Ben Lindstrom
34b7320a9d
- (bal) Minor OpenSC updates. Fix up header locations and update
...
README.smartcard provided by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-08 18:37:07 +00:00
Kevin Steves
265c9d00c3
- (stevesk) wrap munmap() with HAVE_MMAP also.
2002-04-07 22:36:49 +00:00
Kevin Steves
7ff911216b
- (stevesk) --with-privsep-user; default sshd
2002-04-07 19:22:54 +00:00
Kevin Steves
b1184bbf29
- (stevesk) remove configure support for poll.h; it was removed
...
from sshd.c a long time ago.
2002-04-07 18:12:03 +00:00
Kevin Steves
86b9fe6a77
- (stevesk) HAVE_MMAP and HAVE_SYS_MMAN_H and use them in
...
monitor_mm.c
2002-04-07 17:08:53 +00:00
Kevin Steves
c3c825575c
- (stevesk) [monitor_fdpass.c] fatal() for UsePrivilegeSeparation=yes
...
and no fd passing support.
2002-04-07 16:39:12 +00:00
Kevin Steves
a44e0351ee
- (stevesk) HAVE_CONTROL_IN_MSGHDR; not used right now.
...
Future: we may want to test if fd passing works correctly.
2002-04-07 16:18:03 +00:00
Ben Lindstrom
fdee8ef0ac
- (bal) We no longer use atexit()/xatexit()/on_exit()
2002-04-06 23:52:02 +00:00
Ben Lindstrom
0318801591
- (bal) Quiet down configure.ac if /bin/test does not exist.
2002-04-06 20:30:07 +00:00
Ben Lindstrom
8ff2a8d2c2
- (bal) Revered out of runtime IRIX runtime detection of joblimits. Code is
...
incomplete.
2002-04-06 18:58:31 +00:00
Ben Lindstrom
de3895d580
- mouring@cvs.openbsd.org 2002/04/06 18:24:09
...
[scp.c]
Fixes potental double // within path.
http://bugzilla.mindrot.org/show_bug.cgi?id=76
2002-04-06 18:29:59 +00:00
Ben Lindstrom
8d6017566c
- (bal) Slight update to OpenSC support. Better version checking. patch
...
by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-06 18:19:38 +00:00
Ben Lindstrom
06e9515eb8
- djm@cvs.openbsd.org 2002/04/06 00:30:08
...
[sftp-client.c]
Fix occasional corruption on upload due to bad reuse of request id, spotted
by chombier@mac.com ; ok markus@
2002-04-06 04:16:45 +00:00
Ben Lindstrom
dc0594cc54
- (bal) Added MAP_FAILED to allow AIX and Trusted HP to compile.
2002-04-06 04:11:28 +00:00
Damien Miller
12db56ba2f
- (djm) Typo in Suse SPEC file. Fix from Carsten Grohmann
...
<carsten.grohmann@dr-baldeweg.de>
2002-04-06 11:12:52 +10:00
Ben Lindstrom
a11e270115
- stevesk@cvs.openbsd.org 2002/04/05 20:56:21
...
[sshd.8]
clarify sshrc some and handle X11UseLocalhost=yes; ok markus@
2002-04-05 22:18:48 +00:00
Ben Lindstrom
924144e650
- (bal) Too many <sys/queue.h> issues. Remove all workarounds and
...
using internal version only.
2002-04-05 20:23:35 +00:00
Ben Lindstrom
a42694fa25
- (bal) Patch for OpenSC SmartCard library; ok markus@; patch by
...
Juha Yrjölä <jyrjola@cc.hut.fi>
- (bal) Minor documentation update to reflect smartcard library
support changes.
2002-04-05 16:11:45 +00:00
Ben Lindstrom
8a725a843d
- markus@cvs.openbsd.org 2002/04/03 09:26:11
...
[cipher.c myproposal.h]
re-add rijndael-cbc@lysator.liu.se for MacSSH; ash@lab.poc.net
2002-04-04 22:10:38 +00:00
Kevin Steves
e683e76439
- (stevesk) [auth-pam.c auth-pam.h auth-passwd.c auth-sia.c auth-sia.h
...
auth1.c auth2.c] PAM, OSF_SIA password auth cleanup; from djm.
