]> andersk Git - openssh.git/blame - ChangeLog
- (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
[openssh.git] / ChangeLog
CommitLineData
fda04d7d 120030822
2 - (djm) s/get_progname/ssh_get_progname/g to avoid conflict with Heimdal
3 -lbroken; ok dtucker
fcd7f067 4 - (dtucker) [contrib/cygwin/ssh-user-config] Put keys in authorized_keys
5 rather that authorized_keys2. Patch from vinschen@redhat.com.
fda04d7d 6
08d035b6 720030821
8 - (dtucker) OpenBSD CVS Sync
9 - markus@cvs.openbsd.org 2003/08/14 16:08:58
10 [ssh-keygen.c]
11 exit after primetest, ok djm@
a814ba4d 12 - (dtucker) [defines.h] Put CMSG_DATA, CMSG_FIRSTHDR with other CMSG* macros,
13 change CMSG_DATA to use __CMSG_ALIGN (and thus work properly), reformat for
14 consistency.
eacb954e 15 - (dtucker) [configure.ac] Move openpty/ctty test outside of case statement
16 and after normal openpty test.
08d035b6 17
83814987 1820030813
19 - (dtucker) [session.c] Remove #ifdef TIOCSBRK kludge.
8168a86a 20 - (dtucker) OpenBSD CVS Sync
21 - markus@cvs.openbsd.org 2003/08/13 08:33:02
22 [session.c]
23 use more portable tcsendbreak(3) and ignore break_length;
24 ok deraadt, millert
0598d99d 25 - markus@cvs.openbsd.org 2003/08/13 08:46:31
26 [auth1.c readconf.c readconf.h servconf.c servconf.h ssh.c ssh_config
27 ssh_config.5 sshconnect1.c sshd.8 sshd.c sshd_config sshd_config.5]
28 remove RhostsAuthentication; suggested by djm@ before; ok djm@, deraadt@,
29 fgsch@, miod@, henning@, jakob@ and others
37ba5172 30 - markus@cvs.openbsd.org 2003/08/13 09:07:10
31 [readconf.c ssh.c]
32 socks4->socks, since with support both 4 and 5; dtucker@zip.com.au
5af25b1d 33 - (dtucker) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
34 Add a tcsendbreak function for platforms that don't have one, based on the
35 one from OpenBSD.
83814987 36
78e43412 3720030811
38 - (dtucker) OpenBSD CVS Sync
39 (thanks to Simon Wilkinson for help with this -dt)
40 - markus@cvs.openbsd.org 2003/07/16 15:02:06
41 [auth-krb5.c]
42 mcc -> fcc; from Love Hörnquist Åstrand <lha@it.su.se>
43 otherwise the kerberos credentinal is stored in a memory cache
44 in the privileged sshd. ok jabob@, hin@ (some time ago)
8c9f0900 45 - (dtucker) [openbsd-compat/xcrypt.c] Remove Cygwin #ifdef block (duplicate
46 in bsd-cygwin_util.h).
78e43412 47
3095daf7 4820030808
49 - (dtucker) [openbsd-compat/fake-rfc2553.h] Older Linuxes have AI_PASSIVE and
50 AI_CANONNAME in netdb.h but not AI_NUMERICHOST, so check each definition
51 separately before defining them.
26b3608b 52 - (dtucker) [auth-pam.c] Don't set PAM_TTY if tty is null. ok djm@
3095daf7 53
a15f16ab 5420030807
55 - (dtucker) [session.c] Have session_break_req not attempt to send a break
56 if TIOCSBRK and TIOCCBRK are not defined (eg Cygwin).
97722976 57 - (dtucker) [canohost.c] Bug #336: Only check ip options if IP_OPTIONS is
a96fbb21 58 defined (fixes compile error on really old Linuxes).
59 - (dtucker) [defines.h] Bug #336: Add CMSG_DATA and CMSG_FIRSTHDR macros if
60 not already defined (eg Linux with some versions of libc5), based on those
61 from OpenBSD.
871e1d12 62 - (dtucker) [openbsd-compat/bsd-cygwin_util.c openbsd-compat/bsd-cygwin_util.h]
63 Remove incorrect filenames from comments (file names are in Id tags).
a3b678a3 64 - (dtucker) [session.c openbsd-compat/bsd-cygwin_util.h] Move Cygwin
65 specific defines and includes to bsd-cygwin_util.h. Fixes build error too.
a15f16ab 66
2616e1bc 6720030802
68 - (dtucker) [monitor.h monitor_wrap.h] Remove excess ident tags.
1c590258 69 - (dtucker) OpenBSD CVS Sync
70 - markus@cvs.openbsd.org 2003/07/22 13:35:22
71 [auth1.c auth.h auth-passwd.c monitor.c monitor.h monitor_wrap.c
72 monitor_wrap.h readconf.c readconf.h servconf.c servconf.h session.c ssh.1
73 ssh.c ssh_config.5 sshconnect1.c sshd.c sshd_config.5 ssh.h]
74 remove (already disabled) KRB4/AFS support, re-enable -k in ssh(1);
75 test+ok henning@
76 - (dtucker) [Makefile.in acconfig.h configure.ac] Remove KRB4/AFS support.
