Ben Lindstrom
9f04903c50
- stevesk@cvs.openbsd.org 2002/06/20 19:56:07
...
[ssh.1 sshd.8]
move configuration file options from ssh.1/sshd.8 to
ssh_config.5/sshd_config.5; ok deraadt@ millert@
2002-06-21 00:59:05 +00:00
Ben Lindstrom
402c6cc681
- markus@cvs.openbsd.org 2002/06/19 18:01:00
...
[cipher.c monitor.c monitor_wrap.c packet.c packet.h]
make the monitor sync the transfer ssh1 session key;
transfer keycontext only for RC4 (this is still depends on EVP
implementation details and is broken).
2002-06-21 00:43:42 +00:00
Ben Lindstrom
cb72e4f6d2
- deraadt@cvs.openbsd.org 2002/06/19 00:27:55
...
[auth-bsdauth.c auth-skey.c auth1.c auth2-chall.c auth2-none.c authfd.c
authfd.h monitor_wrap.c msg.c nchan.c radix.c readconf.c scp.c sftp.1
ssh-add.1 ssh-add.c ssh-agent.1 ssh-agent.c ssh-keygen.1 ssh-keygen.c
ssh-keysign.c ssh.1 sshconnect.c sshconnect.h sshconnect2.c ttymodes.c
xmalloc.h]
KNF done automatically while reading....
2002-06-21 00:41:51 +00:00
Ben Lindstrom
115422f918
- (bal) Cygwin special handling of empty passwords wrong. Patch by
...
vinschen@redhat.com
2002-06-21 00:26:22 +00:00
Ben Lindstrom
45933dd9aa
- deraadt@cvs.openbsd.org 2002/06/17 06:05:56
...
[scp.c]
make usage like man page
2002-06-21 00:10:58 +00:00
Ben Lindstrom
61c183bea3
- itojun@cvs.openbsd.org 2002/06/16 21:30:58
...
[ssh-keyscan.c]
use TAILQ_xx macro. from lukem@netbsd. markus ok
2002-06-21 00:09:54 +00:00
Ben Lindstrom
2b266b7f08
- markus@cvs.openbsd.org 2002/06/15 01:27:48
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
remove the CONSTRAIN_IDENTITY messages and introduce a new
ADD_ID message with contraints instead. contraints can be
only added together with the private key.
2002-06-21 00:08:39 +00:00
Ben Lindstrom
c90f8a98ea
- markus@cvs.openbsd.org 2002/06/15 00:07:38
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
fix stupid typo
2002-06-21 00:06:54 +00:00
Ben Lindstrom
4eb4c4e1ef
- markus@cvs.openbsd.org 2002/06/15 00:01:36
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
break agent key lifetime protocol and allow other contraints for key
usage.
2002-06-21 00:04:48 +00:00
Ben Lindstrom
f0bfa839bd
- (bal) Fixed AIX environment handling, use setpcred() instead of existing
...
code. (Bugzilla Bug 261)
2002-06-21 00:01:18 +00:00
Ben Lindstrom
3c73dfe55e
- todd@cvs.openbsd.org 2002/06/14 21:35:00
...
[monitor_wrap.c]
spelling; from Brian Poole <raj@cerias.purdue.edu>
2002-06-20 23:53:53 +00:00
Ben Lindstrom
0e23ebcc8b
- (bal) typo of setgroup for cygwin. Patch by vinschen@redhat.com
2002-06-13 21:34:57 +00:00
Ben Lindstrom
b7ae94dd0b
- (bal) Some platforms don't have ONLCR (Notable Mint)
2002-06-12 17:32:30 +00:00
Ben Lindstrom
837461bf9a
- (bal) Build noop setgroups() for cygwin to clean up code (For other
...
platforms without the setgroups() requirement, you MUST define
SETGROUPS_NOOP in the configure.ac) Based on patch by vinschen@redhat.com
2002-06-12 16:57:14 +00:00
Ben Lindstrom
da394cae04
- markus@cvs.openbsd.org 2002/06/12 01:09:52
...
[ssh.c]
ssh_connect returns 0 on success
2002-06-12 16:11:12 +00:00
Ben Lindstrom
2415757253
- markus@cvs.openbsd.org 2002/06/11 23:03:54
...
[ssh.c]
remove unused cruft.
2002-06-12 16:09:39 +00:00
Ben Lindstrom
1aa6427c0f
- (bal) Cygwin fix up from swap uid clean up in ssh.c patch by
...
vinschen@redhat.com
2002-06-11 20:28:05 +00:00
Ben Lindstrom
9a17c9a568
- itojun@cvs.openbsd.org 2002/06/11 08:11:45
...
[canohost.c]
use "ntop" only after initialized
2002-06-11 16:47:22 +00:00
Ben Lindstrom
ce0f634270
- mpech@cvs.openbsd.org 2002/06/11 05:46:20
...
[auth-krb4.c monitor.h serverloop.c session.c ssh-agent.c sshd.c]
pid_t cleanup. Markus need this now to keep hacking.
markus@, millert@ ok
2002-06-11 16:42:49 +00:00
Ben Lindstrom
f9c4884c8e
- markus@cvs.openbsd.org 2002/06/11 04:14:26
...
[ssh.c sshconnect.c sshconnect.h]
no longer use uidswap.[ch] from the ssh client
run less code with euid==0 if ssh is installed setuid root
just switch the euid, don't switch the complete set of groups
(this is only needed by sshd). ok provos@
2002-06-11 16:37:51 +00:00
Ben Lindstrom
8bb6f36c8f
- markus@cvs.openbsd.org 2002/06/10 22:28:41
...
[channels.c channels.h session.c]
move creation of agent socket to session.c; no need for uidswapping
in channel.c.
2002-06-11 15:59:02 +00:00
Ben Lindstrom
914d03758b
- stevesk@cvs.openbsd.org 2002/06/10 21:21:10
...
[ssh_config]
update defaults for RhostsRSAAuthentication and RhostsAuthentication
here too (all options commented out with default value).
2002-06-11 15:55:01 +00:00
Ben Lindstrom
2bf8276393
- stevesk@cvs.openbsd.org 2002/06/10 17:45:20
...
[readconf.c ssh.1]
change RhostsRSAAuthentication and RhostsAuthentication default to no
since ssh is no longer setuid root by default; ok markus@
2002-06-11 15:53:05 +00:00
Ben Lindstrom
1775c9c97a
- stevesk@cvs.openbsd.org 2002/06/10 17:36:23
...
[ssh-add.1 ssh-add.c]
use convtime() to parse and validate key lifetime. can now
use '-t 2h' etc. ok markus@ provos@
2002-06-11 15:51:54 +00:00
Ben Lindstrom
11d470de34
- stevesk@cvs.openbsd.org 2002/06/10 16:56:30
...
[ssh-keysign.8]
merge in stuff from my man page; ok markus@
2002-06-11 15:50:13 +00:00
Ben Lindstrom
2779d28a0f
- stevesk@cvs.openbsd.org 2002/06/10 16:53:06
...
[auth-rsa.c ssh-rsa.c]
display minimum RSA modulus in error(); ok markus@
2002-06-11 15:47:42 +00:00
Ben Lindstrom
18a32a7efa
- itojun@cvs.openbsd.org 2002/06/09 22:17:21
...