2002-04-04 19:02:28 +00:00
Ben Lindstrom
af40bc6a72
- (bal) mispelling in uidswap.c (portable only)
2002-04-03 03:36:54 +00:00
Ben Lindstrom
07739fe305
- markus@cvs.openbsd.org 2002/04/02 20:11:38
...
[ssh-rsa.c]
ignore SSH_BUG_SIGBLOB for ssh-rsa; #187
2002-04-03 03:03:04 +00:00
Ben Lindstrom
2f3d52a2d6
- markus@cvs.openbsd.org 2002/04/02 17:37:48
...
[sftp.c]
always call log_init()
2002-04-02 21:06:18 +00:00
Ben Lindstrom
eecdf23531
- markus@cvs.openbsd.org 2002/04/02 11:49:39
...
[ssh-agent.c]
check $SHELL for -k and -d, too;
http://bugzilla.mindrot.org/show_bug.cgi?id=199
2002-04-02 21:03:51 +00:00
Ben Lindstrom
f26ff5b9d8
- markus@cvs.openbsd.org 2002/04/01 22:07:17
...
[sftp-client.c]
fallback to stat if server does not support lstat
2002-04-02 21:00:31 +00:00
Ben Lindstrom
a1d8114044
- markus@cvs.openbsd.org 2002/04/01 22:02:16
...
[sftp-client.c]
20480 is an upper limit for older server
2002-04-02 20:58:11 +00:00
Ben Lindstrom
1e259bb0bf
- (bal) CVS ID sync of uidswap.c
2002-04-02 20:53:39 +00:00
Ben Lindstrom
47fd8112b5
- markus@cvs.openbsd.org 2002/03/30 18:51:15
...
[monitor.c serverloop.c sftp-int.c sftp.c sshd.c]
check waitpid for EINTR; based on patch from peter@ifm.liu.se
2002-04-02 20:48:19 +00:00
Ben Lindstrom
03f3932829
- stevesk@cvs.openbsd.org 2002/03/29 19:18:33
...
[auth-rsa.c ssh-rsa.c ssh.h]
make RSA modulus minimum #define; ok markus@
2002-04-02 20:43:11 +00:00
Ben Lindstrom
0d0be02a29
- stevesk@cvs.openbsd.org 2002/03/29 19:16:22
...
[sshd.8]
RSA key modulus size minimum 768; ok markus@
2002-04-02 20:39:29 +00:00
Ben Lindstrom
c447fee9f1
- markus@cvs.openbsd.org 2002/03/29 18:59:32
...
[session.c session.h]
retrieve last login time before the pty is allocated, store per session
2002-04-02 20:35:35 +00:00
Ben Lindstrom
2bf56e2dba
- markus@cvs.openbsd.org 2002/03/28 15:34:51
...
[session.c]
do not call record_login twice (for use_privsep)
2002-04-02 20:32:46 +00:00
Ben Lindstrom
155b981494
- markus@cvs.openbsd.org 2002/03/27 22:21:45
...
[ssh-keygen.c]
try to import keys with extra trailing === (seen with ssh.com < 2.0.12)
2002-04-02 20:26:26 +00:00
Ben Lindstrom
cdb66e0e82
- (bal) Hand Sync of scp.c (reverted to upstream code)
...
- deraadt@cvs.openbsd.org 2002/03/30 17:45:46
[scp.c]
stretch banners
2002-04-02 20:17:43 +00:00
Kevin Steves
38c4a28a7e
- (stevesk) [auth1.c] fix password auth for protocol 1 when
...
!USE_PAM && !HAVE_OSF_SIA; merge issue.
2002-04-02 03:24:56 +00:00
Kevin Steves
bd1901b7dc
- (stevesk) [monitor.c] PAM should work again; will *not* work with
...
UsePrivilegeSeparation=yes.
