]> andersk Git - openssh.git/blame - ChangeLog
- dtucker@cvs.openbsd.org 2003/12/09 13:52:55
[openssh.git] / ChangeLog
CommitLineData
ef75d357 120031209
2 - (dtucker) OpenBSD CVS Sync
3 - matthieu@cvs.openbsd.org 2003/11/25 23:10:08
4 [ssh-add.1]
5 ssh-add doesn't need to be a descendant of ssh-agent. Ok markus@, jmc@.
dfeea606 6 - djm@cvs.openbsd.org 2003/11/26 21:44:29
7 [cipher-aes.c]
8 fix #ifdef before #define; ok markus@
9 (RCS ID sync only, Portable already had this)
adfde93f 10 - markus@cvs.openbsd.org 2003/12/02 12:15:10
11 [progressmeter.c]
12 improvments from andreas@:
13 * saner speed estimate for transfers that takes less than a second by
14 rounding the time to 1 second.
15 * when the transfer is finished calculate the actual total speed
16 rather than the current speed which is given during the transfer
fce39749 17 - markus@cvs.openbsd.org 2003/12/02 17:01:15
18 [channels.c session.c ssh-agent.c ssh.h sshd.c]
19 use SSH_LISTEN_BACKLOG (=128) in listen(2).
69e782ea 20 - djm@cvs.openbsd.org 2003/12/07 06:34:18
21 [moduli.c]
22 remove unused debugging #define templates
5acd7dc1 23 - markus@cvs.openbsd.org 2003/12/08 11:00:47
24 [kexgexc.c]
25 print requested group size in debug; ok djm
eb7a33b8 26 - dtucker@cvs.openbsd.org 2003/12/09 13:52:55
27 [moduli.c]
28 Prevent ssh-keygen -T from outputting moduli with a generator of 0, since
29 they can't be used for Diffie-Hellman. Assistance and ok djm@
b97b4f35 30 - (dtucker) [ssh-keyscan.c] Sync RCSIDs, missed in SSH_SSFDMAX change below.
ef75d357 31
e6354014 3220031208
33 - (tim) [configure.ac] Bug 770. Fix --without-rpath.
34
1639bb8f 3520031123
36 - (djm) [canohost.c] Move IPv4inV6 mapped address normalisation to its own
37 function and call it unconditionally
341c3efe 38 - (djm) OpenBSD CVS Sync
39 - djm@cvs.openbsd.org 2003/11/23 23:17:34
40 [ssh-keyscan.c]
41 from portable - use sysconf to detect fd limit; ok markus@
42 (tidy diff by adding SSH_SSFDMAX macro to defines.h)
e7e3e2c8 43 - djm@cvs.openbsd.org 2003/11/23 23:18:45
44 [ssh-keygen.c]
45 consistency PATH_MAX -> MAXPATHLEN; ok markus@
46 (RCS ID sync only)
47 - djm@cvs.openbsd.org 2003/11/23 23:21:21
48 [scp.c]
49 from portable: rename clashing variable limit-> limit_rate; ok markus@
50 (RCS ID sync only)
f7926e97 51 - dtucker@cvs.openbsd.org 2003/11/24 00:16:35
52 [ssh.1 ssh.c]
53 Make ssh -k mean GSSAPIDelegateCredentials=no. Suggestion & ok markus@
d74671e4 54 - (djm) Annotate OpenBSD-derived files in openbsd-compat/ with original
55 source file path (in OpenBSD tree).
1639bb8f 56
7fbb4189 5720031122
58 - (dtucker) [channels.c] Make AIX write limit code clearer. Suggested by djm@
f0b467ef 59 - (dtucker) [auth-passwd.c openbsd-compat/port-aix.c openbsd-compat/port-aix.h]
60 Move AIX specific password authentication code to port-aix.c, call
61 authenticate() until reenter flag is clear.
dbf8efb3 62 - (dtucker) [auth-sia.c configure.ac] Tru64 update from cmadams at hiwaay.net.
63 Use permanently_set_uid for SIA, only define DISABLE_FD_PASSING when SIA
64 is enabled, rely on SIA to check for locked accounts if enabled. ok djm@
10adbb52 65 - (djm) [scp.c] Rename limitbw -> limit_rate to match upstreamed patch
e20054de 66 - (djm) [sftp-int.c] Remove duplicated code from bogus sync
00df6acd 67 - (djm) [packet.c] Shuffle #ifdef to reduce conditionally compiled code
7fbb4189 68
81b161c2 6920031121
70 - (djm) OpenBSD CVS Sync
71 - markus@cvs.openbsd.org 2003/11/20 11:39:28
72 [progressmeter.c]
73 fix rounding errors; from andreas@
aff51935 74 - djm@cvs.openbsd.org 2003/11/21 11:57:03
75 [everything]
76 unexpand and delete whitespace at EOL; ok markus@
77 (done locally and RCS IDs synced)
81b161c2 78
3eaf3960 7920031118
4d1de3a3 80 - (djm) Fix early exit for root auth success when UsePAM=yes and
81 PermitRootLogin=no
3eaf3960 82 - (dtucker) [auth-pam.c] Convert chauthtok_conv into a generic tty_conv,
95077f48 83 and use it for do_pam_session. Fixes problems like pam_motd not
84 displaying anything. ok djm@
f79a6165 85 - (dtucker) [auth-pam.c] Only use pam_putenv if our platform has it. ok djm@
95077f48 86 - (djm) OpenBSD CVS Sync
87 - dtucker@cvs.openbsd.org 2003/11/18 00:40:05
88 [serverloop.c]
89 Correct check for authctxt->valid. ok djm@
b2a5802b 90 - djm@cvs.openbsd.org 2003/11/18 10:53:07
91 [monitor.c]
92 unbreak fake authloop for non-existent users (my screwup). Spotted and
93 tested by dtucker@; ok markus@
4d1de3a3 94
85a68682 9520031117
96 - (djm) OpenBSD CVS Sync
97 - djm@cvs.openbsd.org 2003/11/03 09:03:37
98 [auth-chall.c]
99 make this a little more idiot-proof; ok markus@
100 (includes portable-specific changes)
1a1bc5d5 101 - jakob@cvs.openbsd.org 2003/11/03 09:09:41
102 [sshconnect.c]
103 move changed key warning into warn_changed_key(). ok markus@
f5da7f70 104 - jakob@cvs.openbsd.org 2003/11/03 09:37:32
105 [sshconnect.c]
106 do not free static type pointer in warn_changed_key()
fdaef11e 107 - djm@cvs.openbsd.org 2003/11/04 08:54:09
108 [auth1.c auth2.c auth2-pubkey.c auth.h auth-krb5.c auth-passwd.c]
109 [auth-rhosts.c auth-rh-rsa.c auth-rsa.c monitor.c serverloop.c]
110 [session.c]
111 standardise arguments to auth methods - they should all take authctxt.
112 check authctxt->valid rather then pw != NULL; ok markus@
dc1759e6 113 - jakob@cvs.openbsd.org 2003/11/08 16:02:40
114 [auth1.c]
115 remove unused variable (pw). ok djm@
116 (id sync only - still used in portable)
512d319a 117 - jmc@cvs.openbsd.org 2003/11/08 19:17:29
118 [sftp-int.c]
119 typos from Jonathon Gray;
b6c7b7b7 120 - jakob@cvs.openbsd.org 2003/11/10 16:23:41
121 [bufaux.c bufaux.h cipher.c cipher.h hostfile.c hostfile.h key.c]
122 [key.h sftp-common.c sftp-common.h sftp-server.c sshconnect.c sshd.c]
123 [ssh-dss.c ssh-rsa.c uuencode.c uuencode.h]
124 constify. ok markus@ & djm@
15c8e3fd 125 - dtucker@cvs.openbsd.org 2003/11/12 10:12:15
126 [scp.c]
127 When called with -q, pass -q to ssh; suppresses SSH2 banner. ok markus@
0161a13d 128 - jakob@cvs.openbsd.org 2003/11/12 16:39:58
129 [dns.c dns.h readconf.c ssh_config.5 sshconnect.c]
130 update SSHFP validation. ok markus@
dd376e92 131 - jmc@cvs.openbsd.org 2003/11/12 20:14:51
132 [ssh_config.5]
133 make verb agree with subject, and kill some whitespace;
b930668c 134 - markus@cvs.openbsd.org 2003/11/14 13:19:09
135 [sshconnect2.c]
136 cleanup and minor fixes for the client code; from Simon Wilkinson
d3cbe6f8 137 - djm@cvs.openbsd.org 2003/11/17 09:45:39
138 [msg.c msg.h sshconnect2.c ssh-keysign.c]
139 return error on msg send/receive failure (rather than fatal); ok markus@
0789992b 140 - markus@cvs.openbsd.org 2003/11/17 11:06:07
141 [auth2-gss.c gss-genr.c gss-serv.c monitor.c monitor.h monitor_wrap.c]
142 [monitor_wrap.h sshconnect2.c ssh-gss.h]
143 replace "gssapi" with "gssapi-with-mic"; from Simon Wilkinson;
144 test + ok jakob.
7b2a0de3 145 - (djm) Bug #632: Don't call pam_end indirectly from within kbd-int
146 conversation function
2212fc98 147 - (djm) Export environment variables from authentication subprocess to
148 parent. Part of Bug #717
85a68682 149
1d58af42 15020031115
151 - (dtucker) [regress/agent-ptrace.sh] Test for GDB output from Solaris and
152 HP-UX, skip test on AIX.
153
74117b26 15420031113
155 - (dtucker) [auth-pam.c] Append newlines to lines output by the
156 pam_chauthtok_conv().
9e936326 157 - (dtucker) [README ssh-host-config ssh-user-config Makefile] (All
158 contrib/cygwin). Major update from vinschen at redhat.com.
159 - Makefile provides a `cygwin-postinstall' target to run right after
160 `make install'.
161 - Better support for Windows 2003 Server.
162 - Try to get permissions as correct as possible.
163 - New command line options to allow full automated host configuration.
164 - Create configs from skeletons in /etc/defaults/etc.
165 - Use /bin/bash, allows reading user input with readline support.
166 - Remove really old configs from /usr/local.
4f1b45b4 167 - (dtucker) [auth-pam.c] Add newline to accumulated PAM_TEXT_INFO and
168 PAM_ERROR_MSG messages.
74117b26 169
53554b24 17020031106
171 - (djm) Clarify UsePAM consequences a little more
172
c3d908f0 17320031103
174 - (dtucker) [contrib/cygwin/ssh-host-config] Ensure entries in /etc/services
175 are created correctly with CRLF line terminations. Patch from vinschen at
176 redhat.com.
74677ba3 177 - (dtucker) OpenBSD CVS Sync
178 - markus@cvs.openbsd.org 2003/10/15 09:48:45
179 [monitor_wrap.c]
180 check pmonitor != NULL
9da35e2c 181 - markus@cvs.openbsd.org 2003/10/21 09:50:06
182 [auth2-gss.c]
183 make sure the doid is larger than 2
b0b30ca6 184 - avsm@cvs.openbsd.org 2003/10/26 16:57:43
185 [sshconnect2.c]
186 rename 'supported' static var in userauth_gssapi() to 'gss_supported'
187 to avoid shadowing the global version. markus@ ok
f7fb35fe 188 - markus@cvs.openbsd.org 2003/10/28 09:08:06
189 [misc.c]
190 error->debug for getsockopt+TCP_NODELAY; several requests
d8d9afd0 191 - markus@cvs.openbsd.org 2003/11/02 11:01:03
192 [auth2-gss.c compat.c compat.h sshconnect2.c]
193 remove support for SSH_BUG_GSSAPI_BER; simon@sxw.org.uk
61893035 194 - (dtucker) [regress/agent-ptrace.sh] Use numeric uid and gid.
c3d908f0 195
f8ec2373 19620031021
197 - (dtucker) [INSTALL] Some system crypt() functions support MD5 passwords
198 directly. Noted by Darren.Moffat at sun.com.
