+20010305
+ - (bal) CVS ID touch up on sshpty.[ch] and sshlogin.[ch]
+ - (bal) OpenBSD CVS Sync
+ - deraadt@cvs.openbsd.org 2001/02/17 23:48:48
+ [sshd.8]
+ it's the OpenSSH one
+ - deraadt@cvs.openbsd.org 2001/02/21 07:37:04
+ [ssh-keyscan.c]
+ inline -> __inline__, and some indent
+ - deraadt@cvs.openbsd.org 2001/02/21 09:05:54
+ [authfile.c]
+ improve fd handling
+ - deraadt@cvs.openbsd.org 2001/02/21 09:12:56
+ [sftp-server.c]
+ careful with & and &&; markus ok
+ - stevesk@cvs.openbsd.org 2001/02/21 21:14:04
+ [ssh.c]
+ -i supports DSA identities now; ok markus@
+ - deraadt@cvs.openbsd.org 2001/02/22 04:29:37
+ [servconf.c]
+ grammar; slade@shore.net
+ - deraadt@cvs.openbsd.org 2001/02/22 06:43:55
+ [ssh-keygen.1 ssh-keygen.c]
+ document -d, and -t defaults to rsa1
+ - deraadt@cvs.openbsd.org 2001/02/22 08:03:51
+ [ssh-keygen.1 ssh-keygen.c]
+ bye bye -d
+ - deraadt@cvs.openbsd.org 2001/02/22 18:09:06
+ [sshd_config]
+ activate RSA 2 key
+ - markus@cvs.openbsd.org 2001/02/22 21:57:27
+ [ssh.1 sshd.8]
+ typos/grammar from matt@anzen.com
+ - markus@cvs.openbsd.org 2001/02/22 21:59:44
+ [auth.c auth.h auth1.c auth2.c misc.c misc.h ssh.c]
+ use pwcopy in ssh.c, too
+ - markus@cvs.openbsd.org 2001/02/23 15:34:53
+ [serverloop.c]
+ debug2->3
+ - markus@cvs.openbsd.org 2001/02/23 18:15:13
+ [sshd.c]
+ the random session key depends now on the session_key_int
+ sent by the 'attacker'
+ dig1 = md5(cookie|session_key_int);
+ dig2 = md5(dig1|cookie|session_key_int);
+ fake_session_key = dig1|dig2;
+ this change is caused by a mail from anakin@pobox.com
+ patch based on discussions with my german advisor niels@openbsd.org
+ - deraadt@cvs.openbsd.org 2001/02/24 10:37:55
+ [readconf.c]
+ look for id_rsa by default, before id_dsa
+ - deraadt@cvs.openbsd.org 2001/02/24 10:37:26
+ [sshd_config]
+ ssh2 rsa key before dsa key
+ - markus@cvs.openbsd.org 2001/02/27 10:35:27
+ [packet.c]
+ fix random padding
+
+20010304
+ - (bal) Remove make-ssh-known-hosts.1 since it's no longer valid.
+ - (bal) Updated contrib/README to remove 'make-ssh-known-hosts' and
+ give Mark Roth credit for mdoc2man.pl
+
+20010303
+ - (djm) Remove make-ssh-known-hosts.pl, ssh-keyscan is better.
+ - (djm) Document PAM ChallengeResponseAuthentication in sshd.8
+ - (djm) Disable and comment ChallengeResponseAuthentication in sshd_config
+ - (djm) Allow PRNGd entropy collection from localhost TCP socket. Replace
+ "--with-egd-pool" configure option with "--with-prngd-socket" and
+ "--with-prngd-port" options. Debugged and improved by Lutz Jaenicke
+ <Lutz.Jaenicke@aet.TU-Cottbus.DE>
+
+20010301
+ - (djm) Properly add -lcrypt if needed.
+ - (djm) Force standard PAM conversation function in a few more places.
+ Patch from Redhat 2.5.1p1-2 RPM, probably Nalin Dahyabhai
+ <nalin@redhat.com>
+ - (djm) Cygwin needs pw->pw_gecos copied too. Patch from Corinna Vinschen
+ <vinschen@redhat.com>
+ - (djm) Released 2.5.1p2
+
+20010228
+ - (djm) Detect endianness in configure and use it in rijndael.c. Fixes
+ "Bad packet length" bugs.