2002-04-01 18:04:35 +00:00
Tim Rice
c85496222b
[sshconnect2.c] change uint32_t to u_int32_t
2002-03-31 12:49:38 -08:00
Tim Rice
49e457c43b
[configure.ac] use /bin/test -L to work around broken builtin on Solaris 8
2002-03-31 11:23:06 -08:00
Kevin Steves
117b06dec9
- (stevesk) [configure.ac] remove header check for sys/ttcompat.h
...
bug 167
2002-03-30 17:55:21 +00:00
Ben Lindstrom
b57a4bf93f
- mouring@cvs.openbsd.org 2002/03/27 11:45:42
...
[monitor.c]
monitor_allowed_key() returns int instead of pointer. ok markus@
2002-03-27 18:00:59 +00:00
Ben Lindstrom
599717246c
- markus@cvs.openbsd.org 2002/03/26 23:14:51
...
[kex.c]
generate a new cookie for each SSH2_MSG_KEXINIT message we send out
2002-03-27 17:42:57 +00:00
Ben Lindstrom
e1f9e324e9
- markus@cvs.openbsd.org 2002/03/26 23:13:03
...
[auth-rsa.c]
disallow RSA keys < 768 for protocol 1, too (rhosts-rsa and rsa auth)
2002-03-27 17:38:43 +00:00
Ben Lindstrom
57686a82a5
- markus@cvs.openbsd.org 2002/03/26 22:50:39
...
[channels.h]
CHANNEL_EFD_OUTPUT_ACTIVE is false for CHAN_CLOSE_RCVD, too
2002-03-27 17:36:41 +00:00
Ben Lindstrom
43a5e2f70e
- rees@cvs.openbsd.org 2002/03/26 18:46:59
...
[scard.c]
try_AUT0 in read_pubkey too, for those paranoid few who want to acl 'sh'
2002-03-27 17:33:17 +00:00
Ben Lindstrom
38a69e6b53
- markus@cvs.openbsd.org 2002/03/26 15:58:46
...
[readpass.c readpass.h sshconnect2.c]
client side support for PASSWD_CHANGEREQ
2002-03-27 17:28:46 +00:00
Ben Lindstrom
cd8bbce80b
- markus@cvs.openbsd.org 2002/03/26 15:23:40
...
[bufaux.c]
do not talk about packets in bufaux
2002-03-27 17:23:44 +00:00
Ben Lindstrom
eb041dca1f
- markus@cvs.openbsd.org 2002/03/26 11:37:05
...
[ssh.c]
update Copyright
2002-03-27 17:20:38 +00:00
Ben Lindstrom
f181384a6b
- markus@cvs.openbsd.org 2002/03/26 11:34:49
...
[ssh.1 sshd.8]
update to recent drafts
2002-03-27 17:18:31 +00:00
Ben Lindstrom
53f1830d6a
- (bal) 'pw' should be 'authctxt->pw' in auth1.c spotted by
...
kent@lysator.liu.se
2002-03-27 16:50:03 +00:00
Ben Lindstrom
28364ecf45
- stevesk@cvs.openbsd.org 2002/03/26 03:24:01
...
[monitor.h monitor_fdpass.h monitor_mm.h monitor_wrap.h]
$OpenBSD$
2002-03-26 03:42:20 +00:00
Ben Lindstrom
cf15944c23
- markus@cvs.openbsd.org 2002/03/25 21:13:51
...
[channels.c channels.h compat.c compat.h nchan.c]
don't send stderr data after EOF, accept this from older known (broken)
sshd servers only, fixes http://bugzilla.mindrot.org/show_bug.cgi?id=179
2002-03-26 03:26:24 +00:00
Ben Lindstrom
4f054607f0
- markus@cvs.openbsd.org 2002/03/25 21:04:02
...
[ssh.c]
simplify num_identity_files handling
2002-03-26 03:23:00 +00:00
Ben Lindstrom
c861547f34
- stevesk@cvs.openbsd.org 2002/03/25 20:12:10
...