5c4056b2 199 - (dtucker) [regress/agent-ptrace.sh] Skip agent-test unless SUDO is set,
200 make agent setgid during test.
f8ec2373 201
4897a87c 20220031017
203 - (dtucker) [INSTALL] Note that --with-md5 is now required on platforms with
204 MD5 passwords even if PAM support is enabled. From steev at detritus.net.
205
433e60ac 20620031015
207 - (dtucker) OpenBSD CVS Sync
208 - jmc@cvs.openbsd.org 2003/10/08 08:27:36
209 [scp.1 scp.c sftp-server.8 sftp.1 sftp.c ssh.1 sshd.8]
210 scp and sftp: add options list and sort options. options list requested
211 by deraadt@
212 sshd: use same format as ssh
213 ssh: remove wrong option from list
214 sftp-server: Subsystem is documented in ssh_config(5), not sshd(8)
215 ok deraadt@ markus@
2ecb78df 216 - markus@cvs.openbsd.org 2003/10/08 15:21:24
217 [readconf.c ssh_config.5]
218 default GSS API to no in client, too; ok jakob, deraadt@
d73a67d7 219 - markus@cvs.openbsd.org 2003/10/11 08:24:08
220 [readconf.c readconf.h ssh.1 ssh.c ssh_config.5]
221 remote x11 clients are now untrusted by default, uses xauth(8) to generate
222 untrusted cookies; ForwardX11Trusted=yes restores old behaviour.
223 ok deraadt; feedback and ok djm/fries
b56e99e2 224 - markus@cvs.openbsd.org 2003/10/11 08:26:43
225 [sshconnect2.c]
226 search keys in reverse order; fixes #684
02cd6c56 227 - markus@cvs.openbsd.org 2003/10/11 11:36:23
228 [monitor_wrap.c]
229 return NULL for missing banner; ok djm@
246bb171 230 - jmc@cvs.openbsd.org 2003/10/12 13:12:13
231 [ssh_config.5]
232 note that EnableSSHKeySign should be in the non-hostspecific section;
233 remove unnecessary .Pp;
234 ok markus@
b3054353 235 - markus@cvs.openbsd.org 2003/10/13 08:22:25
236 [scp.1 sftp.1]
237 don't refer to options related to forwarding; ok jmc@
b08b7370 238 - jakob@cvs.openbsd.org 2003/10/14 19:42:10
239 [dns.c dns.h readconf.c ssh-keygen.c sshconnect.c]
240 include SSHFP lookup code (not enabled by default). ok markus@
baf12e3f 241 - jakob@cvs.openbsd.org 2003/10/14 19:43:23
242 [README.dns]
243 update
c88de854 244 - markus@cvs.openbsd.org 2003/10/14 19:54:39
245 [session.c ssh-agent.c]
246 10X for mkdtemp; djm@
c31dc31c 247 - (dtucker) [acconfig.h configure.ac dns.c openbsd-compat/getrrsetbyname.c
248 openbsd-compat/getrrsetbyname.h] DNS fingerprint support is now always
249 compiled in but disabled in config.
11d40248 250 - (dtucker) [auth.c] Check for disabled password expiry on HP-UX Trusted Mode.
ea12f758 251 - (tim) [regress/banner.sh] portability fix.
433e60ac 252
a83a3125 25320031009
254 - (dtucker) [sshd_config.5] UsePAM defaults to "no". ok djm@
255
19e633e7 25620031008
257 - (dtucker) OpenBSD CVS Sync
258 - dtucker@cvs.openbsd.org 2003/10/07 01:47:27
259 [sshconnect2.c]
c8f0cf13 260 Don't use logit for banner, since it truncates to MSGBUFSIZ; bz #668 &
261 #707. ok markus@
7fdf5569 262 - djm@cvs.openbsd.org 2003/10/07 07:04:16
263 [sftp-int.c]
264 sftp quoting fix from admorten AT umich.edu; ok markus@
c8f0cf13 265 - deraadt@cvs.openbsd.org 2003/10/07 21:58:28
266 [sshconnect2.c]
267 set ptr to NULL after free
4c98e94c 268 - dtucker@cvs.openbsd.org 2003/10/07 01:52:13
269 [regress/Makefile regress/banner.sh]
270 Test SSH2 banner. ok markus@
3d3e0ec3 271 - djm@cvs.openbsd.org 2003/10/07 07:04:52
272 [regress/sftp-cmds.sh]
273 more sftp quoting regress tests; ok markus
19e633e7 274
e3df52a9 27520031007
276 - (djm) Delete autom4te.cache after autoreconf
c6630044 277 - (dtucker) [auth-pam.c auth-pam.h session.c] Make PAM use the new static
278 cleanup functions. With & ok djm@
f658a5e8 279 - (dtucker) [contrib/redhat/openssh.spec] Bug #714: Now that UsePAM is a
280 run-time switch, always build --with-md5-passwords.
7111a85c 281 - (dtucker) [configure.ac openbsd-compat/Makefile.in openbsd-compat/strtoul.c]
282 Bug #670: add strtoul() to openbsd-compat for platforms lacking it. ok djm@
605369bb 283 - (dtucker) [configure.ac] Bug #715: Set BROKEN_SETREUID and BROKEN_SETREGID
284 on Reliant Unix. Patch from Robert.Dahlem at siemens.com.
e2798e96 285 - (dtucker) [configure.ac] Bug #710: Check for dlsym() in libdl on
286 Reliant Unix. Based on patch from Robert.Dahlem at siemens.com.
e3df52a9 287
418ae4b4 28820031003
3f1204c3 289 - (dtucker) OpenBSD CVS Sync
418ae4b4 290 - markus@cvs.openbsd.org 2003/10/02 10:41:59
291 [sshd.c]
292 print openssl version, too, several requests; ok henning/djm.
59f552b7 293 - markus@cvs.openbsd.org 2003/10/02 08:26:53
294 [ssh-gss.h]
295 missing $OpenBSD:; dtucker
ba7c26ce 296 - (tim) [contrib/caldera/openssh.spec] Remove obsolete --with-ipv4-default
297 option.
418ae4b4 298
2362db19 29920031002
3f1204c3 300 - (dtucker) OpenBSD CVS Sync
2362db19 301 - markus@cvs.openbsd.org 2003/09/23 20:17:11
302 [Makefile.in auth1.c auth2.c auth.c auth.h auth-krb5.c canohost.c
303 cleanup.c clientloop.c fatal.c gss-serv.c log.c log.h monitor.c monitor.h
304 monitor_wrap.c monitor_wrap.h packet.c serverloop.c session.c session.h
305 ssh-agent.c sshd.c]
306 replace fatal_cleanup() and linked list of fatal callbacks with static
307 cleanup_exit() function. re-refine cleanup_exit() where appropriate,
308 allocate sshd's authctxt eary to allow simpler cleanup in sshd.
309 tested by many, ok deraadt@
0469be42 310 - markus@cvs.openbsd.org 2003/09/23 20:18:52
311 [progressmeter.c]
312 don't print trailing \0; bug #709; Robert.Dahlem@siemens.com
313 ok millert/deraadt@
c15706e2 314 - markus@cvs.openbsd.org 2003/09/23 20:41:11
315 [channels.c channels.h clientloop.c]
316 move client only agent code to clientloop.c
51d2a129 317 - markus@cvs.openbsd.org 2003/09/26 08:19:29
318 [sshd.c]
319 no need to set the listen sockets to non-block; ok deraadt@
5f4a0c58 320 - jmc@cvs.openbsd.org 2003/09/29 11:40:51
321 [ssh.1]
322 - add list of options to -o and .Xr ssh_config(5)
323 - some other cleanup
324 requested by deraadt@;
325 ok deraadt@ markus@
e377c083 326 - markus@cvs.openbsd.org 2003/09/29 20:19:57
327 [servconf.c sshd_config]
328 GSSAPICleanupCreds -> GSSAPICleanupCredentials
97b56d59 329 - (dtucker) [configure.ac] Don't set DISABLE_SHADOW when configuring
330 --with-pam. ok djm@
21c1aca3 331 - (dtucker) [ssh-gss.h] Prototype change missed in sync.
3a23ba0e 332 - (dtucker) [session.c] Fix bus errors on some 64-bit Solaris configurations.
333 Based on patches by Matthias Koeppe and Thomas Baden. ok djm@
2362db19 334
0cdb4344 33520030930
336 - (bal) Fix issues in openbsd-compat/realpath.c
337
4214aa45 33820030925
339 - (dtucker) [configure.ac openbsd-compat/xcrypt.c] Bug #633: Remove
340 DISABLE_SHADOW for HP-UX, use getspnam instead of getprpwnam. Patch from
341 michael_steffens at hp.com, ok djm@
1b4ba39b 342 - (tim) [sshd_config] UsePAM defaults to no.
4214aa45 343
67c4ea7d 34420030924
345 - (djm) Update version.h and spec files for HEAD
cb433561 346 - (dtucker) [configure.ac] IRIX5 needs the same setre[ug]id defines as IRIX6.
67c4ea7d 347
5ba73866 34820030923
291c14e8 349 - (dtucker) [Makefile.in] Bug #644: Fix "make clean" for out-of-tree
5ba73866 350 builds. Portability corrections from tim@.
b27e573d 351 - (dtucker) [configure.ac] Bug #665: uid swapping issues on Mac OS X.
635e0c42 352 Patch from max at quendi.de.
08da2d08 353 - (dtucker) [configure.ac] Bug #657: uid swapping issues on BSDi.
354 - (dtucker) [configure.ac] Bug #653: uid swapping issues on Tru64.
6fb3618d 355 - (dtucker) [configure.ac] Bug #693: uid swapping issues on NCR MP-RAS.
356 Patch from david.haughton at ncr.com
412c0eaa 357 - (dtucker) [configure.ac] Bug #659: uid swapping issues on IRIX 6.
358 Part of patch supplied by bugzilla-openssh at thewrittenword.com
1a086f97 359 - (dtucker) [configure.ac openbsd-compat/fake-rfc2553.c
360 openbsd-compat/fake-rfc2553.h] Bug #659: Test for and handle systems with
361 where gai_strerror is defined as "const char *". Part of patch supplied
362 by bugzilla-openssh at thewrittenword.com
35283c00 363 - (dtucker) [contrib/cygwin/README contrib/cygwin/ssh-host-config] Update
364 ssh-host-config to match current defaults, bump README version. Patch from
365 vinschen at redhat.com.
51e7d820 366 - (dtucker) [uidswap.c] Don't test restoration of uid on Cygwin since the
367 OS does not support permanently dropping privileges. Patch from
368 vinschen at redhat.com.
805dcf3a 369 - (dtucker) [openbsd-compat/port-aix.c] Use correct include for xmalloc.h,
370 add canohost.h to stop warning. Based on patch from openssh-unix-dev at
371 thewrittenword.com
913a4384 372 - (dtucker) [INSTALL] Bug #686: Document requirement for zlib 1.1.4 or
373 higher.
f4f2ff4f 374 - (tim) Fix typo. s/SETEIUD_BREAKS_SETUID/SETEUID_BREAKS_SETUID/
b27e573d 375 - (tim) [configure.ac] Bug 665: move 3 new AC_DEFINES outside of AC_TRY_RUN.
