]> andersk Git - openssh.git/blame - ChangeLog
a - millert@cvs.openbsd.org 2003/06/03 02:56:16
[openssh.git] / ChangeLog
CommitLineData
3a2b2b44 120030603
2 - (djm) Replace setproctitle replacement with code derived from
3 UCB sendmail
c5a7d788 4 - (djm) OpenBSD CVS Sync
5 - markus@cvs.openbsd.org 2003/06/02 09:17:34
6 [auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
7 [canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
8 [sshd_config.5]
9 deprecate VerifyReverseMapping since it's dangerous if combined
10 with IP based access control as noted by Mike Harding; replace with
11 a UseDNS option, UseDNS is on by default and includes the
12 VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
13 ok deraadt@, djm@
d981089c 14 - millert@cvs.openbsd.org 2003/06/03 02:56:16
15 [scp.c]
16 Remove the advertising clause in the UCB license which Berkeley
17 rescinded 22 July 1999. Proofed by myself and Theo.
c5a7d788 18 - (djm) Fix portable-specific uses of verify_reverse_mapping too
3e67f7df 19 - (djm) Sync openbsd-compat with OpenBSD CVS.
20 - No more 4-term BSD licenses in our tree
5d8ca8c7 21 - (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
3a2b2b44 22
aff561f9 2320030602
24 - (djm) Fix segv from bad reordering in auth-pam.c
416c732d 25 - (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
26 clobber
1b7342ab 27 - (tim) openbsd-compat/xmmap.[ch] License clarifications. Add missing
28 CVS ID.
8862e142 29 - (djm) Remove "noip6" option from RedHat spec file. This may now be
30 set at runtime using AddressFamily option.
58ba3cb7 31 - (djm) Fix use of macro before #define in cipher-aes.c
382fe2fa 32 - (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
b0545fe6 33 - (djm) OpenBSD CVS Sync
34 - djm@cvs.openbsd.org 2003/05/26 12:54:40
35 [sshconnect.c]
36 fix format strings; ok markus@
fa5120a0 37 - deraadt@cvs.openbsd.org 2003/05/29 16:58:45
38 [sshd.c uidswap.c]
39 seteuid and setegid; markus ok
0f92946c 40 - jakob@cvs.openbsd.org 2003/06/02 08:31:10
41 [ssh_config.5]
42 VerifyHostKeyDNS is v2 only. ok markus@
aff561f9 43
4f178be8 4420030530
45 - (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
46 roumenpetrov.info
eabb99c6 47 - (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
4f178be8 48
4881aebb 4920030526
50 - (djm) Avoid auth2-chall.c warning when compiling without
51 PAM, BSD_AUTH and SKEY
52
5b0fe364 5320030525
54- (djm) OpenBSD CVS Sync
55 - djm@cvs.openbsd.org 2003/05/24 09:02:22
56 [log.c]
57 pass logged data through strnvis; ok markus
b9ed513a 58 - djm@cvs.openbsd.org 2003/05/24 09:30:40
59 [authfile.c monitor.c sftp-common.c sshpty.c]
60 cast some types for printing; ok markus@
5b0fe364 61
44c78996 6220030524
63 - (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
64
d83ebe4a 6520030523
66 - (djm) Use VIS_SAFE on logged strings rather than default strnvis
67 encoding (which encodes many more characters)
bd47824b 68 - OpenBSD CVS Sync
69 - jmc@cvs.openbsd.org 2003/05/20 12:03:35
70 [sftp.1]
71 - new sentence, new line
72 - added .Xr's
73 - typos
74 ok djm@
3cbc677d 75 - jmc@cvs.openbsd.org 2003/05/20 12:09:31
76 [ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
77 new sentence, new line
da54f5be 78 - djm@cvs.openbsd.org 2003/05/23 08:29:30
79 [sshconnect.c]
80 fix leak; ok markus@
d83ebe4a 81
c453493f 8220030520
83 - (djm) OpenBSD CVS Sync
84 - deraadt@cvs.openbsd.org 2003/05/18 23:22:01
85 [log.c]
86 use syslog_r() in a signal handler called place; markus ok
79d4fc55 87 - (djm) Configure logic to detect syslog_r and friends
c453493f 88
acb50584 8920030519
90 - (djm) Sync auth-pam.h with what we actually implement
91
9220030518
5ff453c0 93 - (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
94 recent merge
f811e52a 95 - (djm) OpenBSD CVS Sync
96 - djm@cvs.openbsd.org 2003/05/16 03:27:12
97 [readconf.c ssh_config ssh_config.5 ssh-keysign.c]
98 add AddressFamily option to ssh_config (like -4, -6 on commandline).