77 - (dtucker) [auth-krb4.c radix.c radix.h] Remove KRB4/AFS specific files.
ac452e85 78 - (dtucker) OpenBSD CVS Sync
79 - markus@cvs.openbsd.org 2003/07/23 07:42:43
80 [sshd_config]
81 remove AFS; itojun@
c35a6dc5 82 - djm@cvs.openbsd.org 2003/07/28 09:49:56
83 [ssh-keygen.1 ssh-keygen.c]
84 Support for generating Diffie-Hellman groups (/etc/moduli) from ssh-keygen.
85 Based on code from Phil Karn, William Allen Simpson and Niels Provos.
86 ok markus@, thanks jmc@
178b1a1d 87 - markus@cvs.openbsd.org 2003/07/29 18:24:00
88 [LICENCE progressmeter.c]
89 replace 4 clause BSD licensed progressmeter code with a replacement
90 from Nils Nordman and myself; ok deraadt@
91 (copied from OpenBSD an re-applied portable changes)
0dd40286 92 - markus@cvs.openbsd.org 2003/07/29 18:26:46
93 [progressmeter.c]
94 fix length for "- stalled -" (included with previous import)
95 - markus@cvs.openbsd.org 2003/07/30 07:44:14
96 [progressmeter.c]
97 use only 4 digits in format_size (included with previous import)
98 - markus@cvs.openbsd.org 2003/07/30 07:53:27
99 [progressmeter.c]
100 whitespace (included with previous import)
0f57e1e6 101 - markus@cvs.openbsd.org 2003/07/31 09:21:02
102 [auth2-none.c]
103 check whether passwd auth is allowd, similar to proto 1; rob@pitman.co.za
104 ok henning
4899ccef 105 - avsm@cvs.openbsd.org 2003/07/31 15:50:16
106 [atomicio.c]
107 correct comment: atomicio takes vwrite, not write; deraadt@ ok
b3a7a008 108 - markus@cvs.openbsd.org 2003/07/31 22:34:03
109 [progressmeter.c]
110 print rate similar old version; round instead truncate;
111 (included in previous progressmeter.c commit)
c5d3dd1b 112 - (dtucker) [openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
113 Add a tcgetpgrp function.
5ae3dc68 114 - (dtucker) [Makefile.in moduli.c moduli.h] Add new files and to Makefile.
f29c37a9 115 - (dtucker) [openbsd-compat/bsd-misc.c] Fix cut-and-paste bug in tcgetpgrp.
2616e1bc 116
cbdeccf3 11720030730
118 - (djm) [auth-pam.c] Don't use crappy APIs like sprintf. Thanks bal
119
a9705c94 12020030726
121 - (dtucker) [openbsd-compat/xcrypt.c] Fix typo: DISABLED_SHADOW ->
122 DISABLE_SHADOW. Fixes HP-UX compile error.
123
7c6eb32f 12420030724
125 - (bal) [auth-passwd.c openbsd-compat/Makefile.in openbsd-compat/xcrypt.c
126 openbsd-compat/xcrypt.h] Split off encryption into xcrypt() interface,
127 and isolate shadow password functions. Tested in Solaris, but should
128 not break other platforms too badly (except maybe HP =). Also brings
129 auth-passwd.c into full sync with OpenBSD tree.
130
82e5907c 13120030723
132 - (dtucker) [configure.ac] Back out change for bug #620.
133
defb525d 13420030719
135 - (dtucker) [configure.ac] Bug #620: Define BROKEN_GETADDRINFO for
136 Solaris/x86. Patch from jrhett at isite.net.
7b390973 137 - (dtucker) OpenBSD CVS Sync
138 - markus@cvs.openbsd.org 2003/07/14 12:36:37
139 [sshd.c]
140 remove undocumented -V option. would be only useful if openssh is used
141 as ssh v1 server for ssh.com's ssh v2.
e053cd2c 142 - markus@cvs.openbsd.org 2003/07/16 10:34:53
143 [ssh.c sshd.c]
144 don't exit on multiple -v or -d; ok deraadt@
145d23ca 145 - markus@cvs.openbsd.org 2003/07/16 10:36:28
146 [sshtty.c]
147 clear IUCLC in enter_raw_mode; from rob@pitman.co.za; ok deraadt@, fgs@
261bd618 148 - deraadt@cvs.openbsd.org 2003/07/18 01:54:25
149 [scp.c]
150 userid is unsigned, but well, force it anyways; andrushock@korovino.net
b3d04e37 151 - djm@cvs.openbsd.org 2003/07/19 00:45:53
152 [sftp-int.c]
153 fix sftp filename parsing for arguments with escaped quotes. bz #517;
154 ok markus
86d0260c 155 - djm@cvs.openbsd.org 2003/07/19 00:46:31
156 [regress/sftp-cmds.sh]
157 regress test for sftp arguments with escaped quotes; ok markus
defb525d 158
e351e493 15920030714
160 - (dtucker) [acconfig.h configure.ac port-aix.c] Older AIXes don't declare
161 loginfailed at all, so assume 3-arg loginfailed if not declared.
1cd5765d 162 - (dtucker) [port-aix.h] Work around name collision on AIX for r_type by
163 undef'ing it.
2aa3a16c 164 - (dtucker) Bug #543: [configure.ac port-aix.c port-aix.h]
165 Call setauthdb() before loginfailed(), which may load password registry-
defb525d 166 specific functions. Based on patch by cawlfiel at us.ibm.com.
b4777c18 167 - (dtucker) [port-aix.h] Fix prototypes.
956b0f56 168 - (dtucker) OpenBSD CVS Sync
169 - avsm@cvs.openbsd.org 2003/07/09 13:58:19
170 [key.c]
171 minor tweak: when generating the hex fingerprint, give strlcat the full
172 bound to the buffer, and add a comment below explaining why the
173 zero-termination is one less than the bound. markus@ ok
40729edd 174 - markus@cvs.openbsd.org 2003/07/10 14:42:28
175 [packet.c]
176 the 2^(blocksize*2) rekeying limit is too expensive for 3DES,
177 blowfish, etc, so enforce a 1GB limit for small blocksizes.
659912db 178 - markus@cvs.openbsd.org 2003/07/10 20:05:55
179 [sftp.c]
180 sync usage with manpage, add missing -R
e351e493 181
f58c0e01 18220030708
183 - (dtucker) [acconfig.h auth-passwd.c configure.ac session.c port-aix.[ch]]
184 Include AIX headers for authentication functions and make calls match
e351e493 185 prototypes. Test for and handle 3-arg and 4-arg variants of loginfailed.
bc7dfc06 186 - (dtucker) [session.c] Check return value of setpcred().
