Darren Tucker
91cf261bd5
20030622
...
- (dtucker) OpenBSD CVS Sync
- djm@cvs.openbsd.org 2003/06/20 05:47:58
[sshd_config.5]
sync description of protocol 2 cipher proposal; ok markus
2003-06-22 20:46:53 +10:00
Darren Tucker
a251f809a0
- (dtucker) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/06/18 11:28:11
[ssh-rsa.c]
backout last change, since it violates pkcs#1
switch to share/misc/license.template
2003-06-22 20:45:15 +10:00
Darren Tucker
6cf1a2cfe8
- (dtucker) [openbsd-compat/setproctitle.c] Ensure SPT_TYPE is defined before
...
testing its value.
When HAVE_SETPROCTITLE is defined (at least on NetBSD, gcc 2.95.3) the test
"#if SPT_TYPE == SPT_REUSEARGV" is not true (probably because SPT_TYPE or
SPT_REUSEARGV is not defined). This results in the following build error:
$ gcc [flags] setproctitle.c
setproctitle.c: In function `compat_init_setproctitle':
setproctitle.c:102: `argv_start' undeclared (first use in this function)
2003-06-22 18:32:10 +10:00
Darren Tucker
e0194e52ca
- (dtucker) OpenBSD CVS Sync (regress/)
...
- markus@cvs.openbsd.org 2003/06/21 09:14:05
[reconfigure.sh]
missing $SUDO; from dtucker@zip.com.au
- (dtucker) [regress/authorized_keys_root] Remove temp data file from CVS.
2003-06-22 12:33:27 +10:00
Darren Tucker
50cea67222
- (dtucker) OpenBSD CVS Sync (regress/)
...
- markus@cvs.openbsd.org 2003/06/12 15:43:32
[Makefile]
test -HUP; dtucker at zip.com.au
2003-06-18 22:45:34 +10:00
Darren Tucker
76437600b2
- (dtucker) OpenBSD CVS Sync (regress/)
...
- markus@cvs.openbsd.org 2003/06/12 15:40:01
[try-ciphers.sh]
add ctr
2003-06-18 22:43:13 +10:00
Darren Tucker
c43362c89a
- (dtucker) OpenBSD CVS Sync (regress/)
...
- mouring@cvs.openbsd.org 2003/05/15 04:07:12
[sftp-cmds.sh]
Advanced put/get testing for sftp. OK @djm
2003-06-18 22:41:41 +10:00
Darren Tucker
ee5f83d3ea
- (dtucker) OpenBSD CVS Sync (regress/)
...
- markus@cvs.openbsd.org 2003/05/14 22:08:27
[ssh-com-client.sh ssh-com-keygen.sh ssh-com-sftp.sh ssh-com.sh]
test against some new commerical versions
2003-06-18 22:36:48 +10:00
Darren Tucker
a4040f5904
- (dtucker) OpenBSD CVS Sync (regress/)
...
- djm@cvs.openbsd.org 2003/04/04 09:34:22
[Makefile sftp-cmds.sh]
More regression tests, including recent directory rename bug; ok markus@
2003-06-18 22:35:11 +10:00
Darren Tucker
d57a76eec5
- (dtucker) OpenBSD CVS Sync (regress/)
...
- markus@cvs.openbsd.org 2003/04/02 12:21:13
[Makefile]
enable rekey test
2003-06-18 22:32:51 +10:00
Darren Tucker
3a222ac0d0
- (dtucker) [regress/copy.1 regress/copy.2] Remove temp data files from CVS.
2003-06-18 22:21:33 +10:00
Darren Tucker
fc8a7ea202
- (dtucker) [reconfigure.sh rekey.sh sftp-badcmds.sh]
...
Import new regression tests from OpenBSD
2003-06-18 22:18:57 +10:00
Damien Miller
0275b52387
- markus@cvs.openbsd.org 2003/06/17 18:14:23
...
[cipher-ctr.c]
use license from /usr/share/misc/license.template for new code
2003-06-18 20:29:35 +10:00
Damien Miller
80163e1b72
- markus@cvs.openbsd.org 2003/06/16 10:22:45
...
[ssh-add.c]
print out key comment on each prompt; make ssh-askpass more useable; ok djm@
2003-06-18 20:29:18 +10:00
Damien Miller
8c1d2e3926
- markus@cvs.openbsd.org 2003/06/16 08:22:35
...
[ssh-rsa.c]
make sure the signature has at least the expected length (don't
insist on len == hlen + oidlen, since this breaks some smartcards)
bugzilla #592 ; ok djm@
2003-06-18 20:29:01 +10:00
Damien Miller
56a0bb07c4
- markus@cvs.openbsd.org 2003/06/12 19:12:03
...
[scard.c scard.h ssh-agent.c ssh.c]
add sc_get_key_label; larsch at trustcenter.de; bugzilla#591
2003-06-18 20:28:40 +10:00
Damien Miller
b2cdcb50a2
- nino@cvs.openbsd.org 2003/06/12 15:34:09
...
[scp.c]
Typo. Ok markus@.
2003-06-18 20:26:34 +10:00
Damien Miller
116aabbb66
- djm@cvs.openbsd.org 2003/06/12 12:22:47
...
[LICENCE]
mention more copyright holders; ok markus@
2003-06-18 20:26:13 +10:00
Damien Miller
469954debd
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/06/12 07:57:38
[monitor.c sshlogin.c sshpty.c]
typos; dtucker at zip.com.au
2003-06-18 20:25:33 +10:00
Damien Miller
53950b68bf
- (djm) Update license on fake-rfc2553.[ch]; ok itojun@
2003-06-14 08:43:22 +10:00
Damien Miller
af63951c57
- (djm) Put licenses on substantial header files
2003-06-11 22:51:32 +10:00
Damien Miller
141efa7036
- (djm) Mention portable copyright holders in LICENSE
2003-06-11 22:50:56 +10:00
Damien Miller
4bfeb14742
- (djm) Sync LICENSE against OpenBSD
2003-06-11 22:08:36 +10:00
Damien Miller
d94f20d28e
- djm@cvs.openbsd.org 2003/06/11 11:18:38
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
make agent constraints (lifetime, confirm) work with smartcard keys;
ok markus@
2003-06-11 22:06:33 +10:00
Damien Miller
0e1b937f13
- jakob@cvs.openbsd.org 2003/06/11 10:18:47
...
