Damien Miller
aa15137c15
- (djm) OpenBSD CVS Sync
...
- markus@cvs.openbsd.org 2002/06/26 08:53:12
[bufaux.c]
limit size of BNs to 8KB; ok provos/deraadt
2002-06-26 19:14:08 +10:00
Damien Miller
f18cd162d3
- (djm) setlogin needs pgid==pid on BSD/OS; from itojun@
2002-06-26 19:12:59 +10:00
Tim Rice
6de3dfd929
[contrib/caldera/openssh.spec] add support for privsep
2002-06-25 19:28:55 -07:00
Kevin Steves
40b011c7fe
- (stevesk) [README.privsep] more for sshd pseudo-account.
2002-06-26 00:43:57 +00:00
Ben Lindstrom
4e3c631b70
- (bal) fixed NeXTStep missing munmap() issue. It defines HAVE_MMAP,
...
but it all damned lies.
2002-06-26 00:29:02 +00:00
Tim Rice
e04ee923d9
UnixWare tip is no longer needed.
2002-06-25 17:25:47 -07:00
Ben Lindstrom
a95fd3f8ad
- (bal) added back in error check for mmap(). I screwed up, Pointed
...
out by stevesk@
2002-06-26 00:22:57 +00:00
Tim Rice
2b3897c3cc
[Makefile.in] fix test on installing ssh-rand-helper.8
2002-06-25 16:45:42 -07:00
Ben Lindstrom
5223727672
- (bal) Updated AIX package build. Patch by dtucker@zip.com.au
2002-06-25 23:38:47 +00:00
Ben Lindstrom
fbcc3f71f2
- markus@cvs.openbsd.org 2002/06/25 18:51:04
...
[sshd.c]
lightweight do_setusercontext after chroot()
2002-06-25 23:24:18 +00:00
Ben Lindstrom
6398a0ef12
- markus@cvs.openbsd.org 2002/06/25 16:22:42
...
[authfd.c]
unnecessary cast
2002-06-25 23:22:54 +00:00
Ben Lindstrom
c2df3ec0c0
- deraadt@cvs.openbsd.org 2002/06/24 17:57:20
...
[sftp-server.c sshpty.c]
explicit (u_int) for uid and gid
2002-06-25 23:21:41 +00:00
Ben Lindstrom
9b4139742f
- itojun@cvs.openbsd.org 2002/06/24 15:49:22
...
[msg.c]
printf type pedant
2002-06-25 23:20:18 +00:00
Ben Lindstrom
c5a7f4fdf9
- markus@cvs.openbsd.org 2002/06/24 14:55:38
...
[authfile.c kex.c ssh-agent.c]
cat to (void) when output from buffer_get_X is ignored
2002-06-25 23:19:13 +00:00
Ben Lindstrom
4fed2be856
- markus@cvs.openbsd.org 2002/06/24 14:33:27
...
[channels.c channels.h clientloop.c serverloop.c]
move channel counter to u_int
2002-06-25 23:17:36 +00:00
Ben Lindstrom
b48057b7dc
- markus@cvs.openbsd.org 2002/06/24 13:12:23
...
[ssh-agent.1]
the socket name contains ssh-agent's ppid; via mpech@ from form@
2002-06-25 23:16:31 +00:00
Ben Lindstrom
daa2179bd0
- markus@cvs.openbsd.org 2002/06/23 21:34:07
...
[channels.c]
tcode is u_int
2002-06-25 23:15:30 +00:00
Kevin Steves
cfae58c059
- (stevesk) [monitor.c] remove duplicate proto15 dispatch entry for PAM
2002-06-25 22:43:19 +00:00
Tim Rice
8eff319298
[acconfig.h configure.ac sshd.c] BROKEN_FD_PASSING fix from Markus
...
for Cygwin, Cray, & SCO
2002-06-25 15:35:15 -07:00
Ben Lindstrom
b129be657c
20020626
...