187 - (dtucker) [auth-passwd.c auth.c session.c sshd.c port-aix.c port-aix.h]
188 Convert aixloginmsg into platform-independant Buffer loginmsg.
f58c0e01 189
309709db 19020030707
191 - (dtucker) [configure.ac] Bug #600: Check that getrusage is declared before
192 searching libraries for it. Fixes build errors on NCR MP-RAS.
193
d72f7b79 19420030706
195 - (dtucker) [ssh-rand-helper.c loginrec.c]
196 Apply atomicio typing change to these too.
197
71b9ced0 19820030703
199 - (dtucker) OpenBSD CVS Sync
200 - djm@cvs.openbsd.org 2003/06/28 07:48:10
201 [sshd.c]
202 report pidfile creation errors, based on patch from Roumen Petrov;
203 ok markus@
dc54438a 204 - deraadt@cvs.openbsd.org 2003/06/28 16:23:06
205 [atomicio.c atomicio.h authfd.c clientloop.c monitor_wrap.c msg.c
206 progressmeter.c scp.c sftp-client.c ssh-keyscan.c ssh.h sshconnect.c
207 sshd.c]
208 deal with typing of write vs read in atomicio
7caca6d4 209 - markus@cvs.openbsd.org 2003/06/29 12:44:38
210 [sshconnect.c]
211 memset 0, not \0; andrushock@korovino.net
8e7c9afc 212 - markus@cvs.openbsd.org 2003/07/02 12:56:34
213 [channels.c]
214 deny dynamic forwarding with -R for v1, too; ok djm@
f49658f5 215 - markus@cvs.openbsd.org 2003/07/02 14:51:16
216 [channels.c ssh.1 ssh_config.5]
217 (re)add socks5 suppport to -D; ok djm@
218 now ssh(1) can act both as a socks 4 and socks 5 server and
219 dynamically forward ports.
03c82656 220 - markus@cvs.openbsd.org 2003/07/02 20:37:48
221 [ssh.c]
222 convert hostkeyalias to lowercase, otherwise uppercase aliases will
223 not match at all; ok henning@
1768a611 224 - markus@cvs.openbsd.org 2003/07/03 08:21:46
225 [regress/dynamic-forward.sh]
226 add socks5; speedup; reformat; based on patch from dtucker@zip.com.au
7664edb6 227 - markus@cvs.openbsd.org 2003/07/03 08:24:13
228 [regress/Makefile]
229 enable tests for dynamic fwd via socks (-D), uses nc(1)
1572b90f 230 - djm@cvs.openbsd.org 2003/07/03 08:09:06
231 [readconf.c readconf.h ssh-keysign.c ssh.c]
232 fix AddressFamily option in config file, from brent@graveland.net;
233 ok markus@
71b9ced0 234
4e00038c 23520030630
236 - (djm) Search for support functions necessary to build our
237 getrrsetbyname() replacement. Patch from Roumen Petrov
238
9f59c5a3 23920030629
c5829391 240 - (dtucker) [includes.h] Bug #602: move #include of netdb.h to after in.h
241 (fixes compiler warnings on Solaris 2.5.1).
242 - (dtucker) [configure.ac] Add sanity test after system-dependant compiler
243 flag modifications.
9f59c5a3 244
9ea150a7 24520030628
246 - (djm) Bug #591: use PKCS#15 private key label as a comment in case
247 of OpenSC. Report and patch from larsch@trustcenter.de
d2168412 248 - (djm) Bug #593: Sanity check OpenSC card reader number; patch from
249 aj@dungeon.inka.de
f0677b69 250 - (dtucker) OpenBSD CVS Sync
251 - markus@cvs.openbsd.org 2003/06/23 09:02:44
252 [ssh_config.5]
253 document EnableSSHKeysign; bugzilla #599; ok deraadt@, jmc@
a27002e5 254 - markus@cvs.openbsd.org 2003/06/24 08:23:46
255 [auth2-hostbased.c auth2-pubkey.c auth2.c channels.c key.c key.h
256 monitor.c packet.c packet.h serverloop.c sshconnect2.c sshd.c]
257 int -> u_int; ok djm@, deraadt@, mouring@
d7ded285 258 - miod@cvs.openbsd.org 2003/06/25 22:39:36
259 [sftp-server.c]
260 Typo police: attribute is better written with an 'r'.
2d9c1828 261 - markus@cvs.openbsd.org 2003/06/26 20:08:33
262 [readconf.c]
263 do not dump core for 'ssh -o proxycommand host'; ok deraadt@
78b2dd04 264 - (dtucker) [regress/dynamic-forward.sh] Import new regression test.
ddb154b3 265 - (dtucker) [configure.ac] Bug #570: Have ./configure --enable-FEATURE
266 actually enable the feature, for those normally disabled. Patch by
267 openssh (at) roumenpetrov.info.
f0677b69 268
e15ba28b 26920030624
270 - (dtucker) Have configure refer the user to config.log and
271 contrib/findssl.sh for OpenSSL header/library mismatches.
272
63a556df 27320030622
c1ffd4bd 274 - (dtucker) OpenBSD CVS Sync
63a556df 275 - markus@cvs.openbsd.org 2003/06/21 09:14:05
c1ffd4bd 276 [regress/reconfigure.sh]
63a556df 277 missing $SUDO; from dtucker@zip.com.au
93527718 278 - markus@cvs.openbsd.org 2003/06/18 11:28:11
c1ffd4bd 279 [ssh-rsa.c]
280 backout last change, since it violates pkcs#1
281 switch to share/misc/license.template
1891396b 282 - djm@cvs.openbsd.org 2003/06/20 05:47:58
283 [sshd_config.5]
284 sync description of protocol 2 cipher proposal; ok markus
4db4d313 285 - djm@cvs.openbsd.org 2003/06/20 05:48:21
286 [sshd_config]
287 sync some implemented options; ok markus@
63a556df 288 - (dtucker) [regress/authorized_keys_root] Remove temp data file from CVS.
