]> andersk Git - openssh.git/log
openssh.git
15 years ago - (djm) Release openssh-5.2p1 V_5_2_P1
djm [Mon, 23 Feb 2009 00:12:29 +0000 (00:12 +0000)] 
 - (djm) Release openssh-5.2p1

15 years ago - (djm) [README] update for 5.2
djm [Mon, 23 Feb 2009 00:11:57 +0000 (00:11 +0000)] 
 - (djm) [README] update for 5.2

15 years agotrim
djm [Mon, 23 Feb 2009 00:11:12 +0000 (00:11 +0000)] 
trim

15 years ago - djm@cvs.openbsd.org 2009/02/23 00:06:15
djm [Mon, 23 Feb 2009 00:09:25 +0000 (00:09 +0000)] 
   - djm@cvs.openbsd.org 2009/02/23 00:06:15
     [version.h]
     openssh-5.2

15 years ago - djm@cvs.openbsd.org 2009/02/22 23:59:25
djm [Mon, 23 Feb 2009 00:00:24 +0000 (00:00 +0000)] 
   - djm@cvs.openbsd.org 2009/02/22 23:59:25
     [sshd_config.5]
     missing period

15 years ago - djm@cvs.openbsd.org 2009/02/22 23:50:57
djm [Sun, 22 Feb 2009 23:53:58 +0000 (23:53 +0000)] 
   - djm@cvs.openbsd.org 2009/02/22 23:50:57
     [ssh_config.5 sshd_config.5]
     don't advertise experimental options

15 years ago - (djm) OpenBSD CVS Sync
djm [Sat, 21 Feb 2009 21:47:02 +0000 (21:47 +0000)] 
 - (djm) OpenBSD CVS Sync
   - tobias@cvs.openbsd.org 2009/02/21 19:32:04
     [misc.c sftp-server-main.c ssh-keygen.c]
     Added missing newlines in error messages.
     ok dtucker

15 years ago - (djm) [contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
djm [Sat, 21 Feb 2009 07:03:04 +0000 (07:03 +0000)] 
 - (djm) [contrib/caldera/openssh.spec contrib/redhat/openssh.spec]
   [contrib/suse/openssh.spec] Prepare for 5.2p1

15 years ago - djm@cvs.openbsd.org 2009/02/18 04:31:21
djm [Sat, 21 Feb 2009 01:45:18 +0000 (01:45 +0000)] 
   - djm@cvs.openbsd.org 2009/02/18 04:31:21
     [schnorr.c]
     signature should hash over the entire group, not just the generator
     (this is still disabled code)

15 years ago - djm@cvs.openbsd.org 2009/02/17 01:28:32
djm [Sat, 21 Feb 2009 01:45:02 +0000 (01:45 +0000)] 
   - djm@cvs.openbsd.org 2009/02/17 01:28:32
     [ssh_config]
     sync with revised default ciphers; pointed out by dkrause@

15 years ago - (djm) [configure.ac] support GNU/kFreeBSD and GNU/kOpensolaris
djm [Mon, 16 Feb 2009 04:37:03 +0000 (04:37 +0000)] 
 - (djm) [configure.ac] support GNU/kFreeBSD and GNU/kOpensolaris
   systems; patch from Aurelien Jarno via rmh AT aybabtu.com

15 years ago - (djm) [regress/conch-ciphers.sh regress/putty-ciphers.sh]
djm [Mon, 16 Feb 2009 04:21:39 +0000 (04:21 +0000)] 
 - (djm) [regress/conch-ciphers.sh regress/putty-ciphers.sh]
   [regress/putty-kex.sh regress/putty-transfer.sh] Downgrade disabled
   interop tests from FATAL error to a warning. Allows some interop
   tests to proceed if others are missing necessary prerequisites.

15 years ago - djm@cvs.openbsd.org 2009/02/14 06:35:49
djm [Sat, 14 Feb 2009 07:00:52 +0000 (07:00 +0000)] 
   - djm@cvs.openbsd.org 2009/02/14 06:35:49
     [PROTOCOL]
     mention that eow and no-more-sessions extensions are sent only to
     OpenSSH peers

15 years ago - markus@cvs.openbsd.org 2009/02/13 11:50:21
djm [Sat, 14 Feb 2009 05:35:01 +0000 (05:35 +0000)] 
   - markus@cvs.openbsd.org 2009/02/13 11:50:21
     [packet.c]
     check for enc !=NULL in packet_start_discard

15 years ago - jmc@cvs.openbsd.org 2009/02/12 07:34:20
djm [Sat, 14 Feb 2009 05:34:39 +0000 (05:34 +0000)] 
   - jmc@cvs.openbsd.org 2009/02/12 07:34:20
     [ssh_config.5]
     kill trailing whitespace;