[monitor_mm.c monitor_wrap.c]
ssize_t args use "%ld" and cast to (long)
size_t args use "%lu" and cast to (u_long)
ok markus@ and thanks millert@
2002-03-26 03:20:45 +00:00
Ben Lindstrom
0936a5bb72
- markus@cvs.openbsd.org 2002/03/25 17:34:27
...
[scard.c scard.h ssh-agent.c ssh-keygen.c ssh.c]
change sc_get_key to sc_get_keys and hide smartcard details in scard.c
2002-03-26 03:17:42 +00:00
Ben Lindstrom
5facb2bbc4
- markus@cvs.openbsd.org 2002/03/25 09:25:06
...
[auth-rh-rsa.c]
rm bogus comment
2002-03-26 03:08:47 +00:00
Ben Lindstrom
f6d367b91a
- markus@cvs.openbsd.org 2002/03/25 09:21:13
...
[auth-rsa.c]
return 0 (not NULL); tomh@po.crl.go.jp
2002-03-26 02:59:31 +00:00
Ben Lindstrom
2e9d866608
- stevesk@cvs.openbsd.org 2002/03/24 23:20:00
...
[monitor.c]
remove "\n" from fatal()
2002-03-26 02:49:34 +00:00
Ben Lindstrom
c2c6cbc527
- markus@cvs.openbsd.org 2002/03/24 18:05:29
...
[scard.c]
we need to figure out AUT0 for sc_private_encrypt, too
2002-03-26 02:44:44 +00:00
Ben Lindstrom
31ee7aeb15
- stevesk@cvs.openbsd.org 2002/03/24 17:53:16
...
[monitor_fdpass.c]
minor cleanup and more error checking; ok markus@
2002-03-26 02:36:29 +00:00
Ben Lindstrom
fcad1c92c9
- stevesk@cvs.openbsd.org 2002/03/24 17:27:03
...
[kexgex.c]
typo; ok markus@
2002-03-26 02:20:06 +00:00
Ben Lindstrom
8b08d8115d
- markus@cvs.openbsd.org 2002/03/24 16:01:13
...
[packet.c]
debug->debug3 for extra padding
2002-03-26 02:09:41 +00:00
Ben Lindstrom
3dc40f997b
- markus@cvs.openbsd.org 2002/03/24 16:00:27
...
[serverloop.c]
remove unused debug
2002-03-26 02:01:30 +00:00
Ben Lindstrom
f90f58d846
- stevesk@cvs.openbsd.org 2002/03/23 20:57:26
...
[sshd.c]
setproctitle() after preauth child; ok markus@
2002-03-26 01:53:03 +00:00
Kevin Steves
6205a18f55
- (stevesk) import OpenBSD <sys/tree.h> as "openbsd-compat/tree.h"
2002-03-26 00:12:49 +00:00
Kevin Steves
b4799a31a5
- (stevesk) [session.c] disable LOGIN_NEEDS_TERM until we are sure
...
it can be removed. only used on solaris. will no longer compile with
privsep shuffling.
2002-03-24 23:19:54 +00:00
Kevin Steves
4408c2098f
- (stevesk) [LICENCE] OpenBSD sync
2002-03-23 02:20:07 +00:00
Tim Rice
f29a6539c0
[cipher.c] fix problem with OpenBSD sync
2002-03-22 13:27:40 -08:00
Kevin Steves
4435a55a4b
- (stevesk) [defines.h] #define MAP_ANON MAP_ANONYMOUS for HP-UX; other
...
platforms may need this--I'm not sure. mmap() issues will need to be
addressed further.
2002-03-22 21:08:03 +00:00
Kevin Steves
219bef12c6
- (stevesk) [defines.h] hp-ux 11 has ancillary data style fd passing, but
...
is missing CMSG_LEN() and CMSG_SPACE() macros.
