report from Jim Knoble
986a22ec 7274 <jmknoble@jmknoble.cx>
bcbf86ec 7275 - Added 'DESTDIR' option to Makefile to ease package building. Patch from
986a22ec 7276 Jim Knoble <jmknoble@jmknoble.cx>
ff8ecdb8 7277 - Updated RPM spec files to use DESTDIR
bfae20ad 7278
bb58aa4b 727920000124
7280 - Pick up version 1.2.2 from OpenBSD CVS (no changes, just version number
7281 increment)
7282
d45317d8 728320000123
7284 - OpenBSD CVS:
7285 - [packet.c]
7286 getsockname() requires initialized tolen; andy@guildsoftware.com
bcbf86ec 7287 - AIX patch from Matt Richards <v2matt@btv.ibm.com> and David Rankin
4c40f834 7288 <drankin@bohemians.lexington.ky.us>
12aa90af 7289 - Fix lastlog support, patch from Andre Lucas <andre.lucas@dial.pipex.com>
d45317d8 7290
e844f761 729120000122
7292 - Fix compilation of bsd-snprintf.c on Solaris, fix from Ben Taylor
7293 <bent@clark.net>
c54a6257 7294 - Merge preformatted manpage patch from Andre Lucas
7295 <andre.lucas@dial.pipex.com>
8eb34e02 7296 - Make IPv4 use the default in RPM packages
7297 - Irix uses preformatted manpages
1e64903d 7298 - Missing htons() in bsd-bindresvport.c, fix from Holger Trapp
7299 <Holger.Trapp@Informatik.TU-Chemnitz.DE>
9bc5ddfe 7300 - OpenBSD CVS updates:
7301 - [packet.c]
7302 use getpeername() in packet_connection_is_on_socket(), fixes sshd -i;
7303 from Holger.Trapp@Informatik.TU-Chemnitz.DE
7304 - [sshd.c]
7305 log with level log() not fatal() if peer behaves badly.
7306 - [readpass.c]
bcbf86ec 7307 instead of blocking SIGINT, catch it ourselves, so that we can clean
7308 the tty modes up and kill ourselves -- instead of our process group
61e96248 7309 leader (scp, cvs, ...) going away and leaving us in noecho mode.
9bc5ddfe 7310 people with cbreak shells never even noticed..
399d9d44 7311 - [ssh-add.1 ssh-agent.1 ssh-keygen.1 ssh.1 sshd.8]
7312 ie. -> i.e.,
e844f761 7313
4c8ef3fb 731420000120
7315 - Don't use getaddrinfo on AIX
7b2ea3a1 7316 - Update to latest OpenBSD CVS:
7317 - [auth-rsa.c]
7318 - fix user/1056, sshd keeps restrictions; dbt@meat.net
7319 - [sshconnect.c]
7320 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
7321 - destroy keys earlier
bcbf86ec 7322 - split key exchange (kex) and user authentication (user-auth),
d468fc76 7323 ok: provos@
7b2ea3a1 7324 - [sshd.c]
7325 - no need for poll.h; from bright@wintelcom.net
7326 - disable agent fwding for proto 1.3, remove abuse of auth-rsa flags.
bcbf86ec 7327 - split key exchange (kex) and user authentication (user-auth),
d468fc76 7328 ok: provos@
f3bba493 7329 - Big manpage and config file cleanup from Andre Lucas
7330 <andre.lucas@dial.pipex.com>
5f4fdfae 7331 - Re-added latest (unmodified) OpenBSD manpages
47f9a56a 7332 - Doc updates
d468fc76 7333 - NetBSD patch from David Rankin <drankin@bohemians.lexington.ky.us> and
7334 Christos Zoulas <christos@netbsd.org>
4c8ef3fb 7335
082bbfb3 733620000119
20af321f 7337 - SCO compile fixes from Gary E. Miller <gem@rellim.com>
082bbfb3 7338 - Compile fix from Darren_Hall@progressive.com
59e76f33 7339 - Linux/glibc-2.1.2 takes a *long* time to look up names for AF_UNSPEC
7340 addresses using getaddrinfo(). Added a configure switch to make the
7341 default lookup mode AF_INET
082bbfb3 7342
a63a7f37 734320000118
7344 - Fixed --with-pid-dir option
51a6baf8 7345 - Makefile fix from Gary E. Miller <gem@rellim.com>
61e96248 7346 - Compile fix for HPUX and Solaris from Andre Lucas
976f7e19 7347 <andre.lucas@dial.pipex.com>
a63a7f37 7348
f914c7fb 734920000117
7350 - Clean up bsd-bindresvport.c. Use arc4random() for picking initial
7351 port, ignore EINVAL errors (Linux) when searching for free port.
bcbf86ec 7352 - Revert __snprintf -> snprintf aliasing. Apparently Solaris
de93b046 7353 __snprintf isn't. Report from Theo de Raadt <theo@cvs.openbsd.org>
9b363e1c 7354 - Document location of Redhat PAM file in INSTALL.
bcbf86ec 7355 - Fixed X11 forwarding bug on Linux. libc advertises AF_INET6
7356 INADDR_ANY_INIT addresses via getaddrinfo, but may not be able to
f4a7cf29 7357 deliver (no IPv6 kernel support)
80a44451 7358 - Released 1.2.1pre27
f914c7fb 7359
f4a7cf29 7360 - Fix rresvport_af failure errors (logic error in bsd-bindresvport.c)
bcbf86ec 7361 - Fix --with-ipaddr-display option test. Fix from Jarno Huuskonen
cf8ad170 7362 <jhuuskon@hytti.uku.fi>
bcbf86ec 7363 - Fix hang on logout if processes are still using the pty. Needs
691a8a9f 7364 further testing.
5957fd29 7365 - Patch from Christos Zoulas <christos@zoulas.com>
7366 - Try $prefix first when looking for OpenSSL.
