+20010409
+ - (stevesk) use setresgid() for setegid() if needed
+ - (stevesk) configure.in: typo
+ - OpenBSD CVS Sync
+ - stevesk@cvs.openbsd.org 2001/04/08 16:01:36
+ [sshd.8]
+ document ListenAddress addr:port
+ - markus@cvs.openbsd.org 2001/04/08 13:03:00
+ [ssh-add.c]
+ init pointers with NULL, thanks to danimal@danimal.org
+ - markus@cvs.openbsd.org 2001/04/08 11:27:33
+ [clientloop.c]
+ leave_raw_mode if ssh2 "session" is closed
+ - markus@cvs.openbsd.org 2001/04/06 21:00:17
+ [auth-rh-rsa.c auth-rhosts.c auth-rsa.c auth2.c channels.c session.c
+ ssh.c sshconnect.c sshconnect.h uidswap.c uidswap.h]
+ do gid/groups-swap in addition to uid-swap, should help if /home/group
+ is chmod 750 + chgrp grp /home/group/, work be deraadt and me, thanks
+ to olar@openwall.com is comments. we had many requests for this.
+ - markus@cvs.openbsd.org 2001/04/07 08:55:18
+ [buffer.c channels.c channels.h readconf.c ssh.c]
+ allow the ssh client act as a SOCKS4 proxy (dynamic local
+ portforwarding). work by Dan Kaminsky <dankamin@cisco.com> and me.
+ thanks to Dan for this great patch: use 'ssh -D 1080 host' and make
+ netscape use localhost:1080 as a socks proxy.
+ - markus@cvs.openbsd.org 2001/04/08 11:24:33
+ [uidswap.c]
+ KNF
+
+20010408
+ - OpenBSD CVS Sync
+ - stevesk@cvs.openbsd.org 2001/04/06 22:12:47
+ [hostfile.c]
+ unused; typo in comment
+ - stevesk@cvs.openbsd.org 2001/04/06 22:25:25
+ [servconf.c]
+ in addition to:
+ ListenAddress host|ipv4_addr|ipv6_addr
+ permit:
+ ListenAddress [host|ipv4_addr|ipv6_addr]:port
+ ListenAddress host|ipv4_addr:port
+ sshd.8 updates coming. ok markus@
+
+20010407
+ - (bal) CVS ID Resync of version.h
+ - OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2001/04/05 23:39:20
+ [serverloop.c]
+ keep the ssh session even if there is no active channel.
+ this is more in line with the protocol spec and makes
+ ssh -N -L 1234:server:110 host
+ more useful.
+ based on discussion with <mats@mindbright.se> long time ago
+ and recent mail from <res@shore.net>
+ - deraadt@cvs.openbsd.org 2001/04/06 16:46:59
+ [scp.c]
+ remove trailing / from source paths; fixes pr#1756
+
+20010406
+ - (stevesk) logintest.c: fix for systems without __progname
+ - (stevesk) Makefile.in: log.o is in libssh.a
+ - OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2001/04/05 10:00:06
+ [compat.c]
+ 2.3.x does old GEX, too; report jakob@
+ - markus@cvs.openbsd.org 2001/04/05 10:39:03
+ [compress.c compress.h packet.c]
+ reset compress state per direction when rekeying.
+ - markus@cvs.openbsd.org 2001/04/05 10:39:48
+ [version.h]
+ temporary version 2.5.4 (supports rekeying).
+ this is not an official release.
+ - markus@cvs.openbsd.org 2001/04/05 10:42:57
+ [auth-chall.c authfd.c channels.c clientloop.c kex.c kexgex.c key.c
+ mac.c packet.c serverloop.c sftp-client.c sftp-client.h sftp-glob.c
+ sftp-glob.h sftp-int.c sftp-server.c sftp.c ssh-keygen.c sshconnect.c
+ sshconnect2.c sshd.c]
+ fix whitespace: unexpand + trailing spaces.
+ - markus@cvs.openbsd.org 2001/04/05 11:09:17
+ [clientloop.c compat.c compat.h]
+ add SSH_BUG_NOREKEY and detect broken (=all old) openssh versions.
+ - markus@cvs.openbsd.org 2001/04/05 15:45:43
+ [ssh.1]
+ ssh defaults to protocol v2; from quisar@quisar.ambre.net
+ - stevesk@cvs.openbsd.org 2001/04/05 15:48:18
+ [canohost.c canohost.h session.c]
+ move get_remote_name_or_ip() to canohost.[ch]; for portable. ok markus@
+ - markus@cvs.openbsd.org 2001/04/05 20:01:10
+ [clientloop.c]
+ for ~R print message if server does not support rekeying. (and fix ~R).