[dns.c]
sync with check_host_key() change
2003-06-11 22:05:45 +10:00
Damien Miller
7392ae6270
- jakob@cvs.openbsd.org 2003/06/11 10:16:16
...
[sshconnect.c]
clean up check_host_key() and improve SSHFP feedback. ok markus@
2003-06-11 22:05:25 +10:00
Damien Miller
2b92d32e19
- deraadt@cvs.openbsd.org 2003/06/10 22:20:52
...
[packet.c progressmeter.c]
mostly ansi cleanup; pval ok
2003-06-11 22:05:06 +10:00
Damien Miller
f1ce505daf
- jmc@cvs.openbsd.org 2003/06/10 09:12:11
...
[scp.1 sftp-server.8 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5]
[sshd.8 sshd_config.5 ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
- section reorder
- COMPATIBILITY merge
- macro cleanup
- kill whitespace at EOL
- new sentence, new line
ssh pages ok markus@
2003-06-11 22:04:39 +10:00
Damien Miller
78f2e5ca98
- (djm) Re-merge OpenSC info into README.smartcard
2003-06-10 21:09:09 +10:00
Damien Miller
c18c06e131
- (djm) Sync README.smartcard with OpenBSD -current
2003-06-10 18:55:22 +10:00
Darren Tucker
400b8786d6
- (dtucker) [uidswap.c] Fix setreuid and add missing args to fatal(). ok djm@
2003-06-06 10:46:04 +10:00
Darren Tucker
881753bef2
- (dtucker) Define EAI_NONAME in fake-rfc2553.h (used by fake-rfc2553.c).
2003-06-05 22:20:11 +10:00
Darren Tucker
4aff13f1e7
- (dtucker) Add includes.h to fake-rfc2553.c so it will build.
2003-06-05 19:37:30 +10:00
Damien Miller
76b5c8a83a
- (djm) Bug #589 - scard-opensc: load only keys with a private keys
...
Patch from larsch@trustcenter.de
2003-06-05 19:19:35 +10:00
Damien Miller
f49078dfdf
- (djm) Bug #588 - Add scard-opensc.o back to Makefile.in
...
Patch from larsch@trustcenter.de
2003-06-05 18:53:42 +10:00
Damien Miller
c28e38d23a
- (djm) Merge all the openbsd/fake-* into fake-rfc2553.[ch]
2003-06-05 18:52:47 +10:00
Damien Miller
b95bb7f9b1
- (djm) Don't use xmalloc() or pull in toplevel headers in fake-* code
2003-06-05 10:04:12 +10:00
Damien Miller
5fe46a45c8
- (djm) Implement paranoid priv dropping checks, based on:
...
"SetUID demystified" - Hao Chen, David Wagner and Drew Dean
Proceedings of USENIX Security Symposium 2002
2003-06-05 09:53:31 +10:00
Damien Miller
10eac0cf8f
- (djm) Support AI_NUMERICHOST in fake-getaddrinfo.c. Needed for recent
...
canohost.c changes.
2003-06-05 09:48:32 +10:00
Damien Miller
0cbb9dea05
- (djm) Always use mysignal() for SIGALRM
2003-06-04 22:56:15 +10:00
Damien Miller
cc685c1cbe
- djm@cvs.openbsd.org 2003/06/04 12:41:22
...
[sftp.c]
kill ssh process on receipt of signal; ok markus@
2003-06-04 22:51:38 +10:00
Damien Miller
b69aaa8db7
- djm@cvs.openbsd.org 2003/06/04 12:40:39
...
[scp.c]
kill ssh process upon receipt of signal, bz #241 .
based on patch from esb AT hawaii.edu; ok markus@
2003-06-04 22:51:24 +10:00
Damien Miller
65d1f5765f
- djm@cvs.openbsd.org 2003/06/04 12:18:49
...
[scp.c]
ansify; ok markus@
2003-06-04 22:51:08 +10:00
Damien Miller
9fc7c699af
- djm@cvs.openbsd.org 2003/06/04 12:03:59
...
[serverloop.c]
remove bitrotten commet; ok markus@
2003-06-04 22:50:54 +10:00
Damien Miller
4c322482bb
- (djm) Update to fix of bug #584 : lock card before return.
...
From larsch@trustcenter.de
2003-06-04 22:12:17 +10:00
Damien Miller
31b3a0a98f
- djm@cvs.openbsd.org 2003/06/04 10:23:48
...
[sshd.c]
remove duplicated group-dropping code; ok markus@
2003-06-04 20:32:12 +10:00
Damien Miller
941ac459ce
- (djm) OpenBSD CVS Sync
...
- djm@cvs.openbsd.org 2003/06/04 08:25:18
[sshconnect.c]
disable challenge/response and keyboard-interactive auth methods
upon hostkey mismatch. based on patch from fcusack AT fcusack.com.
bz #580 ; ok markus@
2003-06-04 20:31:53 +10:00
Damien Miller
2527f5755a
- (djm) Bug #584 : scard-opensc.c doesn't work without PIN. Patch from
...
larsch@trustcenter.de ; ok markus@
2003-06-04 19:22:06 +10:00
Damien Miller
485397c48d
- (djm) Bug #577 - wrong flag in scard-opensc.c sc_private_decrypt.