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:46:17
djm [Sat, 14 Feb 2009 05:34:21 +0000 (05:34 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:46:17
     [ssh_config.5]
     document RemoteForward usage with 0 listen port

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:44:25
djm [Sat, 14 Feb 2009 05:34:05 +0000 (05:34 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:44:25
     [ssh.1]
     consistency: Dq => Ql

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:42:09
djm [Sat, 14 Feb 2009 05:33:49 +0000 (05:33 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:42:09
     [ssh.1]
     document -R0:... usage

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:26:22
djm [Sat, 14 Feb 2009 05:33:31 +0000 (05:33 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:26:22
     [monitor.c]
     some paranoia: check that the serialised key is really KEY_RSA before
     diddling its internals

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:16:01
djm [Sat, 14 Feb 2009 05:33:09 +0000 (05:33 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:16:01
     [serverloop.c]
     tighten check for -R0:... forwarding: only allow dynamic allocation
     if want_reply is set in the packet

15 years ago - djm@cvs.openbsd.org 2009/02/12 03:00:56
djm [Sat, 14 Feb 2009 05:28:21 +0000 (05:28 +0000)] 
   - djm@cvs.openbsd.org 2009/02/12 03:00:56
     [canohost.c canohost.h channels.c channels.h clientloop.c readconf.c]
     [readconf.h serverloop.c ssh.c]
     support remote port forwarding with a zero listen port (-R0:...) to
     dyamically allocate a listen port at runtime (this is actually
     specified in rfc4254); bz#1003 ok markus@

15 years ago - dtucker@cvs.openbsd.org 2009/02/02 11:15:14
djm [Sat, 14 Feb 2009 05:26:19 +0000 (05:26 +0000)] 
   - dtucker@cvs.openbsd.org 2009/02/02 11:15:14
     [sftp.c]
     Initialize a few variables to prevent spurious "may be used
     uninitialized" warnings from newer gcc's.  ok djm@

15 years ago - (djm) [configure.ac loginrec.c] bz#1421: fix lastlog support for OSX.
djm [Thu, 12 Feb 2009 02:12:21 +0000 (02:12 +0000)] 
 - (djm) [configure.ac loginrec.c] bz#1421: fix lastlog support for OSX.
   OSX provides a getlastlogxbyname function that automates the reading of
   a lastlog file. Also, the pututxline function will update lastlog so
   there is no need for loginrec.c to do it explicitly. Collapse some
   overly verbose code while I'm in there.

15 years ago - (djm) [sshpty.c] bz#1419: OSX uses cloning ptys that automagically
djm [Thu, 12 Feb 2009 01:19:20 +0000 (01:19 +0000)] 
 - (djm) [sshpty.c] bz#1419: OSX uses cloning ptys that automagically
   set ownership and modes, so avoid explicitly setting them

15 years ago - (dtucker) [defines.h sshconnect.c] INET6_ADDRSTRLEN is now needed in
dtucker [Sun, 1 Feb 2009 11:19:54 +0000 (11:19 +0000)] 
 - (dtucker) [defines.h sshconnect.c] INET6_ADDRSTRLEN is now needed in
   channels.c too, so move the definition for non-IP6 platforms to defines.h
   where it can be shared.

15 years ago - (tim) [contrib/cygwin/ssh-host-config] Whitespace cleanup. No code changes.
tim [Thu, 29 Jan 2009 20:40:30 +0000 (20:40 +0000)] 
 - (tim) [contrib/cygwin/ssh-host-config] Whitespace cleanup. No code changes.

15 years ago - (tim) [contrib/cygwin/ssh-host-config] Patch from Corinna Vinschen.
tim [Thu, 29 Jan 2009 20:30:01 +0000 (20:30 +0000)] 
 - (tim) [contrib/cygwin/ssh-host-config] Patch from Corinna Vinschen.
   If the CYGWIN environment variable is empty, the installer script
   should not install the service with an empty CYGWIN variable, but
   rather without setting CYGWNI entirely.

15 years ago - (tim) [contrib/cygwin/ssh-host-config] Patch from Corinna Vinschen.
tim [Wed, 28 Jan 2009 20:50:04 +0000 (20:50 +0000)] 
 - (tim) [contrib/cygwin/ssh-host-config] Patch from Corinna Vinschen.
   Changes to work on Cygwin 1.5.x as well as on the new Cygwin 1.7.x.
   The information given for the setting of the CYGWIN environment variable
   is wrong for both releases so I just removed it, together with the
   unnecessary (Cygwin 1.5.x) or wrong (Cygwin 1.7.x) default setting.