+ - markus@cvs.openbsd.org 2001/04/05 21:02:46
+ [buffer.c]
+ better error message
+ - markus@cvs.openbsd.org 2001/04/05 21:05:24
+ [clientloop.c ssh.c]
+ don't request a session for 'ssh -N', pointed out slade@shore.net
+
+20010405
+ - OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2001/04/04 09:48:35
+ [kex.c kex.h kexdh.c kexgex.c packet.c sshconnect2.c sshd.c]
+ don't sent multiple kexinit-requests.
+ send newkeys, block while waiting for newkeys.
+ fix comments.
+ - markus@cvs.openbsd.org 2001/04/04 14:34:58
+ [clientloop.c kex.c kex.h serverloop.c sshconnect2.c sshd.c]
+ enable server side rekeying + some rekey related clientup.
+ todo: we should not send any non-KEX messages after we send KEXINIT
+ - markus@cvs.openbsd.org 2001/04/04 15:50:55
+ [compat.c]
+ f-secure 1.3.2 does not handle IGNORE; from milliondl@ornl.gov
+ - markus@cvs.openbsd.org 2001/04/04 20:25:38
+ [channels.c channels.h clientloop.c kex.c kex.h serverloop.c
+ sshconnect2.c sshd.c]
+ more robust rekeying
+ don't send channel data after rekeying is started.
+ - markus@cvs.openbsd.org 2001/04/04 20:32:56
+ [auth2.c]
+ we don't care about missing bannerfiles; from tsoome@ut.ee, ok deraadt@
+ - markus@cvs.openbsd.org 2001/04/04 22:04:35
+ [kex.c kexgex.c serverloop.c]
+ parse full kexinit packet.
+ make server-side more robust, too.
+ - markus@cvs.openbsd.org 2001/04/04 23:09:18
+ [dh.c kex.c packet.c]
+ clear+free keys,iv for rekeying.
+ + fix DH mem leaks. ok niels@
+ - (stevesk) don't use vhangup() if defined(HAVE_DEV_PTMX); also removes
+ BROKEN_VHANGUP
+
+20010404
+ - OpenBSD CVS Sync
+ - deraadt@cvs.openbsd.org 2001/04/02 17:32:23
+ [ssh-agent.1]
+ grammar; slade@shore.net
+ - stevesk@cvs.openbsd.org 2001/04/03 13:56:11
+ [sftp-glob.c ssh-agent.c ssh-keygen.c]
+ free() -> xfree()
+ - markus@cvs.openbsd.org 2001/04/03 19:53:29
+ [dh.c dh.h kex.c kex.h sshconnect2.c sshd.c]
+ move kex to kex*.c, used dispatch_set() callbacks for kex. should
+ make rekeying easier.
+ - todd@cvs.openbsd.org 2001/04/03 21:19:38
+ [ssh_config]
+ id_rsa1/2 -> id_rsa; ok markus@
+ - markus@cvs.openbsd.org 2001/04/03 23:32:12
+ [kex.c kex.h packet.c sshconnect2.c sshd.c]
+ undo parts of recent my changes: main part of keyexchange does not
+ need dispatch-callbacks, since application data is delayed until
+ the keyexchange completes (if i understand the drafts correctly).
+ add some infrastructure for re-keying.
+ - markus@cvs.openbsd.org 2001/04/04 00:06:54
+ [clientloop.c sshconnect2.c]
+ enable client rekeying
+ (1) force rekeying with ~R, or
+ (2) if the server requests rekeying.
+ works against ssh-2.0.12/2.0.13/2.1.0/2.2.0/2.3.0/2.3.1/2.4.0
+ - (bal) Oops.. Missed including kexdh.c and kexgex.c in OpenBSD sync.
+
+20010403
+ - OpenBSD CVS Sync
+ - stevesk@cvs.openbsd.org 2001/04/02 14:15:31
+ [sshd.8]
+ typo; ok markus@
+ - stevesk@cvs.openbsd.org 2001/04/02 14:20:23
+ [readconf.c servconf.c]
+ correct comment; ok markus@
+ - (stevesk) nchan.c: remove ostate checks and add EINVAL to
+ shutdown(SHUT_RD) error() bypass for HP-UX.
