Commit Graph

2307 Commits

Author SHA1 Message Date
Ben Lindstrom ca8943e6de - (bal) Corrected debug() in uidswap.c to match upstream. 2002-06-06 20:42:04 +00:00
Ben Lindstrom abff1dd050 - stevesk@cvs.openbsd.org 2002/05/28 17:28:02
[uidswap.c]
     format spec change/casts and some KNF; ok markus@
2002-06-06 20:38:49 +00:00
Ben Lindstrom 105ccbe192 - stevesk@cvs.openbsd.org 2002/05/28 16:45:27
[monitor_mm.c]
     print strerror(errno) on mmap/munmap error; ok markus@
2002-06-06 20:33:06 +00:00
Ben Lindstrom 033a49c7cc - stevesk@cvs.openbsd.org 2002/05/26 20:35:10
[ssh.1]
     sort ChallengeResponseAuthentication; ok markus@
2002-06-06 20:30:28 +00:00
Ben Lindstrom 855bf3ac3c - markus@cvs.openbsd.org 2002/05/25 18:51:07
[auth.h auth2.c auth2-hostbased.c auth2-kbdint.c auth2-none.c
      auth2-passwd.c auth2-pubkey.c Makefile.in]
     split auth2.c into one file per method; ok provos@/deraadt@

NOTE: Merged back noticable cygwin and pam stuff.  May need review to
ensure I did not miss anything.
2002-06-06 20:27:55 +00:00
Ben Lindstrom 4887da222b - markus@cvs.openbsd.org 2002/05/25 08:50:39
[sshconnect2.c]
     execlp->execl; from stevesk
2002-06-06 20:05:57 +00:00
Ben Lindstrom 5206b951c6 - markus@cvs.openbsd.org 2002/05/24 08:45:14
[sshconnect2.c]
     stat ssh-keysign first, print error if stat fails;
     some debug->error; fix comment
2002-06-06 19:59:29 +00:00
Ben Lindstrom 9e5bb579f9 - markus@cvs.openbsd.org 2002/05/23 19:39:34
[ssh.c]
     add comment about ssh-keysign
2002-06-06 19:58:27 +00:00
Ben Lindstrom 1bad256822 - markus@cvs.openbsd.org 2002/05/23 19:24:30
[authfile.c authfile.h pathnames.h ssh.c sshconnect.c sshconnect.h
      sshconnect1.c sshconnect2.c ssh-keysign.8 ssh-keysign.c Makefile.in]
     add /usr/libexec/ssh-keysign: a setuid helper program for hostbased
     authentication in protocol v2 (needs to access the hostkeys).

Note: Makefile.in untested.  Will test after merge is finished.
2002-06-06 19:57:33 +00:00
Ben Lindstrom f666fec2d5 - deraadt@cvs.openbsd.org 2002/05/22 23:18:25
[ssh.c sshd.c]
     spelling; abishoff@arc.nasa.gov
2002-06-06 19:51:58 +00:00
Ben Lindstrom 38ed63d759 - deraadt@cvs.openbsd.org 2002/05/19 20:54:52
[log.h]
     extra commas in enum not 100% portable
2002-06-06 19:51:06 +00:00
Ben Lindstrom fac7769f64 - stevesk@cvs.openbsd.org 2002/05/16 22:09:59
[session.c ssh.c]
     don't limit xauth pathlen on client side and longer print length on
     server when debug; ok markus@
2002-06-06 19:49:54 +00:00
Ben Lindstrom 6a24641365 - markus@cvs.openbsd.org 2002/05/16 22:02:50
[cipher.c kex.h mac.c]
     fix warnings (openssl 0.9.7 requires const)
2002-06-06 19:48:16 +00:00
Ben Lindstrom fb62a69488 - markus@cvs.openbsd.org 2002/05/15 21:56:38
[servconf.c sshd.8 sshd_config]
     re-enable privsep and disable setuid for post-3.2.2
2002-06-06 19:47:11 +00:00
Kevin Steves df75dd21f5 - (stevesk) [channels.c] bug #164 patch from YOSHIFUJI Hideaki (changed
setsockopt from debug to error for now).
2002-06-04 20:52:19 +00:00
Tim Rice 28bbb0c458 [configure.ac.orig monitor_fdpass.c] Enahnce msghdr tests to address
build problem on Irix reported by Dave Love <d.love@dl.ac.uk>. Back out
last monitor_fdpass.c changes that are no longer needed with new tests.
Patch tested on Irix by Jan-Frode Myklebust <janfrode@parallab.uib.no>
2002-05-27 17:37:32 -07:00
Damien Miller 8ce8296fd0 sync scard/ 2002-05-22 14:24:01 +10:00
Damien Miller 23dc10ddac crank rpm spec versions 2002-05-22 14:14:54 +10:00
Damien Miller 667fb25f47 Crank version
(also missed changelog message)
2002-05-22 14:14:00 +10:00
Damien Miller 74cc5bb851 fix spelling mistakes spotted by Solar Designer <solar@openwall.com> 2002-05-22 11:02:15 +10:00
Kevin Steves bc5bb55755 - (stevesk) [sshd.c] #ifndef HAVE_CYGWIN for setgroups() 2002-05-21 17:59:13 +00:00
Kevin Steves c5041acef3 - (stevesk) [sshd.c] bug 245; disable setsid() for now 2002-05-21 17:50:21 +00:00
Tim Rice 9de793cc6c [configure.ac] remove extra MD5_MSG="no" line. 2002-05-17 08:59:22 -07:00
Ben Lindstrom 4e67d38a7e - (bal) OpenBSD CVS Sync
- markus@cvs.openbsd.org 2002/05/15 21:05:29
     [version.h]
     enter OpenSSH_3.2.2
 - (bal) Caldara, Suse, and Redhat openssh.specs updated.