15 years ago - markus@cvs.openbsd.org 2009/01/26 09:58:15
djm [Wed, 28 Jan 2009 05:38:41 +0000 (05:38 +0000)] 
   - markus@cvs.openbsd.org 2009/01/26 09:58:15
     [cipher.c cipher.h packet.c]
     Work around the CPNI-957037 Plaintext Recovery Attack by always
     reading 256K of data on packet size or HMAC errors (in CBC mode only).
     Help, feedback and ok djm@
     Feedback from Martin Albrecht and Paterson Kenny

15 years ago - naddy@cvs.openbsd.org 2009/01/24 17:10:22
djm [Wed, 28 Jan 2009 05:34:00 +0000 (05:34 +0000)] 
   - naddy@cvs.openbsd.org 2009/01/24 17:10:22
     [ssh_config.5 sshd_config.5]
     sync list of preferred ciphers; ok djm@

15 years ago - djm@cvs.openbsd.org 2009/01/23 07:58:11
djm [Wed, 28 Jan 2009 05:33:31 +0000 (05:33 +0000)] 
   - djm@cvs.openbsd.org 2009/01/23 07:58:11
     [myproposal.h]
     prefer CTR modes and revised arcfour (i.e w/ discard) modes to CBC
     modes; ok markus@

15 years ago - djm@cvs.openbsd.org 2009/01/22 10:09:16
djm [Wed, 28 Jan 2009 05:33:01 +0000 (05:33 +0000)] 
   - djm@cvs.openbsd.org 2009/01/22 10:09:16
     [auth-options.c]
     another chunk of a2port() diff that got away. wtfdjm??

15 years ago - djm@cvs.openbsd.org 2009/01/22 10:02:34
djm [Wed, 28 Jan 2009 05:31:22 +0000 (05:31 +0000)] 
   - djm@cvs.openbsd.org 2009/01/22 10:02:34
     [clientloop.c misc.c readconf.c readconf.h servconf.c servconf.h]
     [serverloop.c ssh-keyscan.c ssh.c sshd.c]
     make a2port() return -1 when it encounters an invalid port number
     rather than 0, which it will now treat as valid (needed for future work)
     adjust current consumers of a2port() to check its return value is <= 0,
     which in turn required some things to be converted from u_short => int
     make use of int vs. u_short consistent in some other places too
     feedback & ok markus@

15 years ago - djm@cvs.openbsd.org 2009/01/22 09:49:57
djm [Wed, 28 Jan 2009 05:30:33 +0000 (05:30 +0000)] 
   - djm@cvs.openbsd.org 2009/01/22 09:49:57
     [channels.c]
     oops! I committed the wrong version of the Channel->path diff,
     it was missing some tweaks suggested by stevesk@

15 years ago - djm@cvs.openbsd.org 2009/01/22 09:46:01
djm [Wed, 28 Jan 2009 05:29:49 +0000 (05:29 +0000)] 
   - djm@cvs.openbsd.org 2009/01/22 09:46:01
     [channels.c channels.h session.c]
     make Channel->path an allocated string, saving a few bytes here and
     there and fixing bz#1380 in the process; ok markus@

15 years ago - stevesk@cvs.openbsd.org 2009/01/15 17:38:43
djm [Wed, 28 Jan 2009 05:27:31 +0000 (05:27 +0000)] 
   - stevesk@cvs.openbsd.org 2009/01/15 17:38:43
     [readconf.c]
     1) use obsolete instead of alias for consistency
     2) oUserKnownHostsFile not obsolete but oGlobalKnownHostsFile2 is
        so move the comment.
     3) reorder so like options are together
     ok djm@

15 years ago - djm@cvs.openbsd.org 2009/01/14 01:38:06
djm [Wed, 28 Jan 2009 05:24:41 +0000 (05:24 +0000)] 
   - djm@cvs.openbsd.org 2009/01/14 01:38:06
     [channels.c]
     support SOCKS4A protocol, from dwmw2 AT infradead.org via bz#1482;
     "looks ok" markus@

15 years ago - djm@cvs.openbsd.org 2009/01/01 21:17:36
djm [Wed, 28 Jan 2009 05:23:06 +0000 (05:23 +0000)] 
   - djm@cvs.openbsd.org 2009/01/01 21:17:36
     [kexgexs.c]
     fix hash calculation for KEXGEX: hash over the original client-supplied
     values and not the sanity checked versions that we acutally use;
     bz#1540 reported by john.smith AT arrows.demon.co.uk
     ok markus@

15 years ago - djm@cvs.openbsd.org 2009/01/01 21:14:35
djm [Wed, 28 Jan 2009 05:22:34 +0000 (05:22 +0000)] 
   - djm@cvs.openbsd.org 2009/01/01 21:14:35
     [channels.c]
     call channel destroy callbacks on receipt of open failure messages.
     fixes client hangs when connecting to a server that has MaxSessions=0
     set spotted by imorgan AT nas.nasa.gov; ok markus@