+
+20010402
+ - (stevesk) log.c openbsd sync; missing newlines
+ - (stevesk) sshpty.h openbsd sync; PTY_H -> SSHPTY_H
+
+20010330
+ - (djm) Another openbsd-compat/glob.c sync
+ - (djm) OpenBSD CVS Sync
+ - provos@cvs.openbsd.org 2001/03/28 21:59:41
+ [kex.c kex.h sshconnect2.c sshd.c]
+ forgot to include min and max params in hash, okay markus@
+ - provos@cvs.openbsd.org 2001/03/28 22:04:57
+ [dh.c]
+ more sanity checking on primes file
+ - markus@cvs.openbsd.org 2001/03/28 22:43:31
+ [auth.h auth2.c auth2-chall.c]
+ check auth_root_allowed for kbd-int auth, too.
+ - provos@cvs.openbsd.org 2001/03/29 14:24:59
+ [sshconnect2.c]
+ use recommended defaults
+ - stevesk@cvs.openbsd.org 2001/03/29 21:06:21
+ [sshconnect2.c sshd.c]
+ need to set both STOC and CTOS for SSH_BUG_BIGENDIANAES; ok markus@
+ - markus@cvs.openbsd.org 2001/03/29 21:17:40
+ [dh.c dh.h kex.c kex.h]
+ prepare for rekeying: move DH code to dh.c
+ - djm@cvs.openbsd.org 2001/03/29 23:42:01
+ [sshd.c]
+ Protocol 1 key regeneration log => verbose, some KNF; ok markus@
+
+20010329
+ - OpenBSD CVS Sync
+ - stevesk@cvs.openbsd.org 2001/03/26 15:47:59
+ [ssh.1]
+ document more defaults; misc. cleanup. ok markus@
+ - markus@cvs.openbsd.org 2001/03/26 23:12:42
+ [authfile.c]
+ KNF
+ - markus@cvs.openbsd.org 2001/03/26 23:23:24
+ [rsa.c rsa.h ssh-agent.c ssh-keygen.c]
+ try to read private f-secure ssh v2 rsa keys.
+ - markus@cvs.openbsd.org 2001/03/27 10:34:08
+ [ssh-rsa.c sshd.c]
+ use EVP_get_digestbynid, reorder some calls and fix missing free.
+ - markus@cvs.openbsd.org 2001/03/27 10:57:00
+ [compat.c compat.h ssh-rsa.c]
+ some older systems use NID_md5 instead of NID_sha1 for RSASSA-PKCS1-v1_5
+ signatures in SSH protocol 2, ok djm@
+ - provos@cvs.openbsd.org 2001/03/27 17:46:50
+ [compat.c compat.h dh.c dh.h ssh2.h sshconnect2.c sshd.c version.h]
+ make dh group exchange more flexible, allow min and max group size,
+ okay markus@, deraadt@
+ - stevesk@cvs.openbsd.org 2001/03/28 19:56:23
+ [scp.c]
+ start to sync scp closer to rcp; ok markus@
+ - stevesk@cvs.openbsd.org 2001/03/28 20:04:38
+ [scp.c]
+ usage more like rcp and add missing -B to usage; ok markus@
+ - markus@cvs.openbsd.org 2001/03/28 20:50:45
+ [sshd.c]
+ call refuse() before close(); from olemx@ans.pl
+
+20010328
+ - (djm) Reorder tests and library inclusion for Krb4/AFS to try to
+ resolve linking conflicts with libcrypto. Report and suggested fix
+ from Holger Trapp <Holger.Trapp@Informatik.TU-Chemnitz.DE>
+ - (djm) Work around Solaris' broken struct dirent. Diagnosis and suggested
+ fix from Philippe Levan <levan@epix.net>
+ - (djm) Rework krbIV tests to get us closer to building on Redhat. Still
+ doesn't work because of conflicts between krbIV's and OpenSSL's des.h
+ - (djm) Sync openbsd-compat/glob.c
+
+20010327
+ - Attempt sync with sshlogin.c w/ OpenBSD (mainly CVS ID)
+ - Fix pointer issues in waitpid() and wait() replaces. Patch by Lutz
+ Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE>
+ - OpenBSD CVS Sync
+ - djm@cvs.openbsd.org 2001/03/25 00:01:34
+ [session.c]
+ shorten; ok markus@
+ - stevesk@cvs.openbsd.org 2001/03/25 13:16:11
+ [servconf.c servconf.h session.c sshd.8 sshd_config]
+ PrintLastLog option; from chip@valinux.com with some minor
+ changes by me. ok markus@
+ - markus@cvs.openbsd.org 2001/03/26 08:07:09
+ [authfile.c authfile.h ssh-add.c ssh-keygen.c ssh.c sshconnect.c
+ sshconnect.h sshconnect1.c sshconnect2.c sshd.c]
+ simpler key load/save interface, see authfile.h
+ - (djm) Reestablish PAM credentials (which can be supplemental group
+ memberships) after initgroups() blows them away. Report and suggested
+ fix from Nalin Dahyabhai <nalin@redhat.com>
+
+20010324
+ - Fixed permissions ssh-keyscan. Thanks to Christopher Linn <celinn@mtu.edu>.