...
ok markus@
2003-06-04 19:15:10 +10:00
Damien Miller
865173ee03
- (djm) Bug #573 - Remove unneeded Krb headers and compat goop. Patch from
...
simon@sxw.org.uk (Also matches a change in OpenBSD a while ago)
2003-06-04 19:06:59 +10:00
Damien Miller
d311c4e54b
change "No more 4-term BSD licenses in our tree" to
...
"No more 4-term BSD licenses in linked code"
mdoc2man.pl is 4-term BSDL
2003-06-03 13:09:16 +10:00
Damien Miller
dafb12ed28
a - millert@cvs.openbsd.org 2003/06/03 02:56:16
...
[scp.c]
Remove the advertising clause in the UCB license which Berkeley
rescinded 22 July 1999. Proofed by myself and Theo.
2003-06-03 13:06:18 +10:00
Darren Tucker
eb28cbc399
- (dtucker) [port-aix.c bsd-cray.c] Fix uses of verify_reverse_mapping.
2003-06-03 12:45:27 +10:00
Damien Miller
048d88d5aa
trim prior to 3.6p1
2003-06-03 12:43:14 +10:00
Damien Miller
329638e49c
- (djm) Sync openbsd-compat with OpenBSD CVS.
...
- No more 4-term BSD licenses in our tree
2003-06-03 12:12:50 +10:00
Damien Miller
3a961dc0d3
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/06/02 09:17:34
[auth2-hostbased.c auth.c auth-options.c auth-rhosts.c auth-rh-rsa.c]
[canohost.c monitor.c servconf.c servconf.h session.c sshd_config]
[sshd_config.5]
deprecate VerifyReverseMapping since it's dangerous if combined
with IP based access control as noted by Mike Harding; replace with
a UseDNS option, UseDNS is on by default and includes the
VerifyReverseMapping check; with itojun@, provos@, jakob@ and deraadt@
ok deraadt@, djm@
- (djm) Fix portable-specific uses of verify_reverse_mapping too
2003-06-03 10:25:48 +10:00
Damien Miller
35276253a6
- (djm) Replace setproctitle replacement with code derived from
...
UCB sendmail
2003-06-03 10:14:28 +10:00
Damien Miller
eacbb4fcc1
- jakob@cvs.openbsd.org 2003/06/02 08:31:10
...
[ssh_config.5]
VerifyHostKeyDNS is v2 only. ok markus@
2003-06-02 19:10:41 +10:00
Damien Miller
61d3680aca
- deraadt@cvs.openbsd.org 2003/05/29 16:58:45
...
[sshd.c uidswap.c]
seteuid and setegid; markus ok
2003-06-02 19:09:48 +10:00
Damien Miller
ab2db41b61
- djm@cvs.openbsd.org 2003/05/26 12:54:40
...
[sshconnect.c]
fix format strings; ok markus@
2003-06-02 19:09:13 +10:00
Damien Miller
f46844214d
- (djm) Sync license on openbsd-compat/bindresvport.c with OpenBSD CVS
2003-06-02 18:59:08 +10:00
Damien Miller
dcc8312a19
- (djm) Fix use of macro before #define in cipher-aes.c
2003-06-02 18:57:59 +10:00
Damien Miller
dba5950820
- (djm) Remove "noip6" option from RedHat spec file. This may now be
...
set at runtime using AddressFamily option.
2003-06-02 17:43:19 +10:00
Tim Rice
237ca4ab08
openbsd-compat/xmmap.[ch] License clarifications. Add missing CVS ID.
2003-06-01 19:25:27 -07:00
Damien Miller
f2e3e9deba
- (djm) Always use saved_argv in sshd.c as compat_init_setproctitle may
...
clobber
2003-06-02 12:15:54 +10:00
Damien Miller
f3bff94957
- (djm) Fix segv from bad reordering in auth-pam.c
2003-06-02 12:13:40 +10:00
Darren Tucker
2972d6c045
- (dtucker) Define SSHD_ACQUIRES_CTTY for NCR MP-RAS and Reliant Unix.
...
I'm pretty sure these are required. I also want to add -D_XOPEN_SOURCE=1
-D_XOPEN_SOURCE_EXTENDED=1 to CPPFLAGS for MP-RAS but I haven't had confirmation
that it will not break anything else.
2003-05-30 17:43:42 +10:00
Darren Tucker
3cb84e5ec8
- (dtucker) Add missing semicolon in md5crypt.c, patch from openssh at
...
roumenpetrov.info
2003-05-30 16:58:22 +10:00
Damien Miller
a6a7c19dcb
- (djm) Avoid auth2-chall.c warning when compiling without
...
PAM, BSD_AUTH and SKEY
2003-05-26 21:36:13 +10:00
Damien Miller
04bd8b0bcc
- djm@cvs.openbsd.org 2003/05/24 09:30:40
...
[authfile.c monitor.c sftp-common.c sshpty.c]
cast some types for printing; ok markus@
2003-05-25 14:38:33 +10:00
Damien Miller
c11fe255ab
- (djm) OpenBSD CVS Sync
...
- djm@cvs.openbsd.org 2003/05/24 09:02:22
[log.c]
pass logged data through strnvis; ok markus
2003-05-25 14:38:02 +10:00
Darren Tucker
6014578b90
- (dtucker) Correct --osfsia in INSTALL. Patch by skeleten at shillest.net
2003-05-24 11:41:16 +10:00
Damien Miller
08293fa435
- djm@cvs.openbsd.org 2003/05/23 08:29:30
...
[sshconnect.c]
fix leak; ok markus@
2003-05-23 18:44:41 +10:00
Damien Miller
fbf486b4a6
- jmc@cvs.openbsd.org 2003/05/20 12:09:31
...