7367 - Include sys/types.h when including sys/socket.h in test programs
bcbf86ec 7368 - Substitute PID directory in sshd.8. Suggestion from Andrew
19d9ac2a 7369 Stribblehill <a.d.stribblehill@durham.ac.uk>
f4a7cf29 7370
47e45e44 737120000116
7372 - Renamed --with-xauth-path to --with-xauth
7373 - Added --with-pid-dir option
7374 - Released 1.2.1pre26
7375
a82ef8ae 7376 - Compilation fix from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
bcbf86ec 7377 - Fixed broken bugfix for /dev/ptmx on Linux systems which lack
66be05a1 7378 openpty(). Report from Kiyokazu SUTO <suto@ks-and-ks.ne.jp>
a82ef8ae 7379
5cdfe03f 738020000115
7381 - Add --with-xauth-path configure directive and explicit test for
bcbf86ec 7382 /usr/openwin/bin/xauth for Solaris systems. Report from Anders
5cdfe03f 7383 Nordby <anders@fix.no>
bcbf86ec 7384 - Fix incorrect detection of /dev/ptmx on Linux systems that lack
5cdfe03f 7385 openpty. Report from John Seifarth <john@waw.be>
7386 - Look for intXX_t and u_intXX_t in sys/bitypes.h if they are not in
bcbf86ec 7387 sys/types.h. Fixes problems on SCO, report from Gary E. Miller
5cdfe03f 7388 <gem@rellim.com>
7389 - Use __snprintf and __vnsprintf if they are found where snprintf and
7390 vnsprintf are lacking. Suggested by Ben Taylor <bent@shell.clark.net>
7391 and others.
7392
48e671d5 739320000114
7394 - Merged OpenBSD IPv6 patch:
7395 - [sshd.c sshd.8 sshconnect.c ssh.h ssh.c servconf.h servconf.c scp.1]
7396 [scp.c packet.h packet.c login.c log.c canohost.c channels.c]
7397 [hostfile.c sshd_config]
7398 ipv6 support: mostly gethostbyname->getaddrinfo/getnameinfo, new
bcbf86ec 7399 features: sshd allows multiple ListenAddress and Port options. note
7400 that libwrap is not IPv6-ready. (based on patches from
48e671d5 7401 fujiwara@rcac.tdi.co.jp)
7402 - [ssh.c canohost.c]
bcbf86ec 7403 more hints (hints.ai_socktype=SOCK_STREAM) for getaddrinfo,
48e671d5 7404 from itojun@
7405 - [channels.c]
7406 listen on _all_ interfaces for X11-Fwd (hints.ai_flags = AI_PASSIVE)
7407 - [packet.h]
7408 allow auth-kerberos for IPv4 only
7409 - [scp.1 sshd.8 servconf.h scp.c]
7410 document -4, -6, and 'ssh -L 2022/::1/22'
7411 - [ssh.c]
bcbf86ec 7412 'ssh @host' is illegal (null user name), from
48e671d5 7413 karsten@gedankenpolizei.de
7414 - [sshconnect.c]
7415 better error message
7416 - [sshd.c]
7417 allow auth-kerberos for IPv4 only
7418 - Big IPv6 merge:
7419 - Cleanup overrun in sockaddr copying on RHL 6.1
7420 - Replacements for getaddrinfo, getnameinfo, etc based on versions
7421 from patch from KIKUCHI Takahiro <kick@kyoto.wide.ad.jp>
7422 - Replacement for missing structures on systems that lack IPv6
7423 - record_login needed to know about AF_INET6 addresses
7424 - Borrowed more code from OpenBSD: rresvport_af and requisites
7425
2598df62 742620000110
7427 - Fixes to auth-skey to enable it to use the standard OpenSSL libraries
7428
b8a0310d 742920000107
7430 - New config.sub and config.guess to fix problems on SCO. Supplied
7431 by Gary E. Miller <gem@rellim.com>
b6a98a85 7432 - SCO build fix from Gary E. Miller <gem@rellim.com>
2598df62 7433 - Released 1.2.1pre25
b8a0310d 7434
dfb95100 743520000106
7436 - Documentation update & cleanup
7437 - Better KrbIV / AFS detection, based on patch from:
7438 Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
7439
b9795b89 744020000105
bcbf86ec 7441 - Fixed annoying DES corruption problem. libcrypt has been
b9795b89 7442 overriding symbols in libcrypto. Removed libcrypt and crypt.h
7443 altogether (libcrypto includes its own crypt(1) replacement)
7444 - Added platform-specific rules for Irix 6.x. Included warning that
7445 they are untested.
7446
a1ec4d79 744720000103
7448 - Add explicit make rules for files proccessed by fixpaths.
61e96248 7449 - Fix "make install" in RPM spec files. Report from Tenkou N. Hattori
a1ec4d79 7450 <tnh@kondara.org>
bcbf86ec 7451 - Removed "nullok" directive from default PAM configuration files.
7452 Added information on enabling EmptyPasswords on openssh+PAM in
607d73e6 7453 UPGRADING file.
e02735bb 7454 - OpenBSD CVS updates
7455 - [ssh-agent.c]
bcbf86ec 7456 cleanup_exit() for SIGTERM/SIGHUP, too. from fgsch@ and
e02735bb 7457 dgaudet@arctic.org
7458 - [sshconnect.c]
7459 compare correct version for 1.3 compat mode
a1ec4d79 7460
93c7f644 746120000102
7462 - Prevent multiple inclusion of config.h and defines.h. Suggested
7463 by Andre Lucas <andre.lucas@dial.pipex.com>
7464 - Properly clean up on exit of ssh-agent. Patch from Dean Gaudet
7465 <dgaudet@arctic.org>
7466
76b8607f 746719991231
bcbf86ec 7468 - Fix password support on systems with a mixture of shadowed and
7469 non-shadowed passwords (e.g. NIS). Report and fix from
76b8607f 7470 HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp>
bcbf86ec 7471 - Fix broken autoconf typedef detection. Report from Marc G.
723221b5 7472 Fournier <marc.fournier@acadiau.ca>
b92964b7 7473 - Fix occasional crash on LinuxPPC. Patch from Franz Sirl
7474 <Franz.Sirl-kernel@lauterbach.com>
bcbf86ec 7475 - Prevent typedefs from being compiled more than once. Report from
a6ddc88b 7476 Marc G. Fournier <marc.fournier@acadiau.ca>
4811cc0b 7477 - Fill in ut_utaddr utmp field. Report from Benjamin Charron
7478 <iretd@bigfoot.com>
bcbf86ec 7479 - Really fix broken default path. Fix from Jim Knoble
986a22ec 7480 <jmknoble@jmknoble.cx>
ae3a3d31 7481 - Remove test for quad_t. No longer needed.