376 Report by distler AT golem ph utexas edu.
ca043cac 377 - (dtucker) [contrib/aix/pam.conf] Include example pam.conf for AIX from
378 article by genty at austin.ibm.com, included with the author's permission.
ce26c02a 379 - (dtucker) OpenBSD CVS Sync
380 - markus@cvs.openbsd.org 2003/09/18 07:52:54
381 [sshconnect.c]
382 missing {}; bug #656; jclonguet at free.fr
5bd34316 383 - markus@cvs.openbsd.org 2003/09/18 07:54:48
384 [buffer.c]
385 protect against double free; #660; zardoz at users.sf.net
1bd71826 386 - markus@cvs.openbsd.org 2003/09/18 07:56:05
387 [authfile.c]
388 missing buffer_free(&encrypted); #662; zardoz at users.sf.net
c46e584f 389 - markus@cvs.openbsd.org 2003/09/18 08:49:45
390 [deattack.c misc.c session.c ssh-agent.c]
391 more buffer allocation fixes; from Solar Designer; CAN-2003-0682;
392 ok millert@
bb92e5cc 393 - miod@cvs.openbsd.org 2003/09/18 13:02:21
394 [authfd.c bufaux.c dh.c mac.c ssh-keygen.c]
395 A few signedness fixes for harmless situations; markus@ ok
9adbb4a4 396 - markus@cvs.openbsd.org 2003/09/19 09:02:02
397 [packet.c]
398 buffer_dump only if PACKET_DEBUG is defined; Jedi/Sector One; pr 3471
f04181fe 399 - markus@cvs.openbsd.org 2003/09/19 09:03:00
400 [buffer.c]
401 sign fix in buffer_dump; Jedi/Sector One; pr 3473
cd25664d 402 - markus@cvs.openbsd.org 2003/09/19 11:29:40
403 [ssh-agent.c]
404 provide a ssh-agent specific fatal() function; ok deraadt
eec6d341 405 - markus@cvs.openbsd.org 2003/09/19 11:30:39
406 [ssh-keyscan.c]
407 avoid fatal_cleanup, just call exit(); ok deraadt
364b1cde 408 - markus@cvs.openbsd.org 2003/09/19 11:31:33
409 [channels.c]
410 do not call channel_free_all on fatal; ok deraadt
72c4301f 411 - markus@cvs.openbsd.org 2003/09/19 11:33:09
412 [packet.c sshd.c]
413 do not call packet_close on fatal; ok deraadt
815a8407 414 - markus@cvs.openbsd.org 2003/09/19 17:40:20
415 [scp.c]
416 error handling for remote-remote copy; #638; report Harald Koenig;
417 ok millert, fgs, henning, deraadt
82de775c 418 - markus@cvs.openbsd.org 2003/09/19 17:43:35
419 [clientloop.c sshtty.c sshtty.h]
420 remove fatal callbacks from client code; ok deraadt
9e3191db 421 - (bal) "extration" -> "extraction" in ssh-rand-helper.c; repoted by john
422 on #unixhelp@efnet
daa41e62 423 - (tim) [configure.ac] add --disable-etc-default-login option. ok djm
0a23d79f 424 - (djm) Sync with V_3_7 branch:
425 - (djm) Fix SSH1 challenge kludge
426 - (djm) Bug #671: Fix builds on OpenBSD
427 - (djm) Bug #676: Fix PAM stack corruption
428 - (djm) Fix bad free() in PAM code
429 - (djm) Don't call pam_end before pam_init
430 - (djm) Enable build with old OpenSSL again
431 - (djm) Trim deprecated options from INSTALL. Mention UsePAM
432 - (djm) Fix quote handling in sftp; Patch from admorten AT umich.edu
5ba73866 433
a801511e 43420030919
435 - (djm) Bug #683: Remove reference to --with-ipv4-default from INSTALL;
436 djast AT cs.toronto.edu
48646332 437 - (djm) Bug #661: Remove duplicate check for basename; from
438 bugzilla-openssh AT thewrittenword.com
34799445 439 - (djm) Bug #641: Allow RedHat RPM building without GTK-2; Patch from
440 jason AT devrandom.org
fd79af78 441 - (djm) Bug #646: Fix location of x11-ssh-askpass; Jim
4608d193 442 - (dtucker) [openbsd-compat/port-aix.h] Bug #640: Don't include audit.h
443 unless required. Reorder to reduce warnings.
6f99680f 444 - (dtucker) [session.c] Bug #643: Fix size_t -> u_int and fix null deref
445 when /etc/default/login doesn't exist or isn't readable. Fixes from
446 jparsons-lists at saffron.net and georg.oppenberg at deu mci com.
97e3cf19 447 - (dtucker) [acconfig.h] Updated basename test needs HAVE_BASENAME
a801511e 448
33fb67f0 44920030918
450 - (djm) Bug #652: Fix empty password auth
451
263c65df 45220030917
453 - (djm) Sync with V_3_7 branch
20419cc1 454 - (djm) OpenBSD Sync
455 - markus@cvs.openbsd.org 2003/09/16 21:02:40
456 [buffer.c channels.c version.h]
457 more malloc/fatal fixes; ok millert/deraadt; ghudson at MIT.EDU
38d24e7d 458 - (djm) Crank RPM spec file versions
ddd8e845 459 - (tim) [openbsd-compat/inet_ntoa.c] 20030917 "Sync with V_3_7 branch" undid
460 20030916 "Missed dead header in inet_ntoa.c"
38d24e7d 461
95b99395 46220030916
463 - (dtucker) [acconfig.h configure.ac defines.h session.c] Bug #252: Retrieve
464 PATH (or SUPATH) and UMASK from /etc/default/login on platforms that have it
49525395 465 (eg Solaris, Reliant Unix). Patch from Robert.Dahlem at siemens.com.
466 ok djm@
467 - (bal) OpenBSD Sync
468 - deraadt@cvs.openbsd.org 2003/09/16 03:03:47
469 [buffer.c]
470 do not expand buffer before attempting to reallocate it; markus ok
89bbd457 471 - (tim) [configure.ac] Fix portability issues.
bb6dd12a 472 - (bal) Missed dead header in inet_ntoa.c
95b99395 473
bdb15424 47420030914
475 - (dtucker) [Makefile regress/Makefile] Fix portability issues preventing
476 the regression tests from running with Solaris' make. Patch from Brian
477 Poole (raj at cerias.purdue.edu).
906f3b9d 478 - (dtucker) [regress/Makefile] AIX's make doesn't like " +=", so replace
479 with vanilla "=".
bdb15424 480
b64864e1 48120030913
482 - (dtucker) [regress/agent-timeout.sh] Timeout of 5 sec is borderline for
483 slower hosts, increase to 10 sec.
217a0ad5 484 - (dtucker) [auth-passwd.c] On AIX, call setauthdb() before loginsuccess(),
485 required to correctly reset failed login count when using a password
486 registry other than "files" (eg LDAP, see bug #543).
bcebad47 487 - (tim) [configure.ac] define WITH_ABBREV_NO_TTY for SCO.
488 Report by Roger Cornelius.
01224183 489 - (dtucker) [auth-pam.c] Use SSHD_PAM_SERVICE for PAM service name, patch
490 from cjwatson at debian.org.
b64864e1 491
a473643e 49220030912
493 - (tim) [regress/agent-ptrace.sh] sh doesn't like "if ! shell_function; then".
e43957b9 494 - (tim) [Makefile.in] only mkdir regress if it does not exist.
7126ceb2 495 - (tim) [regress/yes-head.sh] shell portability fix.
a473643e 496
af940dcb 49720030911
498 - (dtucker) [configure.ac] Bug #588, #615: Move other libgen tests to after
499 the dirname test, to allow a broken dirname to be detected correctly.
500 Based partially on patch supplied by alex.kiernan at thus.net. ok djm@
446227d6 501 - (tim) [configure.ac] Move libgen tests to before libwrap to unbreak
502 UnixWare 2.03 using --with-tcp-wrappers.
7ed101c0 503 - (tim) [configure.ac] Prefer setuid/setgid on UnixWare and Open Server.
c1b10a96 504 - (tim) [regress/agent-ptrace.sh regress/dynamic-forward.sh
505 regress/sftp-cmds.sh regress/stderr-after-eof.sh regress/test-exec.sh]
506 no longer depends on which(1). patch by dtucker@
af940dcb 507
7b9a8c6e 50820030910
509 - (dtucker) [configure.ac] Bug #636: Add support for Cray's new X1 machine.
510 Patch from wendyp at cray.com.
3490699c 511 - (dtucker) [configure.ac] Part of bug #615: tcsendbreak might be a macro.
2e8d2c13 512 - (dtucker) [regressh/yes-head.sh] Some platforms (eg Solaris) don't have
513 "yes".
7b9a8c6e 514
12e07a07 51520030909
516 - (tim) [regress/Makefile] Fixes for building outside of a read-only
517 source tree.
5d3cef06 518 - (tim) [regress/agent-timeout.sh] s/TIMEOUT/SSHAGENT_TIMEOUT/ Fixes conflict
519 with shell read-only variable.
2b1bb684 520 - (tim) [regress/sftp-badcmds.sh regress/sftp-cmds.sh] Fix errors like
521 UX:rm: ERROR: Cannot remove '.' or '..'
12e07a07 522
252ff4df 52320030908
524 - (tim) [configure.ac openbsd-compat/getrrsetbyname.c] wrap _getshort and
525 _getlong in #ifndef
078ec045 526 - (tim) [configure.ac acconfig.h openbsd-compat/getrrsetbyname.c] test for
527 HEADER.ad in arpa/nameser.h
8f52069e 528 - (tim) [ssh-keygen.c] s/PATH_MAX/MAXPATHLEN/ ok mouring@
252ff4df 529
c9535c4d 53020030907
531 - (dtucker) [agent-ptrace.sh dynamic-forward.sh (all regress/)]
532 Put "which" inside quotes.
5781bb58 533 - (dtucker) [dynamic-forward.sh forwarding.sh sftp-batch.sh (all regress/)]
534 Add ${EXEEXT}: required to work on Cygwin.
7621a857 535 - (dtucker) [regress/sftp-batch.sh] Make temporary batch file name more
536 distinctive, so "rm ${BATCH}.*" doesn't match the script itself.
ac4a169f 537 - (dtucker) [regress/sftp-cmds.sh] Skip quoted file test on Cygwin.
9a7582f1 538 - (dtucker) [openbsd-compat/xcrypt.c] #elsif -> #elif
539 - (dtucker) [acconfig.h] Typo.
4bbf95fa 540 - (dtucker) [CREDITS Makefile.in configure.ac mdoc2man.awk mdoc2man.pl]
541 Replace mdoc2man.pl with mdoc2man.awk, provided by Peter Stuge.
c9535c4d 542
3b8dff69 54320030906
544 - (dtucker) [acconfig.h configure.ac uidswap.c] Prefer setuid/setgid on AIX.
545
5e6f8a42 54620030905
547 - (dtucker) [Makefile.in] Add distclean target for regress/, fix clean target.
548
7ed6b890 54920030904
550 - (dtucker) Portablize regression tests. Parts contributed by Roumen
551 Petrov, David M. Williams and Corinna Vinschen.
552 - [Makefile.in] Add "make tests" target and "make clean" hooks.
584c5ed9 553 - [regress/agent-getpeereid.sh] Skip test on platforms that don't support
554 getpeereid.
