Commit Graph

2113 Commits

Author SHA1 Message Date
Damien Miller f71d2a5d44 - (djm) Bug #234: missing readpassphrase declaration and defines 2002-05-13 15:14:08 +10:00
Kevin Steves 0228155f06 - (stevesk) add initial README.privsep 2002-05-13 03:57:04 +00:00
Kevin Steves c81e12976e - (stevesk) [configure.ac] nicer message: --with-privsep-user=user 2002-05-13 03:51:40 +00:00
Damien Miller b7cb96934e - (djm) Update RPM spec file: different superuser path, use
/var/empty/sshd for privsep
2002-05-13 13:26:57 +10:00
Damien Miller f58c672f0e - (djm) Add --with-privsep-path configure option 2002-05-13 13:15:42 +10:00
Damien Miller 5ad9fd9820 - (djm) Bug #231: UsePrivilegeSeparation turns off Banner. 2002-05-13 11:07:41 +10:00
Damien Miller a18bbd398e - (djm) Add --with-superuser-path=xxx configure option to specify what $PATH
the superuser receives.
2002-05-13 10:48:57 +10:00
Tim Rice 802b956868 fix for systems that have both HAVE_ACCRIGHTS_IN_MSGHDR and
HAVE_CONTROL_IN_MSGHDR. Ie. sys/socket.h has #define msg_accrights msg_control
2002-05-11 15:30:04 -07:00
Tim Rice aef7371fe4 applied a rework of djm's OpenSSL search cleanup patch.
Now only searches system and /usr/local/ssl (OpenSSL's default install path)
 Others must use --with-ssl-dir=....
2002-05-11 13:17:42 -07:00
Kevin Steves f98fb721a0 - (stevesk) [auth.c] Shadow account and expiration cleanup. Now
check for root forced expire.  Still don't check for inactive.
2002-05-10 15:48:52 +00:00
Ben Lindstrom 0b47814b43 - (bal) Back all the way out of auth-passwd.c changes. Breaks too many
things that don't set pw->pw_passwd.
2002-05-10 02:40:15 +00:00
Damien Miller 87aea25f1a - (djm) Try to drop supplemental groups at daemon startup. Patch from
RedHat
2002-05-10 12:20:24 +10:00
Damien Miller cfe4a89eef - (djm) Rework RedHat RPM files. Based on spec from Nalin
Dahyabhai <nalin@redhat.com> and patches from
   Pekka Savola <pekkas@netcore.fi>
2002-05-10 12:19:23 +10:00
Tim Rice a7a5d6d1b5 Unbreak make -f Makefile.in distprep 2002-05-09 07:05:59 -07:00
Damien Miller ffc868ff83 - (djm) Disable PAM kbd-int auth if privsep is turned on (it doesn't work) 2002-05-09 15:59:13 +10:00
Tim Rice 0502a471e0 set SHELL in Makefile in case someone makes from a non bourne compatable shell 2002-05-08 16:04:14 -07:00
Tim Rice 63cf84199d fix logic on when seed_rng() is called.
Report by Chris Maxwell <maxwell@cs.dal.ca>
2002-05-08 15:57:18 -07:00
Tim Rice 4bd2a19890 Add truncate() emulation to address Bug 208 2002-05-07 19:51:31 -07:00
Damien Miller f762a4bea5 - (djm) Don't reinitialise PAM credentials before we have started PAM.
Report from Pekka Savola <pekkas@netcore.fi>
2002-05-08 12:27:55 +10:00
Damien Miller a33501bb5f - (djm) Unbreak PAM auth for protocol 1. Report from Pekka Savola
<pekkas@netcore.fi>
2002-05-08 12:24:42 +10:00
Damien Miller 52910ddc66 - (djm) Unbreak auth-passwd.c for PAM and SIA 2002-05-08 12:18:26 +10:00
Ben Lindstrom 532bbdb99b - (bal) Fixed auth-passwd.c to resolve PermitEmptyPassword issue 2002-05-06 23:06:08 +00:00
Damien Miller 804357ace9 - (djm) Fix readpassphase compilation for systems which have it 2002-05-01 22:00:22 +10:00
Damien Miller 38cd435892 - (djm) Import OpenBSD regression tests. Requires BSD make to run 2002-05-01 13:17:33 +10:00
Tim Rice 2f09289e74 [contrib/caldera/openssh.spec] update fixUP to reflect changes in sshd_config.
[contrib/cygwin/README] remove reference to regex.
patch from Corinna Vinschen <vinschen@redhat.com>
2002-04-29 20:53:12 -07:00
Damien Miller aa100c546c - (djm) Bug #180: Set ToS bits on IPv4-in-IPv6 mapped addresses. Based on
patch from openssh@misc.tecq.org
2002-04-26 16:54:34 +10:00
Damien Miller ae9d5af0de - (djm) Disable PAM password expiry until a complete fix for bug #188 exists 2002-04-26 11:27:24 +10:00
Damien Miller 13ce922cc6 - (djm) Bug #137, #209: fix make problems for scard/Ssh.bin, do uudecode
during distprep only
2002-04-26 11:25:40 +10:00
Kevin Steves 0ea1d9d1f2 - (stevesk) [acconfig.h auth-passwd.c configure.ac sshd.c] HP-UX 10.26
support.  bug #184.  most from dcole@keysoftsys.com.