76a8e733 7482 - Released 1.2.1pre24
7483
7484 - Added support for directory-based lastlogs
7485 - Really fix typedefs, patch from Ben Taylor <bent@clark.net>
76b8607f 7486
13f825f4 748719991230
7488 - OpenBSD CVS updates:
7489 - [auth-passwd.c]
7490 check for NULL 1st
bcbf86ec 7491 - Removed most of the pam code into its own file auth-pam.[ch]. This
a5c9cd31 7492 cleaned up sshd.c up significantly.
bcbf86ec 7493 - PAM authentication was incorrectly interpreting
76b8607f 7494 "PermitRootLogin without-password". Report from Matthias Andree
7495 <ma@dt.e-technik.uni-dortmund.de
a5c9cd31 7496 - Several other cleanups
0bc5b6fb 7497 - Merged Dante SOCKS support patch from David Rankin
7498 <drankin@bohemians.lexington.ky.us>
7499 - Updated documentation with ./configure options
76b8607f 7500 - Released 1.2.1pre23
13f825f4 7501
c73a0cb5 750219991229
bcbf86ec 7503 - Applied another NetBSD portability patch from David Rankin
c73a0cb5 7504 <drankin@bohemians.lexington.ky.us>
7505 - Fix --with-default-path option.
bcbf86ec 7506 - Autodetect perl, patch from David Rankin
a0f84251 7507 <drankin@bohemians.lexington.ky.us>
bcbf86ec 7508 - Print whether OpenSSH was compiled with RSARef, patch from
0a2ff95d 7509 Nalin Dahyabhai <nalin@thermo.stat.ncsu.edu>
bcbf86ec 7510 - Calls to pam_setcred, patch from Nalin Dahyabhai
f91bacbd 7511 <nalin@thermo.stat.ncsu.edu>
e3a93db0 7512 - Detect missing size_t and typedef it.
5ab44a92 7513 - Rename helper.[ch] to (more appropriate) bsd-misc.[ch]
7514 - Minor Makefile cleaning
c73a0cb5 7515
b6019d68 751619991228
7517 - Replacement for getpagesize() for systems which lack it
bcbf86ec 7518 - NetBSD login.c compile fix from David Rankin
70e0115b 7519 <drankin@bohemians.lexington.ky.us>
7520 - Fully set ut_tv if present in utmp or utmpx
d94aa2ae 7521 - Portability fixes for Irix 5.3 (now compiles OK!)
7522 - autoconf and other misc cleanups
ea1970a3 7523 - Merged AIX patch from Darren Hall <dhall@virage.org>
7524 - Cleaned up defines.h
fa9a2dd6 7525 - Released 1.2.1pre22
b6019d68 7526
d2dcff5f 752719991227
7528 - Automatically correct paths in manpages and configuration files. Patch
7529 and script from Andre Lucas <andre.lucas@dial.pipex.com>
7530 - Removed credits from README to CREDITS file, updated.
cb807f40 7531 - Added --with-default-path to specify custom path for server
7532 - Removed #ifdef trickery from acconfig.h into defines.h
36a5b38e 7533 - PAM bugfix. PermitEmptyPassword was being ignored.
7534 - Fixed PAM config files to allow empty passwords if server does.
7535 - Explained spurious PAM auth warning workaround in UPGRADING
21feb5fa 7536 - Use last few chars of tty line as ut_id
5a7794be 7537 - New SuSE RPM spec file from Chris Saia <csaia@wtower.com>
00e6dd70 7538 - OpenBSD CVS updates:
7539 - [packet.h auth-rhosts.c]
7540 check format string for packet_disconnect and packet_send_debug, too
7541 - [channels.c]
7542 use packet_get_maxsize for channels. consistence.
d2dcff5f 7543
f74efc8d 754419991226
7545 - Enabled utmpx support by default for Solaris
7546 - Cleanup sshd.c PAM a little more
986a22ec 7547 - Revised RPM package to include Jim Knoble's <jmknoble@jmknoble.cx>
bc7ea646 7548 X11 ssh-askpass program.
20c43d8c 7549 - Disable logging of PAM success and failures, PAM is verbose enough.
bcbf86ec 7550 Unfortunatly there is currently no way to disable auth failure
7551 messages. Mention this in UPGRADING file and sent message to PAM
20c43d8c 7552 developers
83b7f649 7553 - OpenBSD CVS update:
7554 - [ssh-keygen.1 ssh.1]
bcbf86ec 7555 remove ref to .ssh/random_seed, mention .ssh/environment in
83b7f649 7556 .Sh FILES, too
72251cb6 7557 - Released 1.2.1pre21
bcbf86ec 7558 - Fixed implicit '.' in default path, report from Jim Knoble
986a22ec 7559 <jmknoble@jmknoble.cx>
7560 - Redhat RPM spec fixes from Jim Knoble <jmknoble@jmknoble.cx>
f74efc8d 7561
f498ed15 756219991225
7563 - More fixes from Andre Lucas <andre.lucas@dial.pipex.com>
7564 - Cleanup of auth-passwd.c for shadow and MD5 passwords
7565 - Cleanup and bugfix of PAM authentication code
f74efc8d 7566 - Released 1.2.1pre20
7567
7568 - Merged fixes from Ben Taylor <bent@clark.net>
7569 - Fixed configure support for PAM. Reported by Naz <96na@eng.cam.ac.uk>
7570 - Disabled logging of PAM password authentication failures when password
7571 is empty. (e.g start of authentication loop). Reported by Naz
7572 <96na@eng.cam.ac.uk>)
f498ed15 7573
757419991223
bcbf86ec 7575 - Merged later HPUX patch from Andre Lucas
f498ed15 7576 <andre.lucas@dial.pipex.com>
7577 - Above patch included better utmpx support from Ben Taylor
f74efc8d 7578 <bent@clark.net>
f498ed15 7579
eef6f7e9 758019991222
bcbf86ec 7581 - Fix undefined fd_set type in ssh.h from Povl H. Pedersen
eef6f7e9 7582 <pope@netguide.dk>
ae28776a 7583 - Fix login.c breakage on systems which lack ut_host in struct