335f57ae 555 - [regress/agent-ptrace.sh] Skip tests if platform doesn't support it or
556 gdb cannot be found.
c4cc19d5 557 - [regress/reconfigure/sh] Make path to sshd fully qualified if required.
e4f79c8f 558 - [regress/rekey.sh] Remove dependence on /dev/zero (not all platforms have
559 it). The sparse file will take less disk space too.
c67d1ba1 560 - [regress/sftp-cmds.sh] Ensure files used for test are readable.
9a7cf6f2 561 - [regress/stderr-after-eof.sh] Search for a usable checksum program.
83d96134 562 - [regress/sftp-badcmds.sh regress/sftp-cmds.sh regress/sftp.sh
563 regress/ssh-com-client.sh regress/ssh-com-sftp.sh regress/stderr-data.sh
564 regress/transfer.sh] Use ${EXEEXT} where appropriate.
302294d5 565 - [regress/sftp.sh regress/ssh-com-sftp.sh] Remove dependency on /dev/stdin.
d23e7be4 566 - [regress/agent-ptrace.sh regress/agent-timeout.sh]
567 "grep -q" -> "grep >/dev/null"
c7751424 568 - [regress/agent.sh regress/proto-version.sh regress/ssh-com.sh
c9535c4d 569 regress/test-exec.sh] Handle different ways of echoing without newlines.
46f493c6 570 - [regress/dynamic-forward.sh] Some "which" programs output on stderr.
a687e172 571 - [regress/sftp-cmds.sh] Use portable "test" option.
4638d96a 572 - [regress/test-exec.sh] Use sudo, search for "whoami" equivalent, always
573 use Strictmodes no, wait longer for sshd startup.
d99acf36 574 - [regress/Makefile] Remove BSDisms.
b0315114 575 - [regress/README.regress] Add a basic readme.
c67d1ba1 576 - [Makefile.in regress/agent-getpeereid.sh] config.h is now in $BUILDDIR
577 not $OBJ.
ccb02b94 578 - [Makefile.in regress/agent-ptrace] Fix minor regress issues on Cygwin.
7ed6b890 579
96d0bf74 58020030903
581 - (djm) OpenBSD CVS Sync
582 - markus@cvs.openbsd.org 2003/08/26 09:58:43
583 [auth-passwd.c auth.c auth.h auth1.c auth2-none.c auth2-passwd.c]
584 [auth2.c monitor.c]
585 fix passwd auth for 'username leaks via timing'; with djm@, original
586 patches from solar
5f2a8485 587 - markus@cvs.openbsd.org 2003/08/28 12:54:34
588 [auth.h]
589 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
590 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
b6f9987b 591 - markus@cvs.openbsd.org 2003/09/02 16:40:29
592 [version.h]
593 enter 3.7
d0445371 594 - jmc@cvs.openbsd.org 2003/09/02 18:50:06
595 [sftp.1 ssh_config.5]
596 escape punctuation;
597 ok deraadt@
96d0bf74 598
408fb07b 59920030902
eb18f58d 600 - (djm) OpenBSD CVS Sync
601 - deraadt@cvs.openbsd.org 2003/08/24 17:36:51
602 [auth2-gss.c]
603 64 bit cleanups; markus ok
8f73f7bb 604 - markus@cvs.openbsd.org 2003/08/28 12:54:34
605 [auth-krb5.c auth.h auth1.c monitor.c monitor.h monitor_wrap.c]
606 [monitor_wrap.h readconf.c servconf.c session.c ssh_config.5]
607 [sshconnect1.c sshd.c sshd_config sshd_config.5]
608 remove kerberos support from ssh1, since it has been replaced with GSSAPI;
609 but keep kerberos passwd auth for ssh1 and 2; ok djm, hin, henning, ...
e3e69949 610 - markus@cvs.openbsd.org 2003/08/29 10:03:15
611 [compat.c compat.h]
612 SSH_BUG_K5USER is unused; ok henning@
d7ac5f18 613 - markus@cvs.openbsd.org 2003/08/29 10:04:36
614 [channels.c nchan.c]
615 be less chatty; debug -> debug2, cleanup; ok henning@
8e382949 616 - markus@cvs.openbsd.org 2003/08/31 10:26:04
617 [progressmeter.c]
618 pass file_size + 1 to snprintf: fixes printing of truncated
619 file names; fix based on patch/report from sturm@;
3845a9ac 620 - markus@cvs.openbsd.org 2003/08/31 12:14:22
621 [progressmeter.c]
622 do write to buf[-1]
f89f8ddc 623 - markus@cvs.openbsd.org 2003/08/31 13:29:05
624 [session.c]
625 call ssh_gssapi_storecreds conditionally from do_exec();
626 with sxw@inf.ed.ac.uk
96573c26 627 - markus@cvs.openbsd.org 2003/08/31 13:30:18
628 [gss-serv.c]
629 correct string termination in parse_ename(); sxw@inf.ed.ac.uk
a7958e7b 630 - markus@cvs.openbsd.org 2003/08/31 13:31:57
631 [gss-serv.c]
632 whitspace KNF
105b07db 633 - markus@cvs.openbsd.org 2003/09/01 09:50:04
634 [sshd_config.5]
635 gss kex is not supported; sxw@inf.ed.ac.uk
eac292f8 636 - markus@cvs.openbsd.org 2003/09/01 12:50:46
637 [readconf.c]
638 rm gssapidelegatecreds alias; never supported before
00fee838 639 - markus@cvs.openbsd.org 2003/09/01 13:52:18
640 [ssh.h]
641 rm whitespace
cc4d7cb6 642 - markus@cvs.openbsd.org 2003/09/01 18:15:50
643 [readconf.c readconf.h servconf.c servconf.h ssh.c]
644 remove unused kerberos code; ok henning@
4771605b 645 - markus@cvs.openbsd.org 2003/09/01 20:44:54
646 [auth2-gss.c]
647 fix leak
c53917a9 648 - (djm) Don't initialise pam_conv structures inline. Avoids HP/UX compiler
649 error. Part of Bug #423, patch from michael_steffens AT hp.com
49e82bb9 650 - (djm) Bug #423: reorder setting of PAM_TTY and calling of PAM session
651 management (now done in do_setusercontext). Largely from
652 michael_steffens AT hp.com
5e89e8a5 653 - (djm) Fix openbsd-compat/ again - remove references to strl(cpy|cat).h
654
2274ae66 65520030829
a5aec672 656 - (bal) openbsd-compat/ clean up. Considate headers, add in Id on our
2274ae66 657 files, and added missing license to header.
658
fe46678b 65920030826
660 - (djm) Bug #629: Mark ssh_config option "pamauthenticationviakbdint"
661 as deprecated. Remove mention from README.privsep. Patch from
662 aet AT cc.hut.fi
7364bd04 663 - (dtucker) OpenBSD CVS Sync
664 - markus@cvs.openbsd.org 2003/08/22 10:56:09
665 [auth2.c auth2-gss.c auth.h compat.c compat.h gss-genr.c gss-serv-krb5.c
666 gss-serv.c monitor.c monitor.h monitor_wrap.c monitor_wrap.h readconf.c
667 readconf.h servconf.c servconf.h session.c session.h ssh-gss.h
668 ssh_config.5 sshconnect2.c sshd_config sshd_config.5]
669 support GSS API user authentication; patches from Simon Wilkinson,
670 stripped down and tested by Jakob and myself.
1d9f0c09 671 - markus@cvs.openbsd.org 2003/08/22 13:20:03
672 [sshconnect2.c]
673 remove support for "kerberos-2@ssh.com"
816daa84 674 - markus@cvs.openbsd.org 2003/08/22 13:22:27
675 [auth2.c] (auth2-krb5.c removed)
676 nuke "kerberos-2@ssh.com"
52f6ea0e 677 - markus@cvs.openbsd.org 2003/08/22 20:55:06
678 [LICENCE]
679 add Simon Wilkinson
f99e1ca4 680 - deraadt@cvs.openbsd.org 2003/08/24 17:36:52
681 [monitor.c monitor_wrap.c sshconnect2.c]
682 64 bit cleanups; markus ok
e68d8348 683 - fgsch@cvs.openbsd.org 2003/08/25 08:13:09
684 [sftp-int.c]
685 fix div by zero when listing for filename lengths longer than width.
686 markus@ ok.
ea7bee97 687 - djm@cvs.openbsd.org 2003/08/25 10:33:33
688 [sshconnect2.c]
689 fprintf->logit to silence login banner with "ssh -q"; ok markus@
749560dd 690 - (dtucker) [Makefile.in acconfig.h auth-krb5.c auth-pam.c auth-pam.h
691 configure.ac defines.h gss-serv-krb5.c session.c ssh-gss.h sshconnect1.c
692 sshconnect2.c] Add Portable GSSAPI support, patch by Simon Wilkinson.
780efc0f 693 - (dtucker) [Makefile.in] Remove auth2-krb5.
2b7d75f5 694 - (dtucker) [contrib/aix/inventory.sh] Add public domain notice. ok mouring@
695 (the original author)
da67ae18 696 - (dtucker) [auth.c] Do not check for locked accounts when PAM is enabled.
fe46678b 697
4e2e1af3 69820030825
699 - (djm) Bug #621: Select OpenSC keys by usage attributes. Patch from
700 larsch@trustcenter.de
510a42ce 701 - (bal) openbsd-compat/ OpenBSD updates. Mostly licensing, ansifications
f00d1f78 702 and minor fixes. OK djm@
703 - (bal) redo how we handle 'mysignal()'. Move it to
704 openbsd-compat/bsd-misc.c, s/mysignal/signal/ and #define signal to
705 be our 'mysignal' by default. OK djm@
3e6e3da0 706 - (dtucker) [acconfig.h auth.c configure.ac sshd.8] Bug #422 again: deny
707 any access to locked accounts. ok djm@
5b9e2464 708 - (djm) Bug #564: Perform PAM account checks for all authentications when
709 UsePAM=yes; ok dtucker
a6e67b60 710 - (dtucker) [configure.ac] Bug #533, #551: define BROKEN_GETADDRINFO on
711 Tru64, solves getnameinfo and "bad addr or host" errors. ok djm@
ed00d4b7 712 - (dtucker) [README buildbff.sh inventory.sh] (all in contrib/aix)
713 Update package builder: correctly handle config variables, use lsuser
714 rather than /etc/passwd, fix typos, add Id's.
4e2e1af3 715
fda04d7d 71620030822
717 - (djm) s/get_progname/ssh_get_progname/g to avoid conflict with Heimdal
718 -lbroken; ok dtucker
fcd7f067 719 - (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
720 rather that authorized_keys2. Patch from vinschen@redhat.com.
fda04d7d 721
08d035b6 72220030821
723 - (dtucker) OpenBSD CVS Sync
724 - markus@cvs.openbsd.org 2003/08/14 16:08:58
725 [ssh-keygen.c]
726 exit after primetest, ok djm@
a814ba4d 727 - (dtucker) [defines.h] Put CMSG_DATA, CMSG_FIRSTHDR with other CMSG* macros,
728 change CMSG_DATA to use __CMSG_ALIGN (and thus work properly), reformat for
729 consistency.
eacb954e 730 - (dtucker) [configure.ac] Move openpty/ctty test outside of case statement
731 and after normal openpty test.
08d035b6 732
83814987 73320030813
734 - (dtucker) [session.c] Remove #ifdef TIOCSBRK kludge.