+ - (djm) Fully revert PAM session patch (again). All PAM session init is
+ now done before the final fork().
+ - (djm) EGD detection patch from Tim Rice <tim@multitalents.net>
+ - (djm) Remove /tmp from EGD socket search list
+
+20010227
+ - (bal) Applied shutdown() patch for sftp.c by Corinna Vinschen
+ <vinschen@redhat.com>
+ - (bal) OpenBSD Sync
+ - markus@cvs.openbsd.org 2001/02/23 15:37:45
+ [session.c]
+ handle SSH_PROTOFLAG_SCREEN_NUMBER for buggy clients
+ - (bal) sshd.init support for all Redhat release. Patch by Jim Knoble
+ <jmknoble@jmknoble.cx>
+ - (djm) Fix up POSIX saved uid support. Report from Mark Miller
+ <markm@swoon.net>
+ - (djm) Search for -lcrypt on FreeBSD too
+ - (djm) fatal() on OpenSSL version mismatch
+ - (djm) Move PAM init to after fork for non-Solaris derived PAMs
+ - (djm) Warning fix on entropy.c saved uid stuff. Patch from Mark Miller
+ <markm@swoon.net>
+ - (djm) Fix PAM fix
+ - (djm) Remove 'noreplace' flag from sshd_config in RPM spec files. This
+ change is being made as 2.5.x configfiles are not back-compatible with
+ 2.3.x.
+ - (djm) Avoid warnings for missing broken IP_TOS. Patch from Mark Miller
+ <markm@swoon.net>
+ - (djm) Open Server 5 doesn't need BROKEN_SAVED_UIDS. Patch from Tim Rice
+ <tim@multitalents.net>
+ - (djm) Avoid multiple definition of _PATH_LS. Patch from Tim Rice
+ <tim@multitalents.net>
+
+20010226
+ - (bal) Fixed bsd-snprinf.c so it now honors 'BROKEN_SNPRINTF' again.
+ - (djm) Some systems (SCO3, NeXT) have weird saved uid semantics.
+ Based on patch from Tim Rice <tim@multitalents.net>
+
+20010225
+ - (djm) Use %{_libexecdir} rather than hardcoded path in RPM specfile
+ Patch from Adrian Ho <lexfiend@usa.net>
+ - (bal) Replace 'unsigned long long' to 'u_int64_t' since not every
+ platform defines u_int64_t as being that.
+
+20010224
+ - (bal) Missed part of the UNIX sockets patch. Patch by Corinna
+ Vinschen <vinschen@redhat.com>
+ - (bal) Reorder where 'strftime' is detected to resolve linking
+ issues on SCO. Patch by Tim Rice <tim@multitalents.net>
+
+20010224
+ - (bal) pam_stack fix to correctly detect between RH7 and older RHs.
+ Patch by Pekka Savola <pekkas@netcore.fi>
+ - (bal) Renamed sigaction.[ch] to sigact.[ch]. Causes problems with
+ some platforms.
+ - (bal) Generalize lack of UNIX sockets since this also effects Cray
+ not just Cygwin. Based on patch by Wendy Palm <wendyp@cray.com>
+
+20010223
+ - (bal) Fix --define rh7 in openssh.spec file. Patch by Steve Tell
+ <tell@telltronics.org>
+ - (bal) Patch to force OpenSSH rpm to require the same version of OpenSSL
+ that it was compiled against. Patch by Pekka Savola <pekkas@netcore.fi>
+ - (bal) Double -I for OpenSSL on SCO. Patch by Tim Rice
+ <tim@multitalents.net>
+
+20010222
+ - (bal) Corrected SCO luid patch by svaughan <svaughan@asterion.com>
+ - (bal) Added mdoc2man.pl from Mark Roth <roth@feep.net>
+ - (bal) Removed reference to liblogin from contrib/README. It was
+ integrated into OpenSSH a long while ago.
+ - (stevesk) remove erroneous #ifdef sgi code.
+ Michael Stone <mstone@cs.loyola.edu>
+
+20010221
+ - (bal) Removed -L/usr/ucblib -R/usr/ucblib for Solaris platform.
+ - (bal) Fixed OpenSSL rework to use $saved_*. Patch by Tim Rice
+ <tim@multitalents.net>
+ - (bal) Reverted out of 2001/02/15 patch by djm below because it
+ breaks Solaris.
+ - (djm) Move PAM session setup back to before setuid to user.