99 Portable bug #534; ok markus@
013b1214 100 - itojun@cvs.openbsd.org 2003/05/17 03:25:58
101 [auth-rhosts.c]
102 just in case, put numbers to sscanf %s arg.
25b66522 103 - markus@cvs.openbsd.org 2003/05/17 04:27:52
104 [cipher.c cipher-ctr.c myproposal.h]
105 experimental support for aes-ctr modes from
106 http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
107 ok djm@
25351757 108 - (djm) Remove IPv4 by default hack now that we can specify AF in config
3bf784bc 109 - (djm) Tidy and trim TODO
bffa6723 110 - (djm) Sync openbsd-compat/ with OpenBSD CVS head
9901cb37 111 - (djm) Big KNF on openbsd-compat/
f1da2b8b 112 - (djm) KNF on md5crypt.[ch]
113 - (djm) KNF on auth-sia.[ch]
5ff453c0 114
f123055b 11520030517
116 - (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
117
c936c243 11820030516
119 - (djm) OpenBSD CVS Sync
120 - djm@cvs.openbsd.org 2003/05/15 13:52:10
121 [ssh.c]
122 Make "ssh -V" print the OpenSSL version in a human readable form. Patch
123 from Craig Leres (mindrot at ee.lbl.gov); ok markus@
a2144546 124 - jakob@cvs.openbsd.org 2003/05/15 14:02:47
125 [readconf.c servconf.c]
126 warn for unsupported config option. ok markus@
5bdfde81 127 - markus@cvs.openbsd.org 2003/05/15 14:09:21
128 [auth2-krb5.c]
129 fix 64bit issue; report itojun@
09ab3296 130 - djm@cvs.openbsd.org 2003/05/15 14:55:25
131 [readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
132 add a ConnectTimeout option to ssh, based on patch from
133 Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
b06b11ad 134 - (djm) Add warning for UsePAM when built without PAM support
7be625e1 135 - (djm) A few type mismatch fixes from Bug #565
0eb6370a 136 - (djm) Guard free_pam_environment against NULL argument. Works around
137 HP/UX PAM problems debugged by dtucker
c936c243 138
7efc7f57 13920030515
140 - (djm) OpenBSD CVS Sync
141 - jmc@cvs.openbsd.org 2003/05/14 13:11:56
142 [ssh-agent.1]
143 setup -> set up;
144 from wiz@netbsd
21289cd0 145 - jakob@cvs.openbsd.org 2003/05/14 18:16:20
146 [key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
147 [dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
148 add experimental support for verifying hos keys using DNS as described
149 in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
150 ok markus@ and henning@
16a79097 151 - markus@cvs.openbsd.org 2003/05/14 22:24:42
152 [clientloop.c session.c ssh.1]
153 allow to send a BREAK to the remote system; ok various
b8c2031b 154 - markus@cvs.openbsd.org 2003/05/15 00:28:28
155 [sshconnect2.c]
156 cleanup unregister of per-method packet handlers; ok djm@
d0ec7f42 157 - jakob@cvs.openbsd.org 2003/05/15 01:48:10
158 [readconf.c readconf.h servconf.c servconf.h]
159 always parse kerberos options. ok djm@ markus@
b414a17b 160 - jakob@cvs.openbsd.org 2003/05/15 02:27:15
161 [dns.c]
162 add missing freerrset
3b6e3da9 163 - markus@cvs.openbsd.org 2003/05/15 03:08:29
164 [cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
165 split out custom EVP ciphers
02159d9b 166 - djm@cvs.openbsd.org 2003/05/15 03:10:52
167 [ssh-keygen.c]
168 avoid warning; ok jakob@
4a26f5c5 169 - mouring@cvs.openbsd.org 2003/05/15 03:39:07