[sshconnect.c]
pass salen to sockaddr_ntop so that we are happy on linux/solaris
2002-06-11 15:46:34 +00:00
Ben Lindstrom
5cac423871
- stevesk@cvs.openbsd.org 2002/06/09 22:15:15
...
[ssh.1]
update for no setuid root and ssh-keysign; ok deraadt@
2002-06-11 15:45:02 +00:00
Ben Lindstrom
494709decb
- (bal) ssh-agent.c RCSD fix (|unexpand already done)
2002-06-11 15:42:53 +00:00
Ben Lindstrom
05efee1092
- (bal) RCSID tag updates on channels.c, clientloop.c, nchan.c,
...
sftp-client.c, ssh-agenet.c, ssh-keygen.c and connect.h (we did unexpand
independant of them)
2002-06-09 20:20:58 +00:00
Ben Lindstrom
2749e1c8f5
- markus@cvs.openbsd.org 2002/06/09 04:33:27
...
[sshconnect.c]
abort() - > fatal()
2002-06-09 20:16:22 +00:00
Ben Lindstrom
159ac2e8cd
- itojun@cvs.openbsd.org 2002/06/08 21:15:27
...
[sshconnect.c]
always use getnameinfo. (diag message only)
2002-06-09 20:14:54 +00:00
Ben Lindstrom
2e17b08e48
- markus@cvs.openbsd.org 2002/06/08 12:46:14
...
[readconf.c]
silently ignore deprecated options, since FallBackToRsh might be passed
by remote scp commands.
2002-06-09 20:13:27 +00:00
Ben Lindstrom
af0c6d6a8c
- markus@cvs.openbsd.org 2002/06/08 12:36:53
...
[scp.c]
remove FallBackToRsh
2002-06-09 20:06:29 +00:00
Ben Lindstrom
7a7483d72e
- markus@cvs.openbsd.org 2002/06/08 05:41:18
...
[ssh_config]
remove FallBackToRsh/UseRsh
2002-06-09 20:05:35 +00:00
Ben Lindstrom
1c2bafebb3
- markus@cvs.openbsd.org 2002/06/08 05:40:01
...
[readconf.c]
just warn about Deprecated options for now
2002-06-09 20:04:50 +00:00
Ben Lindstrom
4daea86fd4
- markus@cvs.openbsd.org 2002/06/08 05:17:01
...
[readconf.c readconf.h ssh.1 ssh.c]
deprecate FallBackToRsh and UseRsh; patch from djm@
2002-06-09 20:04:02 +00:00
Ben Lindstrom
a20715788d
- markus@cvs.openbsd.org 2002/06/08 05:07:09
...
[ssh-keysign.c]
only accept 20 byte session ids
2002-06-09 20:01:48 +00:00
Ben Lindstrom
ece420413b
- markus@cvs.openbsd.org 2002/06/08 05:07:56
...
[ssh.c]
nuke ptrace comment
2002-06-09 20:00:09 +00:00
Ben Lindstrom
2ab1968da2
- (bal) Removed --{enable/disable}-suid-ssh
...
this was mistakenly commited with the __progname fix to ssh-keysign.
2002-06-07 16:49:11 +00:00
Ben Lindstrom
378a417389
- (bal) use 'LOGIN_PROGRAM' not '/usr/bin/login' in session.c patch by
...
Bertrand.Velle@apogee-com.fr
2002-06-07 14:49:56 +00:00
Ben Lindstrom
3545352dc4
- (bal) Missed __progname in ssh-keysign.c patch by dtucker@zip.com.au
2002-06-07 14:37:00 +00:00
Ben Lindstrom
03bab2861e
- (bal) Reverse logic, use __func__ first since it's C99
2002-06-07 03:19:35 +00:00
Ben Lindstrom
db41d2390c
- (bal) ssh-keysign should build and install correctly now. Phase two
...
would be to clean out any dead wood and disable ssh setuid on install.
2002-06-07 03:11:38 +00:00
Ben Lindstrom
b85ab30a6e
- (bal) Refixed auth2.c. It was never fully commited while spliting out
...
authentication to different files.
2002-06-07 02:05:25 +00:00
Ben Lindstrom
4eeccc79f6
- (bal) monitor_mm.c typos.
2002-06-07 01:57:25 +00:00
Ben Lindstrom
88d26ed408
- (bal) Forgot to add msg.c Makefile.in.
2002-06-07 01:53:59 +00:00
Ben Lindstrom
a93f12f396
- (bal) Missed msg.[ch] in merge. Required for ssh-keysign.
2002-06-07 01:51:06 +00:00
Ben Lindstrom
937df1d630
- markus@cvs.openbsd.org 2002/06/06 17:30:11
...
[sftp-server.c]
use get_int() macro (hide iqueue)
2002-06-06 21:58:35 +00:00
Ben Lindstrom
2c14047ada
- markus@cvs.openbsd.org 2002/06/06 17:12:44
...
[sftp-server.c]
discard remaining bytes of current request; ok provos@
2002-06-06 21:57:54 +00:00
Ben Lindstrom
d9d6ab6372
- stevesk@cvs.openbsd.org 2002/06/06 01:09:41
...
[monitor.h]
no trailing comma in enum; china@thewrittenword.com
2002-06-06 21:57:01 +00:00
Ben Lindstrom
61d328acf9
- markus@cvs.openbsd.org 2002/06/05 21:55:44
...
[authfd.c authfd.h ssh-add.1 ssh-add.c ssh-agent.c]
ssh-add -t life, Set lifetime (in seconds) when adding identities;
ok provos@
2002-06-06 21:54:57 +00:00
Ben Lindstrom
163f3b8f6b
- markus@cvs.openbsd.org 2002/06/05 20:56:39
...
[ssh-add.c]
add -x/-X to usage
2002-06-06 21:53:11 +00:00
Ben Lindstrom
2f71704b42
- markus@cvs.openbsd.org 2002/06/05 19:57:12
...
[authfd.c authfd.h ssh-add.1 ssh-add.c ssh-agent.c]
ssh-add -x for lock and -X for unlocking the agent.
todo: encrypt private keys with locked...
2002-06-06 21:52:03 +00:00
Ben Lindstrom
21d1ed8303
- markus@cvs.openbsd.org 2002/06/05 16:48:54
...
[ssh-agent.c]
copy current request into an extra buffer and just flush this
request on errors, ok provos@
2002-06-06 21:48:57 +00:00
Ben Lindstrom
b7788f3ebe
- markus@cvs.openbsd.org 2002/06/05 16:08:07
...
[ssh-agent.1 ssh-agent.c]
'-a bind_address' binds the agent to user-specified unix-domain
socket instead of /tmp/ssh-XXXXXXXX/agent.<pid>; ok djm@ (some time ago).
2002-06-06 21:46:08 +00:00
Ben Lindstrom
22fa01cdea
- markus@cvs.openbsd.org 2002/06/05 16:08:07
...
[ssh-agent.1 ssh-agent.c]
'-a bind_address' binds the agent to user-specified unix-domain
socket instead of /tmp/ssh-XXXXXXXX/agent.<pid>; ok djm@ (some time ago).
2002-06-06 21:46:07 +00:00
Ben Lindstrom
7d9c38f37a
- markus@cvs.openbsd.org 2002/06/04 23:05:49
...