- (bal) moved aix_usrinfo() and noted not setting real TTY. Patch by
dtucker@zip.com.au
2002-06-25 17:12:26 +00:00
Tim Rice
78688d7a45
Sync with Caldera
2002-06-25 10:07:25 -07:00
Ben Lindstrom
6b0c96ab59
- (bal) if mmap() is substandard, don't allow compression on server side.
...
Post 'event' we will add more options.
2002-06-25 03:22:03 +00:00
Ben Lindstrom
aa83b984ca
- (bal) Started list of PrivSep issues in TODO
2002-06-25 02:28:22 +00:00
Damien Miller
d3f6ad2cc0
- (djm) Create privsep directory and warn if privsep user is missing
...
during make install
2002-06-25 10:24:47 +10:00
Kevin Steves
d48663602d
- (stevesk) [README.privsep] minor updates
2002-06-24 16:49:22 +00:00
Kevin Steves
34f0d8f404
- (stevesk) [INSTALL acconfig.h configure.ac defines.h] remove --with-rsh
2002-06-24 16:26:49 +00:00
Ben Lindstrom
3f58474214
- deraadt@cvs.openbsd.org 2002/06/23 21:10:02
...
[packet.c]
packet_get_int() returns unsigned for reason & seqnr
2002-06-23 21:49:25 +00:00
Ben Lindstrom
a9d2c89fc5
- deraadt@cvs.openbsd.org 2002/06/23 21:06:41
...
[channels.c channels.h session.c session.h]
display, screen, row, col, xpixel, ypixel are u_int; markus ok
- (bal) Also fixed IPADDR_IN_DISPLAY case where display, screen, row, col,
xpixel are u_int.
2002-06-23 21:48:28 +00:00
Ben Lindstrom
8ada5d0d0d
- deraadt@cvs.openbsd.org 2002/06/23 21:06:13
...
[sshpty.c]
KNF
2002-06-23 21:42:50 +00:00
Ben Lindstrom
e23f4a3d28
- deraadt@cvs.openbsd.org 2002/06/23 20:39:45
...
[session.c]
compression_level is u_int
2002-06-23 21:40:16 +00:00
Ben Lindstrom
822b634099
- deraadt@cvs.openbsd.org 2002/06/23 10:29:52
...
[ssh-agent.c sshd.c]
some minor KNF and %u
2002-06-23 21:38:49 +00:00
Ben Lindstrom
e135363422
- deraadt@cvs.openbsd.org 2002/06/23 09:46:51
...
[bufaux.c servconf.c]
minor KNF. things the fingers do while you read
2002-06-23 21:29:23 +00:00
Ben Lindstrom
58d3b7224f
- deraadt@cvs.openbsd.org 2002/06/23 09:39:55
...
[ssh-keygen.c]
u_int stuff
2002-06-23 21:28:13 +00:00
Ben Lindstrom
b1f483f472
- deraadt@cvs.openbsd.org 2002/06/23 09:30:14
...
[sftp-client.c sftp-client.h sftp-common.c sftp-int.c sftp-server.c
sftp.c]
bunch of u_int vs int stuff
2002-06-23 21:27:18 +00:00
Ben Lindstrom
5c3855210e
- deraadt@cvs.openbsd.org 2002/06/23 03:30:58
...
[scard.c ssh-dss.c ssh-rsa.c sshconnect.c sshconnect2.c sshd.c sshlogin.c
sshpty.c]
various KNF and %d for unsigned
2002-06-23 21:23:20 +00:00
Ben Lindstrom
836f0e9d9a
- deraadt@cvs.openbsd.org 2002/06/23 03:26:19
...
[cipher.c key.c]
KNF
2002-06-23 21:21:30 +00:00
Ben Lindstrom
2953d0fb4e
- deraadt@cvs.openbsd.org 2002/06/23 03:25:50
...