[ssh.1 ssh_config.5 sshd.8 sshd_config.5 ssh-keygen.1]
new sentence, new line
2003-05-23 18:44:23 +10:00
Damien Miller
5067792a72
- (djm) OpenBSD CVS Sync
...
- jmc@cvs.openbsd.org 2003/05/20 12:03:35
[sftp.1]
- new sentence, new line
- added .Xr's
- typos
ok djm@
2003-05-23 18:44:04 +10:00
Damien Miller
d419bdae77
- (djm) Use VIS_SAFE on logged strings rather than default strnvis
...
encoding (which encodes many more characters)
2003-05-23 18:43:40 +10:00
Damien Miller
1340ec297b
- (djm) Configure logic to detect syslog_r and friends
2003-05-20 09:24:42 +10:00
Damien Miller
74a3442d10
- deraadt@cvs.openbsd.org 2003/05/18 23:22:01
...
[log.c]
use syslog_r() in a signal handler called place; markus ok
2003-05-20 09:24:17 +10:00
Damien Miller
eb0e969a4f
- (djm) Sync auth-pam.h with what we actually implement
2003-05-19 11:28:44 +10:00
Damien Miller
5b5ca19ef0
- (djm) KNF on auth-sia.[ch]
2003-05-19 00:50:02 +10:00
Damien Miller
e7fb103192
- (djm) KNF on md5crypt.c
2003-05-19 00:46:46 +10:00
Damien Miller
317412502b
- (djm) Big KNF on openbsd-compat/
2003-05-19 00:13:38 +10:00
Damien Miller
e323df6c48
- (djm) Sync openbsd-compat/ with OpenBSD CVS head
2003-05-18 22:24:09 +10:00
Damien Miller
0b8e9006d8
- (djm) Tidy and trim TODO
2003-05-18 21:44:07 +10:00
Damien Miller
f5399c24dc
- markus@cvs.openbsd.org 2003/05/17 04:27:52
...
[cipher.c cipher-ctr.c myproposal.h]
experimental support for aes-ctr modes from
http://www.ietf.org/internet-drafts/draft-ietf-secsh-newmodes-00.txt
ok djm@
2003-05-18 20:53:59 +10:00
Damien Miller
a9825785e8
- itojun@cvs.openbsd.org 2003/05/17 03:25:58
...
[auth-rhosts.c]
just in case, put numbers to sscanf %s arg.
2003-05-18 20:53:10 +10:00
Damien Miller
7e1bbc55af
- (djm) Remove IPv4 by default hack now that we can specify AF in config
2003-05-18 20:52:40 +10:00
Damien Miller
20a8f97b03
- djm@cvs.openbsd.org 2003/05/16 03:27:12
...
[readconf.c ssh_config ssh_config.5 ssh-keysign.c]
add AddressFamily option to ssh_config (like -4, -6 on commandline).
Portable bug #534 ; ok markus@
2003-05-18 20:50:30 +10:00
Damien Miller
25d9342f04
- (djm) Return of the dreaded PAM_TTY_KLUDGE, which went missing in
...
recent merge
2003-05-18 20:45:47 +10:00
Ben Lindstrom
4c9e9ab165
- (bal) strcat -> strlcat on openbsd-compat/realpath.c (rev 1.8 OpenBSD)
2003-05-18 01:22:43 +00:00
Damien Miller
e27c6cc3ad
- (djm) Guard free_pam_environment against NULL argument. Works around
...
HP/UX PAM problems debugged by dtucker
2003-05-16 18:21:01 +10:00
Damien Miller
c46b6bc4f7
- (djm) A few type mismatch fixes from Bug #565
2003-05-16 15:51:44 +10:00
Damien Miller
6ac2c48a19
- (djm) Add warning for UsePAM when built without PAM support
2003-05-16 11:42:35 +10:00
Damien Miller
b78d5eb6c5
- djm@cvs.openbsd.org 2003/05/15 14:55:25
...
[readconf.c readconf.h ssh_config ssh_config.5 sshconnect.c]
add a ConnectTimeout option to ssh, based on patch from
Jean-Charles Longuet (jclonguet at free.fr); portable #207 ok markus@
2003-05-16 11:39:04 +10:00
Damien Miller
99b4b88aba
- markus@cvs.openbsd.org 2003/05/15 14:09:21
...
[auth2-krb5.c]
fix 64bit issue; report itojun@
2003-05-16 11:38:46 +10:00
Damien Miller
f9b3feb847
- jakob@cvs.openbsd.org 2003/05/15 14:02:47
...
[readconf.c servconf.c]
warn for unsupported config option. ok markus@
2003-05-16 11:38:32 +10:00
Damien Miller
6e80c36e2a
- (djm) OpenBSD CVS Sync
...
- djm@cvs.openbsd.org 2003/05/15 13:52:10
[ssh.c]
Make "ssh -V" print the OpenSSL version in a human readable form. Patch
from Craig Leres (mindrot at ee.lbl.gov); ok markus@
2003-05-16 11:38:00 +10:00
Darren Tucker
5d0ccf3b24
- (dtucker) HP-UX needs to include <sys/strtio.h> for TIOCSBRK
2003-05-15 21:42:59 +10:00
Damien Miller
eff041d19e
- (djm) Bug #444 : Wrong paths after reconfigure
2003-05-15 21:33:46 +10:00
Damien Miller
04cb536054
- (djm) Bug #529 : sshd doesn't work correctly after SIGHUP (copy argv
...
correctly)
2003-05-15 21:29:10 +10:00
Damien Miller
b10f1cd878
- (djm) Only build getrrsetbyname replacement when using --with-dns
2003-05-15 20:55:27 +10:00
Damien Miller
46a7b40d1e
- markus@cvs.openbsd.org 2003/05/15 04:08:41
...