[cipher.c monitor.c monitor_fdpass.c monitor_mm.c monitor_wrap.c]
__FUNCTION__ -> __func__
NOTE: This includes all portable references also.
2002-06-06 21:40:51 +00:00
Ben Lindstrom
3dca4f55f2
- markus@cvs.openbsd.org 2002/06/04 23:02:06
...
[packet.c]
remove __FUNCTION__
2002-06-06 20:59:25 +00:00
Ben Lindstrom
f67e07711f
- markus@cvs.openbsd.org 2002/06/04 19:53:40
...
[monitor.c]
save the session id (hash) for ssh2 (it will be passed with the
initial sign request) and verify that this value is used during
authentication; ok provos@
2002-06-06 20:58:19 +00:00
Ben Lindstrom
dcf6bfbfbd
- markus@cvs.openbsd.org 2002/06/04 19:42:35
...
[monitor.c]
only allow enabled authentication methods; ok provos@
2002-06-06 20:57:17 +00:00
Ben Lindstrom
2e14bc71e6
- deraadt@cvs.openbsd.org 2002/06/03 12:04:07
...
[ssh.h]
compatiblity -> compatibility
decriptor -> descriptor
authentciated -> authenticated
transmition -> transmission
2002-06-06 20:56:07 +00:00
Ben Lindstrom
ceae9d1c33
- markus@cvs.openbsd.org 2002/05/31 13:20:50
...
[ssh-rsa.c]
pad received signature with leading zeros, because RSA_verify expects
a signature of RSA_size. the drafts says the signature is transmitted
unpadded (e.g. putty does not pad), reported by anakin@pobox.com
2002-06-06 20:55:04 +00:00
Ben Lindstrom
01fff0c9d4
- markus@cvs.openbsd.org 2002/05/31 13:16:48
...
[key.c]
add comment:
key_verify returns 1 for a correct signature, 0 for an incorrect signature
and -1 on error.
2002-06-06 20:54:07 +00:00
Ben Lindstrom
511bb24c5b
- markus@cvs.openbsd.org 2002/05/31 11:35:15
...
[auth.h auth2.c]
move Authmethod definitons to per-method file.
NOTE: The rest of this patch is with the import of the auth2-*.c files.
2002-06-06 20:52:37 +00:00
Ben Lindstrom
cec2ea8d02
- markus@cvs.openbsd.org 2002/05/31 10:30:33
...
[sshconnect2.c]
extent ssh-keysign protocol:
pass # of socket-fd to ssh-keysign, keysign verfies locally used
ip-address using this socket-fd, restricts fake local hostnames
to actual local hostnames; ok stevesk@
2002-06-06 20:51:04 +00:00
Ben Lindstrom
f088f4374a
- markus@cvs.openbsd.org 2002/05/30 08:07:31
...
[cipher.c]
use rijndael/aes from libcrypto (openssl >= 0.9.7) instead of
our own implementation. allow use of AES hardware via libcrypto,
ok deraadt@
2002-06-06 20:50:07 +00:00
Ben Lindstrom
a26ea63f8a
- markus@cvs.openbsd.org 2002/05/29 11:21:57
...
[sshd.c]
don't start if privsep is enabled and SSH_PRIVSEP_USER or
_PATH_PRIVSEP_CHROOT_DIR are missing; ok deraadt@
2002-06-06 20:46:25 +00:00
Ben Lindstrom
20abb75f53
- stevesk@cvs.openbsd.org 2002/05/29 03:06:30
...
[ssh.1 sshd.8]
spelling
2002-06-06 20:45:33 +00:00
Ben Lindstrom
10d9936413
- stevesk@cvs.openbsd.org 2002/05/28 21:24:00
...
[uidswap.c]
use correct function name in fatal()
[See the patch above, I saw it before apply the next patch. <sigh>]
2002-06-06 20:44:06 +00:00
Ben Lindstrom
ca8943e6de
- (bal) Corrected debug() in uidswap.c to match upstream.
2002-06-06 20:42:04 +00:00
Ben Lindstrom
abff1dd050
- stevesk@cvs.openbsd.org 2002/05/28 17:28:02
...
[uidswap.c]
format spec change/casts and some KNF; ok markus@
2002-06-06 20:38:49 +00:00
Ben Lindstrom
105ccbe192
- stevesk@cvs.openbsd.org 2002/05/28 16:45:27
...
[monitor_mm.c]
print strerror(errno) on mmap/munmap error; ok markus@
2002-06-06 20:33:06 +00:00
Ben Lindstrom
033a49c7cc
- stevesk@cvs.openbsd.org 2002/05/26 20:35:10
...
[ssh.1]
sort ChallengeResponseAuthentication; ok markus@
2002-06-06 20:30:28 +00:00
Ben Lindstrom
855bf3ac3c
- markus@cvs.openbsd.org 2002/05/25 18:51:07
...
[auth.h auth2.c auth2-hostbased.c auth2-kbdint.c auth2-none.c
auth2-passwd.c auth2-pubkey.c Makefile.in]
split auth2.c into one file per method; ok provos@/deraadt@
NOTE: Merged back noticable cygwin and pam stuff. May need review to
ensure I did not miss anything.
2002-06-06 20:27:55 +00:00
Ben Lindstrom
4887da222b
- markus@cvs.openbsd.org 2002/05/25 08:50:39
...
[sshconnect2.c]
execlp->execl; from stevesk
2002-06-06 20:05:57 +00:00
Ben Lindstrom
5206b951c6
- markus@cvs.openbsd.org 2002/05/24 08:45:14
...
[sshconnect2.c]
stat ssh-keysign first, print error if stat fails;
some debug->error; fix comment
2002-06-06 19:59:29 +00:00
Ben Lindstrom
9e5bb579f9
- markus@cvs.openbsd.org 2002/05/23 19:39:34
...
[ssh.c]
add comment about ssh-keysign
2002-06-06 19:58:27 +00:00
Ben Lindstrom
1bad256822
- markus@cvs.openbsd.org 2002/05/23 19:24:30
...
[authfile.c authfile.h pathnames.h ssh.c sshconnect.c sshconnect.h
sshconnect1.c sshconnect2.c ssh-keysign.8 ssh-keysign.c Makefile.in]
add /usr/libexec/ssh-keysign: a setuid helper program for hostbased
authentication in protocol v2 (needs to access the hostkeys).
Note: Makefile.in untested. Will test after merge is finished.
2002-06-06 19:57:33 +00:00
Ben Lindstrom
f666fec2d5
- deraadt@cvs.openbsd.org 2002/05/22 23:18:25
...
[ssh.c sshd.c]
spelling; abishoff@arc.nasa.gov
2002-06-06 19:51:58 +00:00
Ben Lindstrom
38ed63d759
- deraadt@cvs.openbsd.org 2002/05/19 20:54:52
...
[log.h]
extra commas in enum not 100% portable
2002-06-06 19:51:06 +00:00
Ben Lindstrom
fac7769f64
- stevesk@cvs.openbsd.org 2002/05/16 22:09:59
...
[session.c ssh.c]
don't limit xauth pathlen on client side and longer print length on
server when debug; ok markus@
2002-06-06 19:49:54 +00:00
Ben Lindstrom
6a24641365
- markus@cvs.openbsd.org 2002/05/16 22:02:50
...