8168a86a 735 - (dtucker) OpenBSD CVS Sync
736 - markus@cvs.openbsd.org 2003/08/13 08:33:02
737 [session.c]
738 use more portable tcsendbreak(3) and ignore break_length;
739 ok deraadt, millert
0598d99d 740 - markus@cvs.openbsd.org 2003/08/13 08:46:31
741 [auth1.c readconf.c readconf.h servconf.c servconf.h ssh.c ssh_config
742 ssh_config.5 sshconnect1.c sshd.8 sshd.c sshd_config sshd_config.5]
743 remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,
744 fgsch@, miod@, henning@, jakob@ and others
37ba5172 745 - markus@cvs.openbsd.org 2003/08/13 09:07:10
746 [readconf.c ssh.c]
747 socks4->socks, since with support both 4 and 5; dtucker@zip.com.au
5af25b1d 748 - (dtucker) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
749 Add a tcsendbreak function for platforms that don't have one, based on the
750 one from OpenBSD.
83814987 751
78e43412 75220030811
753 - (dtucker) OpenBSD CVS Sync
754 (thanks to Simon Wilkinson for help with this -dt)
755 - markus@cvs.openbsd.org 2003/07/16 15:02:06
756 [auth-krb5.c]
757 mcc -> fcc; from Love Hörnquist Åstrand <lha@it.su.se>
758 otherwise the kerberos credentinal is stored in a memory cache
759 in the privileged sshd. ok jabob@, hin@ (some time ago)
8c9f0900 760 - (dtucker) [openbsd-compat/xcrypt.c] Remove Cygwin #ifdef block (duplicate
761 in bsd-cygwin_util.h).
78e43412 762
3095daf7 76320030808
764 - (dtucker) [openbsd-compat/fake-rfc2553.h] Older Linuxes have AI_PASSIVE and
765 AI_CANONNAME in netdb.h but not AI_NUMERICHOST, so check each definition
766 separately before defining them.
26b3608b 767 - (dtucker) [auth-pam.c] Don't set PAM_TTY if tty is null. ok djm@
3095daf7 768
a15f16ab 76920030807
770 - (dtucker) [session.c] Have session_break_req not attempt to send a break
771 if TIOCSBRK and TIOCCBRK are not defined (eg Cygwin).
97722976 772 - (dtucker) [canohost.c] Bug #336: Only check ip options if IP_OPTIONS is
a96fbb21 773 defined (fixes compile error on really old Linuxes).
774 - (dtucker) [defines.h] Bug #336: Add CMSG_DATA and CMSG_FIRSTHDR macros if
775 not already defined (eg Linux with some versions of libc5), based on those
776 from OpenBSD.
871e1d12 777 - (dtucker) [openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
778 Remove incorrect filenames from comments (file names are in Id tags).
a3b678a3 779 - (dtucker) [session.c openbsd-compat/bsd-cygwin_util.h] Move Cygwin
780 specific defines and includes to bsd-cygwin_util.h. Fixes build error too.
a15f16ab 781
2616e1bc 78220030802
783 - (dtucker) [monitor.h monitor_wrap.h] Remove excess ident tags.
1c590258 784 - (dtucker) OpenBSD CVS Sync
785 - markus@cvs.openbsd.org 2003/07/22 13:35:22
786 [auth1.c auth.h auth-passwd.c monitor.c monitor.h monitor_wrap.c
787 monitor_wrap.h readconf.c readconf.h servconf.c servconf.h session.c ssh.1
788 ssh.c ssh_config.5 sshconnect1.c sshd.c sshd_config.5 ssh.h]
789 remove (already disabled) KRB4/AFS support, re-enable -k in ssh(1);
790 test+ok henning@
791 - (dtucker) [Makefile.in acconfig.h configure.ac] Remove KRB4/AFS support.
792 - (dtucker) [auth-krb4.c radix.c radix.h] Remove KRB4/AFS specific files.
ac452e85 793 - (dtucker) OpenBSD CVS Sync
794 - markus@cvs.openbsd.org 2003/07/23 07:42:43
795 [sshd_config]
796 remove AFS; itojun@
c35a6dc5 797 - djm@cvs.openbsd.org 2003/07/28 09:49:56
798 [ssh-keygen.1 ssh-keygen.c]
799 Support for generating Diffie-Hellman groups (/etc/moduli) from ssh-keygen.
800 Based on code from Phil Karn, William Allen Simpson and Niels Provos.
801 ok markus@, thanks jmc@
178b1a1d 802 - markus@cvs.openbsd.org 2003/07/29 18:24:00
803 [LICENCE progressmeter.c]
804 replace 4 clause BSD licensed progressmeter code with a replacement
805 from Nils Nordman and myself; ok deraadt@
806 (copied from OpenBSD an re-applied portable changes)
0dd40286 807 - markus@cvs.openbsd.org 2003/07/29 18:26:46
808 [progressmeter.c]
809 fix length for "- stalled -" (included with previous import)
810 - markus@cvs.openbsd.org 2003/07/30 07:44:14
811 [progressmeter.c]
812 use only 4 digits in format_size (included with previous import)
813 - markus@cvs.openbsd.org 2003/07/30 07:53:27
814 [progressmeter.c]
815 whitespace (included with previous import)
0f57e1e6 816 - markus@cvs.openbsd.org 2003/07/31 09:21:02
817 [auth2-none.c]
818 check whether passwd auth is allowd, similar to proto 1; rob@pitman.co.za
819 ok henning
4899ccef 820 - avsm@cvs.openbsd.org 2003/07/31 15:50:16
821 [atomicio.c]
822 correct comment: atomicio takes vwrite, not write; deraadt@ ok
b3a7a008 823 - markus@cvs.openbsd.org 2003/07/31 22:34:03
824 [progressmeter.c]
825 print rate similar old version; round instead truncate;
826 (included in previous progressmeter.c commit)
c5d3dd1b 827 - (dtucker) [openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
828 Add a tcgetpgrp function.
5ae3dc68 829 - (dtucker) [Makefile.in moduli.c moduli.h] Add new files and to Makefile.
f29c37a9 830 - (dtucker) [openbsd-compat/bsd-misc.c] Fix cut-and-paste bug in tcgetpgrp.
2616e1bc 831
cbdeccf3 83220030730
833 - (djm) [auth-pam.c] Don't use crappy APIs like sprintf. Thanks bal
834
a9705c94 83520030726
836 - (dtucker) [openbsd-compat/xcrypt.c] Fix typo: DISABLED_SHADOW ->
837 DISABLE_SHADOW. Fixes HP-UX compile error.
838
7c6eb32f 83920030724
840 - (bal) [auth-passwd.c openbsd-compat/Makefile.in openbsd-compat/xcrypt.c
841 openbsd-compat/xcrypt.h] Split off encryption into xcrypt() interface,
842 and isolate shadow password functions. Tested in Solaris, but should
843 not break other platforms too badly (except maybe HP =). Also brings
844 auth-passwd.c into full sync with OpenBSD tree.
845
82e5907c 84620030723
847 - (dtucker) [configure.ac] Back out change for bug #620.
848
defb525d 84920030719
850 - (dtucker) [configure.ac] Bug #620: Define BROKEN_GETADDRINFO for
851 Solaris/x86. Patch from jrhett at isite.net.
7b390973 852 - (dtucker) OpenBSD CVS Sync
853 - markus@cvs.openbsd.org 2003/07/14 12:36:37
854 [sshd.c]
855 remove undocumented -V option. would be only useful if openssh is used
856 as ssh v1 server for ssh.com's ssh v2.
e053cd2c 857 - markus@cvs.openbsd.org 2003/07/16 10:34:53
858 [ssh.c sshd.c]
859 don't exit on multiple -v or -d; ok deraadt@
145d23ca 860 - markus@cvs.openbsd.org 2003/07/16 10:36:28
861 [sshtty.c]
862 clear IUCLC in enter_raw_mode; from rob@pitman.co.za; ok deraadt@, fgs@
261bd618 863 - deraadt@cvs.openbsd.org 2003/07/18 01:54:25
864 [scp.c]
865 userid is unsigned, but well, force it anyways; andrushock@korovino.net
b3d04e37 866 - djm@cvs.openbsd.org 2003/07/19 00:45:53
867 [sftp-int.c]
868 fix sftp filename parsing for arguments with escaped quotes. bz #517;
869 ok markus
86d0260c 870 - djm@cvs.openbsd.org 2003/07/19 00:46:31
871 [regress/sftp-cmds.sh]
872 regress test for sftp arguments with escaped quotes; ok markus
defb525d 873
e351e493 87420030714
875 - (dtucker) [acconfig.h configure.ac port-aix.c] Older AIXes don't declare
876 loginfailed at all, so assume 3-arg loginfailed if not declared.
1cd5765d 877 - (dtucker) [port-aix.h] Work around name collision on AIX for r_type by
878 undef'ing it.
2aa3a16c 879 - (dtucker) Bug #543: [configure.ac port-aix.c port-aix.h]
880 Call setauthdb() before loginfailed(), which may load password registry-
defb525d 881 specific functions. Based on patch by cawlfiel at us.ibm.com.
b4777c18 882 - (dtucker) [port-aix.h] Fix prototypes.
956b0f56 883 - (dtucker) OpenBSD CVS Sync
884 - avsm@cvs.openbsd.org 2003/07/09 13:58:19
885 [key.c]
886 minor tweak: when generating the hex fingerprint, give strlcat the full
887 bound to the buffer, and add a comment below explaining why the
888 zero-termination is one less than the bound. markus@ ok
40729edd 889 - markus@cvs.openbsd.org 2003/07/10 14:42:28
890 [packet.c]
891 the 2^(blocksize*2) rekeying limit is too expensive for 3DES,
892 blowfish, etc, so enforce a 1GB limit for small blocksizes.
659912db 893 - markus@cvs.openbsd.org 2003/07/10 20:05:55
894 [sftp.c]
895 sync usage with manpage, add missing -R
e351e493 896
f58c0e01 89720030708
898 - (dtucker) [acconfig.h auth-passwd.c configure.ac session.c port-aix.[ch]]
899 Include AIX headers for authentication functions and make calls match
e351e493 900 prototypes. Test for and handle 3-arg and 4-arg variants of loginfailed.
bc7dfc06 901 - (dtucker) [session.c] Check return value of setpcred().
902 - (dtucker) [auth-passwd.c auth.c session.c sshd.c port-aix.c port-aix.h]
903 Convert aixloginmsg into platform-independant Buffer loginmsg.
f58c0e01 904
309709db 90520030707
906 - (dtucker) [configure.ac] Bug #600: Check that getrusage is declared before
907 searching libraries for it. Fixes build errors on NCR MP-RAS.
908
d72f7b79 90920030706
910 - (dtucker) [ssh-rand-helper.c loginrec.c]
911 Apply atomicio typing change to these too.
912
71b9ced0 91320030703
914 - (dtucker) OpenBSD CVS Sync
915 - djm@cvs.openbsd.org 2003/06/28 07:48:10
916 [sshd.c]
917 report pidfile creation errors, based on patch from Roumen Petrov;
918 ok markus@
dc54438a 919 - deraadt@cvs.openbsd.org 2003/06/28 16:23:06
920 [atomicio.c atomicio.h authfd.c clientloop.c monitor_wrap.c msg.c
921 progressmeter.c scp.c sftp-client.c ssh-keyscan.c ssh.h sshconnect.c
922 sshd.c]
923 deal with typing of write vs read in atomicio
7caca6d4 924 - markus@cvs.openbsd.org 2003/06/29 12:44:38
925 [sshconnect.c]
926 memset 0, not \0; andrushock@korovino.net
8e7c9afc 927 - markus@cvs.openbsd.org 2003/07/02 12:56:34
928 [channels.c]
929 deny dynamic forwarding with -R for v1, too; ok djm@
f49658f5 930 - markus@cvs.openbsd.org 2003/07/02 14:51:16
931 [channels.c ssh.1 ssh_config.5]
932 (re)add socks5 suppport to -D; ok djm@
933 now ssh(1) can act both as a socks 4 and socks 5 server and
934 dynamically forward ports.