39ef3618 289 - (dtucker) [openbsd-compat/setproctitle.c] Ensure SPT_TYPE is defined before
290 testing its value.
63a556df 291
b8e04133 29220030618
293 - (djm) OpenBSD CVS Sync
294 - markus@cvs.openbsd.org 2003/06/12 07:57:38
295 [monitor.c sshlogin.c sshpty.c]
296 typos; dtucker at zip.com.au
b9ad9d13 297 - djm@cvs.openbsd.org 2003/06/12 12:22:47
298 [LICENCE]
299 mention more copyright holders; ok markus@
1fb23629 300 - nino@cvs.openbsd.org 2003/06/12 15:34:09
301 [scp.c]
302 Typo. Ok markus@.
244e796f 303 - markus@cvs.openbsd.org 2003/06/12 19:12:03
304 [scard.c scard.h ssh-agent.c ssh.c]
305 add sc_get_key_label; larsch at trustcenter.de; bugzilla#591
9250058a 306 - markus@cvs.openbsd.org 2003/06/16 08:22:35
307 [ssh-rsa.c]
308 make sure the signature has at least the expected length (don't
309 insist on len == hlen + oidlen, since this breaks some smartcards)
310 bugzilla #592; ok djm@
360a4aae 311 - markus@cvs.openbsd.org 2003/06/16 10:22:45
312 [ssh-add.c]
313 print out key comment on each prompt; make ssh-askpass more useable; ok djm@
0a59bd6b 314 - markus@cvs.openbsd.org 2003/06/17 18:14:23
315 [cipher-ctr.c]
316 use license from /usr/share/misc/license.template for new code
1d6c0b69 317 - (dtucker) [reconfigure.sh rekey.sh sftp-badcmds.sh]
318 Import new regression tests from OpenBSD
d4d84f5f 319 - (dtucker) [regress/copy.1 regress/copy.2] Remove temp data files from CVS.
ed49cc81 320 - (dtucker) OpenBSD CVS Sync (regress/)
321 - markus@cvs.openbsd.org 2003/04/02 12:21:13
322 [Makefile]
323 enable rekey test
2c670155 324 - djm@cvs.openbsd.org 2003/04/04 09:34:22
325 [Makefile sftp-cmds.sh]
326 More regression tests, including recent directory rename bug; ok markus@
737447ad 327 - markus@cvs.openbsd.org 2003/05/14 22:08:27
328 [ssh-com-client.sh ssh-com-keygen.sh ssh-com-sftp.sh ssh-com.sh]
329 test against some new commerical versions
68df2aa0 330 - mouring@cvs.openbsd.org 2003/05/15 04:07:12
331 [sftp-cmds.sh]
332 Advanced put/get testing for sftp. OK @djm
eb9bf761 333 - markus@cvs.openbsd.org 2003/06/12 15:40:01
334 [try-ciphers.sh]
335 add ctr
39c0191e 336 - markus@cvs.openbsd.org 2003/06/12 15:43:32
337 [Makefile]
338 test -HUP; dtucker at zip.com.au
b8e04133 339
f5827134 34020030614
341 - (djm) Update license on fake-rfc2553.[ch]; ok itojun@
342
be193d89 34320030611
c12c6ef8 344 - (djm) Mention portable copyright holders in LICENSE
e52ca1e5 345 - (djm) Put licenses on substantial header files
8cb3fa9d 346 - (djm) Sync LICENSE against OpenBSD
be193d89 347 - (djm) OpenBSD CVS Sync
348 - jmc@cvs.openbsd.org 2003/06/10 09:12:11
349 [scp.1 sftp-server.8 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5]
350 [sshd.8 sshd_config.5 ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
351 - section reorder
352 - COMPATIBILITY merge
353 - macro cleanup
354 - kill whitespace at EOL
355 - new sentence, new line
356 ssh pages ok markus@
0daa6547 357 - deraadt@cvs.openbsd.org 2003/06/10 22:20:52
358 [packet.c progressmeter.c]
359 mostly ansi cleanup; pval ok
1432b5c4 360 - jakob@cvs.openbsd.org 2003/06/11 10:16:16
361 [sshconnect.c]
362 clean up check_host_key() and improve SSHFP feedback. ok markus@
cc263107 363 - jakob@cvs.openbsd.org 2003/06/11 10:18:47
364 [dns.c]
365 sync with check_host_key() change
ca719034 366 - djm@cvs.openbsd.org 2003/06/11 11:18:38
367 [authfd.c authfd.h ssh-add.c ssh-agent.c]
368 make agent constraints (lifetime, confirm) work with smartcard keys;
369 ok markus@
be193d89 370
371
8a547250 37220030609
373 - (djm) Sync README.smartcard with OpenBSD -current
a1864983 374 - (djm) Re-merge OpenSC info into README.smartcard
8a547250 375
f5db6a03 37620030606
377 - (dtucker) [uidswap.c] Fix setreuid and add missing args to fatal(). ok djm@
378
02e2a074 37920030605
380 - (djm) Support AI_NUMERICHOST in fake-getaddrinfo.c. Needed for recent
381 canohost.c changes.
688eed4a 382 - (djm) Implement paranoid priv dropping checks, based on:
383 "SetUID demystified" - Hao Chen, David Wagner and Drew Dean
384 Proceedings of USENIX Security Symposium 2002
d6bd2b5a 385 - (djm) Don't use xmalloc() or pull in toplevel headers in fake-* code
52d58495 386 - (djm) Merge all the openbsd/fake-* into fake-rfc2553.[ch]
57c917f8 387 - (djm) Bug #588 - Add scard-opensc.o back to Makefile.in
388 Patch from larsch@trustcenter.de
7b7f164b 389 - (djm) Bug #589 - scard-opensc: load only keys with a private keys
390 Patch from larsch@trustcenter.de
4ed465ec 391 - (dtucker) Add includes.h to fake-rfc2553.c so it will build.
e932f447 392 - (dtucker) Define EAI_NONAME in fake-rfc2553.h (used by fake-rfc2553.c).