[cipher.c kex.h mac.c]
fix warnings (openssl 0.9.7 requires const)
2002-06-06 19:48:16 +00:00
Ben Lindstrom
fb62a69488
- markus@cvs.openbsd.org 2002/05/15 21:56:38
...
[servconf.c sshd.8 sshd_config]
re-enable privsep and disable setuid for post-3.2.2
2002-06-06 19:47:11 +00:00
Kevin Steves
df75dd21f5
- (stevesk) [channels.c] bug #164 patch from YOSHIFUJI Hideaki (changed
...
setsockopt from debug to error for now).
2002-06-04 20:52:19 +00:00
Tim Rice
28bbb0c458
[configure.ac.orig monitor_fdpass.c] Enahnce msghdr tests to address
...
build problem on Irix reported by Dave Love <d.love@dl.ac.uk>. Back out
last monitor_fdpass.c changes that are no longer needed with new tests.
Patch tested on Irix by Jan-Frode Myklebust <janfrode@parallab.uib.no>
2002-05-27 17:37:32 -07:00
Damien Miller
8ce8296fd0
sync scard/
2002-05-22 14:24:01 +10:00
Damien Miller
23dc10ddac
crank rpm spec versions
2002-05-22 14:14:54 +10:00
Damien Miller
667fb25f47
Crank version
...
(also missed changelog message)
2002-05-22 14:14:00 +10:00
Damien Miller
74cc5bb851
fix spelling mistakes spotted by Solar Designer <solar@openwall.com>
2002-05-22 11:02:15 +10:00
Kevin Steves
bc5bb55755
- (stevesk) [sshd.c] #ifndef HAVE_CYGWIN for setgroups()
2002-05-21 17:59:13 +00:00
Kevin Steves
c5041acef3
- (stevesk) [sshd.c] bug 245; disable setsid() for now
2002-05-21 17:50:21 +00:00
Tim Rice
9de793cc6c
[configure.ac] remove extra MD5_MSG="no" line.
2002-05-17 08:59:22 -07:00
Ben Lindstrom
4e67d38a7e
- (bal) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2002/05/15 21:05:29
[version.h]
enter OpenSSH_3.2.2
- (bal) Caldara, Suse, and Redhat openssh.specs updated.
2002-05-15 21:50:14 +00:00
Ben Lindstrom
c5c15dde32
- markus@cvs.openbsd.org 2002/05/15 21:02:53
...
[servconf.c sshd.8 sshd_config]
disable privsep and enable setuid for the 3.2.2 release
2002-05-15 21:37:34 +00:00
Ben Lindstrom
c57bbf158d
- millert@cvs.openbsd.org 2002/05/06 23:34:33
...
[ssh.1 sshd.8]
Kill/adjust r(login|exec)d? references now that those are no longer in
the tree.
2002-05-15 21:36:45 +00:00
Ben Lindstrom
bb2ce36d4d
- deraadt@cvs.openbsd.org 2002/05/04 02:39:35
...
[servconf.c sshd.8 sshd_config]
enable privsep by default; provos ok
(historical)
2002-05-15 21:35:43 +00:00
Ben Lindstrom
2b70e5603f
- (bal) Clarified openbsd-compat/*-cray.* Licence provided by Wendy.
2002-05-15 16:39:51 +00:00
Ben Lindstrom
7339b2a278
- mouring@cvs.openbsd.org 2002/05/15 15:47:49
...
[kex.c monitor.c monitor_wrap.c sshd.c]
'monitor' variable clashes with at least one lame platform (NeXT). i
Renamed to 'pmonitor'. provos@
- (bal) Fixed up PAM case. I think.
2002-05-15 16:25:01 +00:00
Ben Lindstrom
bdde330d2f
- markus@cvs.openbsd.org 2002/05/13 21:26:49
...
[auth-rhosts.c]
handle debug messages during rhosts-rsa and hostbased authentication;
ok provos@
2002-05-15 16:19:37 +00:00
Ben Lindstrom
17401b6b77
- millert@cvs.openbsd.org 2002/05/13 15:53:19
...
[sshd.c]
Call setsid() in the child after sshd accepts the connection and forks.
This is needed for privsep which calls setlogin() when it changes uids.
Without this, there is a race where the login name of an existing
connection, as returned by getlogin(), may be changed to the privsep
user (sshd). markus@ OK
2002-05-15 16:17:56 +00:00
Ben Lindstrom
a574cda45b
- markus@cvs.openbsd.org 2002/05/13 20:44:58
...
[auth-options.c auth.c auth.h]
move the packet_send_debug handling from auth-options.c to auth.c;
ok provos@
2002-05-15 16:16:14 +00:00
Ben Lindstrom
58d4dafeb1
- itojun@cvs.openbsd.org 2002/05/13 02:37:39
...
[auth-skey.c auth2.c]
less warnings. skey_{respond,query} are public (in auth.h)
2002-05-15 16:14:36 +00:00
Ben Lindstrom
966bfdae6b
- stevesk@cvs.openbsd.org 2002/05/11 20:24:48
...
[ssh.h]
typo in comment
2002-05-15 16:09:57 +00:00
Ben Lindstrom
973be0083b
- deraadt@cvs.openbsd.org 2002/05/08 21:06:34
...
[ssh.h]
move to sshd.sshd instead
2002-05-15 16:08:48 +00:00
Ben Lindstrom
1650ba3f57
- deraadt@cvs.openbsd.org 2002/05/07 19:54:36
...
[ssh.h]
use ssh uid
2002-05-15 16:07:11 +00:00
Ben Lindstrom
beecf74e2b
- (bal) CVS ID fix up on auth-passwd.c
2002-05-15 15:59:17 +00:00
Damien Miller
860e929fa2
wrap
2002-05-15 10:12:29 +10:00
Damien Miller
ee5e3b2d8a
wrap
2002-05-15 10:08:17 +10:00
Tim Rice
8dd6febf73
update version.
2002-05-14 09:03:46 -07:00
Tim Rice
fd6fd24a71
remove reference to UnixWare 7 and OpenUNIX 8
...
from PAM-enabled pragraph. UnixWare has no PAM.
2002-05-13 20:50:38 -07:00
Tim Rice
1e28c9e6ba
20020514
...
[sshpty.c] set tty modes when allocating old style bsd ptys to
match what newer style ptys have when allocated. Based on a patch by
Roger Cornelius <rac@tenzing.org>
[README.privsep] UnixWare 7 and OpenUNIX 8 work.
2002-05-13 17:07:18 -07:00
Kevin Steves
f8defa2327
- (stevesk) [README.privsep] PAM+privsep works with Solaris 8.
2002-05-13 23:31:09 +00:00
Damien Miller
05720356d6
- (djm) Add INSTALL warning about SSH protocol 1 blowfish w/ OpenSSL < 0.9.6
2002-05-13 15:22:21 +10:00
Damien Miller
f71d2a5d44
- (djm) Bug #234 : missing readpassphrase declaration and defines
2002-05-13 15:14:08 +10:00
Kevin Steves
0228155f06
- (stevesk) add initial README.privsep
2002-05-13 03:57:04 +00:00
Kevin Steves
c81e12976e
- (stevesk) [configure.ac] nicer message: --with-privsep-user=user
2002-05-13 03:51:40 +00:00
Damien Miller
b7cb96934e
- (djm) Update RPM spec file: different superuser path, use
...