2002-05-15 21:50:14 +00:00
Ben Lindstrom c5c15dde32 - markus@cvs.openbsd.org 2002/05/15 21:02:53
[servconf.c sshd.8 sshd_config]
     disable privsep and enable setuid for the 3.2.2 release
2002-05-15 21:37:34 +00:00
Ben Lindstrom c57bbf158d - millert@cvs.openbsd.org 2002/05/06 23:34:33
[ssh.1 sshd.8]
     Kill/adjust r(login|exec)d? references now that those are no longer in
     the tree.
2002-05-15 21:36:45 +00:00
Ben Lindstrom bb2ce36d4d - deraadt@cvs.openbsd.org 2002/05/04 02:39:35
[servconf.c sshd.8 sshd_config]
     enable privsep by default; provos ok
(historical)
2002-05-15 21:35:43 +00:00
Ben Lindstrom 2b70e5603f - (bal) Clarified openbsd-compat/*-cray.* Licence provided by Wendy. 2002-05-15 16:39:51 +00:00
Ben Lindstrom 7339b2a278 - mouring@cvs.openbsd.org 2002/05/15 15:47:49
[kex.c monitor.c monitor_wrap.c sshd.c]
     'monitor' variable clashes with at least one lame platform (NeXT).  i
     Renamed to 'pmonitor'.  provos@
 - (bal) Fixed up PAM case.  I think.
2002-05-15 16:25:01 +00:00
Ben Lindstrom bdde330d2f - markus@cvs.openbsd.org 2002/05/13 21:26:49
[auth-rhosts.c]
     handle debug messages during rhosts-rsa and hostbased authentication;
     ok provos@
2002-05-15 16:19:37 +00:00
Ben Lindstrom 17401b6b77 - millert@cvs.openbsd.org 2002/05/13 15:53:19
[sshd.c]
     Call setsid() in the child after sshd accepts the connection and forks.
     This is needed for privsep which calls setlogin() when it changes uids.
     Without this, there is a race where the login name of an existing
     connection, as returned by getlogin(), may be changed to the privsep
     user (sshd).  markus@ OK
2002-05-15 16:17:56 +00:00
Ben Lindstrom a574cda45b - markus@cvs.openbsd.org 2002/05/13 20:44:58
[auth-options.c auth.c auth.h]
     move the packet_send_debug handling from auth-options.c to auth.c;
     ok provos@
2002-05-15 16:16:14 +00:00
Ben Lindstrom 58d4dafeb1 - itojun@cvs.openbsd.org 2002/05/13 02:37:39
[auth-skey.c auth2.c]
     less warnings.  skey_{respond,query} are public (in auth.h)
2002-05-15 16:14:36 +00:00
Ben Lindstrom 966bfdae6b - stevesk@cvs.openbsd.org 2002/05/11 20:24:48
[ssh.h]
     typo in comment
2002-05-15 16:09:57 +00:00
Ben Lindstrom 973be0083b - deraadt@cvs.openbsd.org 2002/05/08 21:06:34
[ssh.h]
     move to sshd.sshd instead
2002-05-15 16:08:48 +00:00
Ben Lindstrom 1650ba3f57 - deraadt@cvs.openbsd.org 2002/05/07 19:54:36
[ssh.h]
     use ssh uid
2002-05-15 16:07:11 +00:00
Ben Lindstrom beecf74e2b - (bal) CVS ID fix up on auth-passwd.c 2002-05-15 15:59:17 +00:00
Damien Miller 860e929fa2 wrap 2002-05-15 10:12:29 +10:00
Damien Miller ee5e3b2d8a wrap 2002-05-15 10:08:17 +10:00
Tim Rice 8dd6febf73 update version. 2002-05-14 09:03:46 -07:00
Tim Rice fd6fd24a71 remove reference to UnixWare 7 and OpenUNIX 8
from PAM-enabled pragraph. UnixWare has no PAM.
2002-05-13 20:50:38 -07:00
Tim Rice 1e28c9e6ba 20020514
[sshpty.c] set tty modes when allocating old style bsd ptys to
match what newer style ptys have when allocated. Based on a patch by
Roger Cornelius <rac@tenzing.org>
[README.privsep] UnixWare 7 and OpenUNIX 8 work.
2002-05-13 17:07:18 -07:00
Kevin Steves f8defa2327 - (stevesk) [README.privsep] PAM+privsep works with Solaris 8. 2002-05-13 23:31:09 +00:00
Damien Miller 05720356d6 - (djm) Add INSTALL warning about SSH protocol 1 blowfish w/ OpenSSL < 0.9.6 2002-05-13 15:22:21 +10:00
Damien Miller f71d2a5d44 - (djm) Bug #234: missing readpassphrase declaration and defines 2002-05-13 15:14:08 +10:00
Kevin Steves 0228155f06 - (stevesk) add initial README.privsep 2002-05-13 03:57:04 +00:00
Kevin Steves c81e12976e - (stevesk) [configure.ac] nicer message: --with-privsep-user=user 2002-05-13 03:51:40 +00:00
Damien Miller b7cb96934e - (djm) Update RPM spec file: different superuser path, use
/var/empty/sshd for privsep
2002-05-13 13:26:57 +10:00
Damien Miller f58c672f0e - (djm) Add --with-privsep-path configure option 2002-05-13 13:15:42 +10:00
Damien Miller 5ad9fd9820 - (djm) Bug #231: UsePrivilegeSeparation turns off Banner. 2002-05-13 11:07:41 +10:00
Damien Miller a18bbd398e - (djm) Add --with-superuser-path=xxx configure option to specify what $PATH
the superuser receives.
