summaryrefslogtreecommitdiff
path: root/monitor.c
diff options
context:
space:
mode:
authorColin Watson <cjwatson@debian.org>2011-01-24 12:43:25 +0000
committerColin Watson <cjwatson@debian.org>2011-01-24 12:43:25 +0000
commit626f1d986ff72aa514da63e34744e1de9cf21b9a (patch)
treed215a5280bc2e57251e4a9e08bfd3674ad824a94 /monitor.c
parent6ed622cb6fe8f71bbe0d998cdd12280410bfb420 (diff)
parent0970072c89b079b022538e3c366fbfa2c53fc821 (diff)
* New upstream release (http://www.openssh.org/txt/release-5.7):
- Implement Elliptic Curve Cryptography modes for key exchange (ECDH) and host/user keys (ECDSA) as specified by RFC5656. ECDH and ECDSA offer better performance than plain DH and DSA at the same equivalent symmetric key length, as well as much shorter keys. - sftp(1)/sftp-server(8): add a protocol extension to support a hard link operation. It is available through the "ln" command in the client. The old "ln" behaviour of creating a symlink is available using its "-s" option or through the preexisting "symlink" command. - scp(1): Add a new -3 option to scp: Copies between two remote hosts are transferred through the local host (closes: #508613). - ssh(1): "atomically" create the listening mux socket by binding it on a temporary name and then linking it into position after listen() has succeeded. This allows the mux clients to determine that the server socket is either ready or stale without races (closes: #454784). Stale server sockets are now automatically removed (closes: #523250). - ssh(1): install a SIGCHLD handler to reap expired child process (closes: #594687). - ssh(1)/ssh-agent(1): honour $TMPDIR for client xauth and ssh-agent temporary directories (closes: #357469, although only if you arrange for ssh-agent to actually see $TMPDIR since the setgid bit will cause it to be stripped off).
Diffstat (limited to 'monitor.c')
-rw-r--r--monitor.c9
1 files changed, 5 insertions, 4 deletions
diff --git a/monitor.c b/monitor.c
index f30f7d591..f7c5720d5 100644
--- a/monitor.c
+++ b/monitor.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: monitor.c,v 1.108 2010/07/13 23:13:16 djm Exp $ */ 1/* $OpenBSD: monitor.c,v 1.110 2010/09/09 10:45:45 djm Exp $ */
2/* 2/*
3 * Copyright 2002 Niels Provos <provos@citi.umich.edu> 3 * Copyright 2002 Niels Provos <provos@citi.umich.edu>
4 * Copyright 2002 Markus Friedl <markus@openbsd.org> 4 * Copyright 2002 Markus Friedl <markus@openbsd.org>
@@ -609,10 +609,10 @@ mm_answer_sign(int sock, Buffer *m)
609 p = buffer_get_string(m, &datlen); 609 p = buffer_get_string(m, &datlen);
610 610
611 /* 611 /*
612 * Supported KEX types will only return SHA1 (20 byte) or 612 * Supported KEX types use SHA1 (20 bytes), SHA256 (32 bytes),
613 * SHA256 (32 byte) hashes 613 * SHA384 (48 bytes) and SHA512 (64 bytes).
614 */ 614 */
615 if (datlen != 20 && datlen != 32) 615 if (datlen != 20 && datlen != 32 && datlen != 48 && datlen != 64)
616 fatal("%s: data length incorrect: %u", __func__, datlen); 616 fatal("%s: data length incorrect: %u", __func__, datlen);
617 617
618 /* save session id, it will be passed on the first call */ 618 /* save session id, it will be passed on the first call */
@@ -1734,6 +1734,7 @@ mm_get_kex(Buffer *m)
1734 kex->kex[KEX_DH_GRP14_SHA1] = kexdh_server; 1734 kex->kex[KEX_DH_GRP14_SHA1] = kexdh_server;
1735 kex->kex[KEX_DH_GEX_SHA1] = kexgex_server; 1735 kex->kex[KEX_DH_GEX_SHA1] = kexgex_server;
1736 kex->kex[KEX_DH_GEX_SHA256] = kexgex_server; 1736 kex->kex[KEX_DH_GEX_SHA256] = kexgex_server;
1737 kex->kex[KEX_ECDH_SHA2] = kexecdh_server;
1737#ifdef GSSAPI 1738#ifdef GSSAPI
1738 if (options.gss_keyex) { 1739 if (options.gss_keyex) {
1739 kex->kex[KEX_GSS_GRP1_SHA1] = kexgss_server; 1740 kex->kex[KEX_GSS_GRP1_SHA1] = kexgss_server;