/var/empty/sshd for privsep
2002-05-13 13:26:57 +10:00
Damien Miller
f58c672f0e
- (djm) Add --with-privsep-path configure option
2002-05-13 13:15:42 +10:00
Damien Miller
5ad9fd9820
- (djm) Bug #231 : UsePrivilegeSeparation turns off Banner.
2002-05-13 11:07:41 +10:00
Damien Miller
a18bbd398e
- (djm) Add --with-superuser-path=xxx configure option to specify what $PATH
...
the superuser receives.
2002-05-13 10:48:57 +10:00
Tim Rice
802b956868
fix for systems that have both HAVE_ACCRIGHTS_IN_MSGHDR and
...
HAVE_CONTROL_IN_MSGHDR. Ie. sys/socket.h has #define msg_accrights msg_control
2002-05-11 15:30:04 -07:00
Tim Rice
aef7371fe4
applied a rework of djm's OpenSSL search cleanup patch.
...
Now only searches system and /usr/local/ssl (OpenSSL's default install path)
Others must use --with-ssl-dir=....
2002-05-11 13:17:42 -07:00
Kevin Steves
f98fb721a0
- (stevesk) [auth.c] Shadow account and expiration cleanup. Now
...
check for root forced expire. Still don't check for inactive.
2002-05-10 15:48:52 +00:00
Ben Lindstrom
0b47814b43
- (bal) Back all the way out of auth-passwd.c changes. Breaks too many
...
things that don't set pw->pw_passwd.
2002-05-10 02:40:15 +00:00
Damien Miller
87aea25f1a
- (djm) Try to drop supplemental groups at daemon startup. Patch from
...
RedHat
2002-05-10 12:20:24 +10:00
Damien Miller
cfe4a89eef
- (djm) Rework RedHat RPM files. Based on spec from Nalin
...
Dahyabhai <nalin@redhat.com> and patches from
Pekka Savola <pekkas@netcore.fi>
2002-05-10 12:19:23 +10:00
Tim Rice
a7a5d6d1b5
Unbreak make -f Makefile.in distprep
2002-05-09 07:05:59 -07:00
Damien Miller
ffc868ff83
- (djm) Disable PAM kbd-int auth if privsep is turned on (it doesn't work)
2002-05-09 15:59:13 +10:00
Tim Rice
0502a471e0
set SHELL in Makefile in case someone makes from a non bourne compatable shell
2002-05-08 16:04:14 -07:00
Tim Rice
63cf84199d
fix logic on when seed_rng() is called.
...
Report by Chris Maxwell <maxwell@cs.dal.ca>
2002-05-08 15:57:18 -07:00
Tim Rice
4bd2a19890
Add truncate() emulation to address Bug 208
2002-05-07 19:51:31 -07:00
Damien Miller
f762a4bea5
- (djm) Don't reinitialise PAM credentials before we have started PAM.
...
Report from Pekka Savola <pekkas@netcore.fi>
2002-05-08 12:27:55 +10:00
Damien Miller
a33501bb5f
- (djm) Unbreak PAM auth for protocol 1. Report from Pekka Savola
...
<pekkas@netcore.fi>
2002-05-08 12:24:42 +10:00
Damien Miller
52910ddc66
- (djm) Unbreak auth-passwd.c for PAM and SIA
2002-05-08 12:18:26 +10:00
Ben Lindstrom
532bbdb99b
- (bal) Fixed auth-passwd.c to resolve PermitEmptyPassword issue
2002-05-06 23:06:08 +00:00
Damien Miller
804357ace9
- (djm) Fix readpassphase compilation for systems which have it
2002-05-01 22:00:22 +10:00
Damien Miller
38cd435892
- (djm) Import OpenBSD regression tests. Requires BSD make to run
2002-05-01 13:17:33 +10:00
Tim Rice
2f09289e74
[contrib/caldera/openssh.spec] update fixUP to reflect changes in sshd_config.
...
[contrib/cygwin/README] remove reference to regex.
patch from Corinna Vinschen <vinschen@redhat.com>
2002-04-29 20:53:12 -07:00
Damien Miller
aa100c546c
- (djm) Bug #180 : Set ToS bits on IPv4-in-IPv6 mapped addresses. Based on
...
patch from openssh@misc.tecq.org
2002-04-26 16:54:34 +10:00
Damien Miller
ae9d5af0de
- (djm) Disable PAM password expiry until a complete fix for bug #188 exists
2002-04-26 11:27:24 +10:00
Damien Miller
13ce922cc6
- (djm) Bug #137 , #209 : fix make problems for scard/Ssh.bin, do uudecode
...
during distprep only
2002-04-26 11:25:40 +10:00
Kevin Steves
0ea1d9d1f2
- (stevesk) [acconfig.h auth-passwd.c configure.ac sshd.c] HP-UX 10.26
...
support. bug #184 . most from dcole@keysoftsys.com .
2002-04-25 18:17:04 +00:00
Kevin Steves
30e494fbca
- (stevesk) [defines.h] remove USE_TIMEVAL; unused
2002-04-25 17:56:07 +00:00
Damien Miller
0150c65830
- djm@cvs.openbsd.org 2002/04/23 22:16:29
...
[sshd.c]
Improve error message; ok markus@ stevesk@
2002-04-24 09:49:09 +10:00
Damien Miller
11ec28176e
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2002/04/23 12:54:10
[version.h]
3.2.1
2002-04-24 09:48:14 +10:00
Kevin Steves
5feaaefaf2
- (stevesk) [acconfig.h configure.ac session.c] LOGIN_NO_ENDOPT for HP-UX
2002-04-23 20:45:55 +00:00
Kevin Steves
03df6cd83c
- (stevesk) [acconfig.h] NEED_IN_SYSTM_H unused
2002-04-23 20:11:13 +00:00
Markus Friedl
78cf8c377f
- markus@cvs.openbsd.org 2002/04/23 12:58:26
...
[radix.c]
send complete ticket; semerad@ss1000.ms.mff.cuni.cz
2002-04-23 16:41:12 +02:00
Damien Miller
f75fcc61f4
wrap an out of control line
2002-04-23 23:32:38 +10:00
Damien Miller
fa2bb69d16
- (djm) Bug #206 - blibpath isn't always needed for AIX ld, avoid
...
sizeof(long long int) == 4 breakage. Patch from Matthew Clarke
<Matthew_Clarke@mindlink.bc.ca>
2002-04-23 23:22:25 +10:00
Damien Miller
f1b9d11a3e
- (djm) Bug #214 : Fix utmp for Irix (don't strip "tty"). Patch from
...
Kevin Taylor <no@nowhere.org> (??) via Philipp Grau
<phgrau@zedat.fu-berlin.de>
2002-04-23 23:09:19 +10:00
Damien Miller
d77facda1a
- (djm) Bug #213 : Simplify CMSG_ALIGN macros to avoid symbol clashes.
...
Reported by Doug Manton <dmanton@emea.att.com>
2002-04-23 22:59:51 +10:00
Damien Miller
f5fea44ae3
- (djm) Define BROKEN_REALPATH for AIX, patch from
...