+ - OpenBSD CVS Sync
+ - djm@cvs.openbsd.org 2001/03/23 11:04:07
+ [compat.c compat.h sshconnect2.c sshd.c]
+ Compat for OpenSSH with broken Rijndael/AES. ok markus@
+ - markus@cvs.openbsd.org 2001/03/23 12:02:49
+ [auth1.c]
+ authctxt is now passed to do_authenticated
+ - markus@cvs.openbsd.org 2001/03/23 13:10:57
+ [sftp-int.c]
+ fix put, upload to _absolute_ path, ok djm@
+ - markus@cvs.openbsd.org 2001/03/23 14:28:32
+ [session.c sshd.c]
+ ignore SIGPIPE, restore in child, fixes x11-fwd crashes; with djm@
+ - (djm) Pull out our own SIGPIPE hacks
+
+20010323
+ - OpenBSD CVS Sync
+ - deraadt@cvs.openbsd.org 2001/03/22 20:22:55
+ [sshd.c]
+ do not place linefeeds in buffer
+
+20010322
+ - (djm) Better AIX no tty fix, spotted by Gert Doering <gert@greenie.muc.de>
+ - (bal) version.c CVS ID resync
+ - (bal) auth-chall.c auth-passwd.c auth.h auth1.c auth2.c session.c CVS ID
+ resync
+ - (bal) scp.c CVS ID resync
+ - OpenBSD CVS Sync
+ - markus@cvs.openbsd.org 2001/03/20 19:10:16
+ [readconf.c]
+ default to SSH protocol version 2
+ - markus@cvs.openbsd.org 2001/03/20 19:21:21
+ [session.c]
+ remove unused arg
+ - markus@cvs.openbsd.org 2001/03/20 19:21:21
+ [session.c]
+ remove unused arg
+ - markus@cvs.openbsd.org 2001/03/21 11:43:45
+ [auth1.c auth2.c session.c session.h]
+ merge common ssh v1/2 code
+ - jakob@cvs.openbsd.org 2001/03/21 14:20:45
+ [ssh-keygen.c]
+ add -B flag to usage
+ - markus@cvs.openbsd.org 2001/03/21 21:06:30
+ [session.c]
+ missing init; from mib@unimelb.edu.au
+
+20010321
+ - (djm) Fix ttyname breakage for AIX and Tru64. Patch from Steve
+ VanDevender <stevev@darkwing.uoregon.edu>
+ - (djm) Make sure pam_retval is initialised on call to pam_end. Patch
+ from Solar Designer <solar@openwall.com>
+ - (djm) Don't loop forever when changing password via PAM. Patch
+ from Solar Designer <solar@openwall.com>
+ - (djm) Generate config files before build
+ - (djm) Correctly handle SIA and AIX when no tty present. Spotted and
+ suggested fix from Mike Battersby <mib@unimelb.edu.au>
+
20010320
- (bal) glob.c update to added GLOB_LIMITS (OpenBSD CVS).
- (bal) glob.c update to set gl_pathv to NULL (OpenBSD CVS).
- markus@cvs.openbsd.org 2001/03/19 17:07:23
[auth.c readconf.c]
undo /etc/shell and proto 2,1 change for openssh-2.5.2
+ - markus@cvs.openbsd.org 2001/03/19 17:12:10
+ [version.h]
+ version 2.5.2
+ - (djm) Update RPM spec version
+ - (djm) Release 2.5.2p1
+- tim@mindrot.org 2001/03/19 18:33:47 [defines.h]
+ change S_ISLNK macro to work for UnixWare 2.03
+- tim@mindrot.org 2001/03/19 20:45:11 [openbsd-compat/glob.c]
+ add get_arg_max(). Use sysconf() if ARG_MAX is not defined
20010319
- (djm) Seed PRNG at startup, rather than waiting for arc4random calls to