[ssh.1]
~B is ssh2 only
2003-05-15 14:17:28 +10:00
Damien Miller
156cbe8c67
- (djm) Enable UsePAM when built --with-pam
2003-05-15 14:16:41 +10:00
Damien Miller
d248b5bd1b
- jakob@cvs.openbsd.org 2003/05/15 04:08:44
...
[readconf.c servconf.c]
disable kerberos when not supported. ok markus@
2003-05-15 14:15:23 +10:00
Damien Miller
ffda4cb218
- (djm) Avoid uuencode.c warnings
2003-05-15 13:57:51 +10:00
Damien Miller
34bb56743a
- mouring@cvs.openbsd.org 2003/05/15 03:43:59
...
[sftp-int.c sftp.c]
Teach ls how to display multiple column display and allow users
to return to single column format via 'ls -1'. OK @djm
2003-05-15 13:49:58 +10:00
Damien Miller
19c8f2b310
- mouring@cvs.openbsd.org 2003/05/15 03:43:59
...
[sftp-int.c]
Teach ls how to display multiple column display and allow users
to return to single column format via 'ls -1'. OK @djm
2003-05-15 13:49:21 +10:00
Damien Miller
4962ed6ab4
- mouring@cvs.openbsd.org 2003/05/15 03:39:07
...
[sftp-int.c]
Make put/get (globed and nonglobed) code more consistant. OK djm@
2003-05-15 13:48:59 +10:00
Damien Miller
ed12a26f0d
- djm@cvs.openbsd.org 2003/05/15 03:10:52
...
[ssh-keygen.c]
avoid warning; ok jakob@
2003-05-15 13:37:43 +10:00
Damien Miller
3a3261ff99
- markus@cvs.openbsd.org 2003/05/15 03:08:29
...
[cipher.c cipher-bf1.c cipher-aes.c cipher-3des1.c]
split out custom EVP ciphers
2003-05-15 13:37:19 +10:00
Damien Miller
b0622653ba
- jakob@cvs.openbsd.org 2003/05/15 02:27:15
...
[dns.c]
add missing freerrset
2003-05-15 13:27:28 +10:00
Damien Miller
5975cf12c3
- (djm) Adapt README.dns for portable
2003-05-15 13:23:36 +10:00
Damien Miller
a47f526dd7
- (djm) Tidy Makefile clean targets
2003-05-15 13:23:07 +10:00
Damien Miller
d9ec370ac3
- (djm) Import getrrsetbyname() function from OpenBSD libc (for DNS support)
2003-05-15 12:27:08 +10:00
Damien Miller
2aa0ab463f
- jakob@cvs.openbsd.org 2003/05/15 01:48:10
...
[readconf.c readconf.h servconf.c servconf.h]
always parse kerberos options. ok djm@ markus@
- (djm) Always parse UsePAM
2003-05-15 12:05:28 +10:00
Damien Miller
f842fcb296
- markus@cvs.openbsd.org 2003/05/15 00:28:28
...
[sshconnect2.c]
cleanup unregister of per-method packet handlers; ok djm@
2003-05-15 12:01:28 +10:00
Damien Miller
7abe09bf86
- (djm) Configure glue for DNS support (code doesn't work in portable yet)
2003-05-15 10:53:49 +10:00
Damien Miller
54c459866e
- markus@cvs.openbsd.org 2003/05/14 22:24:42
...
[clientloop.c session.c ssh.1]
allow to send a BREAK to the remote system; ok various
2003-05-15 10:20:13 +10:00
Damien Miller
37876e913a
- jakob@cvs.openbsd.org 2003/05/14 18:16:20
...
[key.c key.h readconf.c readconf.h ssh_config.5 sshconnect.c]
[dns.c dns.h README.dns ssh-keygen.1 ssh-keygen.c]
add experimental support for verifying hos keys using DNS as described
in draft-ietf-secsh-dns-xx.txt. more information in README.dns.
ok markus@ and henning@
2003-05-15 10:19:46 +10:00
Damien Miller
abbae980e7
- (djm) OpenBSD CVS Sync
...
- jmc@cvs.openbsd.org 2003/05/14 13:11:56
[ssh-agent.1]
setup -> set up;
from wiz@netbsd
2003-05-15 10:16:21 +10:00
Damien Miller
1ea7166019
- (djm) Bug #258 : sscanf("[0-9]") -> sscanf("[0123456789]") for portability
2003-05-14 22:33:58 +10:00
Darren Tucker
abef5628e8
- (dtucker) Set ai_socktype and ai_protocol in fake-getaddrinfo.c. ok djm@
2003-05-14 21:48:51 +10:00
Damien Miller
be64d43d01
- markus@cvs.openbsd.org 2003/05/14 08:57:49
...
[monitor.c]
http://bugzilla.mindrot.org/show_bug.cgi?id=560
Privsep child continues to run after monitor killed.
Pass monitor signals through to child; Darren Tucker
2003-05-14 19:31:12 +10:00
Damien Miller
d6ead282db
- jmc@cvs.openbsd.org 2003/05/14 08:25:39
...
[sftp.1]
- better formatting in SYNOPSIS
- whitespace at EOL
ok djm@
2003-05-14 19:30:38 +10:00
Damien Miller
4d99519535
- (djm) Avoid KrbV leak for MIT Kerberos
2003-05-14 19:23:56 +10:00
Damien Miller
9d507dac1f
- (djm) Die screaming if start_pam() is called when UsePAM=no
2003-05-14 15:31:12 +10:00
Damien Miller
4e448a31ae
- (djm) Add new UsePAM configuration directive to allow runtime control
...
over usage of PAM. This allows non-root use of sshd when built with
--with-pam
2003-05-14 15:11:48 +10:00
Damien Miller
9c617693c2
- (djm) Make portable build with MIT krb5 (some issues remain)
2003-05-14 14:31:11 +10:00
Damien Miller
3ab496b3dd
- markus@cvs.openbsd.org 2003/05/14 02:15:47
...