+ fixes problems on Solaris-drived PAMs.
+ - (stevesk) session.c: back out to where we were before:
+ - (djm) Move PAM session initialisation until after fork in sshd. Patch
+ from Nalin Dahyabhai <nalin@redhat.com>
+
+20010220
+ - (bal) Fix mixed up params to memmove() from Jan 5th in setenv.c and
+ getcwd.c.
+ - (bal) OpenBSD CVS Sync:
+ - deraadt@cvs.openbsd.org 2001/02/19 23:09:05
+ [sshd.c]
+ clarify message to make it not mention "ident"
+
+20010219
+ - (bal) Markus' blessing to rename login.[ch] -> sshlogin.[ch] and
+ pty.[ch] -> sshpty.[ch]
+ - (djm) Rework search for OpenSSL location. Skip directories which don't
+ exist, don't add -L$ssldir/lib if it doesn't exist. Should help SCO
+ with its limit of 6 -L options.
+ - OpenBSD CVS Sync:
+ - reinhard@cvs.openbsd.org 2001/02/17 08:24:40
+ [sftp.1]
+ typo
+ - deraadt@cvs.openbsd.org 2001/02/17 16:28:58
+ [ssh.c]
+ cleanup -V output; noted by millert
+ - deraadt@cvs.openbsd.org 2001/02/17 16:48:48
+ [sshd.8]
+ it's the OpenSSH one
+ - markus@cvs.openbsd.org 2001/02/18 11:33:54
+ [dispatch.c]
+ typo, SSH2_MSG_KEXINIT, from aspa@kronodoc.fi
+ - markus@cvs.openbsd.org 2001/02/19 02:53:32
+ [compat.c compat.h serverloop.c]
+ ssh-1.2.{18-22} has broken handling of ignore messages; report from
+ itojun@
+ - markus@cvs.openbsd.org 2001/02/19 03:35:23
+ [version.h]
+ OpenSSH_2.5.1 adds bug compat with 1.2.{18-22}
+ - deraadt@cvs.openbsd.org 2001/02/19 03:36:25
+ [scp.c]
+ np is changed by recursion; vinschen@redhat.com
+ - Update versions in RPM spec files
+ - Release 2.5.1p1
+
+20010218
+ - (bal) Patch for fix FCHMOD reference in ftp-client.c by Tim Rice
+ <tim@multitalents.net>
+ - (Bal) Patch for lack of RA_RESTART in misc.c for mysignal by
+ stevesk
+ - (djm) Fix my breaking of cygwin builds, Patch from Corinna Vinschen
+ <vinschen@redhat.com> and myself.
+ - (djm) Close listen_sock on bind() failures. Patch from Arkadiusz
+ Miskiewicz <misiek@pld.ORG.PL>
+ - (djm) Robustify EGD/PRNGd code in face of socket closures. Patch from
+ Todd C. Miller <Todd.Miller@courtesan.com>
+ - (djm) Use ttyname() to determine name of tty returned by openpty()
+ rather then risking overflow. Patch from Marek Michalkiewicz
+ <marekm@amelek.gda.pl>
+ - (djm) Swapped tests for no_libsocket and no_libnsl in configure.in.
+ Patch from Marek Michalkiewicz <marekm@amelek.gda.pl>
+ - (djm) Doc fixes from Pekka Savola <pekkas@netcore.fi>
+ - (djm) Use SA_INTERRUPT along SA_RESTART if present (equivalent for
+ SunOS)
+ - (djm) SCO needs librpc for libwrap. Patch from Tim Rice
+ <tim@multitalents.net>
+ - (stevesk) misc.c: cpp rework of SA_(INTERRUPT|RESTART) handling.
+ - (stevesk) scp.c: use mysignal() for updateprogressmeter() handler.
+ - (djm) SA_INTERRUPT is the converse of SA_RESTART, apply it only for
+ SIGALRM.
+ - (djm) Move entropy.c over to mysignal()
+ - (djm) SunOS 4.x also needs to define HAVE_BOGUS_SYS_QUEUE_H as it has
+ a <sys/queue.h> that lacks the TAILQ_* macros. Patch from Todd C.
+ Miller <Todd.Miller@courtesan.com>
+ - (djm) Update RPM spec files for 2.5.0p1
+ - (djm) Merge BSD_AUTH support from Markus Friedl and David J. MacKenzie
+ enable with --with-bsd-auth.
