summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2010-03-03 - otto@cvs.openbsd.org 2010/03/01 11:07:06Damien Miller
[ssh-add.c] zap what seems to be a left-over debug message; ok markus@
2010-03-03 - jmc@cvs.openbsd.org 2010/02/26 22:09:28Damien Miller
[ssh-keygen.1 ssh.1 sshd.8] tweak previous;
2010-03-03 - (djm) [PROTOCOL.certkeys] Add RCS IdentDamien Miller
2010-03-01 - (tim) [config.guess config.sub] Bug 1722: Update to latest versions fromTim Rice
http://git.savannah.gnu.org/gitweb/ (2009-12-30 and 2010-01-22 respectively).
2010-03-01mark quilt-setup target as phonyColin Watson
2010-03-01commentary from Jonathan (original patch author) on syslog-level-silent.patchColin Watson
2010-03-01existing upstream bug reference for quieter-signals.patchColin Watson
2010-03-01forwarded lintian-symlink-pickiness.patchColin Watson
2010-03-01Include debian/ssh-askpass-gnome.png in the Debian tarball now thatColin Watson
we're using a source format that permits this, rather than messing around with uudecode.
2010-03-01forwarded old-gssapi.patchColin Watson
2010-03-01forwarded gssapi-compat.patchColin Watson
2010-03-01forwarded doc-hash-tab-completion.patchColin Watson
2010-03-01forwarded selinux-fix-chroot-directory.patchColin Watson
2010-03-01update Last-Update fieldsColin Watson
2010-03-01forwarded gnome-ssh-askpass2-link.patchColin Watson
2010-03-01forwarded doc-connection-sharing.patchColin Watson
2010-03-01forwarded ssh-copy-id-status-check.patchColin Watson
2010-03-01forwarded config-guess-sub.patchColin Watson
2010-03-01forwarded hurd-epfnosupport.patchColin Watson
2010-03-01forwarded authorized-keys-man-symlink.patchColin Watson
2010-03-01ssh-vulnkey.patch: fix offsetsColin Watson
2010-03-01Fix 'debian/rules quilt-setup' to avoid writing .orig files if someColin Watson
patches apply with offsets.
2010-03-01 - (dtucker) [openbsd-compat/port-linux.c] Make failure to write to the OOMDarren Tucker
adjust log at verbose only, since according to cjwatson in bug #1470 some virtualization platforms don't allow writes.
2010-03-01 - (dtucker) [regress/{cert-hostkey,cfgmatch,cipher-speed}.sh} ReplaceDarren Tucker
"echo -n" with "echon" for portability.
2010-02-28 - (tim) [ssh-pkcs11-helper.c] Move declarations before calling functionsTim Rice
to make older compilers (gcc 2.95) happy.
2010-03-01 - (djm) [auth.c] On Cygwin, refuse usernames that have differences inDamien Miller
case from that matched in the system password database. On this platform, passwords are stored case-insensitively, but sshd requires exact case matching for Match blocks in sshd_config(5). Based on a patch from vinschen AT redhat.com.
2010-02-28releasing version 1:5.3p1-3Colin Watson
2010-02-28Update copyright years for GSSAPI patch.Colin Watson
2010-02-28remove trailing whitespaceColin Watson
2010-02-28Remove obsolete header from README.Debian dating from when peopleColin Watson
expected non-free SSH.
2010-02-28more conventional signature styleColin Watson
2010-02-28Remove documentation of building for Debian 3.0 in README.Debian.Colin Watson
Support for this was removed in 1:4.7p1-2.
2010-02-28forwarded gssapi-dump.patchColin Watson
2010-02-28Add GSSAPIStoreCredentialsOnRekey to 'sshd -T' configuration dump.Colin Watson
2010-02-28* Update README.source to match, and add a 'quilt-setup' target toColin Watson
debian/rules for the benefit of those checking out the package from revision control. * All patches are now maintained separately and tagged according to DEP-3.
2010-02-28DEP-3 tagging of all remaining patchesColin Watson
2010-02-28DEP-3 tagging of versioning and file system layoutColin Watson
2010-02-28better patch nameColin Watson
2010-02-28DEP-3 tagging of remaining miscellaneous bug fixesColin Watson
2010-02-27DEP-3 tagging for message adjustments, and start on miscellaneous bug fixesColin Watson
2010-02-27DEP-3 tagging of autotools, SELinux, key blacklisting, and keepalive patchesColin Watson
2010-02-27DEP-3 tagging of GSSAPI patches; split old-gssapi.patch more appropriatelyColin Watson
2010-02-28 - (djm) [openbsd-compat/bsd-cygwin_util.c] Reduce the set of environmentDamien Miller
variables copied into sshd child processes. From vinschen AT redhat.com
2010-02-28- (djm) [ssh-pkcs11-helper.c ] Ensure RNG is initialised and seededDamien Miller
2010-02-27Convert to source format 3.0 (quilt).Colin Watson
2010-02-27 - djm@cvs.openbsd.org 2010/02/26 20:33:21Damien Miller
[Makefile regress/cert-hostkey.sh regress/cert-userkey.sh] regression tests for certified keys
2010-02-27 - OpenBSD CVS SyncDamien Miller
- djm@cvs.openbsd.org 2010/02/26 20:29:54 [PROTOCOL PROTOCOL.agent PROTOCOL.certkeys addrmatch.c auth-options.c] [auth-options.h auth.h auth2-pubkey.c authfd.c dns.c dns.h hostfile.c] [hostfile.h kex.h kexdhs.c kexgexs.c key.c key.h match.h monitor.c] [myproposal.h servconf.c servconf.h ssh-add.c ssh-agent.c ssh-dss.c] [ssh-keygen.1 ssh-keygen.c ssh-rsa.c ssh.1 ssh.c ssh2.h sshconnect.c] [sshconnect2.c sshd.8 sshd.c sshd_config.5] Add support for certificate key types for users and hosts. OpenSSH certificate key types are not X.509 certificates, but a much simpler format that encodes a public key, identity information and some validity constraints and signs it with a CA key. CA keys are regular SSH keys. This certificate style avoids the attack surface of X.509 certificates and is very easy to deploy. Certified host keys allow automatic acceptance of new host keys when a CA certificate is marked as sh/known_hosts. see VERIFYING HOST KEYS in ssh(1) for details. Certified user keys allow authentication of users when the signing CA key is marked as trusted in authorized_keys. See "AUTHORIZED_KEYS FILE FORMAT" in sshd(8) for details. Certificates are minted using ssh-keygen(1), documentation is in the "CERTIFICATES" section of that manpage. Documentation on the format of certificates is in the file PROTOCOL.certkeys feedback and ok markus@
2010-02-24contrib/caldera/openssh.specDamien Miller
contrib/redhat/openssh.spec contrib/suse/openssh.spec
2010-02-24 - (djm) [Makefile.in ssh-pkcs11-helper.8] Add manpage for PKCS#11 helperDamien Miller
2010-02-24 - dtucker@cvs.openbsd.org 2009/11/09 04:20:04Damien Miller
[regress/Makefile keygen-convert.sh] add regression test for ssh-keygen pubkey conversions