15 years ago - okan@cvs.openbsd.org 2008/12/30 00:46:56
djm [Wed, 28 Jan 2009 05:20:17 +0000 (05:20 +0000)] 
   - okan@cvs.openbsd.org 2008/12/30 00:46:56
     [sshd_config.5]
     add AllowAgentForwarding to available Match keywords list
     ok djm

15 years ago - stevesk@cvs.openbsd.org 2008/12/29 02:23:26
djm [Wed, 28 Jan 2009 05:19:52 +0000 (05:19 +0000)] 
   - stevesk@cvs.openbsd.org 2008/12/29 02:23:26
     [pathnames.h]
     no need to escape single quotes in comments

15 years ago - stevesk@cvs.openbsd.org 2008/12/29 01:12:36
djm [Wed, 28 Jan 2009 05:18:03 +0000 (05:18 +0000)] 
   - stevesk@cvs.openbsd.org 2008/12/29 01:12:36
     [ssh-keyscan.1]
     fix example, default key type is rsa for 3+ years; from
     frederic.perrin@resel.fr

15 years ago - stevesk@cvs.openbsd.org 2008/12/10 03:55:20
djm [Wed, 28 Jan 2009 05:16:00 +0000 (05:16 +0000)] 
   - stevesk@cvs.openbsd.org 2008/12/10 03:55:20
     [addrmatch.c]
     o cannot be NULL here but use xfree() to be consistent; ok djm@

15 years ago - stevesk@cvs.openbsd.org 2008/12/09 22:37:33
djm [Wed, 28 Jan 2009 05:15:30 +0000 (05:15 +0000)] 
   - stevesk@cvs.openbsd.org 2008/12/09 22:37:33
     [clientloop.c]
     fix typo in error message

15 years ago - sobrado@cvs.openbsd.org 2008/12/09 15:35:00
djm [Wed, 28 Jan 2009 05:14:09 +0000 (05:14 +0000)] 
   - sobrado@cvs.openbsd.org 2008/12/09 15:35:00
     [sftp.1 sftp.c]
     update for the synopses displayed by the 'help' command, there are a
     few missing flags; add 'bye' to the output of 'help'; sorting and spacing.
     jmc@ suggested replacing .Oo/.Oc with a single .Op macro.
     ok jmc@

15 years ago - djm@cvs.openbsd.org 2008/12/09 04:32:22
djm [Wed, 28 Jan 2009 05:13:39 +0000 (05:13 +0000)] 
   - djm@cvs.openbsd.org 2008/12/09 04:32:22
     [auth2-chall.c]
     replace by-hand string building with xasprinf(); ok deraadt@

15 years ago - stevesk@cvs.openbsd.org 2008/12/09 03:20:42
djm [Wed, 28 Jan 2009 05:13:04 +0000 (05:13 +0000)] 
   - stevesk@cvs.openbsd.org 2008/12/09 03:20:42
     [channels.c servconf.c]
     channel_print_adm_permitted_opens() should deal with all the printing
     for that config option.  suggested by markus@; ok markus@ djm@
     dtucker@

15 years ago - (djm) [contrib/ssh-copy-id.1 contrib/ssh-copy-id] bz#1492: Make
djm [Wed, 21 Jan 2009 09:29:20 +0000 (09:29 +0000)] 
 - (djm) [contrib/ssh-copy-id.1 contrib/ssh-copy-id] bz#1492: Make
   ssh-copy-id copy id_rsa.pub by default (instead of the legacy "identity"
   key). Patch from cjwatson AT debian.org

15 years ago - (djm) [channels.c] bz#1419: support "on demand" X11 forwarding via
djm [Wed, 21 Jan 2009 05:46:26 +0000 (05:46 +0000)] 
 - (djm) [channels.c] bz#1419: support "on demand" X11 forwarding via
   launchd on OS X; patch from vgiffin AT apple.com, slightly tweaked;
   ok dtucker@

15 years ago - (djm) [uidswap.c] bz#1412: Support >16 supplemental groups in OS X.
djm [Wed, 21 Jan 2009 05:04:24 +0000 (05:04 +0000)] 
 - (djm) [uidswap.c] bz#1412: Support >16 supplemental groups in OS X.
   Patch based on one from vgiffin AT apple.com; ok dtucker@

15 years ago - (tim) [configure.ac] Move check_for_libcrypt_later=1 in *-*-sysv5*) section.
tim [Thu, 8 Jan 2009 04:50:08 +0000 (04:50 +0000)] 
 - (tim) [configure.ac] Move check_for_libcrypt_later=1 in *-*-sysv5*) section.
   OpenServer 6 doesn't need libcrypt.