2002-05-13 10:48:57 +10:00
Tim Rice 802b956868 fix for systems that have both HAVE_ACCRIGHTS_IN_MSGHDR and
HAVE_CONTROL_IN_MSGHDR. Ie. sys/socket.h has #define msg_accrights msg_control
2002-05-11 15:30:04 -07:00
Tim Rice aef7371fe4 applied a rework of djm's OpenSSL search cleanup patch.
Now only searches system and /usr/local/ssl (OpenSSL's default install path)
 Others must use --with-ssl-dir=....
2002-05-11 13:17:42 -07:00
Kevin Steves f98fb721a0 - (stevesk) [auth.c] Shadow account and expiration cleanup. Now
check for root forced expire.  Still don't check for inactive.
2002-05-10 15:48:52 +00:00
Ben Lindstrom 0b47814b43 - (bal) Back all the way out of auth-passwd.c changes. Breaks too many
things that don't set pw->pw_passwd.
2002-05-10 02:40:15 +00:00
Damien Miller 87aea25f1a - (djm) Try to drop supplemental groups at daemon startup. Patch from
RedHat
2002-05-10 12:20:24 +10:00
Damien Miller cfe4a89eef - (djm) Rework RedHat RPM files. Based on spec from Nalin
Dahyabhai <nalin@redhat.com> and patches from
   Pekka Savola <pekkas@netcore.fi>
2002-05-10 12:19:23 +10:00
Tim Rice a7a5d6d1b5 Unbreak make -f Makefile.in distprep 2002-05-09 07:05:59 -07:00
Damien Miller ffc868ff83 - (djm) Disable PAM kbd-int auth if privsep is turned on (it doesn't work) 2002-05-09 15:59:13 +10:00
Tim Rice 0502a471e0 set SHELL in Makefile in case someone makes from a non bourne compatable shell 2002-05-08 16:04:14 -07:00
Tim Rice 63cf84199d fix logic on when seed_rng() is called.
Report by Chris Maxwell <maxwell@cs.dal.ca>
2002-05-08 15:57:18 -07:00
Tim Rice 4bd2a19890 Add truncate() emulation to address Bug 208 2002-05-07 19:51:31 -07:00
Damien Miller f762a4bea5 - (djm) Don't reinitialise PAM credentials before we have started PAM.
Report from Pekka Savola <pekkas@netcore.fi>
2002-05-08 12:27:55 +10:00
Damien Miller a33501bb5f - (djm) Unbreak PAM auth for protocol 1. Report from Pekka Savola
<pekkas@netcore.fi>
2002-05-08 12:24:42 +10:00
Damien Miller 52910ddc66 - (djm) Unbreak auth-passwd.c for PAM and SIA 2002-05-08 12:18:26 +10:00
Ben Lindstrom 532bbdb99b - (bal) Fixed auth-passwd.c to resolve PermitEmptyPassword issue 2002-05-06 23:06:08 +00:00
Damien Miller 804357ace9 - (djm) Fix readpassphase compilation for systems which have it 2002-05-01 22:00:22 +10:00
Damien Miller 38cd435892 - (djm) Import OpenBSD regression tests. Requires BSD make to run 2002-05-01 13:17:33 +10:00
Tim Rice 2f09289e74 [contrib/caldera/openssh.spec] update fixUP to reflect changes in sshd_config.
[contrib/cygwin/README] remove reference to regex.
patch from Corinna Vinschen <vinschen@redhat.com>
2002-04-29 20:53:12 -07:00
Damien Miller aa100c546c - (djm) Bug #180: Set ToS bits on IPv4-in-IPv6 mapped addresses. Based on
patch from openssh@misc.tecq.org
2002-04-26 16:54:34 +10:00
Damien Miller ae9d5af0de - (djm) Disable PAM password expiry until a complete fix for bug #188 exists 2002-04-26 11:27:24 +10:00
Damien Miller 13ce922cc6 - (djm) Bug #137, #209: fix make problems for scard/Ssh.bin, do uudecode
during distprep only
2002-04-26 11:25:40 +10:00
Kevin Steves 0ea1d9d1f2 - (stevesk) [acconfig.h auth-passwd.c configure.ac sshd.c] HP-UX 10.26
support.  bug #184.  most from dcole@keysoftsys.com.
