]> andersk Git - openssh.git/commitdiff
- (djm) Add --with-privsep-path configure option
authordjm <djm>
Mon, 13 May 2002 03:15:42 +0000 (03:15 +0000)
committerdjm <djm>
Mon, 13 May 2002 03:15:42 +0000 (03:15 +0000)
ChangeLog
Makefile.in
acconfig.h
configure.ac
pathnames.h

index 5db64405e8654a50e104aaefc89f6a6ee1c1315a..1f976b76911163519b6d9fbdaaac112528ec8a46 100644 (file)
--- a/ChangeLog
+++ b/ChangeLog
@@ -2,6 +2,7 @@
  - (djm) Add --with-superuser-path=xxx configure option to specify what $PATH
    the superuser receives.
  - (djm) Bug #231: UsePrivilegeSeparation turns off Banner.
+ - (djm) Add --with-privsep-path configure option
 
 20020511
  - (tim) [configure.ac] applied a rework of djm's OpenSSL search cleanup patch.
index e3f2506efc33ec04f74d622e4f0b8241ae2af5c8..e32381e4340e556799a1d957079a0624b5ab2022 100644 (file)
@@ -3,6 +3,8 @@
 # uncomment if you run a non bourne compatable shell. Ie. csh
 #SHELL = @SH@
 
+AUTORECONF=autoreconf
+
 prefix=@prefix@
 exec_prefix=@exec_prefix@
 bindir=@bindir@
@@ -21,12 +23,14 @@ VPATH=@srcdir@
 SSH_PROGRAM=@bindir@/ssh
 ASKPASS_PROGRAM=$(libexecdir)/ssh-askpass
 SFTP_SERVER=$(libexecdir)/sftp-server
+PRIVSEP_PATH=@PRIVSEP_PATH@
 
 PATHS= -DSSHDIR=\"$(sysconfdir)\" \
        -D_PATH_SSH_PROGRAM=\"$(SSH_PROGRAM)\" \
        -D_PATH_SSH_ASKPASS_DEFAULT=\"$(ASKPASS_PROGRAM)\" \
        -D_PATH_SFTP_SERVER=\"$(SFTP_SERVER)\" \
        -D_PATH_SSH_PIDDIR=\"$(piddir)\" \
+       -D_PATH_PRIVSEP_CHROOT_DIR=\"$(PRIVSEP_PATH)\"
        -DSSH_RAND_HELPER=\"$(libexecdir)/ssh-rand-helper\"
 
 CC=@CC@
@@ -80,6 +84,7 @@ PATHSUBS      = \
        -D/etc/ssh/moduli=$(sysconfdir)/moduli \
        -D/etc/ssh/sshrc=$(sysconfdir)/sshrc \
        -D/usr/X11R6/bin/xauth=$(XAUTH_PATH) \
+       -D/var/empty=$(PRIVSEP_PATH) \
        -D/usr/bin:/bin:/usr/sbin:/sbin=@user_path@
 
 FIXPATHSCMD    = $(PERL) $(srcdir)/fixpaths $(PATHSUBS)
@@ -184,7 +189,7 @@ catman-do:
        done
 
 distprep: catman-do
-       autoreconf
+       $(AUTORECONF)
        (cd scard && $(MAKE) -f Makefile.in distprep)
 
 install: $(CONFIGFILES) $(MANPAGES) $(TARGETS) install-files host-key
index 5f49965310049cacd1b5bd67cca9fba21b6fb25f..afc3db91b7cd287d8ccbf6d4e96de1a45586bf18 100644 (file)
 /* Define if you want a different $PATH for the superuser */
 #undef SUPERUSER_PATH
 
+/* Path that unprivileged child will chroot() to in privep mode */
+#undef PRIVSEP_PATH
+
 @BOTTOM@
 
 /* ******************* Shouldn't need to edit below this line ************** */
index 6f07b7e365bb907a242b14b84105b484c0102e1d..a615fc31abc763050d8994e758f208e5fd1ff596 100644 (file)
@@ -1792,6 +1792,17 @@ AC_ARG_WITH(rsh,
        ]
 )
 