15 years ago - (tim) [configure.ac defines.h openbsd-compat/port-uw.c
tim [Wed, 7 Jan 2009 18:04:12 +0000 (18:04 +0000)] 
 - (tim) [configure.ac defines.h openbsd-compat/port-uw.c
   openbsd-compat/xcrypt.c] Add SECUREWARE support to OpenServer 6 SVR5 ABI.
   OK djm@ dtucker@

15 years ago - djm@cvs.openbsd.org 2008/12/09 03:02:37
djm [Tue, 9 Dec 2008 03:12:33 +0000 (03:12 +0000)] 
   - djm@cvs.openbsd.org 2008/12/09 03:02:37
     [sftp.1 sftp.c]
     correct sftp(1) and corresponding usage syntax;
     bz#1518 patch from imorgan AT nas.nasa.gov; ok deraadt@ improved diff jmc@

15 years ago - djm@cvs.openbsd.org 2008/12/09 02:58:16
djm [Tue, 9 Dec 2008 03:12:05 +0000 (03:12 +0000)] 
   - djm@cvs.openbsd.org 2008/12/09 02:58:16
     [readconf.c]
     don't leave junk (free'd) pointers around in Forward *fwd argument on
     failure; avoids double-free in ~C -L handler when given an invalid
     forwarding specification; bz#1539 report from adejong AT debian.org
     via Colin Watson; ok markus@ dtucker@

15 years ago - djm@cvs.openbsd.org 2008/12/09 02:39:59
djm [Tue, 9 Dec 2008 03:11:49 +0000 (03:11 +0000)] 
   - djm@cvs.openbsd.org 2008/12/09 02:39:59
     [sftp.c]
     Deal correctly with failures in remote stat() operation in sftp,
     correcting fail-on-error behaviour in batchmode. bz#1541 report and
     fix from anedvedicky AT gmail.com; ok markus@

15 years ago - djm@cvs.openbsd.org 2008/12/09 02:38:18
djm [Tue, 9 Dec 2008 03:11:32 +0000 (03:11 +0000)] 
   - djm@cvs.openbsd.org 2008/12/09 02:38:18
     [clientloop.c]
     The ~C escape handler does not work correctly for multiplexed sessions -
     it opens a commandline on the master session, instead of on the slave
     that requested it. Disable it on slave sessions until such time as it
     is fixed; bz#1543 report from Adrian Bridgett via Colin Watson
     ok markus@

15 years ago - markus@cvs.openbsd.org 2008/12/02 19:09:38
djm [Sun, 7 Dec 2008 22:55:25 +0000 (22:55 +0000)] 
   - markus@cvs.openbsd.org 2008/12/02 19:09:38
     [channels.c]
     s/remote_id/id/ to be more consistent with other code; ok djm@

15 years ago - markus@cvs.openbsd.org 2008/12/02 19:08:59
djm [Sun, 7 Dec 2008 22:55:02 +0000 (22:55 +0000)] 
   - markus@cvs.openbsd.org 2008/12/02 19:08:59
     [serverloop.c]
     backout 1.149, since it's not necessary and openssh clients send
     broken CHANNEL_FAILURE/SUCCESS messages since about 2004; ok djm@

15 years ago - markus@cvs.openbsd.org 2008/12/02 19:01:07
djm [Sun, 7 Dec 2008 22:54:40 +0000 (22:54 +0000)] 
   - markus@cvs.openbsd.org 2008/12/02 19:01:07
     [clientloop.c]
     we have to use the recipient's channel number (RFC 4254) for
     SSH2_MSG_CHANNEL_SUCCESS/SSH2_MSG_CHANNEL_FAILURE messages,
     otherwise we trigger 'Non-public channel' error messages on sshd
     systems with clientkeepalive enabled; noticed by sturm; ok djm;

15 years ago - (djm) [configure.ac] bz#1538: better test for ProPolice/SSP: actually
djm [Sun, 7 Dec 2008 22:35:36 +0000 (22:35 +0000)] 
 - (djm) [configure.ac] bz#1538: better test for ProPolice/SSP: actually
   use some stack in main().
   Report and suggested fix from vapier AT gentoo.org

15 years ago - dtucker@cvs.openbsd.org 2008/11/30 11:59:26
dtucker [Mon, 1 Dec 2008 10:42:13 +0000 (10:42 +0000)] 
   - dtucker@cvs.openbsd.org 2008/11/30 11:59:26
     [monitor_fdpass.c]
     Retry sendmsg/recvmsg on EAGAIN and EINTR; ok djm@

15 years ago - markus@cvs.openbsd.org 2008/11/21 15:47:38
dtucker [Mon, 1 Dec 2008 10:40:48 +0000 (10:40 +0000)] 
   - markus@cvs.openbsd.org 2008/11/21 15:47:38
     [packet.c]
     packet_disconnect() on padding error, too.  should reduce the success
     probability for the CPNI-957037 Plaintext Recovery Attack to 2^-18
     ok djm@

15 years ago - (dtucker) [contrib/cygwin/{Makefile,ssh-host-config}] Add new doc files
dtucker [Mon, 1 Dec 2008 10:34:28 +0000 (10:34 +0000)] 
 - (dtucker) [contrib/cygwin/{Makefile,ssh-host-config}]  Add new doc files
   and tweak the is-sshd-running check in ssh-host-config.  Patch from
   vinschen at redhat com.