[tildexpand.c]
KNF
2002-06-23 21:20:34 +00:00
Ben Lindstrom
e1c0912cb6
- stevesk@cvs.openbsd.org 2002/06/22 23:09:51
...
[monitor.c]
save auth method before monitor_reset_key_state(); bugzilla bug #284 ;
ok provos@
2002-06-23 00:38:24 +00:00
Ben Lindstrom
57f08005d3
- stevesk@cvs.openbsd.org 2002/06/22 20:05:27
...
[sshd.c]
don't call setsid() if debugging or run from inetd; no "Operation not
permitted" errors now; ok millert@ markus@
2002-06-23 00:37:10 +00:00
Ben Lindstrom
959de99aa0
- stevesk@cvs.openbsd.org 2002/06/22 16:45:29
...
[ssh-agent.1 sshd.8 sshd_config.5]
use process ID vs. pid/PID/process identifier
2002-06-23 00:35:25 +00:00
Ben Lindstrom
c06bf70b41
- stevesk@cvs.openbsd.org 2002/06/22 16:41:57
...
[scp.1]
typo
2002-06-23 00:34:37 +00:00
Ben Lindstrom
2dfacb3d40
- stevesk@cvs.openbsd.org 2002/06/22 16:40:19
...
[sshd.c]
check /var/empty owner mode; ok provos@
2002-06-23 00:33:47 +00:00
Ben Lindstrom
624e3f2065
- stevesk@cvs.openbsd.org 2002/06/22 16:32:54
...
[sshd.8]
add /var/empty in FILES section
2002-06-23 00:32:57 +00:00
Ben Lindstrom
c001cd3577
- naddy@cvs.openbsd.org 2002/06/22 11:51:39
...
[ssh.1]
typo
2002-06-23 00:32:11 +00:00
Ben Lindstrom
bf69e3b95d
- stevesk@cvs.openbsd.org 2002/06/22 02:40:23
...
[ssh.1]
section 5 not 4 for ssh_config
2002-06-23 00:31:24 +00:00
Ben Lindstrom
5590aa5b1f
- OpenBSD CVS Sync
...
- stevesk@cvs.openbsd.org 2002/06/22 02:00:29
[ssh.h]
correct comment
2002-06-23 00:30:30 +00:00
Ben Lindstrom
883844dc07
- (bal) add extern char *getopt. Based on report by dtucker@zip.com.au
2002-06-23 00:20:50 +00:00
Ben Lindstrom
1a1b851775
- (bal) removed GNUism for getops in ssh-agent since glibc lacks optreset.
2002-06-23 00:18:15 +00:00
Kevin Steves
90d5de7670
- (stevesk) [configure.ac] bug #255 LOGIN_NEEDS_UTMPX for AIX.
2002-06-22 18:51:48 +00:00
Ben Lindstrom
ee9ac35fc2
- (bal) getopt now can be staticly compiled on those platforms missing
...
optreset. Patch by binder@arago.de
2002-06-22 00:26:59 +00:00
Damien Miller
f102bf6e50
- (djm) Release 3.3p1
2002-06-22 01:44:45 +10:00
Damien Miller
263d68fc56
- (djm) Update README.privsep; spotted by fries@
2002-06-22 00:45:50 +10:00
Damien Miller
53baddb775
- (djm) contrib/redhat/openssh.spec hacking:
...
- Merge in spec changes from seba@iq.pl (Sebastian Pachuta)
- Add new {ssh,sshd}_config.5 manpages
- Add new ssh-keysign program and remove setuid from ssh client
2002-06-21 16:42:41 +10:00
Damien Miller
4903eb4b74
- (djm) Warn and disable compression on platforms which can't handle both
...
useprivilegeseparation=yes and compression=yes
2002-06-21 16:20:44 +10:00
Damien Miller
444f9fca60
- ID sync for auth-passwd.c
2002-06-21 16:05:12 +10:00
Damien Miller
2d6b83353b
- djm@cvs.openbsd.org 2002/06/21 05:50:51
...