2002-04-25 18:17:04 +00:00
Kevin Steves 30e494fbca - (stevesk) [defines.h] remove USE_TIMEVAL; unused 2002-04-25 17:56:07 +00:00
Damien Miller 0150c65830 - djm@cvs.openbsd.org 2002/04/23 22:16:29
[sshd.c]
     Improve error message; ok markus@ stevesk@
2002-04-24 09:49:09 +10:00
Damien Miller 11ec28176e - (djm) OpenBSD CVS Sync
- markus@cvs.openbsd.org 2002/04/23 12:54:10
     [version.h]
     3.2.1
2002-04-24 09:48:14 +10:00
Kevin Steves 5feaaefaf2 - (stevesk) [acconfig.h configure.ac session.c] LOGIN_NO_ENDOPT for HP-UX 2002-04-23 20:45:55 +00:00
Kevin Steves 03df6cd83c - (stevesk) [acconfig.h] NEED_IN_SYSTM_H unused 2002-04-23 20:11:13 +00:00
Markus Friedl 78cf8c377f - markus@cvs.openbsd.org 2002/04/23 12:58:26
[radix.c]
     send complete ticket; semerad@ss1000.ms.mff.cuni.cz
2002-04-23 16:41:12 +02:00
Damien Miller f75fcc61f4 wrap an out of control line 2002-04-23 23:32:38 +10:00
Damien Miller fa2bb69d16 - (djm) Bug #206 - blibpath isn't always needed for AIX ld, avoid
sizeof(long long int) == 4 breakage. Patch from Matthew Clarke
   <Matthew_Clarke@mindlink.bc.ca>
2002-04-23 23:22:25 +10:00
Damien Miller f1b9d11a3e - (djm) Bug #214: Fix utmp for Irix (don't strip "tty"). Patch from
Kevin Taylor <no@nowhere.org> (??) via Philipp Grau
   <phgrau@zedat.fu-berlin.de>
2002-04-23 23:09:19 +10:00
Damien Miller d77facda1a - (djm) Bug #213: Simplify CMSG_ALIGN macros to avoid symbol clashes.
Reported by Doug Manton <dmanton@emea.att.com>
2002-04-23 22:59:51 +10:00
Damien Miller f5fea44ae3 - (djm) Define BROKEN_REALPATH for AIX, patch from
Antti Tapaninen <aet@cc.hut.fi>
2002-04-23 22:52:45 +10:00
Damien Miller 654a4ef969 - (djm) Redhat spec enables KrbV by default 2002-04-23 21:17:17 +10:00
Damien Miller 0b3894d5b5 - (djm) Update RPM spec file versions 2002-04-23 21:15:31 +10:00
Damien Miller ef7c11de6e - (djm) Trim ChangeLog to include only post-3.1 changes 2002-04-23 21:13:32 +10:00
Damien Miller 2797f7f03a - markus@cvs.openbsd.org 2002/04/22 21:04:52
[channels.c clientloop.c clientloop.h ssh.c]
     request reply (success/failure) for -R style fwd in protocol v2,
     depends on ordered replies.
     fixes http://bugzilla.mindrot.org/show_bug.cgi?id=215; ok provos@
2002-04-23 21:09:44 +10:00
Damien Miller d7de14b6ad - markus@cvs.openbsd.org 2002/04/22 16:16:53
[servconf.c sshd.8 sshd_config]
     do not auto-enable KerberosAuthentication; ok djm@, provos@, deraadt@
2002-04-23 21:04:51 +10:00
Damien Miller 635fe98a7f - markus@cvs.openbsd.org 2002/04/22 06:15:47
[radix.c]
     fix check for overflow
2002-04-23 21:00:33 +10:00
Damien Miller f61c01506f - stevesk@cvs.openbsd.org 2002/04/21 16:25:06
[sshconnect1.c]
     spelling in error message; ok markus@
2002-04-23 20:56:02 +10:00
Damien Miller 7a8558d3ea - stevesk@cvs.openbsd.org 2002/04/21 16:19:27
[sshd.8 sshd_config]
     document default AFSTokenPassing no; ok deraadt@
2002-04-23 20:51:15 +10:00
Damien Miller bad0e0162f - markus@cvs.openbsd.org 2002/04/20 09:17:19
[radix.c]
     rewrite using the buffer_* API, fixes overflow; ok deraadt@
2002-04-23 20:46:56 +10:00
Damien Miller 3b23566a5b - markus@cvs.openbsd.org 2002/04/20 09:14:58
[bufaux.c bufaux.h]
     add buffer_{get,put}_short
2002-04-23 20:42:36 +10:00
Damien Miller 7941855f09 - (djm) Make privsep work with PAM (still experimental) 2002-04-23 20:28:48 +10:00
Damien Miller 594a71b9b9 - (djm) Bug #222: Fix tests for getaddrinfo on OSF/1. Spotted by
Robert Urban <urban@spielwiese.de>
2002-04-23 20:22:59 +10:00
Tim Rice f02dccc0dc [entropy.c.] Portability fix for SCO Unix 3.2v4.x (SCO OSR 3.0).
entropy.c needs seteuid(getuid()) for the setuid(original_uid) to succeed.
Patch by gert@greenie.muc.de. This fixes one part of Bug 208
2002-04-21 11:26:10 -07:00
Damien Miller a370f4dcc6 - (djm) Avoid SIGCHLD breakage when run from rsync. Fix from
Sturle Sunde <sturle.sunde@usit.uio.no>
2002-04-18 22:53:22 +10:00
Tim Rice 43a1c13e0f [configure.ac] Issue warning on --with-default-path=/some_path
if LOGIN_CAP is enabled. Report & testing by Tuc <tuc@ttsg.com>
2002-04-17 21:19:14 -07:00
Damien Miller 5efd71038d - (djm) Fix .Nm in mdoc2man.pl from pspencer@fields.utoronto.ca 2002-04-17 12:30:45 +10:00
Damien Miller bd63874d4b - (djm) Tell users to configure /dev/random support into OpenSSL in INSTALL 2002-04-17 12:22:58 +10:00
Tim Rice 66480f188e [configure.ac] add tests for recvmsg and sendmsg.