03c82656 935 - markus@cvs.openbsd.org 2003/07/02 20:37:48
936 [ssh.c]
937 convert hostkeyalias to lowercase, otherwise uppercase aliases will
938 not match at all; ok henning@
1768a611 939 - markus@cvs.openbsd.org 2003/07/03 08:21:46
940 [regress/dynamic-forward.sh]
941 add socks5; speedup; reformat; based on patch from dtucker@zip.com.au
7664edb6 942 - markus@cvs.openbsd.org 2003/07/03 08:24:13
943 [regress/Makefile]
944 enable tests for dynamic fwd via socks (-D), uses nc(1)
1572b90f 945 - djm@cvs.openbsd.org 2003/07/03 08:09:06
946 [readconf.c readconf.h ssh-keysign.c ssh.c]
947 fix AddressFamily option in config file, from brent@graveland.net;
948 ok markus@
71b9ced0 949
4e00038c 95020030630
951 - (djm) Search for support functions necessary to build our
952 getrrsetbyname() replacement. Patch from Roumen Petrov
953
9f59c5a3 95420030629
c5829391 955 - (dtucker) [includes.h] Bug #602: move #include of netdb.h to after in.h
956 (fixes compiler warnings on Solaris 2.5.1).
957 - (dtucker) [configure.ac] Add sanity test after system-dependant compiler
958 flag modifications.
9f59c5a3 959
9ea150a7 96020030628
961 - (djm) Bug #591: use PKCS#15 private key label as a comment in case
962 of OpenSC. Report and patch from larsch@trustcenter.de
d2168412 963 - (djm) Bug #593: Sanity check OpenSC card reader number; patch from
964 aj@dungeon.inka.de
f0677b69 965 - (dtucker) OpenBSD CVS Sync
966 - markus@cvs.openbsd.org 2003/06/23 09:02:44
967 [ssh_config.5]
968 document EnableSSHKeysign; bugzilla #599; ok deraadt@, jmc@
a27002e5 969 - markus@cvs.openbsd.org 2003/06/24 08:23:46
970 [auth2-hostbased.c auth2-pubkey.c auth2.c channels.c key.c key.h
971 monitor.c packet.c packet.h serverloop.c sshconnect2.c sshd.c]
972 int -> u_int; ok djm@, deraadt@, mouring@
d7ded285 973 - miod@cvs.openbsd.org 2003/06/25 22:39:36
974 [sftp-server.c]
975 Typo police: attribute is better written with an 'r'.
2d9c1828 976 - markus@cvs.openbsd.org 2003/06/26 20:08:33
977 [readconf.c]
978 do not dump core for 'ssh -o proxycommand host'; ok deraadt@
78b2dd04 979 - (dtucker) [regress/dynamic-forward.sh] Import new regression test.
ddb154b3 980 - (dtucker) [configure.ac] Bug #570: Have ./configure --enable-FEATURE
981 actually enable the feature, for those normally disabled. Patch by
982 openssh (at) roumenpetrov.info.
f0677b69 983
e15ba28b 98420030624
985 - (dtucker) Have configure refer the user to config.log and
986 contrib/findssl.sh for OpenSSL header/library mismatches.
987
63a556df 98820030622
c1ffd4bd 989 - (dtucker) OpenBSD CVS Sync
63a556df 990 - markus@cvs.openbsd.org 2003/06/21 09:14:05
c1ffd4bd 991 [regress/reconfigure.sh]
63a556df 992 missing $SUDO; from dtucker@zip.com.au
93527718 993 - markus@cvs.openbsd.org 2003/06/18 11:28:11
c1ffd4bd 994 [ssh-rsa.c]
995 backout last change, since it violates pkcs#1
996 switch to share/misc/license.template
1891396b 997 - djm@cvs.openbsd.org 2003/06/20 05:47:58
998 [sshd_config.5]
999 sync description of protocol 2 cipher proposal; ok markus
4db4d313 1000 - djm@cvs.openbsd.org 2003/06/20 05:48:21
1001 [sshd_config]
1002 sync some implemented options; ok markus@
63a556df 1003 - (dtucker) [regress/authorized_keys_root] Remove temp data file from CVS.
39ef3618 1004 - (dtucker) [openbsd-compat/setproctitle.c] Ensure SPT_TYPE is defined before
1005 testing its value.
63a556df 1006
b8e04133 100720030618
1008 - (djm) OpenBSD CVS Sync
1009 - markus@cvs.openbsd.org 2003/06/12 07:57:38
1010 [monitor.c sshlogin.c sshpty.c]
1011 typos; dtucker at zip.com.au
b9ad9d13 1012 - djm@cvs.openbsd.org 2003/06/12 12:22:47
1013 [LICENCE]
1014 mention more copyright holders; ok markus@
1fb23629 1015 - nino@cvs.openbsd.org 2003/06/12 15:34:09
1016 [scp.c]
1017 Typo. Ok markus@.
244e796f 1018 - markus@cvs.openbsd.org 2003/06/12 19:12:03
1019 [scard.c scard.h ssh-agent.c ssh.c]
1020 add sc_get_key_label; larsch at trustcenter.de; bugzilla#591
9250058a 1021 - markus@cvs.openbsd.org 2003/06/16 08:22:35
1022 [ssh-rsa.c]
1023 make sure the signature has at least the expected length (don't
1024 insist on len == hlen + oidlen, since this breaks some smartcards)
1025 bugzilla #592; ok djm@
360a4aae 1026 - markus@cvs.openbsd.org 2003/06/16 10:22:45
1027 [ssh-add.c]
1028 print out key comment on each prompt; make ssh-askpass more useable; ok djm@
0a59bd6b 1029 - markus@cvs.openbsd.org 2003/06/17 18:14:23
1030 [cipher-ctr.c]
1031 use license from /usr/share/misc/license.template for new code
1d6c0b69 1032 - (dtucker) [reconfigure.sh rekey.sh sftp-badcmds.sh]
1033 Import new regression tests from OpenBSD
d4d84f5f 1034 - (dtucker) [regress/copy.1 regress/copy.2] Remove temp data files from CVS.
ed49cc81 1035 - (dtucker) OpenBSD CVS Sync (regress/)
1036 - markus@cvs.openbsd.org 2003/04/02 12:21:13
1037 [Makefile]
1038 enable rekey test
2c670155 1039 - djm@cvs.openbsd.org 2003/04/04 09:34:22
1040 [Makefile sftp-cmds.sh]
1041 More regression tests, including recent directory rename bug; ok markus@
737447ad 1042 - markus@cvs.openbsd.org 2003/05/14 22:08:27
1043 [ssh-com-client.sh ssh-com-keygen.sh ssh-com-sftp.sh ssh-com.sh]
1044 test against some new commerical versions
68df2aa0 1045 - mouring@cvs.openbsd.org 2003/05/15 04:07:12
1046 [sftp-cmds.sh]
1047 Advanced put/get testing for sftp. OK @djm
eb9bf761 1048 - markus@cvs.openbsd.org 2003/06/12 15:40:01
1049 [try-ciphers.sh]
1050 add ctr
39c0191e 1051 - markus@cvs.openbsd.org 2003/06/12 15:43:32
1052 [Makefile]
1053 test -HUP; dtucker at zip.com.au
b8e04133 1054
f5827134 105520030614
1056 - (djm) Update license on fake-rfc2553.[ch]; ok itojun@
1057
be193d89 105820030611
c12c6ef8 1059 - (djm) Mention portable copyright holders in LICENSE
e52ca1e5 1060 - (djm) Put licenses on substantial header files
8cb3fa9d 1061 - (djm) Sync LICENSE against OpenBSD
be193d89 1062 - (djm) OpenBSD CVS Sync
1063 - jmc@cvs.openbsd.org 2003/06/10 09:12:11
1064 [scp.1 sftp-server.8 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5]
1065 [sshd.8 sshd_config.5 ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
1066 - section reorder
1067 - COMPATIBILITY merge
1068 - macro cleanup
1069 - kill whitespace at EOL
1070 - new sentence, new line
1071 ssh pages ok markus@
0daa6547 1072 - deraadt@cvs.openbsd.org 2003/06/10 22:20:52
1073 [packet.c progressmeter.c]
1074 mostly ansi cleanup; pval ok
1432b5c4 1075 - jakob@cvs.openbsd.org 2003/06/11 10:16:16
1076 [sshconnect.c]
1077 clean up check_host_key() and improve SSHFP feedback. ok markus@
cc263107 1078 - jakob@cvs.openbsd.org 2003/06/11 10:18:47
1079 [dns.c]
1080 sync with check_host_key() change
ca719034 1081 - djm@cvs.openbsd.org 2003/06/11 11:18:38
1082 [authfd.c authfd.h ssh-add.c ssh-agent.c]
1083 make agent constraints (lifetime, confirm) work with smartcard keys;
1084 ok markus@
be193d89 1085
1086
8a547250 108720030609
1088 - (djm) Sync README.smartcard with OpenBSD -current
a1864983 1089 - (djm) Re-merge OpenSC info into README.smartcard
8a547250 1090
f5db6a03 109120030606
1092 - (dtucker) [uidswap.c] Fix setreuid and add missing args to fatal(). ok djm@
1093
02e2a074 109420030605
1095 - (djm) Support AI_NUMERICHOST in fake-getaddrinfo.c. Needed for recent
1096 canohost.c changes.
688eed4a 1097 - (djm) Implement paranoid priv dropping checks, based on:
1098 "SetUID demystified" - Hao Chen, David Wagner and Drew Dean
1099 Proceedings of USENIX Security Symposium 2002
d6bd2b5a 1100 - (djm) Don't use xmalloc() or pull in toplevel headers in fake-* code
52d58495 1101 - (djm) Merge all the openbsd/fake-* into fake-rfc2553.[ch]
57c917f8 1102 - (djm) Bug #588 - Add scard-opensc.o back to Makefile.in
1103 Patch from larsch@trustcenter.de
7b7f164b 1104 - (djm) Bug #589 - scard-opensc: load only keys with a private keys
1105 Patch from larsch@trustcenter.de
4ed465ec 1106 - (dtucker) Add includes.h to fake-rfc2553.c so it will build.
e932f447 1107 - (dtucker) Define EAI_NONAME in fake-rfc2553.h (used by fake-rfc2553.c).
02e2a074 1108
b08a39ff 110920030604
d60e487c 1110 - (djm) Bug #573 - Remove unneeded Krb headers and compat goop. Patch from
1111 simon@sxw.org.uk (Also matches a change in OpenBSD a while ago)
8acdec60 1112 - (djm) Bug #577 - wrong flag in scard-opensc.c sc_private_decrypt.
11f1e60e 1113 Patch from larsch@trustcenter.de; ok markus@
1114 - (djm) Bug #584: scard-opensc.c doesn't work without PIN. Patch from
1115 larsch@trustcenter.de; ok markus@
d453a600 1116 - (djm) OpenBSD CVS Sync
1117 - djm@cvs.openbsd.org 2003/06/04 08:25:18
1118 [sshconnect.c]
1119 disable challenge/response and keyboard-interactive auth methods
1120 upon hostkey mismatch. based on patch from fcusack AT fcusack.com.