7584 utmp. Reported by Willard Dawson <willard.dawson@sbs.siemens.com>
eef6f7e9 7585
a7effaac 758619991221
bcbf86ec 7587 - Integration of large HPUX patch from Andre Lucas
7588 <andre.lucas@dial.pipex.com>. Integrating it had a few other
a7effaac 7589 benefits:
7590 - Ability to disable shadow passwords at configure time
7591 - Ability to disable lastlog support at configure time
7592 - Support for IP address in $DISPLAY
ae2f7af7 7593 - OpenBSD CVS update:
7594 - [sshconnect.c]
7595 say "REMOTE HOST IDENTIFICATION HAS CHANGED"
59dd7a31 7596 - Fix DISABLE_SHADOW support
7597 - Allow MD5 passwords even if shadow passwords are disabled
16034de9 7598 - Release 1.2.1pre19
a7effaac 7599
3f1d9bcd 760019991218
bcbf86ec 7601 - Redhat init script patch from Chun-Chung Chen
3f1d9bcd 7602 <cjj@u.washington.edu>
7e1c2490 7603 - Avoid breakage on systems without IPv6 headers
3f1d9bcd 7604
60d804c8 760519991216
bcbf86ec 7606 - Makefile changes for Solaris from Peter Kocks
60d804c8 7607 <peter.kocks@baygate.com>
89cafde6 7608 - Minor updates to docs
7609 - Merged OpenBSD CVS changes:
7610 - [authfd.c ssh-agent.c]
7611 keysize warnings talk about identity files
7612 - [packet.c]
7613 "Connection closed by x.x.x.x": fatal() -> log()
bcbf86ec 7614 - Correctly handle empty passwords in shadow file. Patch from:
c9d323f0 7615 "Chris, the Young One" <cky@pobox.com>
7616 - Released 1.2.1pre18
60d804c8 7617
7dc6fc6d 761819991215
7619 - Integrated patchs from Juergen Keil <jk@tools.de>
7620 - Avoid void* pointer arithmatic
7621 - Use LDFLAGS correctly
68227e6d 7622 - Fix SIGIO error in scp
7623 - Simplify status line printing in scp
61e96248 7624 - Added better test for inline functions compiler support from
906a2515 7625 Darren_Hall@progressive.com
7dc6fc6d 7626
95f1eccc 762719991214
7628 - OpenBSD CVS Changes
7629 - [canohost.c]
bcbf86ec 7630 fix get_remote_port() and friends for sshd -i;
95f1eccc 7631 Holger.Trapp@Informatik.TU-Chemnitz.DE
7632 - [mpaux.c]
7633 make code simpler. no need for memcpy. niels@ ok
7634 - [pty.c]
7635 namebuflen not sizeof namebuflen; bnd@ep-ag.com via djm@mindrot.org
7636 fix proto; markus
7637 - [ssh.1]
7638 typo; mark.baushke@solipsa.com
7639 - [channels.c ssh.c ssh.h sshd.c]
7640 type conflict for 'extern Type *options' in channels.c; dot@dotat.at
7641 - [sshconnect.c]
7642 move checking of hostkey into own function.
7643 - [version.h]
7644 OpenSSH-1.2.1
884bcb37 7645 - Clean up broken includes in pty.c
7303768f 7646 - Some older systems don't have poll.h, they use sys/poll.h instead
7647 - Doc updates
95f1eccc 7648
847e8865 764919991211
bcbf86ec 7650 - Fix compilation on systems with AFS. Reported by
847e8865 7651 aloomis@glue.umd.edu
bcbf86ec 7652 - Fix installation on Solaris. Reported by
847e8865 7653 Gordon Rowell <gordonr@gormand.com.au>
7654 - Fix gccisms (__attribute__ and inline). Report by edgy@us.ibm.com,
7655 patch from Markus Friedl <markus.friedl@informatik.uni-erlangen.de>
7656 - Auto-locate xauth. Patch from David Agraz <dagraz@jahoopa.com>
7657 - Compile fix from David Agraz <dagraz@jahoopa.com>
7658 - Avoid compiler warning in bsd-snprintf.c
bcbf86ec 7659 - Added pam_limits.so to default PAM config. Suggested by
986a22ec 7660 Jim Knoble <jmknoble@jmknoble.cx>
847e8865 7661
8946db53 766219991209
7663 - Import of patch from Ben Taylor <bent@clark.net>:
7664 - Improved PAM support
7665 - "uninstall" rule for Makefile
7666 - utmpx support
7667 - Should fix PAM problems on Solaris
2d86a6cc 7668 - OpenBSD CVS updates:
7669 - [readpass.c]
7670 avoid stdio; based on work by markus, millert, and I
7671 - [sshd.c]
7672 make sure the client selects a supported cipher
7673 - [sshd.c]
bcbf86ec 7674 fix sighup handling. accept would just restart and daemon handled
7675 sighup only after the next connection was accepted. use poll on
2d86a6cc 7676 listen sock now.
7677 - [sshd.c]
7678 make that a fatal
87e91331 7679 - Applied patch from David Rankin <drankin@bohemians.lexington.ky.us>
7680 to fix libwrap support on NetBSD
5001b9e4 7681 - Released 1.2pre17
8946db53 7682
6d8c4ea4 768319991208
bcbf86ec 7684 - Compile fix for Solaris with /dev/ptmx from
6d8c4ea4 7685 David Agraz <dagraz@jahoopa.com>
7686
4285816a 768719991207
986a22ec 7688 - sshd Redhat init script patch from Jim Knoble <jmknoble@jmknoble.cx>
4285816a 7689 fixes compatability with 4.x and 5.x
db28aeb5 7690 - Fixed default SSH_ASKPASS
bcbf86ec 7691 - Fix PAM account and session being called multiple times. Problem
d465f2ca 7692 reported by Adrian Baugh <adrian@merlin.keble.ox.ac.uk>
a408af76 7693 - Merged more OpenBSD changes:
7694 - [atomicio.c authfd.c scp.c serverloop.c ssh.h sshconnect.c sshd.c]
bcbf86ec 7695 move atomicio into it's own file. wrap all socket write()s which
a408af76 7696 were doing write(sock, buf, len) != len, with atomicio() calls.