[monitor_fdpass.c] add checks for HAVE_SENDMSG and HAVE_RECVMSG for
systems that HAVE_ACCRIGHTS_IN_MSGHDR but no recvmsg or sendmsg.
2002-04-15 21:10:09 -07:00
Kevin Steves eb3630205a - (stevesk) bsd-cygwin_util.[ch] BSD license from Corinna Vinschen 2002-04-15 22:00:51 +00:00
Damien Miller 8be24f3846 - (djm) Unbreak "make install". Fix from Darren Tucker <dtucker@zip.com.au> 2002-04-15 13:23:59 +10:00
Damien Miller 49411ff8a7 - (djm) Random number collection doc fixes from Ben 2002-04-14 23:16:04 +10:00
Damien Miller 32e4818015 - (djm) ssh-rand-helper improvements
- Add commandline debugging options
   - Don't write binary data if stdout is a tty (use hex instead)
   - Give it a manpage
2002-04-14 19:27:12 +10:00
Damien Miller fd4c9eee25 - (djm) Add KrbV support patch from Simon Wilkinson <simon@sxw.org.uk> 2002-04-13 11:04:40 +10:00
Ben Lindstrom 927dfd2d7e - (bal) disable privsep if no MAP_ANON. We can re-enable it
after the release when we can do more testing.
2002-04-12 18:51:22 +00:00
Ben Lindstrom c42f7cfd16 - (bal) Mistaken in Cygwin scripts for ssh starting. Patch by
Corinna Vinschen <vinschen@redhat.com>
2002-04-12 17:44:13 +00:00
Tim Rice ae49fe64ca [configure.ac] add <sys/types.h> to msghdr tests.
Change -L to -h on testing for /bin being symbolic link
2002-04-12 10:26:21 -07:00
Kevin Steves 19fa9b544f - (stevesk) [auth-sia.[ch]] add BSD license from Chris Adams 2002-04-12 15:36:07 +00:00
Tim Rice 813f0452ed [acconfig.h defines.h includes.h] put includes in includes.h and
defines in defines.h [rijndael.c openbsd-compat/fake-socket.h
openbsd-compat/inet_aton.c] include "includes.h" instead of "config.h"
ok stevesk@
2002-04-11 20:35:39 -07:00
Kevin Steves 0c283d8444 - (stevesk) [auth-sia.c] cleanup 2002-04-11 20:39:40 +00:00
Kevin Steves fe6ca54ac2 - (stevesk) [configure.ac monitor.c] HAVE_SOCKETPAIR 2002-04-10 22:04:54 +00:00
Ben Lindstrom 027e4de24f - markus@cvs.openbsd.org 2002/04/10 08:56:01
[version.h]
     OpenSSH_3.2
 - Added p1 to idenify Portable release version.
2002-04-10 16:26:20 +00:00
Ben Lindstrom b5115eaf80 - markus@cvs.openbsd.org 2002/04/10 08:21:47
[auth1.c compat.c compat.h]
     strip '@' from username only for KerbV and known broken clients, bug #204
2002-04-10 16:17:34 +00:00
Kevin Steves 6939b233d0 - (stevesk) [auth-sia.c] compile fix Chris Adams <cmadams@hiwaay.net> 2002-04-10 16:09:51 +00:00
Ben Lindstrom 34b7320a9d - (bal) Minor OpenSC updates. Fix up header locations and update
README.smartcard provided by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-08 18:37:07 +00:00
Kevin Steves 265c9d00c3 - (stevesk) wrap munmap() with HAVE_MMAP also. 2002-04-07 22:36:49 +00:00
Kevin Steves 7ff911216b - (stevesk) --with-privsep-user; default sshd 2002-04-07 19:22:54 +00:00
Kevin Steves b1184bbf29 - (stevesk) remove configure support for poll.h; it was removed
from sshd.c a long time ago.
2002-04-07 18:12:03 +00:00
Kevin Steves 86b9fe6a77 - (stevesk) HAVE_MMAP and HAVE_SYS_MMAN_H and use them in
monitor_mm.c
2002-04-07 17:08:53 +00:00
Kevin Steves c3c825575c - (stevesk) [monitor_fdpass.c] fatal() for UsePrivilegeSeparation=yes
and no fd passing support.
2002-04-07 16:39:12 +00:00
Kevin Steves a44e0351ee - (stevesk) HAVE_CONTROL_IN_MSGHDR; not used right now.
Future: we may want to test if fd passing works correctly.
2002-04-07 16:18:03 +00:00
Ben Lindstrom fdee8ef0ac - (bal) We no longer use atexit()/xatexit()/on_exit() 2002-04-06 23:52:02 +00:00
Ben Lindstrom 0318801591 - (bal) Quiet down configure.ac if /bin/test does not exist. 2002-04-06 20:30:07 +00:00
Ben Lindstrom 8ff2a8d2c2 - (bal) Revered out of runtime IRIX runtime detection of joblimits. Code is
incomplete.