[monitor.c]
Don't initialise compression buffers when compression=no in sshd_config;
ok Niels@
2002-06-21 15:59:49 +10:00
Ben Lindstrom
90ac0b5945
- (bal) Still more Makefile.in updates for ssh{d}_config.5
2002-06-21 01:38:53 +00:00
Ben Lindstrom
900464e454
- (bal) Missed integrating ssh_config.5 and sshd_config.5
2002-06-21 01:24:01 +00:00
Ben Lindstrom
47e1b40c08
- stevesk@cvs.openbsd.org 2002/05/25 20:40:08
...
[LICENCE]
missed Per Allansson (auth2-chall.c)
2002-06-21 01:19:12 +00:00
Ben Lindstrom
1b8d730b7d
- markus@cvs.openbsd.org 2002/06/20 23:37:12
...
[sshd_config]
add Compression
2002-06-21 01:11:36 +00:00
Ben Lindstrom
23e0f667f8
- markus@cvs.openbsd.org 2002/06/20 23:05:56
...
[servconf.c servconf.h session.c sshd.c]
allow Compression=yes/no in sshd_config
2002-06-21 01:09:47 +00:00
Ben Lindstrom
9721e92ba8
- stevesk@cvs.openbsd.org 2002/06/20 20:03:34
...
[ssh_config sshd_config]
refer to config file man page
2002-06-21 01:06:03 +00:00
Ben Lindstrom
ba8e0dd7a0
tevesk@cvs.openbsd.org 2002/06/20 20:00:05
...
[scp.1 sftp.1]
ssh_config(5)
2002-06-21 01:00:40 +00:00
Ben Lindstrom
9f04903c50
- stevesk@cvs.openbsd.org 2002/06/20 19:56:07
...
[ssh.1 sshd.8]
move configuration file options from ssh.1/sshd.8 to
ssh_config.5/sshd_config.5; ok deraadt@ millert@
2002-06-21 00:59:05 +00:00
Ben Lindstrom
402c6cc681
- markus@cvs.openbsd.org 2002/06/19 18:01:00
...
[cipher.c monitor.c monitor_wrap.c packet.c packet.h]
make the monitor sync the transfer ssh1 session key;
transfer keycontext only for RC4 (this is still depends on EVP
implementation details and is broken).
2002-06-21 00:43:42 +00:00
Ben Lindstrom
cb72e4f6d2
- deraadt@cvs.openbsd.org 2002/06/19 00:27:55
...
[auth-bsdauth.c auth-skey.c auth1.c auth2-chall.c auth2-none.c authfd.c
authfd.h monitor_wrap.c msg.c nchan.c radix.c readconf.c scp.c sftp.1
ssh-add.1 ssh-add.c ssh-agent.1 ssh-agent.c ssh-keygen.1 ssh-keygen.c
ssh-keysign.c ssh.1 sshconnect.c sshconnect.h sshconnect2.c ttymodes.c
xmalloc.h]
KNF done automatically while reading....
2002-06-21 00:41:51 +00:00
Ben Lindstrom
115422f918
- (bal) Cygwin special handling of empty passwords wrong. Patch by
...
vinschen@redhat.com
2002-06-21 00:26:22 +00:00
Ben Lindstrom
45933dd9aa
- deraadt@cvs.openbsd.org 2002/06/17 06:05:56
...
[scp.c]
make usage like man page
2002-06-21 00:10:58 +00:00
Ben Lindstrom
61c183bea3
- itojun@cvs.openbsd.org 2002/06/16 21:30:58
...
[ssh-keyscan.c]
use TAILQ_xx macro. from lukem@netbsd. markus ok
2002-06-21 00:09:54 +00:00
Ben Lindstrom
2b266b7f08
- markus@cvs.openbsd.org 2002/06/15 01:27:48
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
remove the CONSTRAIN_IDENTITY messages and introduce a new
ADD_ID message with contraints instead. contraints can be
only added together with the private key.