15 years agocmsg thing was originally spotted by des
dtucker [Sun, 23 Nov 2008 08:05:53 +0000 (08:05 +0000)] 
cmsg thing was originally spotted by des

15 years ago - (dtucker) [monitor_fdpass.c] Reduce diff vs OpenBSD by moving some
dtucker [Sun, 23 Nov 2008 03:03:19 +0000 (03:03 +0000)] 
 - (dtucker) [monitor_fdpass.c] Reduce diff vs OpenBSD by moving some
    declarations, removing an unnecessary union member and adding whitespace.
    ok djm some time ago.

15 years ago - (tim) [addrmatch.c configure.ac] Some platforms do not have sin6_scope_id
tim [Wed, 19 Nov 2008 05:26:41 +0000 (05:26 +0000)] 
 - (tim) [addrmatch.c configure.ac] Some platforms do not have sin6_scope_id
   member of sockaddr_in6. Also reported in Bug 1491 by David Leonard. OK and
   feedback by djm@

15 years agotest commit
djm [Wed, 19 Nov 2008 00:54:24 +0000 (00:54 +0000)] 
test commit

15 years ago - djm@cvs.openbsd.org 2008/11/10 02:06:35
dtucker [Tue, 11 Nov 2008 05:55:25 +0000 (05:55 +0000)] 
   - djm@cvs.openbsd.org 2008/11/10 02:06:35
     [regress/putty-ciphers.sh]
     PuTTY supports AES CTR modes, so interop test against them too

15 years ago - stevesk@cvs.openbsd.org 2008/11/11 03:55:11
dtucker [Tue, 11 Nov 2008 05:40:22 +0000 (05:40 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/11 03:55:11
     [channels.c]
     for sshd -T print 'permitopen any' vs. 'permitopen' for case of no
     permitopen's; ok and input dtucker@

15 years ago - stevesk@cvs.openbsd.org 2008/11/11 02:58:09
dtucker [Tue, 11 Nov 2008 05:39:44 +0000 (05:39 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/11 02:58:09
     [servconf.c]
     USE_AFS not referenced so remove #ifdef.  fixes sshd -T not printing
     kerberosgetafstoken. ok dtucker@
     (Id sync only, we still want the ifdef in portable)

15 years ago - tobias@cvs.openbsd.org 2008/11/09 12:34:47
dtucker [Tue, 11 Nov 2008 05:33:48 +0000 (05:33 +0000)] 
   - tobias@cvs.openbsd.org 2008/11/09 12:34:47
     [session.c ssh.1]
     typo fixed (overriden -> overridden)
     ok espie, jmc

15 years ago - dtucker@cvs.openbsd.org 2008/11/07 23:34:48
dtucker [Tue, 11 Nov 2008 05:33:03 +0000 (05:33 +0000)] 
   - dtucker@cvs.openbsd.org 2008/11/07 23:34:48
     [auth2-jpake.c]
     Move JPAKE define to make life easier for portable.  ok djm@

15 years ago - stevesk@cvs.openbsd.org 2008/11/07 18:50:18
dtucker [Tue, 11 Nov 2008 05:32:25 +0000 (05:32 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/07 18:50:18
     [nchan.c]
     add space to some log/debug messages for readability; ok djm@ markus@

15 years ago - stevesk@cvs.openbsd.org 2008/11/07 00:42:12
dtucker [Tue, 11 Nov 2008 05:31:43 +0000 (05:31 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/07 00:42:12
     [ssh-keygen.c]
     spelling/typo in comment

15 years ago - (dtucker) OpenBSD CVS Sync
dtucker [Tue, 11 Nov 2008 05:31:05 +0000 (05:31 +0000)] 
 - (dtucker) OpenBSD CVS Sync
   - jmc@cvs.openbsd.org 2008/11/05 11:22:54
     [servconf.c]
     passord -> password;
     fixes user/5975 from Rene Maroufi

15 years ago - stevesk@cvs.openbsd.org 2008/11/05 03:23:09
djm [Wed, 5 Nov 2008 05:30:31 +0000 (05:30 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/05 03:23:09
     [clientloop.c ssh.1]
     add dynamic forward escape command line; ok djm@

