upstream commit

make sandboxed privilege separation the default, not just
 for new installs; "absolutely" deraadt@

Upstream-ID: 5221ef3b927d2df044e9aa3f5db74ae91743f69b
This commit is contained in:
djm@openbsd.org 2016-02-17 05:29:04 +00:00 committed by Damien Miller
parent eb3f7337a6
commit c5c3f3279a
2 changed files with 5 additions and 5 deletions

View File

@ -1,5 +1,5 @@
/* $OpenBSD: servconf.c,v 1.284 2016/01/29 02:54:45 dtucker Exp $ */ /* $OpenBSD: servconf.c,v 1.285 2016/02/17 05:29:04 djm Exp $ */
/* /*
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
* All rights reserved * All rights reserved
@ -356,9 +356,9 @@ fill_default_server_options(ServerOptions *options)
assemble_algorithms(options); assemble_algorithms(options);
/* Turn privilege separation on by default */ /* Turn privilege separation and sandboxing on by default */
if (use_privsep == -1) if (use_privsep == -1)
use_privsep = PRIVSEP_NOSANDBOX; use_privsep = PRIVSEP_ON;
#define CLEAR_ON_NONE(v) \ #define CLEAR_ON_NONE(v) \
do { \ do { \

View File

@ -1,4 +1,4 @@
# $OpenBSD: sshd_config,v 1.97 2015/08/06 14:53:21 deraadt Exp $ # $OpenBSD: sshd_config,v 1.98 2016/02/17 05:29:04 djm Exp $
# This is the sshd server system-wide configuration file. See # This is the sshd server system-wide configuration file. See
# sshd_config(5) for more information. # sshd_config(5) for more information.
@ -107,7 +107,7 @@ AuthorizedKeysFile .ssh/authorized_keys
#PrintLastLog yes #PrintLastLog yes
#TCPKeepAlive yes #TCPKeepAlive yes
#UseLogin no #UseLogin no
UsePrivilegeSeparation sandbox # Default for new installations. #UsePrivilegeSeparation sandbox
#PermitUserEnvironment no #PermitUserEnvironment no
#Compression delayed #Compression delayed
#ClientAliveInterval 0 #ClientAliveInterval 0