7697 - [auth-skey.c]
7698 fd leak
7699 - [authfile.c]
7700 properly name fd variable
7701 - [channels.c]
7702 display great hatred towards strcpy
7703 - [pty.c pty.h sshd.c]
7704 use openpty() if it exists (it does on BSD4_4)
7705 - [tildexpand.c]
7706 check for ~ expansion past MAXPATHLEN
7707 - Modified helper.c to use new atomicio function.
7708 - Reformat Makefile a little
7709 - Moved RC4 routines from rc4.[ch] into helper.c
7710 - Added autoconf code to detect /dev/ptmx (Solaris) and /dev/ptc (AIX)
9983a8ca 7711 - Updated SuSE spec from Chris Saia <csaia@wtower.com>
7712 - Tweaked Redhat spec
9158d92f 7713 - Clean up bad imports of a few files (forgot -kb)
7714 - Released 1.2pre16
4285816a 7715
9c7b6dfd 771619991204
7717 - Small cleanup of PAM code in sshd.c
57112b5a 7718 - Merged OpenBSD CVS changes:
7719 - [auth-krb4.c auth-passwd.c auth-skey.c ssh.h]
7720 move skey-auth from auth-passwd.c to auth-skey.c, same for krb4
7721 - [auth-rsa.c]
7722 warn only about mismatch if key is _used_
7723 warn about keysize-mismatch with log() not error()
7724 channels.c readconf.c readconf.h ssh.c ssh.h sshconnect.c
7725 ports are u_short
7726 - [hostfile.c]
7727 indent, shorter warning
7728 - [nchan.c]
7729 use error() for internal errors
7730 - [packet.c]
7731 set loglevel for SSH_MSG_DISCONNECT to log(), not fatal()
7732 serverloop.c
7733 indent
7734 - [ssh-add.1 ssh-add.c ssh.h]
7735 document $SSH_ASKPASS, reasonable default
7736 - [ssh.1]
7737 CheckHostIP is not available for connects via proxy command
7738 - [sshconnect.c]
7739 typo
7740 easier to read client code for passwd and skey auth
7741 turn of checkhostip for proxy connects, since we don't know the remote ip
9c7b6dfd 7742
dad3b556 774319991126
7744 - Add definition for __P()
7745 - Added [v]snprintf() replacement for systems that lack it
7746
0ce43ae4 774719991125
7748 - More reformatting merged from OpenBSD CVS
7749 - Merged OpenBSD CVS changes:
7750 - [channels.c]
7751 fix packet_integrity_check() for !have_hostname_in_open.
7752 report from mrwizard@psu.edu via djm@ibs.com.au
7753 - [channels.c]
7754 set SO_REUSEADDR and SO_LINGER for forwarded ports.
7755 chip@valinux.com via damien@ibs.com.au
7756 - [nchan.c]
7757 it's not an error() if shutdown_write failes in nchan.
7758 - [readconf.c]
7759 remove dead #ifdef-0-code
7760 - [readconf.c servconf.c]
7761 strcasecmp instead of tolower
7762 - [scp.c]
7763 progress meter overflow fix from damien@ibs.com.au
7764 - [ssh-add.1 ssh-add.c]
7765 SSH_ASKPASS support
7766 - [ssh.1 ssh.c]
7767 postpone fork_after_authentication until command execution,
7768 request/patch from jahakala@cc.jyu.fi via damien@ibs.com.au
7769 plus: use daemon() for backgrounding
cf8dd513 7770 - Added BSD compatible install program and autoconf test, thanks to
7771 Niels Kristian Bech Jensen <nkbj@image.dk>
7772 - Solaris fixing, thanks to Ben Taylor <bent@clark.net>
09041313 7773 - Merged beginnings of AIX support from Tor-Ake Fransson <torake@hotmail.com>
3dbefdb8 7774 - Release 1.2pre15
0ce43ae4 7775
5260325f 777619991124
7777 - Merged very large OpenBSD source code reformat
7778 - OpenBSD CVS updates
7779 - [channels.c cipher.c compat.c log-client.c scp.c serverloop.c]
7780 [ssh.h sshd.8 sshd.c]
7781 syslog changes:
7782 * Unified Logmessage for all auth-types, for success and for failed
7783 * Standard connections get only ONE line in the LOG when level==LOG:
7784 Auth-attempts are logged only, if authentication is:
7785 a) successfull or
7786 b) with passwd or
7787 c) we had more than AUTH_FAIL_LOG failues
7788 * many log() became verbose()
7789 * old behaviour with level=VERBOSE
7790 - [readconf.c readconf.h ssh.1 ssh.h sshconnect.c sshd.c]
7791 tranfer s/key challenge/response data in SSH_SMSG_AUTH_TIS_CHALLENGE
7792 messages. allows use of s/key in windows (ttssh, securecrt) and
7793 ssh-1.2.27 clients without 'ssh -v', ok: niels@
7794 - [sshd.8]
7795 -V, for fallback to openssh in SSH2 compatibility mode
7796 - [sshd.c]
7797 fix sigchld race; cjc5@po.cwru.edu
7798
4655fe80 779919991123
7800 - Added SuSE package files from Chris Saia <csaia@wtower.com>
8b241e50 7801 - Restructured package-related files under packages/*
4655fe80 7802 - Added generic PAM config
8b241e50 7803 - Numerous little Solaris fixes
9c08d6ce 7804 - Add recommendation to use GNU make to INSTALL document
4655fe80 7805
60bed5fd 780619991122
7807 - Make <enter> close gnome-ssh-askpass (Debian bug #50299)
2f2cc3f9 7808 - OpenBSD CVS Changes
bcbf86ec 7809 - [ssh-keygen.c]
7810 don't create ~/.ssh only if the user wants to store the private
7811 key there. show fingerprint instead of public-key after
2f2cc3f9 7812 keygeneration. ok niels@
b09a984b 7813 - Added OpenBSD bsd-strlcat.c, created bsd-strlcat.h
96ad4350 7814 - Added timersub() macro
b09a984b 7815 - Tidy RCSIDs of bsd-*.c
bcbf86ec 7816 - Added autoconf test and macro to deal with old PAM libraries
96ad4350 7817 pam_strerror definition (one arg vs two).