Antti Tapaninen <aet@cc.hut.fi>
2002-04-23 22:52:45 +10:00
Damien Miller
654a4ef969
- (djm) Redhat spec enables KrbV by default
2002-04-23 21:17:17 +10:00
Damien Miller
0b3894d5b5
- (djm) Update RPM spec file versions
2002-04-23 21:15:31 +10:00
Damien Miller
ef7c11de6e
- (djm) Trim ChangeLog to include only post-3.1 changes
2002-04-23 21:13:32 +10:00
Damien Miller
2797f7f03a
- markus@cvs.openbsd.org 2002/04/22 21:04:52
...
[channels.c clientloop.c clientloop.h ssh.c]
request reply (success/failure) for -R style fwd in protocol v2,
depends on ordered replies.
fixes http://bugzilla.mindrot.org/show_bug.cgi?id=215 ; ok provos@
2002-04-23 21:09:44 +10:00
Damien Miller
d7de14b6ad
- markus@cvs.openbsd.org 2002/04/22 16:16:53
...
[servconf.c sshd.8 sshd_config]
do not auto-enable KerberosAuthentication; ok djm@, provos@, deraadt@
2002-04-23 21:04:51 +10:00
Damien Miller
635fe98a7f
- markus@cvs.openbsd.org 2002/04/22 06:15:47
...
[radix.c]
fix check for overflow
2002-04-23 21:00:33 +10:00
Damien Miller
f61c01506f
- stevesk@cvs.openbsd.org 2002/04/21 16:25:06
...
[sshconnect1.c]
spelling in error message; ok markus@
2002-04-23 20:56:02 +10:00
Damien Miller
7a8558d3ea
- stevesk@cvs.openbsd.org 2002/04/21 16:19:27
...
[sshd.8 sshd_config]
document default AFSTokenPassing no; ok deraadt@
2002-04-23 20:51:15 +10:00
Damien Miller
bad0e0162f
- markus@cvs.openbsd.org 2002/04/20 09:17:19
...
[radix.c]
rewrite using the buffer_* API, fixes overflow; ok deraadt@
2002-04-23 20:46:56 +10:00
Damien Miller
3b23566a5b
- markus@cvs.openbsd.org 2002/04/20 09:14:58
...
[bufaux.c bufaux.h]
add buffer_{get,put}_short
2002-04-23 20:42:36 +10:00
Damien Miller
7941855f09
- (djm) Make privsep work with PAM (still experimental)
2002-04-23 20:28:48 +10:00
Damien Miller
594a71b9b9
- (djm) Bug #222 : Fix tests for getaddrinfo on OSF/1. Spotted by
...
Robert Urban <urban@spielwiese.de>
2002-04-23 20:22:59 +10:00
Tim Rice
f02dccc0dc
[entropy.c.] Portability fix for SCO Unix 3.2v4.x (SCO OSR 3.0).
...
entropy.c needs seteuid(getuid()) for the setuid(original_uid) to succeed.
Patch by gert@greenie.muc.de . This fixes one part of Bug 208
2002-04-21 11:26:10 -07:00
Damien Miller
a370f4dcc6
- (djm) Avoid SIGCHLD breakage when run from rsync. Fix from
...
Sturle Sunde <sturle.sunde@usit.uio.no>
2002-04-18 22:53:22 +10:00
Tim Rice
43a1c13e0f
[configure.ac] Issue warning on --with-default-path=/some_path
...
if LOGIN_CAP is enabled. Report & testing by Tuc <tuc@ttsg.com>
2002-04-17 21:19:14 -07:00
Damien Miller
5efd71038d
- (djm) Fix .Nm in mdoc2man.pl from pspencer@fields.utoronto.ca
2002-04-17 12:30:45 +10:00
Damien Miller
bd63874d4b
- (djm) Tell users to configure /dev/random support into OpenSSL in INSTALL
2002-04-17 12:22:58 +10:00
Tim Rice
66480f188e
[configure.ac] add tests for recvmsg and sendmsg.
...
[monitor_fdpass.c] add checks for HAVE_SENDMSG and HAVE_RECVMSG for
systems that HAVE_ACCRIGHTS_IN_MSGHDR but no recvmsg or sendmsg.
2002-04-15 21:10:09 -07:00
Kevin Steves
eb3630205a
- (stevesk) bsd-cygwin_util.[ch] BSD license from Corinna Vinschen
2002-04-15 22:00:51 +00:00
Damien Miller
8be24f3846
- (djm) Unbreak "make install". Fix from Darren Tucker <dtucker@zip.com.au>
2002-04-15 13:23:59 +10:00
Damien Miller
49411ff8a7
- (djm) Random number collection doc fixes from Ben
2002-04-14 23:16:04 +10:00
Damien Miller
32e4818015
- (djm) ssh-rand-helper improvements
...
- Add commandline debugging options
- Don't write binary data if stdout is a tty (use hex instead)
- Give it a manpage
2002-04-14 19:27:12 +10:00
Damien Miller
fd4c9eee25
- (djm) Add KrbV support patch from Simon Wilkinson <simon@sxw.org.uk>
2002-04-13 11:04:40 +10:00
Ben Lindstrom
927dfd2d7e
- (bal) disable privsep if no MAP_ANON. We can re-enable it
...
after the release when we can do more testing.
2002-04-12 18:51:22 +00:00
Ben Lindstrom
c42f7cfd16
- (bal) Mistaken in Cygwin scripts for ssh starting. Patch by
...
Corinna Vinschen <vinschen@redhat.com>
2002-04-12 17:44:13 +00:00
Tim Rice
ae49fe64ca
[configure.ac] add <sys/types.h> to msghdr tests.
...
Change -L to -h on testing for /bin being symbolic link
2002-04-12 10:26:21 -07:00
Kevin Steves
19fa9b544f
- (stevesk) [auth-sia.[ch]] add BSD license from Chris Adams
2002-04-12 15:36:07 +00:00
Tim Rice
813f0452ed
[acconfig.h defines.h includes.h] put includes in includes.h and
...
defines in defines.h [rijndael.c openbsd-compat/fake-socket.h
openbsd-compat/inet_aton.c] include "includes.h" instead of "config.h"
ok stevesk@
2002-04-11 20:35:39 -07:00
Kevin Steves
0c283d8444
- (stevesk) [auth-sia.c] cleanup
2002-04-11 20:39:40 +00:00
Kevin Steves
fe6ca54ac2
- (stevesk) [configure.ac monitor.c] HAVE_SOCKETPAIR
2002-04-10 22:04:54 +00:00
Ben Lindstrom
027e4de24f
- markus@cvs.openbsd.org 2002/04/10 08:56:01
...
[version.h]
OpenSSH_3.2
- Added p1 to idenify Portable release version.
2002-04-10 16:26:20 +00:00
Ben Lindstrom
b5115eaf80
- markus@cvs.openbsd.org 2002/04/10 08:21:47
...
[auth1.c compat.c compat.h]
strip '@' from username only for KerbV and known broken clients, bug #204
2002-04-10 16:17:34 +00:00
Kevin Steves
6939b233d0
- (stevesk) [auth-sia.c] compile fix Chris Adams <cmadams@hiwaay.net>
2002-04-10 16:09:51 +00:00
Ben Lindstrom
34b7320a9d
- (bal) Minor OpenSC updates. Fix up header locations and update
...