170 [sftp-int.c]
171 Make put/get (globed and nonglobed) code more consistant. OK djm@
c44f10c6 172 - mouring@cvs.openbsd.org 2003/05/15 03:43:59
dc69f53c 173 [sftp-int.c sftp.c]
c44f10c6 174 Teach ls how to display multiple column display and allow users
175 to return to single column format via 'ls -1'. OK @djm
1457e7ff 176 - jakob@cvs.openbsd.org 2003/05/15 04:08:44
177 [readconf.c servconf.c]
178 disable kerberos when not supported. ok markus@
861f0365 179 - markus@cvs.openbsd.org 2003/05/15 04:08:41
180 [ssh.1]
181 ~B is ssh2 only
d0ec7f42 182 - (djm) Always parse UsePAM
3e05e934 183 - (djm) Configure glue for DNS support (code doesn't work in portable yet)
4460d509 184 - (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
86ee6794 185 - (djm) Tidy Makefile clean targets
2636769c 186 - (djm) Adapt README.dns for portable
2d2e4a34 187 - (djm) Avoid uuencode.c warnings
1457e7ff 188 - (djm) Enable UsePAM when built --with-pam
67467c30 189 - (djm) Only build getrrsetbyname replacement when using --with-dns
f420d2ba 190 - (djm) Bug #529: sshd doesn't work correctly after SIGHUP (copy argv
191 correctly)
3c49ef10 192 - (djm) Bug #444: Wrong paths after reconfigure
321735c7 193 - (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
f420d2ba 194
dd3ebb5a 19520030514
196 - (djm) Bug #117: Don't lie to PAM about username
0608f8a7 197 - (djm) RCSID sync w/ OpenBSD
204fde99 198 - (djm) OpenBSD CVS Sync
199 - djm@cvs.openbsd.org 2003/04/09 12:00:37
200 [readconf.c]
201 strip trailing whitespace from config lines before parsing.
202 Fixes bz 528; ok markus@
18ae3c67 203 - markus@cvs.openbsd.org 2003/04/12 10:13:57
204 [cipher.c]
205 hide cipher details; ok djm@
45c42d58 206 - markus@cvs.openbsd.org 2003/04/12 10:15:36
207 [misc.c]
208 debug->debug2
c825cd79 209 - naddy@cvs.openbsd.org 2003/04/12 11:40:15
210 [ssh.1]
211 document -V switch, fix wording; ok markus@
3e131a6d 212 - markus@cvs.openbsd.org 2003/04/14 14:17:50
213 [channels.c sshconnect.c sshd.c ssh-keyscan.c]
214 avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
927e9f8b 215 - mouring@cvs.openbsd.org 2003/04/14 21:31:27
216 [sftp-int.c]
217 Missing globfree(&g) in process_put() spotted by Vince Brimhall
218 <VBrimhall@novell.com>. ok@ Theo
219 - markus@cvs.openbsd.org 2003/04/16 14:35:27
220 [auth.h]
221 document struct Authctxt; with solar
b9e5aff6 222 - deraadt@cvs.openbsd.org 2003/04/26 04:29:49
223 [ssh-keyscan.c]
224 -t in usage(); rogier@quaak.org
9a26a6e2 225 - mouring@cvs.openbsd.org 2003/04/30 01:16:20
226 [sshd.8 sshd_config.5]
227 Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
228 Bug #550 and * escaping suggested by jmc@.
09dc8896 229 - david@cvs.openbsd.org 2003/04/30 20:41:07
230 [sshd.8]
231 fix invalid .Pf macro usage introduced in previous commit
232 ok jmc@ mouring@
3566c73c 233 - markus@cvs.openbsd.org 2003/05/11 16:56:48
234 [authfile.c ssh-keygen.c]
235 change key_load_public to try to read a public from:
236 rsa1 private or rsa1 public and ssh2 keys.
237 this makes ssh-keygen -e fail for ssh1 keys more gracefully
238 for example; report from itojun (netbsd pr 20550).