2002-03-22 20:53:32 +00:00
Kevin Steves
205cc1ef46
- (stevesk) [auth2.c] merge cleanup/sync
2002-03-22 20:43:05 +00:00
Kevin Steves
1adb120779
- (stevesk) [monitor_fdpass.c] support for access rights style file
...
descriptor passing
2002-03-22 19:32:53 +00:00
Kevin Steves
4846f4ab69
- (stevesk) configure and cpp __FUNCTION__ gymnastics to handle nielsisms
2002-03-22 18:19:53 +00:00
Kevin Steves
7e147607f5
- (stevesk) [monitor.c monitor_wrap.c] #ifdef HAVE_PW_CLASS_IN_PASSWD
2002-03-22 18:07:17 +00:00
Kevin Steves
939c9db9b1
- (stevesk) HAVE_ACCRIGHTS_IN_MSGHDR configure support
2002-03-22 17:23:25 +00:00
Ben Lindstrom
681d932634
- markus@cvs.openbsd.org 2002/03/21 23:07:37
...
[clientloop.c]
remove unused, sync w/ cmdline patch in my tree.
2002-03-22 03:53:00 +00:00
Ben Lindstrom
ba72d30aa5
- rees@cvs.openbsd.org 2002/03/21 22:44:05
...
[authfd.c authfd.h ssh-add.c ssh-agent.c ssh.c]
Add PIN-protection for secret key.
2002-03-22 03:51:06 +00:00
Ben Lindstrom
266ec63eb3
- rees@cvs.openbsd.org 2002/03/21 21:54:34
...
[scard.c scard.h ssh-keygen.c]
Add PIN-protection for secret key.
2002-03-22 03:47:38 +00:00
Ben Lindstrom
943481cc77
- markus@cvs.openbsd.org 2002/03/21 21:23:34
...
[sshd.c]
add privsep_preauth() and remove 1 goto; ok provos@
2002-03-22 03:43:46 +00:00
Ben Lindstrom
fa1336ff47
- markus@cvs.openbsd.org 2002/03/21 20:51:12
...
[sshd_config]
add privsep (off)
2002-03-22 03:40:58 +00:00
Ben Lindstrom
818659a163
- rees@cvs.openbsd.org 2002/03/21 18:08:15
...
[scard.c]
In sc_put_key(), sc_reader_id should be id.
2002-03-22 03:38:35 +00:00
Ben Lindstrom
eda98a728d
- markus@cvs.openbsd.org 2002/03/21 16:58:13
...
[clientloop.c]
remove unused
2002-03-22 03:35:48 +00:00
Ben Lindstrom
70e3ad8231
- markus@cvs.openbsd.org 2002/03/21 16:57:15
...
[scard.c]
remove const
2002-03-22 03:33:43 +00:00
Ben Lindstrom
0b675b1659
- markus@cvs.openbsd.org 2002/03/21 16:38:06
...
[scard.c]
make compile w/ openssl 0.9.7
2002-03-22 03:28:11 +00:00
Ben Lindstrom
5589f4b55f
- jakob@cvs.openbsd.org 2002/03/21 15:17:26
...
[clientloop.c ssh.1]
add built-in command line for adding new port forwardings on the fly.
based on a patch from brian wellington. ok markus@.
2002-03-22 03:24:32 +00:00
Ben Lindstrom
58b391b1bd
- markus@cvs.openbsd.org 2002/03/21 10:21:20
...
[ssh-add.c]
ignore errors for nonexisting default keys in ssh-add,
fixes http://bugzilla.mindrot.org/show_bug.cgi?id=158
Last patch was SUPPOSE to be:
- stevesk@cvs.openbsd.org 2002/03/20 21:08:08
[sshd.c]
strerror() on chdir() fail; ok provos@
But it got co-mingled. <sigh> Flog me at will.
2002-03-22 03:21:16 +00:00
Ben Lindstrom
1ee9ec32a3
- markus@cvs.openbsd.org 2002/03/21 10:21:20
...
[ssh-add.c]
ignore errors for nonexisting default keys in ssh-add,
fixes http://bugzilla.mindrot.org/show_bug.cgi?id=158
2002-03-22 03:14:45 +00:00
Ben Lindstrom
c743134191
- stevesk@cvs.openbsd.org 2002/03/20 19:12:25
...