02e2a074 393
b08a39ff 39420030604
d60e487c 395 - (djm) Bug #573 - Remove unneeded Krb headers and compat goop. Patch from
396 simon@sxw.org.uk (Also matches a change in OpenBSD a while ago)
8acdec60 397 - (djm) Bug #577 - wrong flag in scard-opensc.c sc_private_decrypt.
11f1e60e 398 Patch from larsch@trustcenter.de; ok markus@
399 - (djm) Bug #584: scard-opensc.c doesn't work without PIN. Patch from
400 larsch@trustcenter.de; ok markus@
d453a600 401 - (djm) OpenBSD CVS Sync
402 - djm@cvs.openbsd.org 2003/06/04 08:25:18
403 [sshconnect.c]
404 disable challenge/response and keyboard-interactive auth methods
405 upon hostkey mismatch. based on patch from fcusack AT fcusack.com.
406 bz #580; ok markus@
ee50371d 407 - djm@cvs.openbsd.org 2003/06/04 10:23:48
408 [sshd.c]
409 remove duplicated group-dropping code; ok markus@
b08a39ff 410 - djm@cvs.openbsd.org 2003/06/04 12:03:59
411 [serverloop.c]
412 remove bitrotten commet; ok markus@
cf3248b8 413 - djm@cvs.openbsd.org 2003/06/04 12:18:49
414 [scp.c]
415 ansify; ok markus@
0f764b2f 416 - djm@cvs.openbsd.org 2003/06/04 12:40:39
417 [scp.c]
418 kill ssh process upon receipt of signal, bz #241.
419 based on patch from esb AT hawaii.edu; ok markus@
1b558925 420 - djm@cvs.openbsd.org 2003/06/04 12:41:22
421 [sftp.c]
422 kill ssh process on receipt of signal; ok markus@
fba33e81 423 - (djm) Update to fix of bug #584: lock card before return.
424 From larsch@trustcenter.de
8d9bb5dd 425 - (djm) Always use mysignal() for SIGALRM
d60e487c 426
3a2b2b44 42720030603
428 - (djm) Replace setproctitle replacement with code derived from
429 UCB sendmail
c5a7d788 430 - (djm) OpenBSD CVS Sync
431 - markus@cvs.openbsd.org 2003/06/02 09:17:34
432 [auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
433 [canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
434 [sshd_config.5]
435 deprecate VerifyReverseMapping since it's dangerous if combined
436 with IP based access control as noted by Mike Harding; replace with
437 a UseDNS option, UseDNS is on by default and includes the
438 VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
439 ok deraadt@, djm@
d981089c 440 - millert@cvs.openbsd.org 2003/06/03 02:56:16
441 [scp.c]
442 Remove the advertising clause in the UCB license which Berkeley
443 rescinded 22 July 1999. Proofed by myself and Theo.
c5a7d788 444 - (djm) Fix portable-specific uses of verify_reverse_mapping too
3e67f7df 445 - (djm) Sync openbsd-compat with OpenBSD CVS.
484d59c7 446 - No more 4-term BSD licenses in linked code
5d8ca8c7 447 - (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
3a2b2b44 448
aff561f9 44920030602
450 - (djm) Fix segv from bad reordering in auth-pam.c
416c732d 451 - (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
452 clobber
1b7342ab 453 - (tim) openbsd-compat/xmmap.[ch] License clarifications. Add missing
454 CVS ID.
8862e142 455 - (djm) Remove "noip6" option from RedHat spec file. This may now be
456 set at runtime using AddressFamily option.
58ba3cb7 457 - (djm) Fix use of macro before #define in cipher-aes.c
382fe2fa 458 - (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
b0545fe6 459 - (djm) OpenBSD CVS Sync
460 - djm@cvs.openbsd.org 2003/05/26 12:54:40
461 [sshconnect.c]
462 fix format strings; ok markus@
fa5120a0 463 - deraadt@cvs.openbsd.org 2003/05/29 16:58:45
464 [sshd.c uidswap.c]
465 seteuid and setegid; markus ok
0f92946c 466 - jakob@cvs.openbsd.org 2003/06/02 08:31:10
467 [ssh_config.5]
468 VerifyHostKeyDNS is v2 only. ok markus@
aff561f9 469
4f178be8 47020030530
471 - (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
472 roumenpetrov.info
eabb99c6 473 - (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
4f178be8 474
4881aebb 47520030526
476 - (djm) Avoid auth2-chall.c warning when compiling without
477 PAM, BSD_AUTH and SKEY
478
5b0fe364 47920030525
480- (djm) OpenBSD CVS Sync
481 - djm@cvs.openbsd.org 2003/05/24 09:02:22
482 [log.c]
483 pass logged data through strnvis; ok markus
b9ed513a 484 - djm@cvs.openbsd.org 2003/05/24 09:30:40
485 [authfile.c monitor.c sftp-common.c sshpty.c]
486 cast some types for printing; ok markus@
5b0fe364 487
44c78996 48820030524
489 - (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
490
d83ebe4a 49120030523
492 - (djm) Use VIS_SAFE on logged strings rather than default strnvis
493 encoding (which encodes many more characters)
bd47824b 494 - OpenBSD CVS Sync
495 - jmc@cvs.openbsd.org 2003/05/20 12:03:35
496 [sftp.1]
497 - new sentence, new line
498 - added .Xr's
499 - typos
500 ok djm@
3cbc677d 501 - jmc@cvs.openbsd.org 2003/05/20 12:09:31
502 [ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
503 new sentence, new line
da54f5be 504 - djm@cvs.openbsd.org 2003/05/23 08:29:30
505 [sshconnect.c]
506 fix leak; ok markus@
d83ebe4a 507
c453493f 50820030520
509 - (djm) OpenBSD CVS Sync
510 - deraadt@cvs.openbsd.org 2003/05/18 23:22:01
511 [log.c]
512 use syslog_r() in a signal handler called place; markus ok
79d4fc55 513 - (djm) Configure logic to detect syslog_r and friends
c453493f 514
acb50584 51520030519
516 - (djm) Sync auth-pam.h with what we actually implement
517
51820030518
5ff453c0 519 - (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
520 recent merge
f811e52a 521 - (djm) OpenBSD CVS Sync
522 - djm@cvs.openbsd.org 2003/05/16 03:27:12
523 [readconf.c ssh_config ssh_config.5 ssh-keysign.c]
524 add AddressFamily option to ssh_config (like -4, -6 on commandline).