15 years ago - stevesk@cvs.openbsd.org 2008/11/04 19:18:00
djm [Wed, 5 Nov 2008 05:30:06 +0000 (05:30 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/04 19:18:00
     [readconf.c]
     because parse_forward() is now used to parse all forward types (DLR),
     and it malloc's space for host variables, we don't need to malloc
     here.  fixes small memory leaks.

     previously dynamic forwards were not parsed in parse_forward() and
     space was not malloc'd in that case.

     ok djm@

15 years ago - djm@cvs.openbsd.org 2008/11/04 08:22:13
djm [Wed, 5 Nov 2008 05:20:46 +0000 (05:20 +0000)] 
   - djm@cvs.openbsd.org 2008/11/04 08:22:13
     [auth.h auth2.c monitor.c monitor.h monitor_wrap.c monitor_wrap.h]
     [readconf.c readconf.h servconf.c servconf.h ssh2.h ssh_config.5]
     [sshconnect2.c sshd_config.5 jpake.c jpake.h schnorr.c auth2-jpake.c]
     [Makefile.in]
     Add support for an experimental zero-knowledge password authentication
     method using the J-PAKE protocol described in F. Hao, P. Ryan,
     "Password Authenticated Key Exchange by Juggling", 16th Workshop on
     Security Protocols, Cambridge, April 2008.

     This method allows password-based authentication without exposing
     the password to the server. Instead, the client and server exchange
     cryptographic proofs to demonstrate of knowledge of the password while
     revealing nothing useful to an attacker or compromised endpoint.

     This is experimental, work-in-progress code and is presently
     compiled-time disabled (turn on -DJPAKE in Makefile.inc).

     "just commit it.  It isn't too intrusive." deraadt@

15 years ago - djm@cvs.openbsd.org 2008/11/04 07:58:09
djm [Wed, 5 Nov 2008 05:12:54 +0000 (05:12 +0000)] 
   - djm@cvs.openbsd.org 2008/11/04 07:58:09
     [auth.c]
     need unistd.h for close() prototype
     (ID sync only)

15 years ago - OpenBSD CVS Sync
djm [Wed, 5 Nov 2008 05:12:11 +0000 (05:12 +0000)] 
 - OpenBSD CVS Sync
   - djm@cvs.openbsd.org 2008/11/03 08:59:41
     [servconf.c]
     include MaxSessions in sshd -T output; patch from imorgan AT nas.nasa.gov

15 years ago - (djm) [contrib/sshd.pam.generic contrib/caldera/sshd.pam]
djm [Mon, 3 Nov 2008 09:18:12 +0000 (09:18 +0000)] 
 - (djm) [contrib/sshd.pam.generic contrib/caldera/sshd.pam]
   [contrib/redhat/sshd.pam] Move pam_nologin to account group from
   incorrect auth group in example files;
   patch from imorgan AT nas.nasa.gov

15 years ago - (djm) [contrib/caldera/ssh-host-keygen contrib/suse/rc.sshd]
djm [Mon, 3 Nov 2008 09:16:01 +0000 (09:16 +0000)] 
 - (djm) [contrib/caldera/ssh-host-keygen contrib/suse/rc.sshd]
   Make example scripts generate keys with default sizes rather than fixed,
   non-default 1024 bits; patch from imorgan AT nas.nasa.gov

15 years ago - stevesk@cvs.openbsd.org 2008/11/03 02:44:41
djm [Mon, 3 Nov 2008 08:28:21 +0000 (08:28 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/03 02:44:41
     [readconf.c]
     fix comment

15 years ago - stevesk@cvs.openbsd.org 2008/11/03 01:07:02
djm [Mon, 3 Nov 2008 08:28:07 +0000 (08:28 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/03 01:07:02
     [readconf.c]
     remove valueless comment

15 years ago - stevesk@cvs.openbsd.org 2008/11/02 00:16:16
djm [Mon, 3 Nov 2008 08:27:52 +0000 (08:27 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/02 00:16:16
     [ttymodes.c]
     protocol 2 tty modes support is now 7.5 years old so remove these
     debug3()s; ok deraadt@

15 years ago - stevesk@cvs.openbsd.org 2008/11/01 17:40:33
djm [Mon, 3 Nov 2008 08:27:34 +0000 (08:27 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/01 17:40:33
     [clientloop.c readconf.c readconf.h ssh.c]
     merge dynamic forward parsing into parse_forward(); 'i think this is OK' djm@

15 years ago - sobrado@cvs.openbsd.org 2008/11/01 11:14:36
djm [Mon, 3 Nov 2008 08:27:07 +0000 (08:27 +0000)] 
   - sobrado@cvs.openbsd.org 2008/11/01 11:14:36
     [ssh-keyscan.1 ssh-keyscan.c]
     the ellipsis is not an optional argument; while here, improve spacing.