[servconf.c servconf.h ssh.h sshd.c]
for unprivileged user, group do:
pw=getpwnam(SSH_PRIVSEP_USER); do_setusercontext(pw). ok provos@
2002-03-22 03:11:49 +00:00
Ben Lindstrom
f34e4eb6c7
- markus@cvs.openbsd.org 2002/03/19 15:31:47
...
[auth.c]
check for NULL; from provos@
2002-03-22 03:08:30 +00:00
Ben Lindstrom
7ebb635d81
- markus@cvs.openbsd.org 2002/03/19 14:27:39
...
[auth.c auth1.c auth2.c]
make getpwnamallow() allways call pwcopy()
2002-03-22 03:04:08 +00:00
Ben Lindstrom
6328ab3989
- markus@cvs.openbsd.org 2002/03/19 10:49:35
...
[auth-krb5.c auth-rh-rsa.c auth.c cipher.c key.c misc.h packet.c session.c
sftp-client.c sftp-glob.h sftp.c ssh-add.c ssh.c sshconnect2.c sshd.c
ttymodes.c]
KNF whitespace
2002-03-22 02:54:23 +00:00
Ben Lindstrom
08105192fd
- markus@cvs.openbsd.org 2002/03/19 10:35:39
...
[auth-options.c auth.h session.c session.h sshd.c]
clean up prototypes
2002-03-22 02:50:06 +00:00
Ben Lindstrom
cb1f60efb5
- mpech@cvs.openbsd.org 2002/03/19 06:32:56
...
[sftp-int.c]
use xfree() after xstrdup().
markus@ ok
2002-03-22 02:47:28 +00:00
Ben Lindstrom
85520a6705
- stevesk@cvs.openbsd.org 2002/03/19 05:23:08
...
[sshd.8]
Banner has no default.
2002-03-22 02:44:40 +00:00
Ben Lindstrom
7a7edf77ed
- stevesk@cvs.openbsd.org 2002/03/19 03:03:43
...
[pathnames.h servconf.c servconf.h sshd.c]
_PATH_PRIVSEP_CHROOT_DIR; ok provos@
2002-03-22 02:42:37 +00:00
Ben Lindstrom
01426a67c8
- stevesk@cvs.openbsd.org 2002/03/18 23:52:51
...
[servconf.c]
UnprivUser/UnprivGroup usable now--specify numeric user/group; ok
provos@
2002-03-22 02:40:03 +00:00
Ben Lindstrom
191c8e5eb9
- provos@cvs.openbsd.org 2002/03/18 17:59:09
...
[sshd.8]
document UsePrivilegeSeparation
2002-03-22 02:37:50 +00:00
Ben Lindstrom
000dda5373
- provos@cvs.openbsd.org 2002/03/18 17:53:08
...
[sshd.8]
credits for privsep
2002-03-22 02:33:12 +00:00
Ben Lindstrom
7a2073c50b
- provos@cvs.openbsd.org 2002/03/18 17:50:31
...
[auth-bsdauth.c auth-options.c auth-rh-rsa.c auth-rsa.c auth-skey.c auth.h
auth1.c auth2-chall.c auth2.c kex.c kex.h kexdh.c kexgex.c servconf.c
session.h servconf.h serverloop.c session.c sshd.c]
integrate privilege separated openssh; its turned off by default for now.
work done by me and markus@
applied, but outside of ensure that smaller code bits migrated with
their owners.. no work was tried to 'fix' it to work. =) Later project!
2002-03-22 02:30:41 +00:00
Ben Lindstrom
0f345f5ee1
- provos@cvs.openbsd.org 2002/03/18 17:31:54
...
[compress.c]
export compression streams for ssh-privsep
2002-03-22 01:51:24 +00:00
Ben Lindstrom
88aa1b4527
- provos@cvs.openbsd.org 2002/03/18 17:25:29
...
[bufaux.c bufaux.h]
buffer_skip_string and extra sanity checking; needed by ssh-privsep
2002-03-22 01:47:52 +00:00