1121 bz #580; ok markus@
ee50371d 1122 - djm@cvs.openbsd.org 2003/06/04 10:23:48
1123 [sshd.c]
1124 remove duplicated group-dropping code; ok markus@
b08a39ff 1125 - djm@cvs.openbsd.org 2003/06/04 12:03:59
1126 [serverloop.c]
1127 remove bitrotten commet; ok markus@
cf3248b8 1128 - djm@cvs.openbsd.org 2003/06/04 12:18:49
1129 [scp.c]
1130 ansify; ok markus@
0f764b2f 1131 - djm@cvs.openbsd.org 2003/06/04 12:40:39
1132 [scp.c]
1133 kill ssh process upon receipt of signal, bz #241.
1134 based on patch from esb AT hawaii.edu; ok markus@
1b558925 1135 - djm@cvs.openbsd.org 2003/06/04 12:41:22
1136 [sftp.c]
1137 kill ssh process on receipt of signal; ok markus@
fba33e81 1138 - (djm) Update to fix of bug #584: lock card before return.
1139 From larsch@trustcenter.de
8d9bb5dd 1140 - (djm) Always use mysignal() for SIGALRM
d60e487c 1141
3a2b2b44 114220030603
1143 - (djm) Replace setproctitle replacement with code derived from
1144 UCB sendmail
c5a7d788 1145 - (djm) OpenBSD CVS Sync
1146 - markus@cvs.openbsd.org 2003/06/02 09:17:34
1147 [auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
1148 [canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
1149 [sshd_config.5]
1150 deprecate VerifyReverseMapping since it's dangerous if combined
1151 with IP based access control as noted by Mike Harding; replace with
1152 a UseDNS option, UseDNS is on by default and includes the
1153 VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
1154 ok deraadt@, djm@
d981089c 1155 - millert@cvs.openbsd.org 2003/06/03 02:56:16
1156 [scp.c]
1157 Remove the advertising clause in the UCB license which Berkeley
1158 rescinded 22 July 1999. Proofed by myself and Theo.
c5a7d788 1159 - (djm) Fix portable-specific uses of verify_reverse_mapping too
3e67f7df 1160 - (djm) Sync openbsd-compat with OpenBSD CVS.
484d59c7 1161 - No more 4-term BSD licenses in linked code
5d8ca8c7 1162 - (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
3a2b2b44 1163
aff561f9 116420030602
1165 - (djm) Fix segv from bad reordering in auth-pam.c
416c732d 1166 - (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
1167 clobber
1b7342ab 1168 - (tim) openbsd-compat/xmmap.[ch] License clarifications. Add missing
1169 CVS ID.
8862e142 1170 - (djm) Remove "noip6" option from RedHat spec file. This may now be
1171 set at runtime using AddressFamily option.
58ba3cb7 1172 - (djm) Fix use of macro before #define in cipher-aes.c
382fe2fa 1173 - (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
b0545fe6 1174 - (djm) OpenBSD CVS Sync
1175 - djm@cvs.openbsd.org 2003/05/26 12:54:40
1176 [sshconnect.c]
1177 fix format strings; ok markus@
fa5120a0 1178 - deraadt@cvs.openbsd.org 2003/05/29 16:58:45
1179 [sshd.c uidswap.c]
1180 seteuid and setegid; markus ok
0f92946c 1181 - jakob@cvs.openbsd.org 2003/06/02 08:31:10
1182 [ssh_config.5]
1183 VerifyHostKeyDNS is v2 only. ok markus@
aff561f9 1184
4f178be8 118520030530
1186 - (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
1187 roumenpetrov.info
eabb99c6 1188 - (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
4f178be8 1189
4881aebb 119020030526
1191 - (djm) Avoid auth2-chall.c warning when compiling without
1192 PAM, BSD_AUTH and SKEY
1193
5b0fe364 119420030525
1195- (djm) OpenBSD CVS Sync
1196 - djm@cvs.openbsd.org 2003/05/24 09:02:22
1197 [log.c]
1198 pass logged data through strnvis; ok markus
b9ed513a 1199 - djm@cvs.openbsd.org 2003/05/24 09:30:40
1200 [authfile.c monitor.c sftp-common.c sshpty.c]
1201 cast some types for printing; ok markus@
5b0fe364 1202
44c78996 120320030524
1204 - (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
1205
d83ebe4a 120620030523
1207 - (djm) Use VIS_SAFE on logged strings rather than default strnvis
1208 encoding (which encodes many more characters)
bd47824b 1209 - OpenBSD CVS Sync
1210 - jmc@cvs.openbsd.org 2003/05/20 12:03:35
1211 [sftp.1]
1212 - new sentence, new line
1213 - added .Xr's
1214 - typos
1215 ok djm@
3cbc677d 1216 - jmc@cvs.openbsd.org 2003/05/20 12:09:31
1217 [ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
1218 new sentence, new line
da54f5be 1219 - djm@cvs.openbsd.org 2003/05/23 08:29:30
1220 [sshconnect.c]
1221 fix leak; ok markus@
d83ebe4a 1222
c453493f 122320030520
1224 - (djm) OpenBSD CVS Sync
1225 - deraadt@cvs.openbsd.org 2003/05/18 23:22:01
1226 [log.c]
1227 use syslog_r() in a signal handler called place; markus ok
79d4fc55 1228 - (djm) Configure logic to detect syslog_r and friends
c453493f 1229
acb50584 123020030519
1231 - (djm) Sync auth-pam.h with what we actually implement
1232
123320030518
5ff453c0 1234 - (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
1235 recent merge
f811e52a 1236 - (djm) OpenBSD CVS Sync
1237 - djm@cvs.openbsd.org 2003/05/16 03:27:12
1238 [readconf.c ssh_config ssh_config.5 ssh-keysign.c]
1239 add AddressFamily option to ssh_config (like -4, -6 on commandline).
1240 Portable bug #534; ok markus@
013b1214 1241 - itojun@cvs.openbsd.org 2003/05/17 03:25:58
1242 [auth-rhosts.c]
1243 just in case, put numbers to sscanf %s arg.
25b66522 1244 - markus@cvs.openbsd.org 2003/05/17 04:27:52
1245 [cipher.c cipher-ctr.c myproposal.h]
1246 experimental support for aes-ctr modes from
1247 http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
1248 ok djm@
25351757 1249 - (djm) Remove IPv4 by default hack now that we can specify AF in config
3bf784bc 1250 - (djm) Tidy and trim TODO
bffa6723 1251 - (djm) Sync openbsd-compat/ with OpenBSD CVS head
9901cb37 1252 - (djm) Big KNF on openbsd-compat/
f1da2b8b 1253 - (djm) KNF on md5crypt.[ch]
1254 - (djm) KNF on auth-sia.[ch]
5ff453c0 1255
f123055b 125620030517
1257 - (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
1258
c936c243 125920030516
1260 - (djm) OpenBSD CVS Sync
1261 - djm@cvs.openbsd.org 2003/05/15 13:52:10
1262 [ssh.c]
1263 Make "ssh -V" print the OpenSSL version in a human readable form. Patch
1264 from Craig Leres (mindrot at ee.lbl.gov); ok markus@
a2144546 1265 - jakob@cvs.openbsd.org 2003/05/15 14:02:47
1266 [readconf.c servconf.c]
1267 warn for unsupported config option. ok markus@
5bdfde81 1268 - markus@cvs.openbsd.org 2003/05/15 14:09:21
1269 [auth2-krb5.c]
1270 fix 64bit issue; report itojun@
09ab3296 1271 - djm@cvs.openbsd.org 2003/05/15 14:55:25
1272 [readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
1273 add a ConnectTimeout option to ssh, based on patch from
1274 Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
b06b11ad 1275 - (djm) Add warning for UsePAM when built without PAM support
7be625e1 1276 - (djm) A few type mismatch fixes from Bug #565
0eb6370a 1277 - (djm) Guard free_pam_environment against NULL argument. Works around
1278 HP/UX PAM problems debugged by dtucker
c936c243 1279
7efc7f57 128020030515
1281 - (djm) OpenBSD CVS Sync
1282 - jmc@cvs.openbsd.org 2003/05/14 13:11:56
1283 [ssh-agent.1]
1284 setup -> set up;
1285 from wiz@netbsd
21289cd0 1286 - jakob@cvs.openbsd.org 2003/05/14 18:16:20
1287 [key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
1288 [dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
1289 add experimental support for verifying hos keys using DNS as described
1290 in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
1291 ok markus@ and henning@
16a79097 1292 - markus@cvs.openbsd.org 2003/05/14 22:24:42
1293 [clientloop.c session.c ssh.1]
1294 allow to send a BREAK to the remote system; ok various
b8c2031b 1295 - markus@cvs.openbsd.org 2003/05/15 00:28:28
1296 [sshconnect2.c]
1297 cleanup unregister of per-method packet handlers; ok djm@
d0ec7f42 1298 - jakob@cvs.openbsd.org 2003/05/15 01:48:10
1299 [readconf.c readconf.h servconf.c servconf.h]
1300 always parse kerberos options. ok djm@ markus@
b414a17b 1301 - jakob@cvs.openbsd.org 2003/05/15 02:27:15
1302 [dns.c]
1303 add missing freerrset
3b6e3da9 1304 - markus@cvs.openbsd.org 2003/05/15 03:08:29
1305 [cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
1306 split out custom EVP ciphers
02159d9b 1307 - djm@cvs.openbsd.org 2003/05/15 03:10:52
1308 [ssh-keygen.c]
1309 avoid warning; ok jakob@
4a26f5c5 1310 - mouring@cvs.openbsd.org 2003/05/15 03:39:07
1311 [sftp-int.c]
1312 Make put/get (globed and nonglobed) code more consistant. OK djm@
c44f10c6 1313 - mouring@cvs.openbsd.org 2003/05/15 03:43:59
dc69f53c 1314 [sftp-int.c sftp.c]
c44f10c6 1315 Teach ls how to display multiple column display and allow users
1316 to return to single column format via 'ls -1'. OK @djm
1457e7ff 1317 - jakob@cvs.openbsd.org 2003/05/15 04:08:44
1318 [readconf.c servconf.c]
1319 disable kerberos when not supported. ok markus@
861f0365 1320 - markus@cvs.openbsd.org 2003/05/15 04:08:41
1321 [ssh.1]
1322 ~B is ssh2 only
d0ec7f42 1323 - (djm) Always parse UsePAM
3e05e934 1324 - (djm) Configure glue for DNS support (code doesn't work in portable yet)
4460d509 1325 - (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
86ee6794 1326 - (djm) Tidy Makefile clean targets
2636769c 1327 - (djm) Adapt README.dns for portable
2d2e4a34 1328 - (djm) Avoid uuencode.c warnings
1457e7ff 1329 - (djm) Enable UsePAM when built --with-pam
67467c30 1330 - (djm) Only build getrrsetbyname replacement when using --with-dns
f420d2ba 1331 - (djm) Bug #529: sshd doesn't work correctly after SIGHUP (copy argv
1332 correctly)
3c49ef10 1333 - (djm) Bug #444: Wrong paths after reconfigure
321735c7 1334 - (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
f420d2ba 1335
dd3ebb5a 133620030514
1337 - (djm) Bug #117: Don't lie to PAM about username
0608f8a7 1338 - (djm) RCSID sync w/ OpenBSD
204fde99 1339 - (djm) OpenBSD CVS Sync
1340 - djm@cvs.openbsd.org 2003/04/09 12:00:37
1341 [readconf.c]
1342 strip trailing whitespace from config lines before parsing.