0d942eff 239 - markus@cvs.openbsd.org 2003/05/11 20:30:25
240 [channels.c clientloop.c serverloop.c session.c ssh.c]
241 make channel_new() strdup the 'remote_name' (not the caller); ok theo
43348518 242 - markus@cvs.openbsd.org 2003/05/12 16:55:37
243 [sshconnect2.c]
244 for pubkey authentication try the user keys in the following order:
245 1. agent keys that are found in the config file
246 2. other agent keys
247 3. keys that are only listed in the config file
248 this helps when an agent has many keys, where the server might
249 close the connection before the correct key is used. report & ok pb@
dc109cfe 250 - markus@cvs.openbsd.org 2003/05/12 18:35:18
251 [ssh-keyscan.1]
252 typo: DSA keys are of type ssh-dss; Brian Poole
81466908 253 - markus@cvs.openbsd.org 2003/05/14 00:52:59
254 [ssh2.h]
255 ranges for per auth method messages
256 - djm@cvs.openbsd.org 2003/05/14 01:00:44
257 [sftp.1]
258 emphasise the batchmode functionality and make reference to pubkey auth,
259 both of which are FAQs; ok markus@
802e01b8 260 - markus@cvs.openbsd.org 2003/05/14 02:15:47
261 [auth2.c monitor.c sshconnect2.c auth2-krb5.c]
262 implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
263 server interops with commercial client; ok jakob@ djm@
72c5fe79 264 - jmc@cvs.openbsd.org 2003/05/14 08:25:39
265 [sftp.1]
266 - better formatting in SYNOPSIS
267 - whitespace at EOL
268 ok djm@
3a39206f 269 - markus@cvs.openbsd.org 2003/05/14 08:57:49
270 [monitor.c]
271 http://bugzilla.mindrot.org/show_bug.cgi?id=560
272 Privsep child continues to run after monitor killed.
273 Pass monitor signals through to child; Darren Tucker
751092f9 274 - (djm) Make portable build with MIT krb5 (some issues remain)
7fceb20d 275 - (djm) Add new UsePAM configuration directive to allow runtime control
276 over usage of PAM. This allows non-root use of sshd when built with
277 --with-pam
817e6d38 278 - (djm) Die screaming if start_pam() is called when UsePAM=no
83ccf11a 279 - (djm) Avoid KrbV leak for MIT Kerberos
b1848832 280 - (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
fa065de2 281 - (djm) Bug #258: sscanf("[0-9]") -> sscanf("[0123456789]") for portability
dd3ebb5a 282
91f3aa9b 28320030512
284 - (djm) Redhat spec: Don't install profile.d scripts when not
285 building with GNOME/GTK askpass (patch from bet@rahul.net)
286
5def520a 28720030510
288 - (dtucker) Bug #318: Create ssh_prng_cmds.out during "make" rather than
289 "make install". Patch by roth@feep.net.
ad84c479 290 - (dtucker) Bug #536: Test for and work around openpty/controlling tty
291 problem on Linux (fixes "could not set controlling tty" errors).
05114c74 292 - (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
293 proper challenge-response module
23ab1f36 294 - (djm) 2-clause license on loginrec.c, with permission from
295 andre@ae-35.com
5def520a 296
43ce025d 29720030504
dd594f99 298 - (dtucker) Bug #497: Move #include of bsd-cygwin_util.h to openbsd-compat.h.
299 Patch from vinschen@redhat.com.
43ce025d 300
2cd5dbba 30120030503
302 - (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
303 by wendyp@cray.com.
304
bf7c1e6c 30520030502
306 - (dtucker) Bug #544: ignore invalid cmsg_type on Linux 2.0 kernels,
307 privsep should now work.
73d9dad3 308 - (dtucker) Move handling of bad password authentications into a platform
990278ef 309 specific record_failed_login() function (affects AIX & Unicos). ok mouring@
bf7c1e6c 310
68ece370 31120030429
312 - (djm) Add back radix.o (used by AFS support), after it went missing from
313 Makefile many moons ago
314 - (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
315 - (djm) Fix blibpath specification for AIX/gcc
316 - (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
317
ded9dd18 31820030428
319 - (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
320 hacked code.
321
aceb0423 32220030427
323 - (bal) Bug #541: return; was dropped by mistake. Reported by
324 furrier@iglou.com
c8a50a34 325 - (bal) Since we don't support platforms lacking u_int_64. We may
326 as well clean out some of those evil #ifdefs
9a6fee8b 327 - (bal) auth1.c minor resync while looking at the code.
d7cf277b 328 - (bal) auth2.c same changed as above.
aceb0423 329
0a626302 33020030409
331 - (djm) Bug #539: Specify creation mode with O_CREAT for lastlog. Report
332 from matth@eecs.berkeley.edu
d35929b5 333 - (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
ffd7b36b 334 - (djm) OpenBSD CVS Sync
335 - markus@cvs.openbsd.org 2003/04/02 09:48:07
336 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
337 [readconf.h serverloop.c sshconnect2.c]
338 reapply rekeying chage, tested by henning@, ok djm@
16f1b5ca 339 - markus@cvs.openbsd.org 2003/04/02 14:36:26
340 [ssh-keysign.c]
341 potential segfault if KEY_UNSPEC; cjwatson@debian.org; bug #526
6c1bc5c5 342 - itojun@cvs.openbsd.org 2003/04/03 07:25:27
343 [progressmeter.c]
344 $OpenBSD$
345 - itojun@cvs.openbsd.org 2003/04/03 10:17:35
346 [progressmeter.c]
347 remove $OpenBSD$, as other *.c does not have it.