525 Portable bug #534; ok markus@
013b1214 526 - itojun@cvs.openbsd.org 2003/05/17 03:25:58
527 [auth-rhosts.c]
528 just in case, put numbers to sscanf %s arg.
25b66522 529 - markus@cvs.openbsd.org 2003/05/17 04:27:52
530 [cipher.c cipher-ctr.c myproposal.h]
531 experimental support for aes-ctr modes from
532 http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
533 ok djm@
25351757 534 - (djm) Remove IPv4 by default hack now that we can specify AF in config
3bf784bc 535 - (djm) Tidy and trim TODO
bffa6723 536 - (djm) Sync openbsd-compat/ with OpenBSD CVS head
9901cb37 537 - (djm) Big KNF on openbsd-compat/
f1da2b8b 538 - (djm) KNF on md5crypt.[ch]
539 - (djm) KNF on auth-sia.[ch]
5ff453c0 540
f123055b 54120030517
542 - (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
543
c936c243 54420030516
545 - (djm) OpenBSD CVS Sync
546 - djm@cvs.openbsd.org 2003/05/15 13:52:10
547 [ssh.c]
548 Make "ssh -V" print the OpenSSL version in a human readable form. Patch
549 from Craig Leres (mindrot at ee.lbl.gov); ok markus@
a2144546 550 - jakob@cvs.openbsd.org 2003/05/15 14:02:47
551 [readconf.c servconf.c]
552 warn for unsupported config option. ok markus@
5bdfde81 553 - markus@cvs.openbsd.org 2003/05/15 14:09:21
554 [auth2-krb5.c]
555 fix 64bit issue; report itojun@
09ab3296 556 - djm@cvs.openbsd.org 2003/05/15 14:55:25
557 [readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
558 add a ConnectTimeout option to ssh, based on patch from
559 Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
b06b11ad 560 - (djm) Add warning for UsePAM when built without PAM support
7be625e1 561 - (djm) A few type mismatch fixes from Bug #565
0eb6370a 562 - (djm) Guard free_pam_environment against NULL argument. Works around
563 HP/UX PAM problems debugged by dtucker
c936c243 564
7efc7f57 56520030515
566 - (djm) OpenBSD CVS Sync
567 - jmc@cvs.openbsd.org 2003/05/14 13:11:56
568 [ssh-agent.1]
569 setup -> set up;
570 from wiz@netbsd
21289cd0 571 - jakob@cvs.openbsd.org 2003/05/14 18:16:20
572 [key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
573 [dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
574 add experimental support for verifying hos keys using DNS as described
575 in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
576 ok markus@ and henning@
16a79097 577 - markus@cvs.openbsd.org 2003/05/14 22:24:42
578 [clientloop.c session.c ssh.1]
579 allow to send a BREAK to the remote system; ok various
b8c2031b 580 - markus@cvs.openbsd.org 2003/05/15 00:28:28
581 [sshconnect2.c]
582 cleanup unregister of per-method packet handlers; ok djm@
d0ec7f42 583 - jakob@cvs.openbsd.org 2003/05/15 01:48:10
584 [readconf.c readconf.h servconf.c servconf.h]
585 always parse kerberos options. ok djm@ markus@
b414a17b 586 - jakob@cvs.openbsd.org 2003/05/15 02:27:15
587 [dns.c]
588 add missing freerrset
3b6e3da9 589 - markus@cvs.openbsd.org 2003/05/15 03:08:29
590 [cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
591 split out custom EVP ciphers
02159d9b 592 - djm@cvs.openbsd.org 2003/05/15 03:10:52
593 [ssh-keygen.c]
594 avoid warning; ok jakob@
4a26f5c5 595 - mouring@cvs.openbsd.org 2003/05/15 03:39:07
596 [sftp-int.c]
597 Make put/get (globed and nonglobed) code more consistant. OK djm@
c44f10c6 598 - mouring@cvs.openbsd.org 2003/05/15 03:43:59
dc69f53c 599 [sftp-int.c sftp.c]
c44f10c6 600 Teach ls how to display multiple column display and allow users
601 to return to single column format via 'ls -1'. OK @djm
1457e7ff 602 - jakob@cvs.openbsd.org 2003/05/15 04:08:44
603 [readconf.c servconf.c]
604 disable kerberos when not supported. ok markus@
861f0365 605 - markus@cvs.openbsd.org 2003/05/15 04:08:41
606 [ssh.1]
607 ~B is ssh2 only
d0ec7f42 608 - (djm) Always parse UsePAM
3e05e934 609 - (djm) Configure glue for DNS support (code doesn't work in portable yet)
4460d509 610 - (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
86ee6794 611 - (djm) Tidy Makefile clean targets
2636769c 612 - (djm) Adapt README.dns for portable
2d2e4a34 613 - (djm) Avoid uuencode.c warnings
1457e7ff 614 - (djm) Enable UsePAM when built --with-pam
67467c30 615 - (djm) Only build getrrsetbyname replacement when using --with-dns
f420d2ba 616 - (djm) Bug #529: sshd doesn't work correctly after SIGHUP (copy argv
617 correctly)
3c49ef10 618 - (djm) Bug #444: Wrong paths after reconfigure
321735c7 619 - (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
f420d2ba 620
dd3ebb5a 62120030514
622 - (djm) Bug #117: Don't lie to PAM about username
0608f8a7 623 - (djm) RCSID sync w/ OpenBSD
204fde99 624 - (djm) OpenBSD CVS Sync
625 - djm@cvs.openbsd.org 2003/04/09 12:00:37
626 [readconf.c]
627 strip trailing whitespace from config lines before parsing.