[auth2.c monitor.c sshconnect2.c auth2-krb5.c]
implement kerberos over ssh2 ("kerberos-2@ssh.com"); tested with jakob@
server interops with commercial client; ok jakob@ djm@
2003-05-14 13:47:37 +10:00
Damien Miller
fb7508edc8
- djm@cvs.openbsd.org 2003/05/14 01:00:44
...
[sftp.1]
emphasise the batchmode functionality and make reference to pubkey auth,
both of which are FAQs; ok markus@
2003-05-14 13:47:07 +10:00
Damien Miller
935063553a
- markus@cvs.openbsd.org 2003/05/12 18:35:18
...
[ssh-keyscan.1]
typo: DSA keys are of type ssh-dss; Brian Poole
2003-05-14 13:46:33 +10:00
Damien Miller
280ecfb6e4
- markus@cvs.openbsd.org 2003/05/12 16:55:37
...
[sshconnect2.c]
for pubkey authentication try the user keys in the following order:
1. agent keys that are found in the config file
2. other agent keys
3. keys that are only listed in the config file
this helps when an agent has many keys, where the server might
close the connection before the correct key is used. report & ok pb@
2003-05-14 13:46:00 +10:00
Damien Miller
b1ca8bb159
- markus@cvs.openbsd.org 2003/05/11 20:30:25
...
[channels.c clientloop.c serverloop.c session.c ssh.c]
make channel_new() strdup the 'remote_name' (not the caller); ok theo
2003-05-14 13:45:42 +10:00
Damien Miller
db2747259c
- markus@cvs.openbsd.org 2003/05/11 16:56:48
...
[authfile.c ssh-keygen.c]
change key_load_public to try to read a public from:
rsa1 private or rsa1 public and ssh2 keys.
this makes ssh-keygen -e fail for ssh1 keys more gracefully
for example; report from itojun (netbsd pr 20550).
2003-05-14 13:45:22 +10:00
Damien Miller
3155432cd9
- david@cvs.openbsd.org 2003/04/30 20:41:07
...
[sshd.8]
fix invalid .Pf macro usage introduced in previous commit
ok jmc@ mouring@
2003-05-14 13:44:58 +10:00
Damien Miller
049245d260
- mouring@cvs.openbsd.org 2003/04/30 01:16:20
...
[sshd.8 sshd_config.5]
Escape ?, * and ! in .Ql for nroff compatibility. OpenSSH Portable
Bug #550 and * escaping suggested by jmc@.
2003-05-14 13:44:42 +10:00
Damien Miller
ea5ade28fb
- deraadt@cvs.openbsd.org 2003/04/26 04:29:49
...
[ssh-keyscan.c]
-t in usage(); rogier@quaak.org
2003-05-14 13:43:53 +10:00
Damien Miller
8ce778a9f0
- markus@cvs.openbsd.org 2003/04/16 14:35:27
...
[auth.h]
document struct Authctxt; with solar
2003-05-14 13:43:25 +10:00
Damien Miller
2372ace572
- markus@cvs.openbsd.org 2003/04/14 14:17:50
...
[channels.c sshconnect.c sshd.c ssh-keyscan.c]
avoid hardcoded SOCK_xx; with itojun@; should allow ssh over SCTP
2003-05-14 13:42:23 +10:00
Damien Miller
44e72a764f
- naddy@cvs.openbsd.org 2003/04/12 11:40:15
...
[ssh.1]
document -V switch, fix wording; ok markus@
2003-05-14 13:42:08 +10:00
Damien Miller
ef095ce00a
- markus@cvs.openbsd.org 2003/04/12 10:15:36
...
[misc.c]
debug->debug2
2003-05-14 13:41:39 +10:00
Damien Miller
a201bb3f8a
- markus@cvs.openbsd.org 2003/04/12 10:13:57
...
[cipher.c]
hide cipher details; ok djm@
2003-05-14 13:41:23 +10:00
Damien Miller
c652cac5f7
- (djm) OpenBSD CVS Sync
...
- djm@cvs.openbsd.org 2003/04/09 12:00:37
[readconf.c]
strip trailing whitespace from config lines before parsing.
Fixes bz 528; ok markus@
2003-05-14 13:40:54 +10:00
Damien Miller
d558092522
- (djm) RCSID sync w/ OpenBSD
2003-05-14 13:40:06 +10:00
Damien Miller
1a27a1ee8c
- (djm) Bug #117 : Don't lie to PAM about username
2003-05-14 10:27:09 +10:00
Damien Miller
75d3b05c57
- (djm) Redhat spec: Don't install profile.d scripts when not
...
building with GNOME/GTK askpass (patch from bet@rahul.net )
2003-05-12 18:15:49 +10:00
Damien Miller
0d8b792931
- (djm) 2-clause license on loginrec.c, with permission from
...
andre@ae-35.com
2003-05-10 23:42:12 +10:00
Damien Miller
4f9f42a9bb
- (djm) Merge FreeBSD PAM code: replaces PAM password auth kludge with
...
proper challenge-response module
2003-05-10 19:28:02 +10:00
Darren Tucker
c437cda328
- (dtucker) Bug #536 : Test for and work around openpty/controlling tty
...
problem on Linux (fixes "could not set controlling tty" errors).
Also renames STREAMS_PUSH_ACQUIRES_CTTY to the more generic SSHD_ACQUIRES_CTTY
and moves the Solaris-specific comments to configure.ac.
2003-05-10 17:05:46 +10:00
Darren Tucker
e8831091c3
- (dtucker) Bug #318 : Create ssh_prng_cmds.out during "make" rather than
...
"make install". Patch by roth@feep.net .
2003-05-10 16:48:23 +10:00
Darren Tucker
ac279284f6
Add bug# to ChangeLog.