530f1889 7818 - Fix EGD problems (Thanks to Ben Taylor <bent@clark.net>)
bcbf86ec 7819 - Retry /dev/urandom reads interrupted by signal (report from
530f1889 7820 Robert Hardy <rhardy@webcon.net>)
1647c2b5 7821 - Added a setenv replacement for systems which lack it
d84a9a44 7822 - Only display public key comment when presenting ssh-askpass dialog
7823 - Released 1.2pre14
60bed5fd 7824
bcbf86ec 7825 - Configure, Make and changelog corrections from Tudor Bosman
2ddcfdf3 7826 <tudorb@jm.nu> and Niels Kristian Bech Jensen <nkbj@image.dk>
7827
9d6b7add 782819991121
2f2cc3f9 7829 - OpenBSD CVS Changes:
60bed5fd 7830 - [channels.c]
7831 make this compile, bad markus
7832 - [log.c readconf.c servconf.c ssh.h]
7833 bugfix: loglevels are per host in clientconfig,
7834 factor out common log-level parsing code.
7835 - [servconf.c]
7836 remove unused index (-Wall)
7837 - [ssh-agent.c]
7838 only one 'extern char *__progname'
7839 - [sshd.8]
7840 document SIGHUP, -Q to synopsis
7841 - [sshconnect.c serverloop.c sshd.c packet.c packet.h]
7842 [channels.c clientloop.c]
7843 SSH_CMSG_MAX_PACKET_SIZE, some clients use this, some need this, niels@
7844 [hope this time my ISP stays alive during commit]
7845 - [OVERVIEW README] typos; green@freebsd
7846 - [ssh-keygen.c]
7847 replace xstrdup+strcat with strlcat+fixed buffer, fixes OF (bad me)
7848 exit if writing the key fails (no infinit loop)
7849 print usage() everytime we get bad options
7850 - [ssh-keygen.c] overflow, djm@mindrot.org
7851 - [sshd.c] fix sigchld race; cjc5@po.cwru.edu
61e96248 7852
2b942fe0 785319991120
bcbf86ec 7854 - Merged more Solaris support from Marc G. Fournier
2b942fe0 7855 <marc.fournier@acadiau.ca>
7856 - Wrote autoconf tests for integer bit-types
7857 - Fixed enabling kerberos support
bcbf86ec 7858 - Fix segfault in ssh-keygen caused by buffer overrun in filename
13c36c4c 7859 handling.
2b942fe0 7860
06479889 786119991119
7862 - Merged PAM buffer overrun patch from Chip Salzenberg <chip@valinux.com>
2ad77510 7863 - Merged OpenBSD CVS changes
7864 - [auth-rhosts.c auth-rsa.c ssh-agent.c sshconnect.c sshd.c]
7865 more %d vs. %s in fmt-strings
7866 - [authfd.c]
7867 Integers should not be printed with %s
7b1cc56c 7868 - EGD uses a socket, not a named pipe. Duh.
7869 - Fix includes in fingerprint.c
29dbde15 7870 - Fix scp progress bar bug again.
bcbf86ec 7871 - Move ssh-askpass from ${libdir}/ssh to ${libexecdir}/ssh at request of
736890c4 7872 David Rankin <drankin@bohemians.lexington.ky.us>
91b8065d 7873 - Added autoconf option to enable Kerberos 4 support (untested)
7874 - Added autoconf option to enable AFS support (untested)
7875 - Added autoconf option to enable S/Key support (untested)
7876 - Added autoconf option to enable TCP wrappers support (compiles OK)
beb43d31 7877 - Renamed BSD helper function files to bsd-*
bcbf86ec 7878 - Added tests for login and daemon and enable OpenBSD replacements for
caf3bc51 7879 when they are absent.
7880 - Added non-PAM MD5 password support patch from Tudor Bosman <tudorb@jm.nu>
06479889 7881
2bd61362 788219991118
7883 - Merged OpenBSD CVS changes
7884 - [scp.c] foregroundproc() in scp
7885 - [sshconnect.h] include fingerprint.h
bcbf86ec 7886 - [sshd.c] bugfix: the log() for passwd-auth escaped during logging
2bd61362 7887 changes.
0c16a097 7888 - [ssh.1] Spell my name right.
2bd61362 7889 - Added openssh.com info to README
7890
f095fcc7 789119991117
7892 - Merged OpenBSD CVS changes
7893 - [ChangeLog.Ylonen] noone needs this anymore
7894 - [authfd.c] close-on-exec for auth-socket, ok deraadt
bcbf86ec 7895 - [hostfile.c]
7896 in known_hosts key lookup the entry for the bits does not need
7897 to match, all the information is contained in n and e. This
7898 solves the problem with buggy servers announcing the wrong
f095fcc7 7899 modulus length. markus and me.
bcbf86ec 7900 - [serverloop.c]
7901 bugfix: check for space if child has terminated, from:
f095fcc7 7902 iedowse@maths.tcd.ie
7903 - [ssh-add.1 ssh-add.c ssh-keygen.1 ssh-keygen.c sshconnect.c]
7904 [fingerprint.c fingerprint.h]
7905 rsa key fingerprints, idea from Bjoern Groenvall <bg@sics.se>
7906 - [ssh-agent.1] typo
7907 - [ssh.1] add OpenSSH information to AUTHOR section. okay markus@
bcbf86ec 7908 - [sshd.c]
f095fcc7 7909 force logging to stderr while loading private key file
7910 (lost while converting to new log-levels)
7911
4d195447 791219991116
7913 - Fix some Linux libc5 problems reported by Miles Wilson <mw@mctitle.com>
7914 - Merged OpenBSD CVS changes:
7915 - [auth-rh-rsa.c auth-rsa.c authfd.c authfd.h hostfile.c mpaux.c]
7916 [mpaux.h ssh-add.c ssh-agent.c ssh.h ssh.c sshd.c]
7917 the keysize of rsa-parameter 'n' is passed implizit,
7918 a few more checks and warnings about 'pretended' keysizes.