1343 Fixes bz 528; ok markus@
18ae3c67 1344 - markus@cvs.openbsd.org 2003/04/12 10:13:57
1345 [cipher.c]
1346 hide cipher details; ok djm@
45c42d58 1347 - markus@cvs.openbsd.org 2003/04/12 10:15:36
1348 [misc.c]
1349 debug->debug2
c825cd79 1350 - naddy@cvs.openbsd.org 2003/04/12 11:40:15
1351 [ssh.1]
1352 document -V switch, fix wording; ok markus@
3e131a6d 1353 - markus@cvs.openbsd.org 2003/04/14 14:17:50
1354 [channels.c sshconnect.c sshd.c ssh-keyscan.c]
1355 avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
927e9f8b 1356 - mouring@cvs.openbsd.org 2003/04/14 21:31:27
1357 [sftp-int.c]
1358 Missing globfree(&g) in process_put() spotted by Vince Brimhall
1359 <VBrimhall@novell.com>. ok@ Theo
1360 - markus@cvs.openbsd.org 2003/04/16 14:35:27
1361 [auth.h]
1362 document struct Authctxt; with solar
b9e5aff6 1363 - deraadt@cvs.openbsd.org 2003/04/26 04:29:49
1364 [ssh-keyscan.c]
1365 -t in usage(); rogier@quaak.org
9a26a6e2 1366 - mouring@cvs.openbsd.org 2003/04/30 01:16:20
1367 [sshd.8 sshd_config.5]
1368 Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
1369 Bug #550 and * escaping suggested by jmc@.
09dc8896 1370 - david@cvs.openbsd.org 2003/04/30 20:41:07
1371 [sshd.8]
1372 fix invalid .Pf macro usage introduced in previous commit
1373 ok jmc@ mouring@
3566c73c 1374 - markus@cvs.openbsd.org 2003/05/11 16:56:48
1375 [authfile.c ssh-keygen.c]
1376 change key_load_public to try to read a public from:
1377 rsa1 private or rsa1 public and ssh2 keys.
1378 this makes ssh-keygen -e fail for ssh1 keys more gracefully
1379 for example; report from itojun (netbsd pr 20550).
0d942eff 1380 - markus@cvs.openbsd.org 2003/05/11 20:30:25
1381 [channels.c clientloop.c serverloop.c session.c ssh.c]
1382 make channel_new() strdup the 'remote_name' (not the caller); ok theo
43348518 1383 - markus@cvs.openbsd.org 2003/05/12 16:55:37
1384 [sshconnect2.c]
1385 for pubkey authentication try the user keys in the following order:
1386 1. agent keys that are found in the config file
1387 2. other agent keys
1388 3. keys that are only listed in the config file
1389 this helps when an agent has many keys, where the server might
1390 close the connection before the correct key is used. report & ok pb@
dc109cfe 1391 - markus@cvs.openbsd.org 2003/05/12 18:35:18
1392 [ssh-keyscan.1]
1393 typo: DSA keys are of type ssh-dss; Brian Poole
81466908 1394 - markus@cvs.openbsd.org 2003/05/14 00:52:59
1395 [ssh2.h]
1396 ranges for per auth method messages
1397 - djm@cvs.openbsd.org 2003/05/14 01:00:44
1398 [sftp.1]
1399 emphasise the batchmode functionality and make reference to pubkey auth,
1400 both of which are FAQs; ok markus@
802e01b8 1401 - markus@cvs.openbsd.org 2003/05/14 02:15:47
1402 [auth2.c monitor.c sshconnect2.c auth2-krb5.c]
1403 implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
1404 server interops with commercial client; ok jakob@ djm@
72c5fe79 1405 - jmc@cvs.openbsd.org 2003/05/14 08:25:39
1406 [sftp.1]
1407 - better formatting in SYNOPSIS
1408 - whitespace at EOL
1409 ok djm@
3a39206f 1410 - markus@cvs.openbsd.org 2003/05/14 08:57:49
1411 [monitor.c]
1412 http://bugzilla.mindrot.org/show_bug.cgi?id=560
1413 Privsep child continues to run after monitor killed.
1414 Pass monitor signals through to child; Darren Tucker
751092f9 1415 - (djm) Make portable build with MIT krb5 (some issues remain)
7fceb20d 1416 - (djm) Add new UsePAM configuration directive to allow runtime control
1417 over usage of PAM. This allows non-root use of sshd when built with
1418 --with-pam
817e6d38 1419 - (djm) Die screaming if start_pam() is called when UsePAM=no
83ccf11a 1420 - (djm) Avoid KrbV leak for MIT Kerberos
b1848832 1421 - (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
fa065de2 1422 - (djm) Bug #258: sscanf("[0-9]") -> sscanf("[0123456789]") for portability
dd3ebb5a 1423
91f3aa9b 142420030512
1425 - (djm) Redhat spec: Don't install profile.d scripts when not
1426 building with GNOME/GTK askpass (patch from bet@rahul.net)
1427
5def520a 142820030510
1429 - (dtucker) Bug #318: Create ssh_prng_cmds.out during "make" rather than
1430 "make install". Patch by roth@feep.net.
ad84c479 1431 - (dtucker) Bug #536: Test for and work around openpty/controlling tty
1432 problem on Linux (fixes "could not set controlling tty" errors).
05114c74 1433 - (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
1434 proper challenge-response module
23ab1f36 1435 - (djm) 2-clause license on loginrec.c, with permission from
1436 andre@ae-35.com
5def520a 1437
43ce025d 143820030504
dd594f99 1439 - (dtucker) Bug #497: Move #include of bsd-cygwin_util.h to openbsd-compat.h.
1440 Patch from vinschen@redhat.com.
43ce025d 1441
2cd5dbba 144220030503
1443 - (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
1444 by wendyp@cray.com.
1445
bf7c1e6c 144620030502
1447 - (dtucker) Bug #544: ignore invalid cmsg_type on Linux 2.0 kernels,
1448 privsep should now work.
73d9dad3 1449 - (dtucker) Move handling of bad password authentications into a platform
990278ef 1450 specific record_failed_login() function (affects AIX & Unicos). ok mouring@
bf7c1e6c 1451
68ece370 145220030429
1453 - (djm) Add back radix.o (used by AFS support), after it went missing from
1454 Makefile many moons ago
1455 - (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
1456 - (djm) Fix blibpath specification for AIX/gcc
1457 - (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
1458
ded9dd18 145920030428
1460 - (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
1461 hacked code.
1462
aceb0423 146320030427
1464 - (bal) Bug #541: return; was dropped by mistake. Reported by
1465 furrier@iglou.com
c8a50a34 1466 - (bal) Since we don't support platforms lacking u_int_64. We may
1467 as well clean out some of those evil #ifdefs
9a6fee8b 1468 - (bal) auth1.c minor resync while looking at the code.
d7cf277b 1469 - (bal) auth2.c same changed as above.
aceb0423 1470
0a626302 147120030409
1472 - (djm) Bug #539: Specify creation mode with O_CREAT for lastlog. Report
1473 from matth@eecs.berkeley.edu
d35929b5 1474 - (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
ffd7b36b 1475 - (djm) OpenBSD CVS Sync
1476 - markus@cvs.openbsd.org 2003/04/02 09:48:07
1477 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1478 [readconf.h serverloop.c sshconnect2.c]
1479 reapply rekeying chage, tested by henning@, ok djm@
16f1b5ca 1480 - markus@cvs.openbsd.org 2003/04/02 14:36:26
1481 [ssh-keysign.c]
1482 potential segfault if KEY_UNSPEC; cjwatson@debian.org; bug #526
6c1bc5c5 1483 - itojun@cvs.openbsd.org 2003/04/03 07:25:27
1484 [progressmeter.c]
1485 $OpenBSD$
1486 - itojun@cvs.openbsd.org 2003/04/03 10:17:35
1487 [progressmeter.c]
1488 remove $OpenBSD$, as other *.c does not have it.
806e4c11 1489 - markus@cvs.openbsd.org 2003/04/07 08:29:57
1490 [monitor_wrap.c]
1491 typo: get correct counters; introduced during rekeying change.
2f5b2528 1492 - millert@cvs.openbsd.org 2003/04/07 21:58:05
1493 [progressmeter.c]
1494 The UCB copyright here is incorrect. This code did not originate
1495 at UCB, it was written by Luke Mewburn. Updated the copyright at
1496 the author's request. markus@ OK
1497 - itojun@cvs.openbsd.org 2003/04/08 20:21:29
1498 [*.c *.h]
1499 rename log() into logit() to avoid name conflict. markus ok, from
1500 netbsd
1501 - (djm) XXX - Performed locally using:
1502 "perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
70e1f62f 1503 - hin@cvs.openbsd.org 2003/04/09 08:23:52
1504 [servconf.c]
1505 Don't include <krb.h> when compiling with Kerberos 5 support
2f5b2528 1506 - (djm) Fix up missing include for packet.c
a3568201 1507 - (djm) Fix missed log => logit occurance (reference by function pointer)
0a626302 1508
4d0cb2e5 150920030402
1510 - (bal) if IP_TOS is not found or broken don't try to compile in
1511 packet_set_tos() function call. bug #527
1512
a4e5acef 151320030401
1514 - (djm) OpenBSD CVS Sync
1515 - jmc@cvs.openbsd.org 2003/03/28 10:11:43
1516 [scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
1517 [ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
1518 - killed whitespace
1519 - new sentence new line
1520 - .Bk for arguments
1521 ok markus@
177f584b 1522 - markus@cvs.openbsd.org 2003/04/01 10:10:23
1523 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1524 [readconf.h serverloop.c sshconnect2.c]
1525 rekeying bugfixes and automatic rekeying:
1526 * both client and server rekey _automatically_
1527 (a) after 2^31 packets, because after 2^32 packets
1528 the sequence number for packets wraps
1529 (b) after 2^(blocksize_in_bits/4) blocks
1530 (see: draft-ietf-secsh-newmodes-00.txt)
1531 (a) and (b) are _enabled_ by default, and only disabled for known
1532 openssh versions, that don't support rekeying properly.
1533 * client option 'RekeyLimit'
1534 * do not reply to requests during rekeying
1535 - markus@cvs.openbsd.org 2003/04/01 10:22:21
1536 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
1537 [readconf.h serverloop.c sshconnect2.c]
1538 backout rekeying changes (for 3.6.1)
519bdfe8 1539 - markus@cvs.openbsd.org 2003/04/01 10:31:26
1540 [compat.c compat.h kex.c]
1541 bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
1542 tested by ho@ and myself
9dd240a3 1543 - markus@cvs.openbsd.org 2003/04/01 10:56:46
1544 [version.h]
1545 3.6.1
ac01b518 1546 - (djm) Crank spec file versions
b32453fe 1547 - (djm) Release 3.6.1p1
a4e5acef 1548
fd77a40f 154920030326
1550 - (djm) OpenBSD CVS Sync
1551 - deraadt@cvs.openbsd.org 2003/03/26 04:02:51
1552 [sftp-server.c]
1553 one last fix to the tree: race fix broke stuff; pr 3169;
1554 srp@srparish.net, help from djm
1555
8021857c 155620030325
1557 - (djm) Fix getpeerid support for 64 bit BE systems. From
1558 Arnd Bergmann <arndb@de.ibm.com>
1559
cdb64c4d 156020030324
1561 - (djm) OpenBSD CVS Sync
1562 - markus@cvs.openbsd.org 2003/03/23 19:02:00
1563 [monitor.c]
1564 unbreak rekeying for privsep; ok millert@
1565 - Release 3.6p1
62086365 1566 - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
1567 Report from murple@murple.net, diagnosis from dtucker@zip.com.au
cdb64c4d 1568
0b202697 1569$Id$
This page took 0.591015 seconds and 5 git commands to generate.