+ - (stevesk) entropy.c: typo; should be SIGPIPE
+
+20010217
+ - (bal) OpenBSD Sync:
+ - markus@cvs.openbsd.org 2001/02/16 13:38:18
+ [channel.c]
+ remove debug
+ - markus@cvs.openbsd.org 2001/02/16 14:03:43
+ [session.c]
+ proper payload-length check for x11 w/o screen-number
+
+20010216
+ - (bal) added '--with-prce' to allow overriding of system regex when
+ required (tested by David Dulek <ddulek@fastenal.com>)
+ - (bal) Added DG/UX case and set that they have a broken IPTOS.
+ - (djm) Mini-configure reorder patch from Tim Rice <tim@multitalents.net>
+ Fixes linking on SCO.
+ - (djm) Make gnome-ssh-askpass handle multi-line prompts. Patch from
+ Nalin Dahyabhai <nalin@redhat.com>
+ - (djm) BSD license for gnome-ssh-askpass (was X11)
+ - (djm) KNF on gnome-ssh-askpass
+ - (djm) USE_PIPES for a few more sysv platforms
+ - (djm) Cleanup configure.in a little
+ - (djm) Ask users to check config.log when we can't find necessary libs
+ - (djm) Set "login ID" on systems with setluid. Only enabled for SCO
+ OpenServer for now. Based on patch from svaughan <svaughan@asterion.com>
+ - (djm) OpenBSD CVS:
+ - markus@cvs.openbsd.org 2001/02/15 16:19:59
+ [channels.c channels.h serverloop.c sshconnect.c sshconnect.h]
+ [sshconnect1.c sshconnect2.c]
+ genericize password padding function for SSH1 and SSH2.
+ add stylized echo to 2, too.
+ - (djm) Add roundup() macro to defines.h
+ - (stevesk) set SA_RESTART flag in mysignal() for SIGCHLD;
+ needed on Unixware 2.x.
+
20010215
- (djm) Move PAM session setup back to before setuid to user. Fixes
problems on Solaris-derived PAMs.
ssh-keygen.c sshd.8]
PermitRootLogin={yes,without-password,forced-commands-only,no}
(before this change, root could login even if PermitRootLogin==no)
- - deraadt@cvs.openbsd.org 2001/02/12 22:56:09
+ - deraadt@cvs.openbsd.org 2001/02/12 22:56:09
[clientloop.c packet.c ssh-keyscan.c]
deal with EAGAIN/EINTR selects which were skipped
- - markus@cvs.openssh.org 2001/02/13 22:49:40
- [auth1.c auth2.c]
- setproctitle(user) only if getpwnam succeeds
- - markus@cvs.openbsd.org 2001/02/12 23:26:20
- [sshd.c]
- missing memset; from solar@openwall.com
- - stevesk@cvs.openbsd.org 2001/02/12 20:53:33
- [sftp-int.c]
- lumask now works with 1 numeric arg; ok markus@, djm@
- - djm@cvs.openbsd.org 2001/02/14 9:46:03
- [sftp-client.c sftp-int.c sftp.1]
- Fix and document 'preserve modes & times' option ('-p' flag in sftp);
- ok markus@
+ - markus@cvs.openssh.org 2001/02/13 22:49:40
+ [auth1.c auth2.c]
+ setproctitle(user) only if getpwnam succeeds
+ - markus@cvs.openbsd.org 2001/02/12 23:26:20
+ [sshd.c]
+ missing memset; from solar@openwall.com
+ - stevesk@cvs.openbsd.org 2001/02/12 20:53:33
+ [sftp-int.c]
+ lumask now works with 1 numeric arg; ok markus@, djm@
+ - djm@cvs.openbsd.org 2001/02/14 9:46:03
+ [sftp-client.c sftp-int.c sftp.1]
+ Fix and document 'preserve modes & times' option ('-p' flag in sftp);
+ ok markus@
+ - (bal) replaced PATH_MAX in sftp-int.c w/ MAXPATHLEN.
+ - (djm) Move to Jim's 1.2.0 X11 askpass program
+ - (stevesk) OpenBSD sync:
+ - deraadt@cvs.openbsd.org 2001/02/15 01:38:04
+ [serverloop.c]
+ indent
20010214
- (djm) Don't try to close PAM session or delete credentials if the