7919 - [cipher.c cipher.h packet.c packet.h sshd.c]
7920 remove support for cipher RC4
7921 - [ssh.c]
7922 a note for legay systems about secuity issues with permanently_set_uid(),
7923 the private hostkey and ptrace()
7924 - [sshconnect.c]
7925 more detailed messages about adding and checking hostkeys
7926
dad9a31e 792719991115
7928 - Merged OpenBSD CVS changes:
bcbf86ec 7929 - [ssh-add.c] change passphrase loop logic and remove ref to
dad9a31e 7930 $DISPLAY, ok niels
7931 - Changed to ssh-add.c broke askpass support. Revised it to be a little more
bcbf86ec 7932 modular.
dad9a31e 7933 - Revised autoconf support for enabling/disabling askpass support.
e7c0f9d5 7934 - Merged more OpenBSD CVS changes:
704b1659 7935 [auth-krb4.c]
7936 - disconnect if getpeername() fails
7937 - missing xfree(*client)
7938 [canohost.c]
7939 - disconnect if getpeername() fails
7940 - fix comment: we _do_ disconnect if ip-options are set
7941 [sshd.c]
7942 - disconnect if getpeername() fails
7943 - move checking of remote port to central place
7944 [auth-rhosts.c] move checking of remote port to central place
7945 [log-server.c] avoid extra fd per sshd, from millert@
7946 [readconf.c] print _all_ bad config-options in ssh(1), too
7947 [readconf.h] print _all_ bad config-options in ssh(1), too
7948 [ssh.c] print _all_ bad config-options in ssh(1), too
7949 [sshconnect.c] disconnect if getpeername() fails
e7c0f9d5 7950 - OpenBSD's changes to sshd.c broke the PAM stuff, re-merged it.
c75a1a66 7951 - Various small cleanups to bring diff (against OpenBSD) size down.
f601d847 7952 - Merged more Solaris compability from Marc G. Fournier
7953 <marc.fournier@acadiau.ca>
7954 - Wrote autoconf tests for __progname symbol
986a22ec 7955 - RPM spec file fixes from Jim Knoble <jmknoble@jmknoble.cx>
0c372277 7956 - Released 1.2pre12
7957
7958 - Another OpenBSD CVS update:
7959 - [ssh-keygen.1] fix .Xr
dad9a31e 7960
92da7197 796119991114
7962 - Solaris compilation fixes (still imcomplete)
7963
94f7bb9e 796419991113
dd092f97 7965 - Build patch from Niels Kristian Bech Jensen <nkbj@image.dk>
7966 - Don't install config files if they already exist
7967 - Fix inclusion of additional preprocessor directives from acconfig.h
94f7bb9e 7968 - Removed redundant inclusions of config.h
e9c75a39 7969 - Added 'Obsoletes' lines to RPM spec file
94f7bb9e 7970 - Merged OpenBSD CVS changes:
7971 - [bufaux.c] save a view malloc/memcpy/memset/free's, ok niels
bcbf86ec 7972 - [scp.c] fix overflow reported by damien@ibs.com.au: off_t
94f7bb9e 7973 totalsize, ok niels,aaron
bcbf86ec 7974 - Delay fork (-f option) in ssh until after port forwarded connections
94f7bb9e 7975 have been initialised. Patch from Jani Hakala <jahakala@cc.jyu.fi>
b2344d54 7976 - Added shadow password patch from Thomas Neumann <tom@smart.ruhr.de>
7977 - Added ifdefs to auth-passwd.c to exclude it when PAM is enabled
dd092f97 7978 - Tidied default config file some more
7979 - Revised Redhat initscript to fix bug: sshd (re)start would fail
7980 if executed from inside a ssh login.
94f7bb9e 7981
e35c1dc2 798219991112
7983 - Merged changes from OpenBSD CVS
7984 - [sshd.c] session_key_int may be zero
b4748e2f 7985 - [auth-rh-rsa.c servconf.c servconf.h ssh.h sshd.8 sshd.c sshd_config]
bcbf86ec 7986 IgnoreUserKnownHosts(default=no), used for RhostRSAAuth, ok
b4748e2f 7987 deraadt,millert
7988 - Brought default sshd_config more in line with OpenBSD's
547c9f30 7989 - Grab server in gnome-ssh-askpass (Debian bug #49872)
7990 - Released 1.2pre10
e35c1dc2 7991
8bc7973f 7992 - Added INSTALL documentation
6fa724bc 7993 - Merged yet more changes from OpenBSD CVS
7994 - [auth-rh-rsa.c auth-rhosts.c auth-rsa.c channels.c clientloop.c]
7995 [ssh.c ssh.h sshconnect.c sshd.c]
7996 make all access to options via 'extern Options options'
7997 and 'extern ServerOptions options' respectively;
7998 options are no longer passed as arguments:
7999 * make options handling more consistent
8000 * remove #include "readconf.h" from ssh.h
8001 * readconf.h is only included if necessary
8002 - [mpaux.c] clear temp buffer
8003 - [servconf.c] print _all_ bad options found in configfile
045672f9 8004 - Make ssh-askpass support optional through autoconf
59b0f0d4 8005 - Fix nasty division-by-zero error in scp.c
8006 - Released 1.2pre11
8bc7973f 8007
4cca272e 800819991111
8009 - Added (untested) Entropy Gathering Daemon (EGD) support
67d68e3a 8010 - Fixed /dev/urandom fd leak (Debian bug #49722)
5bbb5681 8011 - Merged OpenBSD CVS changes:
8012 - [auth-rh-rsa.c] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
8013 - [ssh.1] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
8014 - [sshd.8] user/958: check ~/.ssh/known_hosts for rhosts-rsa, too
bcbf86ec 8015 - Fix integer overflow which was messing up scp's progress bar for large
3f1d9bcd 8016 file transfers. Fix submitted to OpenBSD developers. Report and fix
8017 from Kees Cook <cook@cpoint.net>
6a17f9c2 8018 - Merged more OpenBSD CVS changes:
bcbf86ec 8019 - [auth-krb4.c auth-passwd.c] remove x11- and krb-cleanup from fatal()
6a17f9c2 8020 + krb-cleanup cleanup
8021 - [clientloop.c log-client.c log-server.c ]
8022 [readconf.c readconf.h servconf.c servconf.h ]
8023 [ssh.1 ssh.c ssh.h sshd.8]
8024 add LogLevel {QUIET, FATAL, ERROR, INFO, CHAT, DEBUG} to ssh/sshd,
8025 obsoletes QuietMode and FascistLogging in sshd.