2002-04-06 18:58:31 +00:00
Ben Lindstrom de3895d580 - mouring@cvs.openbsd.org 2002/04/06 18:24:09
[scp.c]
     Fixes potental double // within path.
     http://bugzilla.mindrot.org/show_bug.cgi?id=76
2002-04-06 18:29:59 +00:00
Ben Lindstrom 8d6017566c - (bal) Slight update to OpenSC support. Better version checking. patch
by Juha Yrjölä <jyrjola@cc.hut.fi>
2002-04-06 18:19:38 +00:00
Ben Lindstrom 06e9515eb8 - djm@cvs.openbsd.org 2002/04/06 00:30:08
[sftp-client.c]
     Fix occasional corruption on upload due to bad reuse of request id, spotted
     by chombier@mac.com; ok markus@
2002-04-06 04:16:45 +00:00
Ben Lindstrom dc0594cc54 - (bal) Added MAP_FAILED to allow AIX and Trusted HP to compile. 2002-04-06 04:11:28 +00:00
Damien Miller 12db56ba2f - (djm) Typo in Suse SPEC file. Fix from Carsten Grohmann
<carsten.grohmann@dr-baldeweg.de>
2002-04-06 11:12:52 +10:00
Ben Lindstrom a11e270115 - stevesk@cvs.openbsd.org 2002/04/05 20:56:21
[sshd.8]
     clarify sshrc some and handle X11UseLocalhost=yes; ok markus@
2002-04-05 22:18:48 +00:00
Ben Lindstrom 924144e650 - (bal) Too many <sys/queue.h> issues. Remove all workarounds and
using internal version only.
2002-04-05 20:23:35 +00:00
Ben Lindstrom a42694fa25 - (bal) Patch for OpenSC SmartCard library; ok markus@; patch by
Juha Yrjölä <jyrjola@cc.hut.fi>
 - (bal) Minor documentation update to reflect smartcard library
   support changes.
2002-04-05 16:11:45 +00:00
Ben Lindstrom 8a725a843d - markus@cvs.openbsd.org 2002/04/03 09:26:11
[cipher.c myproposal.h]
     re-add rijndael-cbc@lysator.liu.se for MacSSH; ash@lab.poc.net
2002-04-04 22:10:38 +00:00
Kevin Steves e683e76439 - (stevesk) [auth-pam.c auth-pam.h auth-passwd.c auth-sia.c auth-sia.h
auth1.c auth2.c] PAM, OSF_SIA password auth cleanup; from djm.
2002-04-04 19:02:28 +00:00
Ben Lindstrom af40bc6a72 - (bal) mispelling in uidswap.c (portable only) 2002-04-03 03:36:54 +00:00
Ben Lindstrom 07739fe305 - markus@cvs.openbsd.org 2002/04/02 20:11:38
[ssh-rsa.c]
     ignore SSH_BUG_SIGBLOB for ssh-rsa; #187
2002-04-03 03:03:04 +00:00
Ben Lindstrom 2f3d52a2d6 - markus@cvs.openbsd.org 2002/04/02 17:37:48
[sftp.c]
     always call log_init()
2002-04-02 21:06:18 +00:00
Ben Lindstrom eecdf23531 - markus@cvs.openbsd.org 2002/04/02 11:49:39
[ssh-agent.c]
     check $SHELL for -k and -d, too;
     http://bugzilla.mindrot.org/show_bug.cgi?id=199
2002-04-02 21:03:51 +00:00
Ben Lindstrom f26ff5b9d8 - markus@cvs.openbsd.org 2002/04/01 22:07:17
[sftp-client.c]
     fallback to stat if server does not support lstat
2002-04-02 21:00:31 +00:00
Ben Lindstrom a1d8114044 - markus@cvs.openbsd.org 2002/04/01 22:02:16
[sftp-client.c]
     20480 is an upper limit for older server
2002-04-02 20:58:11 +00:00
Ben Lindstrom 1e259bb0bf - (bal) CVS ID sync of uidswap.c 2002-04-02 20:53:39 +00:00
Ben Lindstrom 47fd8112b5 - markus@cvs.openbsd.org 2002/03/30 18:51:15
[monitor.c serverloop.c sftp-int.c sftp.c sshd.c]
     check waitpid for EINTR; based on patch from peter@ifm.liu.se
2002-04-02 20:48:19 +00:00
Ben Lindstrom 03f3932829 - stevesk@cvs.openbsd.org 2002/03/29 19:18:33
[auth-rsa.c ssh-rsa.c ssh.h]
     make RSA modulus minimum #define; ok markus@
2002-04-02 20:43:11 +00:00
Ben Lindstrom 0d0be02a29 - stevesk@cvs.openbsd.org 2002/03/29 19:16:22
[sshd.8]
     RSA key modulus size minimum 768; ok markus@
2002-04-02 20:39:29 +00:00
Ben Lindstrom c447fee9f1 - markus@cvs.openbsd.org 2002/03/29 18:59:32
[session.c session.h]
     retrieve last login time before the pty is allocated, store per session
2002-04-02 20:35:35 +00:00
Ben Lindstrom 2bf56e2dba - markus@cvs.openbsd.org 2002/03/28 15:34:51
[session.c]
     do not call record_login twice (for use_privsep)
2002-04-02 20:32:46 +00:00
Ben Lindstrom 155b981494 - markus@cvs.openbsd.org 2002/03/27 22:21:45
[ssh-keygen.c]
     try to import keys with extra trailing === (seen with ssh.com < 2.0.12)
2002-04-02 20:26:26 +00:00
Ben Lindstrom cdb66e0e82 - (bal) Hand Sync of scp.c (reverted to upstream code)
- deraadt@cvs.openbsd.org 2002/03/30 17:45:46
     [scp.c]
     stretch banners
2002-04-02 20:17:43 +00:00
Kevin Steves 38c4a28a7e - (stevesk) [auth1.c] fix password auth for protocol 1 when
!USE_PAM && !HAVE_OSF_SIA; merge issue.