628 Fixes bz 528; ok markus@
18ae3c67 629 - markus@cvs.openbsd.org 2003/04/12 10:13:57
630 [cipher.c]
631 hide cipher details; ok djm@
45c42d58 632 - markus@cvs.openbsd.org 2003/04/12 10:15:36
633 [misc.c]
634 debug->debug2
c825cd79 635 - naddy@cvs.openbsd.org 2003/04/12 11:40:15
636 [ssh.1]
637 document -V switch, fix wording; ok markus@
3e131a6d 638 - markus@cvs.openbsd.org 2003/04/14 14:17:50
639 [channels.c sshconnect.c sshd.c ssh-keyscan.c]
640 avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
927e9f8b 641 - mouring@cvs.openbsd.org 2003/04/14 21:31:27
642 [sftp-int.c]
643 Missing globfree(&g) in process_put() spotted by Vince Brimhall
644 <VBrimhall@novell.com>. ok@ Theo
645 - markus@cvs.openbsd.org 2003/04/16 14:35:27
646 [auth.h]
647 document struct Authctxt; with solar
b9e5aff6 648 - deraadt@cvs.openbsd.org 2003/04/26 04:29:49
649 [ssh-keyscan.c]
650 -t in usage(); rogier@quaak.org
9a26a6e2 651 - mouring@cvs.openbsd.org 2003/04/30 01:16:20
652 [sshd.8 sshd_config.5]
653 Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
654 Bug #550 and * escaping suggested by jmc@.
09dc8896 655 - david@cvs.openbsd.org 2003/04/30 20:41:07
656 [sshd.8]
657 fix invalid .Pf macro usage introduced in previous commit
658 ok jmc@ mouring@
3566c73c 659 - markus@cvs.openbsd.org 2003/05/11 16:56:48
660 [authfile.c ssh-keygen.c]
661 change key_load_public to try to read a public from:
662 rsa1 private or rsa1 public and ssh2 keys.
663 this makes ssh-keygen -e fail for ssh1 keys more gracefully
664 for example; report from itojun (netbsd pr 20550).
0d942eff 665 - markus@cvs.openbsd.org 2003/05/11 20:30:25
666 [channels.c clientloop.c serverloop.c session.c ssh.c]
667 make channel_new() strdup the 'remote_name' (not the caller); ok theo
43348518 668 - markus@cvs.openbsd.org 2003/05/12 16:55:37
669 [sshconnect2.c]
670 for pubkey authentication try the user keys in the following order:
671 1. agent keys that are found in the config file
672 2. other agent keys
673 3. keys that are only listed in the config file
674 this helps when an agent has many keys, where the server might
675 close the connection before the correct key is used. report & ok pb@
dc109cfe 676 - markus@cvs.openbsd.org 2003/05/12 18:35:18
677 [ssh-keyscan.1]
678 typo: DSA keys are of type ssh-dss; Brian Poole
81466908 679 - markus@cvs.openbsd.org 2003/05/14 00:52:59
680 [ssh2.h]
681 ranges for per auth method messages
682 - djm@cvs.openbsd.org 2003/05/14 01:00:44
683 [sftp.1]
684 emphasise the batchmode functionality and make reference to pubkey auth,
685 both of which are FAQs; ok markus@
802e01b8 686 - markus@cvs.openbsd.org 2003/05/14 02:15:47
687 [auth2.c monitor.c sshconnect2.c auth2-krb5.c]
688 implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
689 server interops with commercial client; ok jakob@ djm@
72c5fe79 690 - jmc@cvs.openbsd.org 2003/05/14 08:25:39
691 [sftp.1]
692 - better formatting in SYNOPSIS
693 - whitespace at EOL
694 ok djm@
3a39206f 695 - markus@cvs.openbsd.org 2003/05/14 08:57:49
696 [monitor.c]
697 http://bugzilla.mindrot.org/show_bug.cgi?id=560
698 Privsep child continues to run after monitor killed.
699 Pass monitor signals through to child; Darren Tucker
751092f9 700 - (djm) Make portable build with MIT krb5 (some issues remain)
7fceb20d 701 - (djm) Add new UsePAM configuration directive to allow runtime control
702 over usage of PAM. This allows non-root use of sshd when built with
703 --with-pam
817e6d38 704 - (djm) Die screaming if start_pam() is called when UsePAM=no
83ccf11a 705 - (djm) Avoid KrbV leak for MIT Kerberos
b1848832 706 - (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
fa065de2 707 - (djm) Bug #258: sscanf("[0-9]") -> sscanf("[0123456789]") for portability
dd3ebb5a 708
91f3aa9b 70920030512
710 - (djm) Redhat spec: Don't install profile.d scripts when not
711 building with GNOME/GTK askpass (patch from bet@rahul.net)
712
5def520a 71320030510
714 - (dtucker) Bug #318: Create ssh_prng_cmds.out during "make" rather than
715 "make install". Patch by roth@feep.net.
ad84c479 716 - (dtucker) Bug #536: Test for and work around openpty/controlling tty
717 problem on Linux (fixes "could not set controlling tty" errors).
05114c74 718 - (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
719 proper challenge-response module
23ab1f36 720 - (djm) 2-clause license on loginrec.c, with permission from
721 andre@ae-35.com
5def520a 722
43ce025d 72320030504
dd594f99 724 - (dtucker) Bug #497: Move #include of bsd-cygwin_util.h to openbsd-compat.h.
725 Patch from vinschen@redhat.com.
43ce025d 726
2cd5dbba 72720030503
728 - (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
729 by wendyp@cray.com.