e35c1dc2 8026 - [sshd.c] fix fatal/assert() bug reported by damien@ibs.com.au:
8027 allow session_key_int != sizeof(session_key)
8028 [this should fix the pre-assert-removal-core-files]
8029 - Updated default config file to use new LogLevel option and to improve
8030 readability
8031
f370266e 803219991110
67d68e3a 8033 - Merged several minor fixes:
f370266e 8034 - ssh-agent commandline parsing
8035 - RPM spec file now installs ssh setuid root
8036 - Makefile creates libdir
4cca272e 8037 - Merged beginnings of Solaris compability from Marc G. Fournier
8038 <marc.fournier@acadiau.ca>
f370266e 8039
d4f11b59 804019991109
8041 - Autodetection of SSL/Crypto library location via autoconf
8042 - Fixed location of ssh-askpass to follow autoconf
8043 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
8044 - Autodetection of RSAref library for US users
8045 - Minor doc updates
560557bb 8046 - Merged OpenBSD CVS changes:
8047 - [rsa.c] bugfix: use correct size for memset()
8048 - [sshconnect.c] warn if announced size of modulus 'n' != real size
f025becb 8049 - Added GNOME passphrase requestor (use --with-gnome-askpass)
d397b172 8050 - RPM build now creates subpackages
aa51e7cc 8051 - Released 1.2pre9
d4f11b59 8052
e1a9c08d 805319991108
8054 - Removed debian/ directory. This is now being maintained separately.
8055 - Added symlinks for slogin in RPM spec file
8056 - Fixed permissions on manpages in RPM spec file
8057 - Added references to required libraries in README file
8058 - Removed config.h.in from CVS
8059 - Removed pwdb support (better pluggable auth is provided by glibc)
8060 - Made PAM and requisite libdl optional
8061 - Removed lots of unnecessary checks from autoconf
8062 - Added support and autoconf test for openpty() function (Unix98 pty support)
8063 - Fix for scp not finding ssh if not installed as /usr/bin/ssh
8064 - Added TODO file
8065 - Merged parts of Debian patch From Phil Hands <phil@hands.com>:
8066 - Added ssh-askpass program
8067 - Added ssh-askpass support to ssh-add.c
8068 - Create symlinks for slogin on install
8069 - Fix "distclean" target in makefile
8070 - Added example for ssh-agent to manpage
8071 - Added support for PAM_TEXT_INFO messages
8072 - Disable internal /etc/nologin support if PAM enabled
8073 - Merged latest OpenBSD CVS changes:
5bae4ab8 8074 - [all] replace assert() with error, fatal or packet_disconnect
e1a9c08d 8075 - [sshd.c] don't send fail-msg but disconnect if too many authentication
8076 failures
e1a9c08d 8077 - [sshd.c] remove unused argument. ok dugsong
8078 - [sshd.c] typo
8079 - [rsa.c] clear buffers used for encryption. ok: niels
8080 - [rsa.c] replace assert() with error, fatal or packet_disconnect
ade6fccd 8081 - [auth-krb4.c] remove unused argument. ok dugsong
e1a9c08d 8082 - Fixed coredump after merge of OpenBSD rsa.c patch
9010d60a 8083 - Released 1.2pre8
e1a9c08d 8084
3028328e 808519991102
8086 - Merged change from OpenBSD CVS
8087 - One-line cleanup in sshd.c
8088
474832c5 808919991030
8090 - Integrated debian package support from Dan Brosemer <odin@linuxfreak.com>
69256d9d 8091 - Merged latest updates for OpenBSD CVS:
8092 - channels.[ch] - remove broken x11 fix and document istate/ostate
8093 - ssh-agent.c - call setsid() regardless of argv[]
8094 - ssh.c - save a few lines when disabling rhosts-{rsa-}auth
8095 - Documentation cleanups
8096 - Renamed README -> README.Ylonen
8097 - Renamed README.openssh ->README
474832c5 8098
339660f6 809919991029
8100 - Renamed openssh* back to ssh* at request of Theo de Raadt
8101 - Incorporated latest changes from OpenBSD's CVS
8102 - Integrated Makefile patch from Niels Kristian Bech Jensen <nkbj@image.dk>
8103 - Integrated PAM env patch from Nalin Dahyabhai <nalin.dahyabhai@pobox.com>
549b3eed 8104 - Make distclean now removed configure script
8105 - Improved PAM logging
8106 - Added some debug() calls for PAM
4ecd19ea 8107 - Removed redundant subdirectories
bcbf86ec 8108 - Integrated part of a patch from Dan Brosemer <odin@linuxfreak.com> for
4ecd19ea 8109 building on Debian.
242588e6 8110 - Fixed off-by-one error in PAM env patch
8111 - Released 1.2pre6
339660f6 8112
5881cd60 811319991028
8114 - Further PAM enhancements.
8115 - Much cleaner
8116 - Now uses account and session modules for all logins.
8117 - Integrated patch from Dan Brosemer <odin@linuxfreak.com>
8118 - Build fixes
8119 - Autoconf
8120 - Change binary names to open*
8121 - Fixed autoconf script to detect PAM on RH6.1
8122 - Added tests for libpwdb, and OpenBSD functions to autoconf
221395b3 8123 - Released 1.2pre4
fca82d2e 8124
8125 - Imported latest OpenBSD CVS code
8126 - Updated README.openssh
93f04616 8127 - Released 1.2pre5
fca82d2e 8128
5881cd60 812919991027
8130 - Adapted PAM patch.
8131 - Released 1.0pre2
8132
8133 - Excised my buggy replacements for strlcpy and mkdtemp
8134 - Imported correct OpenBSD strlcpy and mkdtemp routines.
8135 - Reduced arc4random_stir entropy read to 32 bytes (256 bits)
8136 - Picked up correct version number from OpenBSD
8137 - Added sshd.pam PAM configuration file
8138 - Added sshd.init Redhat init script
8139 - Added openssh.spec RPM spec file
8140 - Released 1.2pre3
8141
814219991026
8143 - Fixed include paths of OpenSSL functions
8144 - Use OpenSSL MD5 routines
8145 - Imported RC4 code from nanocrypt
8146 - Wrote replacements for OpenBSD arc4random* functions
8147 - Wrote replacements for strlcpy and mkdtemp
8148 - Released 1.0pre1
0b202697 8149
8150$Id$
This page took 2.420879 seconds and 5 git commands to generate.