README.smartcard provided by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-08 18:37:07 +00:00
Kevin Steves
265c9d00c3
- (stevesk) wrap munmap() with HAVE_MMAP also.
2002-04-07 22:36:49 +00:00
Kevin Steves
7ff911216b
- (stevesk) --with-privsep-user; default sshd
2002-04-07 19:22:54 +00:00
Kevin Steves
b1184bbf29
- (stevesk) remove configure support for poll.h; it was removed
...
from sshd.c a long time ago.
2002-04-07 18:12:03 +00:00
Kevin Steves
86b9fe6a77
- (stevesk) HAVE_MMAP and HAVE_SYS_MMAN_H and use them in
...
monitor_mm.c
2002-04-07 17:08:53 +00:00
Kevin Steves
c3c825575c
- (stevesk) [monitor_fdpass.c] fatal() for UsePrivilegeSeparation=yes
...
and no fd passing support.
2002-04-07 16:39:12 +00:00
Kevin Steves
a44e0351ee
- (stevesk) HAVE_CONTROL_IN_MSGHDR; not used right now.
...
Future: we may want to test if fd passing works correctly.
2002-04-07 16:18:03 +00:00
Ben Lindstrom
fdee8ef0ac
- (bal) We no longer use atexit()/xatexit()/on_exit()
2002-04-06 23:52:02 +00:00
Ben Lindstrom
0318801591
- (bal) Quiet down configure.ac if /bin/test does not exist.
2002-04-06 20:30:07 +00:00
Ben Lindstrom
8ff2a8d2c2
- (bal) Revered out of runtime IRIX runtime detection of joblimits. Code is
...
incomplete.
2002-04-06 18:58:31 +00:00
Ben Lindstrom
de3895d580
- mouring@cvs.openbsd.org 2002/04/06 18:24:09
...
[scp.c]
Fixes potental double // within path.
http://bugzilla.mindrot.org/show_bug.cgi?id=76
2002-04-06 18:29:59 +00:00
Ben Lindstrom
8d6017566c
- (bal) Slight update to OpenSC support. Better version checking. patch
...
by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-06 18:19:38 +00:00
Ben Lindstrom
06e9515eb8
- djm@cvs.openbsd.org 2002/04/06 00:30:08
...
[sftp-client.c]
Fix occasional corruption on upload due to bad reuse of request id, spotted
by chombier@mac.com ; ok markus@
2002-04-06 04:16:45 +00:00
Ben Lindstrom
dc0594cc54
- (bal) Added MAP_FAILED to allow AIX and Trusted HP to compile.
2002-04-06 04:11:28 +00:00
Damien Miller
12db56ba2f
- (djm) Typo in Suse SPEC file. Fix from Carsten Grohmann
...
<carsten.grohmann@dr-baldeweg.de>
2002-04-06 11:12:52 +10:00
Ben Lindstrom
a11e270115
- stevesk@cvs.openbsd.org 2002/04/05 20:56:21
...
[sshd.8]
clarify sshrc some and handle X11UseLocalhost=yes; ok markus@
2002-04-05 22:18:48 +00:00
Ben Lindstrom
924144e650
- (bal) Too many <sys/queue.h> issues. Remove all workarounds and
...
using internal version only.
2002-04-05 20:23:35 +00:00
Ben Lindstrom
a42694fa25
- (bal) Patch for OpenSC SmartCard library; ok markus@; patch by
...
Juha Yrjölä <jyrjola@cc.hut.fi>
- (bal) Minor documentation update to reflect smartcard library
support changes.
2002-04-05 16:11:45 +00:00
Ben Lindstrom
8a725a843d
- markus@cvs.openbsd.org 2002/04/03 09:26:11
...
[cipher.c myproposal.h]
re-add rijndael-cbc@lysator.liu.se for MacSSH; ash@lab.poc.net
2002-04-04 22:10:38 +00:00
Kevin Steves
e683e76439
- (stevesk) [auth-pam.c auth-pam.h auth-passwd.c auth-sia.c auth-sia.h
...
auth1.c auth2.c] PAM, OSF_SIA password auth cleanup; from djm.
2002-04-04 19:02:28 +00:00
Ben Lindstrom
af40bc6a72
- (bal) mispelling in uidswap.c (portable only)
2002-04-03 03:36:54 +00:00
Ben Lindstrom
07739fe305
- markus@cvs.openbsd.org 2002/04/02 20:11:38
...
[ssh-rsa.c]
ignore SSH_BUG_SIGBLOB for ssh-rsa; #187
2002-04-03 03:03:04 +00:00
Ben Lindstrom
2f3d52a2d6
- markus@cvs.openbsd.org 2002/04/02 17:37:48
...
[sftp.c]
always call log_init()
2002-04-02 21:06:18 +00:00
Ben Lindstrom
eecdf23531
- markus@cvs.openbsd.org 2002/04/02 11:49:39
...
[ssh-agent.c]
check $SHELL for -k and -d, too;
http://bugzilla.mindrot.org/show_bug.cgi?id=199
2002-04-02 21:03:51 +00:00
Ben Lindstrom
f26ff5b9d8
- markus@cvs.openbsd.org 2002/04/01 22:07:17
...
[sftp-client.c]
fallback to stat if server does not support lstat
2002-04-02 21:00:31 +00:00
Ben Lindstrom
a1d8114044
- markus@cvs.openbsd.org 2002/04/01 22:02:16
...
[sftp-client.c]
20480 is an upper limit for older server
2002-04-02 20:58:11 +00:00
Ben Lindstrom
1e259bb0bf
- (bal) CVS ID sync of uidswap.c
2002-04-02 20:53:39 +00:00
Ben Lindstrom
47fd8112b5
- markus@cvs.openbsd.org 2002/03/30 18:51:15
...
[monitor.c serverloop.c sftp-int.c sftp.c sshd.c]
check waitpid for EINTR; based on patch from peter@ifm.liu.se
2002-04-02 20:48:19 +00:00
Ben Lindstrom
03f3932829
- stevesk@cvs.openbsd.org 2002/03/29 19:18:33
...
[auth-rsa.c ssh-rsa.c ssh.h]
make RSA modulus minimum #define; ok markus@
2002-04-02 20:43:11 +00:00
Ben Lindstrom
0d0be02a29
- stevesk@cvs.openbsd.org 2002/03/29 19:16:22
...
[sshd.8]
RSA key modulus size minimum 768; ok markus@
2002-04-02 20:39:29 +00:00
Ben Lindstrom
c447fee9f1
- markus@cvs.openbsd.org 2002/03/29 18:59:32
...
[session.c session.h]
retrieve last login time before the pty is allocated, store per session
2002-04-02 20:35:35 +00:00
Ben Lindstrom
2bf56e2dba
- markus@cvs.openbsd.org 2002/03/28 15:34:51
...
[session.c]
do not call record_login twice (for use_privsep)
2002-04-02 20:32:46 +00:00
Ben Lindstrom
155b981494
- markus@cvs.openbsd.org 2002/03/27 22:21:45
...