2002-04-02 03:24:56 +00:00
Kevin Steves bd1901b7dc - (stevesk) [monitor.c] PAM should work again; will *not* work with
UsePrivilegeSeparation=yes.
2002-04-01 18:04:35 +00:00
Tim Rice c85496222b [sshconnect2.c] change uint32_t to u_int32_t 2002-03-31 12:49:38 -08:00
Tim Rice 49e457c43b [configure.ac] use /bin/test -L to work around broken builtin on Solaris 8 2002-03-31 11:23:06 -08:00
Kevin Steves 117b06dec9 - (stevesk) [configure.ac] remove header check for sys/ttcompat.h
bug 167
2002-03-30 17:55:21 +00:00
Ben Lindstrom b57a4bf93f - mouring@cvs.openbsd.org 2002/03/27 11:45:42
[monitor.c]
     monitor_allowed_key() returns int instead of pointer.  ok markus@
2002-03-27 18:00:59 +00:00
Ben Lindstrom 599717246c - markus@cvs.openbsd.org 2002/03/26 23:14:51
[kex.c]
     generate a new cookie for each SSH2_MSG_KEXINIT message we send out
2002-03-27 17:42:57 +00:00
Ben Lindstrom e1f9e324e9 - markus@cvs.openbsd.org 2002/03/26 23:13:03
[auth-rsa.c]
     disallow RSA keys < 768 for protocol 1, too (rhosts-rsa and rsa auth)
2002-03-27 17:38:43 +00:00
Ben Lindstrom 57686a82a5 - markus@cvs.openbsd.org 2002/03/26 22:50:39
[channels.h]
     CHANNEL_EFD_OUTPUT_ACTIVE is false for CHAN_CLOSE_RCVD, too
2002-03-27 17:36:41 +00:00
Ben Lindstrom 43a5e2f70e - rees@cvs.openbsd.org 2002/03/26 18:46:59
[scard.c]
     try_AUT0 in read_pubkey too, for those paranoid few who want to acl 'sh'
2002-03-27 17:33:17 +00:00
Ben Lindstrom 38a69e6b53 - markus@cvs.openbsd.org 2002/03/26 15:58:46
[readpass.c readpass.h sshconnect2.c]
     client side support for PASSWD_CHANGEREQ
2002-03-27 17:28:46 +00:00
Ben Lindstrom cd8bbce80b - markus@cvs.openbsd.org 2002/03/26 15:23:40
[bufaux.c]
     do not talk about packets in bufaux
2002-03-27 17:23:44 +00:00
Ben Lindstrom eb041dca1f - markus@cvs.openbsd.org 2002/03/26 11:37:05
[ssh.c]
     update Copyright
2002-03-27 17:20:38 +00:00
Ben Lindstrom f181384a6b - markus@cvs.openbsd.org 2002/03/26 11:34:49
[ssh.1 sshd.8]
     update to recent drafts
2002-03-27 17:18:31 +00:00
Ben Lindstrom 53f1830d6a - (bal) 'pw' should be 'authctxt->pw' in auth1.c spotted by
kent@lysator.liu.se
2002-03-27 16:50:03 +00:00
Ben Lindstrom 28364ecf45 - stevesk@cvs.openbsd.org 2002/03/26 03:24:01
[monitor.h monitor_fdpass.h monitor_mm.h monitor_wrap.h]
     $OpenBSD$
2002-03-26 03:42:20 +00:00
Ben Lindstrom cf15944c23 - markus@cvs.openbsd.org 2002/03/25 21:13:51
[channels.c channels.h compat.c compat.h nchan.c]
     don't send stderr data after EOF, accept this from older known (broken)
     sshd servers only, fixes http://bugzilla.mindrot.org/show_bug.cgi?id=179
2002-03-26 03:26:24 +00:00
Ben Lindstrom 4f054607f0 - markus@cvs.openbsd.org 2002/03/25 21:04:02
[ssh.c]
     simplify num_identity_files handling
2002-03-26 03:23:00 +00:00
Ben Lindstrom c861547f34 - stevesk@cvs.openbsd.org 2002/03/25 20:12:10
[monitor_mm.c monitor_wrap.c]
     ssize_t args use "%ld" and cast to (long)
     size_t args use "%lu" and cast to (u_long)
     ok markus@ and thanks millert@
2002-03-26 03:20:45 +00:00
Ben Lindstrom 0936a5bb72 - markus@cvs.openbsd.org 2002/03/25 17:34:27
[scard.c scard.h ssh-agent.c ssh-keygen.c ssh.c]
     change sc_get_key to sc_get_keys and hide smartcard details in scard.c
2002-03-26 03:17:42 +00:00
Ben Lindstrom 5facb2bbc4 - markus@cvs.openbsd.org 2002/03/25 09:25:06
[auth-rh-rsa.c]
     rm bogus comment
2002-03-26 03:08:47 +00:00
Ben Lindstrom f6d367b91a - markus@cvs.openbsd.org 2002/03/25 09:21:13
[auth-rsa.c]
     return 0 (not NULL); tomh@po.crl.go.jp
2002-03-26 02:59:31 +00:00
Ben Lindstrom 2e9d866608 - stevesk@cvs.openbsd.org 2002/03/24 23:20:00
[monitor.c]
     remove "\n" from fatal()
2002-03-26 02:49:34 +00:00