806e4c11 348 - markus@cvs.openbsd.org 2003/04/07 08:29:57
349 [monitor_wrap.c]
350 typo: get correct counters; introduced during rekeying change.
2f5b2528 351 - millert@cvs.openbsd.org 2003/04/07 21:58:05
352 [progressmeter.c]
353 The UCB copyright here is incorrect. This code did not originate
354 at UCB, it was written by Luke Mewburn. Updated the copyright at
355 the author's request. markus@ OK
356 - itojun@cvs.openbsd.org 2003/04/08 20:21:29
357 [*.c *.h]
358 rename log() into logit() to avoid name conflict. markus ok, from
359 netbsd
360 - (djm) XXX - Performed locally using:
361 "perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
70e1f62f 362 - hin@cvs.openbsd.org 2003/04/09 08:23:52
363 [servconf.c]
364 Don't include <krb.h> when compiling with Kerberos 5 support
2f5b2528 365 - (djm) Fix up missing include for packet.c
a3568201 366 - (djm) Fix missed log => logit occurance (reference by function pointer)
0a626302 367
4d0cb2e5 36820030402
369 - (bal) if IP_TOS is not found or broken don't try to compile in
370 packet_set_tos() function call. bug #527
371
a4e5acef 37220030401
373 - (djm) OpenBSD CVS Sync
374 - jmc@cvs.openbsd.org 2003/03/28 10:11:43
375 [scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
376 [ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
377 - killed whitespace
378 - new sentence new line
379 - .Bk for arguments
380 ok markus@
177f584b 381 - markus@cvs.openbsd.org 2003/04/01 10:10:23
382 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
383 [readconf.h serverloop.c sshconnect2.c]
384 rekeying bugfixes and automatic rekeying:
385 * both client and server rekey _automatically_
386 (a) after 2^31 packets, because after 2^32 packets
387 the sequence number for packets wraps
388 (b) after 2^(blocksize_in_bits/4) blocks
389 (see: draft-ietf-secsh-newmodes-00.txt)
390 (a) and (b) are _enabled_ by default, and only disabled for known
391 openssh versions, that don't support rekeying properly.
392 * client option 'RekeyLimit'
393 * do not reply to requests during rekeying
394 - markus@cvs.openbsd.org 2003/04/01 10:22:21
395 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
396 [readconf.h serverloop.c sshconnect2.c]
397 backout rekeying changes (for 3.6.1)
519bdfe8 398 - markus@cvs.openbsd.org 2003/04/01 10:31:26
399 [compat.c compat.h kex.c]
400 bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
401 tested by ho@ and myself
9dd240a3 402 - markus@cvs.openbsd.org 2003/04/01 10:56:46
403 [version.h]
404 3.6.1
ac01b518 405 - (djm) Crank spec file versions
b32453fe 406 - (djm) Release 3.6.1p1
a4e5acef 407
fd77a40f 40820030326
409 - (djm) OpenBSD CVS Sync
410 - deraadt@cvs.openbsd.org 2003/03/26 04:02:51
411 [sftp-server.c]
412 one last fix to the tree: race fix broke stuff; pr 3169;
413 srp@srparish.net, help from djm
414
8021857c 41520030325
416 - (djm) Fix getpeerid support for 64 bit BE systems. From
417 Arnd Bergmann <arndb@de.ibm.com>
418
cdb64c4d 41920030324
420 - (djm) OpenBSD CVS Sync
421 - markus@cvs.openbsd.org 2003/03/23 19:02:00
422 [monitor.c]
423 unbreak rekeying for privsep; ok millert@
424 - Release 3.6p1
62086365 425 - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
426 Report from murple@murple.net, diagnosis from dtucker@zip.com.au
cdb64c4d 427
0b202697 428$Id$
This page took 0.381992 seconds and 5 git commands to generate.