+PRIVSEP_PATH=/var/empty
+AC_ARG_WITH(privsep-path,
+       [  --with-privsep-path=xxx Path for privilege seperation chroot ],
+       [
+               if test "x$withval" != "$no" ; then
+                       PRIVSEP_PATH=$withval
+               fi
+       ]
+)
+AC_SUBST(PRIVSEP_PATH)
+
 AC_ARG_WITH(xauth,
        [  --with-xauth=PATH       Specify path to xauth program ],
        [
@@ -2363,41 +2374,43 @@ D=`eval echo ${sysconfdir}` ; D=`eval echo ${D}`
 E=`eval echo ${libexecdir}/ssh-askpass` ; E=`eval echo ${E}`
 F=`eval echo ${mandir}/${mansubdir}X` ; F=`eval echo ${F}`
 G=`eval echo ${piddir}` ; G=`eval echo ${G}`
-H=`eval echo ${user_path}` ; H=`eval echo ${H}`
-I=`eval echo ${superuser_path}` ; I=`eval echo ${I}`
+H=`eval echo ${PRIVSEP_PATH}` ; H=`eval echo ${H}`
+I=`eval echo ${user_path}` ; I=`eval echo ${I}`
+J=`eval echo ${superuser_path}` ; J=`eval echo ${J}`
 
 echo ""
 echo "OpenSSH has been configured with the following options:"
-echo "                 User binaries: $B"
-echo "               System binaries: $C"
-echo "           Configuration files: $D"
-echo "               Askpass program: $E"
-echo "                  Manual pages: $F"
-echo "                      PID file: $G"
+echo "                     User binaries: $B"
+echo "                   System binaries: $C"
+echo "               Configuration files: $D"
+echo "                   Askpass program: $E"
+echo "                      Manual pages: $F"
+echo "                          PID file: $G"
+echo "  Privilege separation chroot path: $H"
 if test "$USES_LOGIN_CONF" = "yes" ; then
-echo "        At runtime, sshd will use the path defined in /etc/login.conf"
+echo "   At runtime, sshd will use the path defined in /etc/login.conf"
 else
-echo "        sshd default user PATH: $H"
+echo "            sshd default user PATH: $I"
 fi
 if test ! -z "$superuser_path" ; then
-echo "      sshd superuser user PATH: $I"
-fi
-echo "                Manpage format: $MANTYPE"
-echo "                   PAM support: ${PAM_MSG}"
-echo "            KerberosIV support: $KRB4_MSG"
-echo "             KerberosV support: $KRB5_MSG"
-echo "             Smartcard support: $SCARD_MSG"
-echo "                   AFS support: $AFS_MSG"
-echo "                 S/KEY support: $SKEY_MSG"
-echo "          TCP Wrappers support: $TCPW_MSG"
-echo "          MD5 password support: $MD5_MSG"
-echo "   IP address in \$DISPLAY hack: $DISPLAY_HACK_MSG"
-echo "      Use IPv4 by default hack: $IPV4_HACK_MSG"
-echo "       Translate v4 in v6 hack: $IPV4_IN6_HACK_MSG"
-echo "              BSD Auth support: $BSD_AUTH_MSG"
-echo "          Random number source: $RAND_MSG"
+echo "          sshd superuser user PATH: $J"
+fi
+echo "                    Manpage format: $MANTYPE"
+echo "                       PAM support: ${PAM_MSG}"
+echo "                KerberosIV support: $KRB4_MSG"
+echo "                 KerberosV support: $KRB5_MSG"
+echo "                 Smartcard support: $SCARD_MSG"
+echo "                       AFS support: $AFS_MSG"
+echo "                     S/KEY support: $SKEY_MSG"
+echo "              TCP Wrappers support: $TCPW_MSG"
+echo "              MD5 password support: $MD5_MSG"
+echo "      IP address in \$DISPLAY hack: $DISPLAY_HACK_MSG"
+echo "          Use IPv4 by default hack: $IPV4_HACK_MSG"
+echo "           Translate v4 in v6 hack: $IPV4_IN6_HACK_MSG"
+echo "                  BSD Auth support: $BSD_AUTH_MSG"
+echo "              Random number source: $RAND_MSG"
 if test ! -z "$USE_RAND_HELPER" ; then
-       echo " ssh-rand-helper collects from: $RAND_HELPER_MSG"
+echo "     ssh-rand-helper collects from: $RAND_HELPER_MSG"
 fi
 
 echo ""
index 943830c0891cfa3e774d56e4d8716a33df3c4ca5..691293c33d999efcd875bb39a11f008ca6aa4f72 100644 (file)
 #endif
 
 /* chroot directory for unprivileged user when UsePrivilegeSeparation=yes */
+#ifndef _PATH_PRIVSEP_CHROOT_DIR
 #define _PATH_PRIVSEP_CHROOT_DIR       "/var/empty"
+#endif
+
 #ifndef _PATH_LS
 #define _PATH_LS                       "ls"
 #endif
This page took 0.607875 seconds and 5 git commands to generate.