Ben Lindstrom c2c6cbc527 - markus@cvs.openbsd.org 2002/03/24 18:05:29
[scard.c]
     we need to figure out AUT0 for sc_private_encrypt, too
2002-03-26 02:44:44 +00:00
Ben Lindstrom 31ee7aeb15 - stevesk@cvs.openbsd.org 2002/03/24 17:53:16
[monitor_fdpass.c]
     minor cleanup and more error checking; ok markus@
2002-03-26 02:36:29 +00:00
Ben Lindstrom fcad1c92c9 - stevesk@cvs.openbsd.org 2002/03/24 17:27:03
[kexgex.c]
     typo; ok markus@
2002-03-26 02:20:06 +00:00
Ben Lindstrom 8b08d8115d - markus@cvs.openbsd.org 2002/03/24 16:01:13
[packet.c]
     debug->debug3 for extra padding
2002-03-26 02:09:41 +00:00
Ben Lindstrom 3dc40f997b - markus@cvs.openbsd.org 2002/03/24 16:00:27
[serverloop.c]
     remove unused debug
2002-03-26 02:01:30 +00:00
Ben Lindstrom f90f58d846 - stevesk@cvs.openbsd.org 2002/03/23 20:57:26
[sshd.c]
     setproctitle() after preauth child; ok markus@
2002-03-26 01:53:03 +00:00
Kevin Steves 6205a18f55 - (stevesk) import OpenBSD <sys/tree.h> as "openbsd-compat/tree.h" 2002-03-26 00:12:49 +00:00
Kevin Steves b4799a31a5 - (stevesk) [session.c] disable LOGIN_NEEDS_TERM until we are sure
it can be removed. only used on solaris. will no longer compile with
   privsep shuffling.
2002-03-24 23:19:54 +00:00
Kevin Steves 4408c2098f - (stevesk) [LICENCE] OpenBSD sync 2002-03-23 02:20:07 +00:00
Tim Rice f29a6539c0 [cipher.c] fix problem with OpenBSD sync 2002-03-22 13:27:40 -08:00
Kevin Steves 4435a55a4b - (stevesk) [defines.h] #define MAP_ANON MAP_ANONYMOUS for HP-UX; other
platforms may need this--I'm not sure.  mmap() issues will need to be
   addressed further.
2002-03-22 21:08:03 +00:00
Kevin Steves 219bef12c6 - (stevesk) [defines.h] hp-ux 11 has ancillary data style fd passing, but
is missing CMSG_LEN() and CMSG_SPACE() macros.
2002-03-22 20:53:32 +00:00
Kevin Steves 205cc1ef46 - (stevesk) [auth2.c] merge cleanup/sync 2002-03-22 20:43:05 +00:00
Kevin Steves 1adb120779 - (stevesk) [monitor_fdpass.c] support for access rights style file
descriptor passing
2002-03-22 19:32:53 +00:00
Kevin Steves 4846f4ab69 - (stevesk) configure and cpp __FUNCTION__ gymnastics to handle nielsisms 2002-03-22 18:19:53 +00:00
Kevin Steves 7e147607f5 - (stevesk) [monitor.c monitor_wrap.c] #ifdef HAVE_PW_CLASS_IN_PASSWD 2002-03-22 18:07:17 +00:00
Kevin Steves 939c9db9b1 - (stevesk) HAVE_ACCRIGHTS_IN_MSGHDR configure support 2002-03-22 17:23:25 +00:00
Ben Lindstrom 681d932634 - markus@cvs.openbsd.org 2002/03/21 23:07:37
[clientloop.c]
     remove unused, sync w/ cmdline patch in my tree.
2002-03-22 03:53:00 +00:00
Ben Lindstrom ba72d30aa5 - rees@cvs.openbsd.org 2002/03/21 22:44:05
[authfd.c authfd.h ssh-add.c ssh-agent.c ssh.c]
     Add PIN-protection for secret key.
2002-03-22 03:51:06 +00:00
Ben Lindstrom 266ec63eb3 - rees@cvs.openbsd.org 2002/03/21 21:54:34
[scard.c scard.h ssh-keygen.c]
     Add PIN-protection for secret key.
2002-03-22 03:47:38 +00:00
Ben Lindstrom 943481cc77 - markus@cvs.openbsd.org 2002/03/21 21:23:34
[sshd.c]
     add privsep_preauth() and remove 1 goto; ok provos@
2002-03-22 03:43:46 +00:00
Ben Lindstrom fa1336ff47 - markus@cvs.openbsd.org 2002/03/21 20:51:12
[sshd_config]
     add privsep (off)
2002-03-22 03:40:58 +00:00
Ben Lindstrom 818659a163 - rees@cvs.openbsd.org 2002/03/21 18:08:15
[scard.c]
     In sc_put_key(), sc_reader_id should be id.
2002-03-22 03:38:35 +00:00
Ben Lindstrom eda98a728d - markus@cvs.openbsd.org 2002/03/21 16:58:13
[clientloop.c]
     remove unused
2002-03-22 03:35:48 +00:00
Ben Lindstrom 70e3ad8231 - markus@cvs.openbsd.org 2002/03/21 16:57:15
[scard.c]
     remove const
2002-03-22 03:33:43 +00:00
Ben Lindstrom 0b675b1659 - markus@cvs.openbsd.org 2002/03/21 16:38:06
[scard.c]
     make compile w/ openssl 0.9.7
2002-03-22 03:28:11 +00:00