2002-04-25 18:17:04 +00:00
Kevin Steves 30e494fbca - (stevesk) [defines.h] remove USE_TIMEVAL; unused 2002-04-25 17:56:07 +00:00
Damien Miller 0150c65830 - djm@cvs.openbsd.org 2002/04/23 22:16:29
[sshd.c]
     Improve error message; ok markus@ stevesk@
2002-04-24 09:49:09 +10:00
Damien Miller 11ec28176e - (djm) OpenBSD CVS Sync
- markus@cvs.openbsd.org 2002/04/23 12:54:10
     [version.h]
     3.2.1
2002-04-24 09:48:14 +10:00
Kevin Steves 5feaaefaf2 - (stevesk) [acconfig.h configure.ac session.c] LOGIN_NO_ENDOPT for HP-UX 2002-04-23 20:45:55 +00:00
Kevin Steves 03df6cd83c - (stevesk) [acconfig.h] NEED_IN_SYSTM_H unused 2002-04-23 20:11:13 +00:00
Markus Friedl 78cf8c377f - markus@cvs.openbsd.org 2002/04/23 12:58:26
[radix.c]
     send complete ticket; semerad@ss1000.ms.mff.cuni.cz
2002-04-23 16:41:12 +02:00
Damien Miller f75fcc61f4 wrap an out of control line 2002-04-23 23:32:38 +10:00
Damien Miller fa2bb69d16 - (djm) Bug #206 - blibpath isn't always needed for AIX ld, avoid
sizeof(long long int) == 4 breakage. Patch from Matthew Clarke
   <Matthew_Clarke@mindlink.bc.ca>
2002-04-23 23:22:25 +10:00
Damien Miller f1b9d11a3e - (djm) Bug #214: Fix utmp for Irix (don't strip "tty"). Patch from
Kevin Taylor <no@nowhere.org> (??) via Philipp Grau
   <phgrau@zedat.fu-berlin.de>
2002-04-23 23:09:19 +10:00
Damien Miller d77facda1a - (djm) Bug #213: Simplify CMSG_ALIGN macros to avoid symbol clashes.
Reported by Doug Manton <dmanton@emea.att.com>
2002-04-23 22:59:51 +10:00
Damien Miller f5fea44ae3 - (djm) Define BROKEN_REALPATH for AIX, patch from
Antti Tapaninen <aet@cc.hut.fi>
2002-04-23 22:52:45 +10:00
Damien Miller 654a4ef969 - (djm) Redhat spec enables KrbV by default 2002-04-23 21:17:17 +10:00
Damien Miller 0b3894d5b5 - (djm) Update RPM spec file versions 2002-04-23 21:15:31 +10:00
Damien Miller ef7c11de6e - (djm) Trim ChangeLog to include only post-3.1 changes 2002-04-23 21:13:32 +10:00
Damien Miller 2797f7f03a - markus@cvs.openbsd.org 2002/04/22 21:04:52
[channels.c clientloop.c clientloop.h ssh.c]
     request reply (success/failure) for -R style fwd in protocol v2,
     depends on ordered replies.
     fixes http://bugzilla.mindrot.org/show_bug.cgi?id=215; ok provos@
2002-04-23 21:09:44 +10:00
Damien Miller d7de14b6ad - markus@cvs.openbsd.org 2002/04/22 16:16:53
[servconf.c sshd.8 sshd_config]
     do not auto-enable KerberosAuthentication; ok djm@, provos@, deraadt@
2002-04-23 21:04:51 +10:00
Damien Miller 635fe98a7f - markus@cvs.openbsd.org 2002/04/22 06:15:47
[radix.c]
     fix check for overflow
2002-04-23 21:00:33 +10:00
Damien Miller f61c01506f - stevesk@cvs.openbsd.org 2002/04/21 16:25:06
[sshconnect1.c]
     spelling in error message; ok markus@
2002-04-23 20:56:02 +10:00
Damien Miller 7a8558d3ea - stevesk@cvs.openbsd.org 2002/04/21 16:19:27
[sshd.8 sshd_config]
     document default AFSTokenPassing no; ok deraadt@
2002-04-23 20:51:15 +10:00
Damien Miller bad0e0162f - markus@cvs.openbsd.org 2002/04/20 09:17:19
[radix.c]
     rewrite using the buffer_* API, fixes overflow; ok deraadt@
2002-04-23 20:46:56 +10:00
Damien Miller 3b23566a5b - markus@cvs.openbsd.org 2002/04/20 09:14:58
[bufaux.c bufaux.h]
     add buffer_{get,put}_short
2002-04-23 20:42:36 +10:00