2002-06-21 00:08:39 +00:00
Ben Lindstrom
c90f8a98ea
- markus@cvs.openbsd.org 2002/06/15 00:07:38
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
fix stupid typo
2002-06-21 00:06:54 +00:00
Ben Lindstrom
4eb4c4e1ef
- markus@cvs.openbsd.org 2002/06/15 00:01:36
...
[authfd.c authfd.h ssh-add.c ssh-agent.c]
break agent key lifetime protocol and allow other contraints for key
usage.
2002-06-21 00:04:48 +00:00
Ben Lindstrom
f0bfa839bd
- (bal) Fixed AIX environment handling, use setpcred() instead of existing
...
code. (Bugzilla Bug 261)
2002-06-21 00:01:18 +00:00
Ben Lindstrom
3c73dfe55e
- todd@cvs.openbsd.org 2002/06/14 21:35:00
...
[monitor_wrap.c]
spelling; from Brian Poole <raj@cerias.purdue.edu>
2002-06-20 23:53:53 +00:00
Ben Lindstrom
0e23ebcc8b
- (bal) typo of setgroup for cygwin. Patch by vinschen@redhat.com
2002-06-13 21:34:57 +00:00
Ben Lindstrom
b7ae94dd0b
- (bal) Some platforms don't have ONLCR (Notable Mint)
2002-06-12 17:32:30 +00:00
Ben Lindstrom
837461bf9a
- (bal) Build noop setgroups() for cygwin to clean up code (For other
...
platforms without the setgroups() requirement, you MUST define
SETGROUPS_NOOP in the configure.ac) Based on patch by vinschen@redhat.com
2002-06-12 16:57:14 +00:00
Ben Lindstrom
da394cae04
- markus@cvs.openbsd.org 2002/06/12 01:09:52
...
[ssh.c]
ssh_connect returns 0 on success
2002-06-12 16:11:12 +00:00
Ben Lindstrom
2415757253
- markus@cvs.openbsd.org 2002/06/11 23:03:54
...
[ssh.c]
remove unused cruft.
2002-06-12 16:09:39 +00:00
Ben Lindstrom
1aa6427c0f
- (bal) Cygwin fix up from swap uid clean up in ssh.c patch by
...
vinschen@redhat.com
2002-06-11 20:28:05 +00:00
Ben Lindstrom
9a17c9a568
- itojun@cvs.openbsd.org 2002/06/11 08:11:45
...
[canohost.c]
use "ntop" only after initialized
2002-06-11 16:47:22 +00:00
Ben Lindstrom
ce0f634270
- mpech@cvs.openbsd.org 2002/06/11 05:46:20
...
[auth-krb4.c monitor.h serverloop.c session.c ssh-agent.c sshd.c]
pid_t cleanup. Markus need this now to keep hacking.
markus@, millert@ ok
2002-06-11 16:42:49 +00:00
Ben Lindstrom
f9c4884c8e
- markus@cvs.openbsd.org 2002/06/11 04:14:26
...
[ssh.c sshconnect.c sshconnect.h]
no longer use uidswap.[ch] from the ssh client
run less code with euid==0 if ssh is installed setuid root
just switch the euid, don't switch the complete set of groups
(this is only needed by sshd). ok provos@
2002-06-11 16:37:51 +00:00
Ben Lindstrom
8bb6f36c8f
- markus@cvs.openbsd.org 2002/06/10 22:28:41
...
[channels.c channels.h session.c]
move creation of agent socket to session.c; no need for uidswapping
in channel.c.
2002-06-11 15:59:02 +00:00
Ben Lindstrom
914d03758b
- stevesk@cvs.openbsd.org 2002/06/10 21:21:10
...
[ssh_config]
update defaults for RhostsRSAAuthentication and RhostsAuthentication
here too (all options commented out with default value).