730
bf7c1e6c 73120030502
732 - (dtucker) Bug #544: ignore invalid cmsg_type on Linux 2.0 kernels,
733 privsep should now work.
73d9dad3 734 - (dtucker) Move handling of bad password authentications into a platform
990278ef 735 specific record_failed_login() function (affects AIX & Unicos). ok mouring@
bf7c1e6c 736
68ece370 73720030429
738 - (djm) Add back radix.o (used by AFS support), after it went missing from
739 Makefile many moons ago
740 - (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
741 - (djm) Fix blibpath specification for AIX/gcc
742 - (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
743
ded9dd18 74420030428
745 - (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
746 hacked code.
747
aceb0423 74820030427
749 - (bal) Bug #541: return; was dropped by mistake. Reported by
750 furrier@iglou.com
c8a50a34 751 - (bal) Since we don't support platforms lacking u_int_64. We may
752 as well clean out some of those evil #ifdefs
9a6fee8b 753 - (bal) auth1.c minor resync while looking at the code.
d7cf277b 754 - (bal) auth2.c same changed as above.
aceb0423 755
0a626302 75620030409
757 - (djm) Bug #539: Specify creation mode with O_CREAT for lastlog. Report
758 from matth@eecs.berkeley.edu
d35929b5 759 - (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
ffd7b36b 760 - (djm) OpenBSD CVS Sync
761 - markus@cvs.openbsd.org 2003/04/02 09:48:07
762 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
763 [readconf.h serverloop.c sshconnect2.c]
764 reapply rekeying chage, tested by henning@, ok djm@
16f1b5ca 765 - markus@cvs.openbsd.org 2003/04/02 14:36:26
766 [ssh-keysign.c]
767 potential segfault if KEY_UNSPEC; cjwatson@debian.org; bug #526
6c1bc5c5 768 - itojun@cvs.openbsd.org 2003/04/03 07:25:27
769 [progressmeter.c]
770 $OpenBSD$
771 - itojun@cvs.openbsd.org 2003/04/03 10:17:35
772 [progressmeter.c]
773 remove $OpenBSD$, as other *.c does not have it.
806e4c11 774 - markus@cvs.openbsd.org 2003/04/07 08:29:57
775 [monitor_wrap.c]
776 typo: get correct counters; introduced during rekeying change.
2f5b2528 777 - millert@cvs.openbsd.org 2003/04/07 21:58:05
778 [progressmeter.c]
779 The UCB copyright here is incorrect. This code did not originate
780 at UCB, it was written by Luke Mewburn. Updated the copyright at
781 the author's request. markus@ OK
782 - itojun@cvs.openbsd.org 2003/04/08 20:21:29
783 [*.c *.h]
784 rename log() into logit() to avoid name conflict. markus ok, from
785 netbsd
786 - (djm) XXX - Performed locally using:
787 "perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
70e1f62f 788 - hin@cvs.openbsd.org 2003/04/09 08:23:52
789 [servconf.c]
790 Don't include <krb.h> when compiling with Kerberos 5 support
2f5b2528 791 - (djm) Fix up missing include for packet.c
a3568201 792 - (djm) Fix missed log => logit occurance (reference by function pointer)
0a626302 793
4d0cb2e5 79420030402
795 - (bal) if IP_TOS is not found or broken don't try to compile in
796 packet_set_tos() function call. bug #527
797
a4e5acef 79820030401
799 - (djm) OpenBSD CVS Sync
800 - jmc@cvs.openbsd.org 2003/03/28 10:11:43
801 [scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
802 [ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
803 - killed whitespace
804 - new sentence new line
805 - .Bk for arguments
806 ok markus@
177f584b 807 - markus@cvs.openbsd.org 2003/04/01 10:10:23
808 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
809 [readconf.h serverloop.c sshconnect2.c]
810 rekeying bugfixes and automatic rekeying:
811 * both client and server rekey _automatically_
812 (a) after 2^31 packets, because after 2^32 packets
813 the sequence number for packets wraps
814 (b) after 2^(blocksize_in_bits/4) blocks
815 (see: draft-ietf-secsh-newmodes-00.txt)
816 (a) and (b) are _enabled_ by default, and only disabled for known
817 openssh versions, that don't support rekeying properly.
818 * client option 'RekeyLimit'
819 * do not reply to requests during rekeying
820 - markus@cvs.openbsd.org 2003/04/01 10:22:21
821 [clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
822 [readconf.h serverloop.c sshconnect2.c]
823 backout rekeying changes (for 3.6.1)
519bdfe8 824 - markus@cvs.openbsd.org 2003/04/01 10:31:26
825 [compat.c compat.h kex.c]
826 bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
827 tested by ho@ and myself
9dd240a3 828 - markus@cvs.openbsd.org 2003/04/01 10:56:46
829 [version.h]
830 3.6.1
ac01b518 831 - (djm) Crank spec file versions
b32453fe 832 - (djm) Release 3.6.1p1
a4e5acef 833
fd77a40f 83420030326
835 - (djm) OpenBSD CVS Sync
836 - deraadt@cvs.openbsd.org 2003/03/26 04:02:51
837 [sftp-server.c]
838 one last fix to the tree: race fix broke stuff; pr 3169;
839 srp@srparish.net, help from djm
840
8021857c 84120030325
842 - (djm) Fix getpeerid support for 64 bit BE systems. From
843 Arnd Bergmann <arndb@de.ibm.com>
844
cdb64c4d 84520030324
846 - (djm) OpenBSD CVS Sync
847 - markus@cvs.openbsd.org 2003/03/23 19:02:00
848 [monitor.c]
849 unbreak rekeying for privsep; ok millert@
850 - Release 3.6p1
62086365 851 - Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
852 Report from murple@murple.net, diagnosis from dtucker@zip.com.au
cdb64c4d 853
0b202697 854$Id$
This page took 0.429292 seconds and 5 git commands to generate.