[ssh-keygen.c]
try to import keys with extra trailing === (seen with ssh.com < 2.0.12)
2002-04-02 20:26:26 +00:00
Ben Lindstrom
cdb66e0e82
- (bal) Hand Sync of scp.c (reverted to upstream code)
...
- deraadt@cvs.openbsd.org 2002/03/30 17:45:46
[scp.c]
stretch banners
2002-04-02 20:17:43 +00:00
Kevin Steves
38c4a28a7e
- (stevesk) [auth1.c] fix password auth for protocol 1 when
...
!USE_PAM && !HAVE_OSF_SIA; merge issue.
2002-04-02 03:24:56 +00:00
Kevin Steves
bd1901b7dc
- (stevesk) [monitor.c] PAM should work again; will *not* work with
...
UsePrivilegeSeparation=yes.
2002-04-01 18:04:35 +00:00
Tim Rice
c85496222b
[sshconnect2.c] change uint32_t to u_int32_t
2002-03-31 12:49:38 -08:00
Tim Rice
49e457c43b
[configure.ac] use /bin/test -L to work around broken builtin on Solaris 8
2002-03-31 11:23:06 -08:00
Kevin Steves
117b06dec9
- (stevesk) [configure.ac] remove header check for sys/ttcompat.h
...
bug 167
2002-03-30 17:55:21 +00:00
Ben Lindstrom
b57a4bf93f
- mouring@cvs.openbsd.org 2002/03/27 11:45:42
...
[monitor.c]
monitor_allowed_key() returns int instead of pointer. ok markus@
2002-03-27 18:00:59 +00:00
Ben Lindstrom
599717246c
- markus@cvs.openbsd.org 2002/03/26 23:14:51
...
[kex.c]
generate a new cookie for each SSH2_MSG_KEXINIT message we send out
2002-03-27 17:42:57 +00:00
Ben Lindstrom
e1f9e324e9
- markus@cvs.openbsd.org 2002/03/26 23:13:03
...
[auth-rsa.c]
disallow RSA keys < 768 for protocol 1, too (rhosts-rsa and rsa auth)
2002-03-27 17:38:43 +00:00
Ben Lindstrom
57686a82a5
- markus@cvs.openbsd.org 2002/03/26 22:50:39
...
[channels.h]
CHANNEL_EFD_OUTPUT_ACTIVE is false for CHAN_CLOSE_RCVD, too
2002-03-27 17:36:41 +00:00
Ben Lindstrom
43a5e2f70e
- rees@cvs.openbsd.org 2002/03/26 18:46:59
...
[scard.c]
try_AUT0 in read_pubkey too, for those paranoid few who want to acl 'sh'
2002-03-27 17:33:17 +00:00
Ben Lindstrom
38a69e6b53
- markus@cvs.openbsd.org 2002/03/26 15:58:46
...
[readpass.c readpass.h sshconnect2.c]
client side support for PASSWD_CHANGEREQ
2002-03-27 17:28:46 +00:00
Ben Lindstrom
cd8bbce80b
- markus@cvs.openbsd.org 2002/03/26 15:23:40
...
[bufaux.c]
do not talk about packets in bufaux
2002-03-27 17:23:44 +00:00
Ben Lindstrom
eb041dca1f
- markus@cvs.openbsd.org 2002/03/26 11:37:05
...
[ssh.c]
update Copyright
2002-03-27 17:20:38 +00:00
Ben Lindstrom
f181384a6b
- markus@cvs.openbsd.org 2002/03/26 11:34:49
...
[ssh.1 sshd.8]
update to recent drafts
2002-03-27 17:18:31 +00:00
Ben Lindstrom
53f1830d6a
- (bal) 'pw' should be 'authctxt->pw' in auth1.c spotted by
...
kent@lysator.liu.se
2002-03-27 16:50:03 +00:00
Ben Lindstrom
28364ecf45
- stevesk@cvs.openbsd.org 2002/03/26 03:24:01
...
[monitor.h monitor_fdpass.h monitor_mm.h monitor_wrap.h]
$OpenBSD$
2002-03-26 03:42:20 +00:00
Ben Lindstrom
cf15944c23
- markus@cvs.openbsd.org 2002/03/25 21:13:51
...
[channels.c channels.h compat.c compat.h nchan.c]
don't send stderr data after EOF, accept this from older known (broken)
sshd servers only, fixes http://bugzilla.mindrot.org/show_bug.cgi?id=179
2002-03-26 03:26:24 +00:00
Ben Lindstrom
4f054607f0
- markus@cvs.openbsd.org 2002/03/25 21:04:02
...
[ssh.c]
simplify num_identity_files handling
2002-03-26 03:23:00 +00:00
Ben Lindstrom
c861547f34
- stevesk@cvs.openbsd.org 2002/03/25 20:12:10
...
[monitor_mm.c monitor_wrap.c]
ssize_t args use "%ld" and cast to (long)
size_t args use "%lu" and cast to (u_long)
ok markus@ and thanks millert@
2002-03-26 03:20:45 +00:00
Ben Lindstrom
0936a5bb72
- markus@cvs.openbsd.org 2002/03/25 17:34:27
...
[scard.c scard.h ssh-agent.c ssh-keygen.c ssh.c]
change sc_get_key to sc_get_keys and hide smartcard details in scard.c
2002-03-26 03:17:42 +00:00
Ben Lindstrom
5facb2bbc4
- markus@cvs.openbsd.org 2002/03/25 09:25:06
...
[auth-rh-rsa.c]
rm bogus comment
2002-03-26 03:08:47 +00:00
Ben Lindstrom
f6d367b91a
- markus@cvs.openbsd.org 2002/03/25 09:21:13
...
[auth-rsa.c]
return 0 (not NULL); tomh@po.crl.go.jp
2002-03-26 02:59:31 +00:00
Ben Lindstrom
2e9d866608
- stevesk@cvs.openbsd.org 2002/03/24 23:20:00
...
[monitor.c]
remove "\n" from fatal()
2002-03-26 02:49:34 +00:00
Ben Lindstrom
c2c6cbc527
- markus@cvs.openbsd.org 2002/03/24 18:05:29
...
[scard.c]
we need to figure out AUT0 for sc_private_encrypt, too
2002-03-26 02:44:44 +00:00
Ben Lindstrom
31ee7aeb15
- stevesk@cvs.openbsd.org 2002/03/24 17:53:16
...
[monitor_fdpass.c]
minor cleanup and more error checking; ok markus@
2002-03-26 02:36:29 +00:00
Ben Lindstrom
fcad1c92c9
- stevesk@cvs.openbsd.org 2002/03/24 17:27:03
...
[kexgex.c]
typo; ok markus@
2002-03-26 02:20:06 +00:00
Ben Lindstrom
8b08d8115d
- markus@cvs.openbsd.org 2002/03/24 16:01:13
...
[packet.c]
debug->debug3 for extra padding
2002-03-26 02:09:41 +00:00
Ben Lindstrom
3dc40f997b
- markus@cvs.openbsd.org 2002/03/24 16:00:27
...
[serverloop.c]
remove unused debug
2002-03-26 02:01:30 +00:00
Ben Lindstrom
f90f58d846
- stevesk@cvs.openbsd.org 2002/03/23 20:57:26
...
[sshd.c]
setproctitle() after preauth child; ok markus@
2002-03-26 01:53:03 +00:00