+20050209
+ - (dtucker) OpenBSD CVS Sync
+ - dtucker@cvs.openbsd.org 2005/01/28 09:45:53
+ [ssh_config]
+ Make it clear that the example entries in ssh_config are only some of the
+ commonly-used options and refer the user to ssh_config(5) for more
+ details; ok djm@
+ - jmc@cvs.openbsd.org 2005/01/28 15:05:43
+ [ssh_config.5]
+ grammar;
+ - jmc@cvs.openbsd.org 2005/01/28 18:14:09
+ [ssh_config.5]
+ wording;
+ ok markus@
+
+20050208
+ - (dtucker) [regress/test-exec.sh] Bug #912: Set _POSIX2_VERSION for the
+ regress tests so newer versions of GNU head(1) behave themselves. Patch
+ by djm, so ok me.
+ - (dtucker) [openbsd-compat/port-aix.c] Silence compiler warnings.
+ - (dtucker) [audit.c audit.h auth.c auth1.c auth2.c loginrec.c monitor.c
+ monitor_wrap.c monitor_wrap.h session.c sshd.c]: Prepend all of the audit
+ defines and enums with SSH_ to prevent namespace collisions on some
+ platforms (eg AIX).
+
+20050204
+ - (dtucker) [monitor.c] Permit INVALID_USER audit events from slave too.
+ - (dtucker) [auth.c] Fix parens in audit log check.
+
+20050202
+ - (dtucker) [configure.ac openbsd-compat/realpath.c] Sync up with realpath
+ rev 1.11 from OpenBSD and make it use fchdir if available. ok djm@
+ - (dtucker) [auth.c loginrec.h openbsd-compat/{bsd-cray,port-aix}.{c,h}]
+ Make record_failed_login() call provide hostname rather than having the
+ implementations having to do lookups themselves. Only affects AIX and
+ UNICOS (the latter only uses the "user" parameter anyway). ok djm@
+ - (dtucker) [session.c sshd.c] Bug #445: Propogate KRB5CCNAME if set to child
+ the process. Since we also unset KRB5CCNAME at startup, if it's set after
+ authentication it must have been set by the platform's native auth system.
+ This was already done for AIX; this enables it for the general case.
+ - (dtucker) [auth.c canohost.c canohost.h configure.ac defines.h loginrec.c]
+ Bug #974: Teach sshd to write failed login records to btmp for failed auth
+ attempts (currently only for password, kbdint and C/R, only on Linux and
+ HP-UX), based on code from login.c from util-linux. With ashok_kovai at
+ hotmail.com, ok djm@
+ - (dtucker) [Makefile.in auth.c auth.h auth1.c auth2.c loginrec.c monitor.c
+ monitor.h monitor_wrap.c monitor_wrap.h session.c sshd.c] Bug #125:
+ (first stage) Add audit instrumentation to sshd, currently disabled by
+ default. with suggestions from and ok djm@
+
+20050201
+ - (dtucker) [log.c] Bug #973: force log_init() to open syslog, since on some
+ platforms syslog will revert to its default values. This may result in
+ messages from external libraries (eg libwrap) being sent to a different
+ facility.
+ - (dtucker) [sshd_config.5] Bug #701: remove warning about
+ keyboard-interactive since this is no longer the case.
+
+20050124
+ - (dtucker) OpenBSD CVS Sync
+ - otto@cvs.openbsd.org 2005/01/21 08:32:02
+ [auth-passwd.c sshd.c]
+ Warn in advance for password and account expiry; initialize loginmsg
+ buffer earlier and clear it after privsep fork. ok and help dtucker@
+ markus@
+ - dtucker@cvs.openbsd.org 2005/01/22 08:17:59
+ [auth.c]
+ Log source of connections denied by AllowUsers, DenyUsers, AllowGroups and
+ DenyGroups. bz #909, ok djm@
+ - djm@cvs.openbsd.org 2005/01/23 10:18:12
+ [cipher.c]
+ config option "Ciphers" should be case-sensitive; ok dtucker@
+ - dtucker@cvs.openbsd.org 2005/01/24 10:22:06
+ [scp.c sftp.c]
+ Have scp and sftp wait for the spawned ssh to exit before they exit
+ themselves. This prevents ssh from being unable to restore terminal
+ modes (not normally a problem on OpenBSD but common with -Portable
+ on POSIX platforms). From peak at argo.troja.mff.cuni.cz (bz#950);
+ ok djm@ markus@
+ - dtucker@cvs.openbsd.org 2005/01/24 10:29:06
+ [moduli]
+ Import new moduli; requested by deraadt@ a week ago
+ - dtucker@cvs.openbsd.org 2005/01/24 11:47:13
+ [auth-passwd.c]
+ #if -> #ifdef so builds without HAVE_LOGIN_CAP work too; ok djm@ otto@
+
20050120
- (dtucker) OpenBSD CVS Sync
- markus@cvs.openbsd.org 2004/12/23 17:35:48
- markus@cvs.openbsd.org 2004/12/23 17:38:07
[ssh-keygen.c]
leak; from mpech
+ - djm@cvs.openbsd.org 2004/12/23 23:11:00
+ [servconf.c servconf.h sshd.c sshd_config sshd_config.5]
+ bz #898: support AddressFamily in sshd_config. from
+ peak@argo.troja.mff.cuni.cz; ok deraadt@
+ - markus@cvs.openbsd.org 2005/01/05 08:51:32
+ [sshconnect.c]
+ remove dead code, log connect() failures with level error, ok djm@
+ - jmc@cvs.openbsd.org 2005/01/08 00:41:19
+ [sshd_config.5]
+ `login'(n) -> `log in'(v);
+ - dtucker@cvs.openbsd.org 2005/01/17 03:25:46
+ [moduli.c]
+ Correct spelling: SCHNOOR->SCHNORR; ok djm@
+ - dtucker@cvs.openbsd.org 2005/01/17 22:48:39
+ [sshd.c]
+ Make debugging output continue after reexec; ok djm@
+ - dtucker@cvs.openbsd.org 2005/01/19 13:11:47
+ [auth-bsdauth.c auth2-chall.c]
+ Have keyboard-interactive code call the drivers even for responses for
+ invalid logins. This allows the drivers themselves to decide how to
+ handle them and prevent leaking information where possible. Existing
+ behaviour for bsdauth is maintained by checking authctxt->valid in the
+ bsdauth driver. Note that any third-party kbdint drivers will now need
+ to be able to handle responses for invalid logins. ok markus@
+ - djm@cvs.openbsd.org 2004/12/22 02:13:19
+ [cipher-ctr.c cipher.c]
+ remove fallback AES support for old OpenSSL, as OpenBSD has had it for
+ many years now; ok deraadt@
+ (Id sync only: Portable will continue to support older OpenSSLs)
+ - (dtucker) [auth-pam.c] Bug #971: Prevent leaking information about user
+ existence via keyboard-interactive/pam, in conjunction with previous
+ auth2-chall.c change; with Colin Watson and djm.
+ - (dtucker) [loginrec.h] Bug #952: Increase size of username field to 128
+ bytes to prevent errors from login_init_entry() when the username is
+ exactly 64 bytes(!) long. From brhamon at cisco.com, ok djm@
+ - (dtucker) [auth-chall.c auth.h auth2-chall.c] Bug #936: Remove pam from
+ the list of available kbdint devices if UsePAM=no. ok djm@
20050118
- (dtucker) [INSTALL Makefile.in configure.ac survey.sh.in] Implement