2003-05-04 11:36:25 +10:00
Darren Tucker
70a08cd29d
- (dtucker) Move #include of bsd-cygwin_util.h to openbsd-compat.h. Patch from
...
vinschen@redhat.com .
2003-05-04 10:41:20 +10:00
Darren Tucker
04cc5385b1
- (dtucker) Add missing "void" to record_failed_login in bsd-cray.c. Noted
...
by wendyp@cray.com .
2003-05-03 07:32:56 +10:00
Darren Tucker
bd570d7a22
Added ok for record_failed_login() change
2003-05-02 23:50:09 +10:00
Darren Tucker
97363a8b24
- (dtucker) Move handling of bad password authentications into a platform
...
specific record_failed_login() function (affects AIX & Unicos).
2003-05-02 23:42:25 +10:00
Darren Tucker
3c01654deb
- (dtucker) Bug #544 : ignore invalid cmsg_type on Linux 2.0 kernels,
...
privsep should now work.
2003-05-02 20:48:21 +10:00
Damien Miller
eab4bae038
- (djm) Add back radix.o (used by AFS support), after it went missing from
...
Makefile many moons ago
- (djm) Apply "owl-always-auth" patch from Openwall/Solar Designer
- (djm) Fix blibpath specification for AIX/gcc
- (djm) Some systems have basename in -lgen. Fix from ayamura@ayamura.org
2003-04-29 23:22:40 +10:00
Ben Lindstrom
0e7f4363f3
- (bal) [defines.h progressmeter.c scp.c] Some more culling of non 64bit
...
hacked code.
2003-04-28 23:30:43 +00:00
Ben Lindstrom
f50ad1fd04
- (bal) auth2.c same changed as above.
2003-04-27 18:44:31 +00:00
Ben Lindstrom
683036ee2c
- (bal) auth1.c minor resync while looking at the code.
2003-04-27 18:41:30 +00:00
Ben Lindstrom
796b9a5495
- (bal) Since we don't support platforms lacking u_int_64. We may
...
as well clean out some of those evil #ifdefs
2003-04-27 18:01:37 +00:00
Ben Lindstrom
93b6b776ad
- (bal) Bug #541 : return; was dropped by mistake. Reported by
...
furrier@iglou.com
2003-04-27 17:55:33 +00:00
Damien Miller
2a3f20e397
- (djm) Fix missed log => logit occurance (reference by function pointer)
2003-04-09 21:12:00 +10:00
Damien Miller
bf2a0174e3
- hin@cvs.openbsd.org 2003/04/09 08:23:52
...
[servconf.c]
Don't include <krb.h> when compiling with Kerberos 5 support
2003-04-09 21:07:14 +10:00
Damien Miller
a0898b8505
- itojun@cvs.openbsd.org 2003/04/08 20:21:29
...
[*.c *.h]
rename log() into logit() to avoid name conflict. markus ok, from
netbsd
- (djm) XXX - Performed locally using:
"perl -p -i -e 's/(\s|^)log\(/$1logit\(/g' *.c *.h"
- (djm) Fix up missing include for packet.c
2003-04-09 21:05:52 +10:00
Damien Miller
b1ecd9cd97
- markus@cvs.openbsd.org 2003/04/07 08:29:57
...
[monitor_wrap.c]
typo: get correct counters; introduced during rekeying change.
2003-04-09 20:51:24 +10:00
Damien Miller
3bed191ca2
- itojun@cvs.openbsd.org 2003/04/03 07:25:27
...
[progressmeter.c]
$OpenBSD$
- itojun@cvs.openbsd.org 2003/04/03 10:17:35
[progressmeter.c]
remove $OpenBSD$, as other *.c does not have it.
2003-04-09 20:50:59 +10:00
Damien Miller
703ced55bb
- markus@cvs.openbsd.org 2003/04/02 14:36:26
...
[ssh-keysign.c]
potential segfault if KEY_UNSPEC; cjwatson@debian.org ; bug #526
2003-04-09 20:50:26 +10:00
Damien Miller
a5539d2698
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/04/02 09:48:07
[clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
[readconf.h serverloop.c sshconnect2.c]
reapply rekeying chage, tested by henning@, ok djm@
2003-04-09 20:50:06 +10:00
Damien Miller
a92a589e97
- (djm) Make the spec work with Redhat 9.0 (which renames sharutils)
2003-04-09 19:41:25 +10:00
Damien Miller
d186d74410
- (djm) Bug #539 : Specify creation mode with O_CREAT for lastlog. Report
...
from matth@eecs.berkeley.edu
2003-04-09 19:40:33 +10:00
Ben Lindstrom
c8a49d743a
- (bal) if IP_TOS is not found or broken don't try to compile in
...
packet_set_tos() function call. bug #527
2003-04-02 15:18:22 +00:00
Damien Miller
a0ab669c13
- (djm) Release 3.6.1p1
2003-04-01 21:47:16 +10:00
Damien Miller
b80e52ab6f
- (djm) Crank spec file versions
2003-04-01 21:46:53 +10:00
Damien Miller
13c1c7a75e
- markus@cvs.openbsd.org 2003/04/01 10:56:46
...
[version.h]
3.6.1
2003-04-01 21:45:26 +10:00
Damien Miller
d32090426b
- markus@cvs.openbsd.org 2003/04/01 10:31:26
...
[compat.c compat.h kex.c]
bugfix causes stalled connections for ssh.com < 3.0; noticed by ho@;
tested by ho@ and myself
2003-04-01 21:44:37 +10:00
Damien Miller
2dc074ef4b
- markus@cvs.openbsd.org 2003/04/01 10:10:23
...
[clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
[readconf.h serverloop.c sshconnect2.c]
rekeying bugfixes and automatic rekeying:
* both client and server rekey _automatically_
(a) after 2^31 packets, because after 2^32 packets
the sequence number for packets wraps
(b) after 2^(blocksize_in_bits/4) blocks
(see: draft-ietf-secsh-newmodes-00.txt)
(a) and (b) are _enabled_ by default, and only disabled for known
openssh versions, that don't support rekeying properly.
* client option 'RekeyLimit'
* do not reply to requests during rekeying
- markus@cvs.openbsd.org 2003/04/01 10:22:21
[clientloop.c monitor.c monitor_wrap.c packet.c packet.h readconf.c]
[readconf.h serverloop.c sshconnect2.c]
backout rekeying changes (for 3.6.1)
2003-04-01 21:43:39 +10:00
Damien Miller
495dca3518
- (djm) OpenBSD CVS Sync
...
- jmc@cvs.openbsd.org 2003/03/28 10:11:43
[scp.1 sftp.1 ssh.1 ssh-add.1 ssh-agent.1 ssh_config.5 sshd_config.5]
[ssh-keygen.1 ssh-keyscan.1 ssh-keysign.8]
- killed whitespace
- new sentence new line
- .Bk for arguments
ok markus@
2003-04-01 21:42:14 +10:00
Damien Miller
b3207e8061
- (djm) OpenBSD CVS Sync
...
- deraadt@cvs.openbsd.org 2003/03/26 04:02:51
[sftp-server.c]
one last fix to the tree: race fix broke stuff; pr 3169;
srp@srparish.net , help from djm
2003-03-26 16:01:11 +11:00
Damien Miller
68d893dfed
- (djm) Fix getpeerid support for 64 bit BE systems. From
...
Arnd Bergmann <arndb@de.ibm.com>
2003-03-25 09:07:52 +11:00
Damien Miller
62b6b17080
- Fix sshd BindAddress and -b options for systems using fake-getaddrinfo.
...
Report from murple@murple.net , diagnosis from dtucker@zip.com.au
2003-03-24 13:35:58 +11:00
Damien Miller
b062c293e0
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/03/23 19:02:00
[monitor.c]
unbreak rekeying for privsep; ok millert@
2003-03-24 09:12:09 +11:00
Tim Rice
009b23f6ab
[contrib/caldera/openssh.spec] workaround RPM quirk. Fix %files section
2003-03-20 20:50:41 -08:00
Ben Lindstrom
c8c548d248
- (bal) Disable Privsep for Tru64 after pre-authentication due to issues
...
with SIA. Also, clean up of tru64 support patch by Chris Adams
<cmadams@hiwaay.net>
2003-03-21 01:18:09 +00:00
Ben Lindstrom
a5a2648b81
- (bal) Collection of Cray patches (bsd-cray.h fix for CRAYT3E and improved
...
guessing rules)
2003-03-21 01:05:37 +00:00
Ben Lindstrom
d54d9382a4
- (bal) scp.c 'limit' conflicts with Cray. Rename to 'limitbw'
2003-03-21 00:55:32 +00:00
Ben Lindstrom
5bd6eb71da
- (bal) The days of lack of int64_t support are over. Sorry kids.
2003-03-21 00:34:34 +00:00
Damien Miller
4874c32531
- markus@cvs.openbsd.org 2003/03/17 11:43:47
...
[version.h]
enter 3.6
2003-03-20 10:11:34 +11:00
Damien Miller
05f5578e1f
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/03/17 10:38:38
[progressmeter.c]
don't print \n if backgrounded; from ho@
2003-03-20 10:08:05 +11:00
Tim Rice
4e4dc561ae
[configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h]
...
add nanosleep(). testing/corrections by Darren Tucker <dtucker@zip.com.au>
2003-03-18 10:21:40 -08:00
Damien Miller
cafbcc7334
- (djm) Fix return value checks for RAND_bytes. Report from
...
Steve G <linux_4ever@yahoo.com>
2003-03-17 16:13:53 +11:00
Damien Miller
c51d0735a4
- markus@cvs.openbsd.org 2003/03/13 11:44:50
...
[ssh-agent.c]
ssh-agent is similar to ssh-keysign (allows other processes to use
private rsa keys). however, it gets key over socket and not from
a file, so we have to do blinding here as well.
2003-03-15 11:37:09 +11:00
Damien Miller
ed33d3b4d2
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/03/13 11:42:19
[authfile.c ssh-keysign.c]
move RSA_blinding_on to generic key load method
2003-03-15 11:36:18 +11:00
Damien Miller
c1365e19b0
Fix bug #
2003-03-13 09:42:51 +11:00
Damien Miller
c9c1d3757f
- (djm) AIX package builder update from dtucker@zip.com.au
2003-03-10 12:10:45 +11:00
Damien Miller
933cc8fb9c
- (djm) Bug #245 : TTY problems on Solaris. Fix by stevesk@ and
...
dtucker@zip.com.au
2003-03-10 11:38:10 +11:00
Damien Miller
f211efc690
- (djm) One more portable-specific one from dlheine@suif.Stanford.EDU/
...
CLOUSEAU
2003-03-10 11:23:06 +11:00
Damien Miller
0011138d47
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2003/03/05 22:33:43
[channels.c monitor.c scp.c session.c sftp-client.c sftp-int.c]
[sftp-server.c ssh-add.c sshconnect2.c]
fix memory leaks; from dlheine@suif.Stanford.EDU/CLOUSEAU; ok djm@
2003-03-10 11:21:17 +11:00
Damien Miller
ca49a97788
- (djm) Fix some compile errors spotted by dtucker and his fabulous
...
tinderbox
2003-02-25 10:22:35 +11:00
Damien Miller
fe1f14375a
- (djm) Bug #456 : Support for NEC SX6 with Unicos; from wendyp@cray.com
2003-02-24 15:45:42 +11:00