15 years ago - stevesk@cvs.openbsd.org 2008/11/01 06:43:33
djm [Mon, 3 Nov 2008 08:26:35 +0000 (08:26 +0000)] 
   - stevesk@cvs.openbsd.org 2008/11/01 06:43:33
     [channels.c]
     fix some typos in log messages; ok djm@

15 years ago - djm@cvs.openbsd.org 2008/11/01 04:50:08
djm [Mon, 3 Nov 2008 08:26:18 +0000 (08:26 +0000)] 
   - djm@cvs.openbsd.org 2008/11/01 04:50:08
     [sshconnect2.c]
     sprinkle ARGSUSED on dispatch handlers
     nuke stale unusued prototype

15 years ago - stevesk@cvs.openbsd.org 2008/10/31 15:05:34
djm [Mon, 3 Nov 2008 08:26:00 +0000 (08:26 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/31 15:05:34
     [dispatch.c]
     remove unused #define DISPATCH_MIN; ok markus@

15 years ago - stevesk@cvs.openbsd.org 2008/10/30 19:31:16
djm [Mon, 3 Nov 2008 08:25:40 +0000 (08:25 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/30 19:31:16
     [clientloop.c sshd.c]
     don't need to #include "monitor_fdpass.h"

15 years ago - stevesk@cvs.openbsd.org 2008/10/17 18:36:24
djm [Mon, 3 Nov 2008 08:25:21 +0000 (08:25 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/17 18:36:24
     [ssh_config.5]
     correct and clarify VisualHostKey; ok jmc@

15 years ago - stevesk@cvs.openbsd.org 2008/10/14 18:11:33
djm [Mon, 3 Nov 2008 08:25:03 +0000 (08:25 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/14 18:11:33
     [sshconnect.c]
     use #define ROQUIET here; no binary change. ok dtucker@

15 years ago - stevesk@cvs.openbsd.org 2008/10/10 16:43:27
djm [Mon, 3 Nov 2008 08:24:45 +0000 (08:24 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/10 16:43:27
     [ssh_config.5]
     use 'Privileged ports can be forwarded only when logging in as root on
     the remote machine.' for RemoteForward just like ssh.1 -R.
     ok djm@ jmc@

15 years ago - stevesk@cvs.openbsd.org 2008/10/10 05:00:12
djm [Mon, 3 Nov 2008 08:24:16 +0000 (08:24 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/10 05:00:12
     [key.c]
     typo in error message; ok djm@

15 years ago - stevesk@cvs.openbsd.org 2008/10/10 04:55:16
djm [Mon, 3 Nov 2008 08:23:45 +0000 (08:23 +0000)] 
   - stevesk@cvs.openbsd.org 2008/10/10 04:55:16
     [scp.c]
     spelling in comment; ok djm@

15 years ago - jmc@cvs.openbsd.org 2008/10/09 06:54:22
djm [Mon, 3 Nov 2008 08:23:28 +0000 (08:23 +0000)] 
   - jmc@cvs.openbsd.org 2008/10/09 06:54:22
     [ssh.c]
     add -y to usage();

15 years ago - djm@cvs.openbsd.org 2008/10/09 03:50:54
djm [Mon, 3 Nov 2008 08:23:10 +0000 (08:23 +0000)] 
   - djm@cvs.openbsd.org 2008/10/09 03:50:54
     [servconf.c sshd_config.5]
     support setting PermitEmptyPasswords in a Match block
     requested in PR3891; ok dtucker@

15 years ago - djm@cvs.openbsd.org 2008/10/08 23:34:03
djm [Mon, 3 Nov 2008 08:22:37 +0000 (08:22 +0000)] 
   - djm@cvs.openbsd.org 2008/10/08 23:34:03
     [ssh.1 ssh.c]
     Add -y option to force logging via syslog rather than stderr.
     Useful for daemonised ssh connection (ssh -f). Patch originally from
     and ok'd by markus@

15 years agoaadt@cvs.openbsd.org 2008/10/03 23:56:28
djm [Mon, 3 Nov 2008 08:22:09 +0000 (08:22 +0000)] 
aadt@cvs.openbsd.org 2008/10/03 23:56:28
     [sshconnect2.c]
     Repair strnvis() buffersize of 4*n+1, with termination gauranteed by the
     function.
     spotted by des@freebsd, who commited an incorrect fix to the freebsd tree
     and (as is fairly typical) did not report the problem to us.  But this fix
     is correct.
     ok djm

This page took 0.092054 seconds and 4 git commands to generate.