2002-06-11 15:55:01 +00:00
Ben Lindstrom
2bf8276393
- stevesk@cvs.openbsd.org 2002/06/10 17:45:20
...
[readconf.c ssh.1]
change RhostsRSAAuthentication and RhostsAuthentication default to no
since ssh is no longer setuid root by default; ok markus@
2002-06-11 15:53:05 +00:00
Ben Lindstrom
1775c9c97a
- stevesk@cvs.openbsd.org 2002/06/10 17:36:23
...
[ssh-add.1 ssh-add.c]
use convtime() to parse and validate key lifetime. can now
use '-t 2h' etc. ok markus@ provos@
2002-06-11 15:51:54 +00:00
Ben Lindstrom
11d470de34
- stevesk@cvs.openbsd.org 2002/06/10 16:56:30
...
[ssh-keysign.8]
merge in stuff from my man page; ok markus@
2002-06-11 15:50:13 +00:00
Ben Lindstrom
2779d28a0f
- stevesk@cvs.openbsd.org 2002/06/10 16:53:06
...
[auth-rsa.c ssh-rsa.c]
display minimum RSA modulus in error(); ok markus@
2002-06-11 15:47:42 +00:00
Ben Lindstrom
18a32a7efa
- itojun@cvs.openbsd.org 2002/06/09 22:17:21
...
[sshconnect.c]
pass salen to sockaddr_ntop so that we are happy on linux/solaris
2002-06-11 15:46:34 +00:00
Ben Lindstrom
5cac423871
- stevesk@cvs.openbsd.org 2002/06/09 22:15:15
...
[ssh.1]
update for no setuid root and ssh-keysign; ok deraadt@
2002-06-11 15:45:02 +00:00
Ben Lindstrom
494709decb
- (bal) ssh-agent.c RCSD fix (|unexpand already done)
2002-06-11 15:42:53 +00:00
Ben Lindstrom
05efee1092
- (bal) RCSID tag updates on channels.c, clientloop.c, nchan.c,
...
sftp-client.c, ssh-agenet.c, ssh-keygen.c and connect.h (we did unexpand
independant of them)
2002-06-09 20:20:58 +00:00
Ben Lindstrom
2749e1c8f5
- markus@cvs.openbsd.org 2002/06/09 04:33:27
...
[sshconnect.c]
abort() - > fatal()
2002-06-09 20:16:22 +00:00
Ben Lindstrom
159ac2e8cd
- itojun@cvs.openbsd.org 2002/06/08 21:15:27
...
[sshconnect.c]
always use getnameinfo. (diag message only)
2002-06-09 20:14:54 +00:00
Ben Lindstrom
2e17b08e48
- markus@cvs.openbsd.org 2002/06/08 12:46:14
...
[readconf.c]
silently ignore deprecated options, since FallBackToRsh might be passed
by remote scp commands.
2002-06-09 20:13:27 +00:00
Ben Lindstrom
af0c6d6a8c
- markus@cvs.openbsd.org 2002/06/08 12:36:53
...
[scp.c]
remove FallBackToRsh
2002-06-09 20:06:29 +00:00
Ben Lindstrom
7a7483d72e
- markus@cvs.openbsd.org 2002/06/08 05:41:18
...
[ssh_config]
remove FallBackToRsh/UseRsh
2002-06-09 20:05:35 +00:00
Ben Lindstrom
1c2bafebb3
- markus@cvs.openbsd.org 2002/06/08 05:40:01
...
[readconf.c]
just warn about Deprecated options for now
2002-06-09 20:04:50 +00:00
Ben Lindstrom
4daea86fd4
- markus@cvs.openbsd.org 2002/06/08 05:17:01
...
[readconf.c readconf.h ssh.1 ssh.c]
deprecate FallBackToRsh and UseRsh; patch from djm@
2002-06-09 20:04:02 +00:00