Age | Commit message (Collapse) | Author | |
---|---|---|---|
2010-01-04 | Refer to sshd_config(5) rather than sshd(8) in postinst-written | Colin Watson | |
/etc/ssh/sshd_config, and add UsePAM commentary from upstream-shipped configuration file (closes: #415008, although unfortunately this will only be conveniently visible on new installations). | |||
2010-01-04 | Remove/adjust manual page references to BSD-specific /etc/rc (closes: | Colin Watson | |
#513417). | |||
2010-01-04 | Remove manual page references to login.conf, which aren't applicable on | Colin Watson | |
non-BSD systems (closes: #154434). | |||
2010-01-04 | Adjust short descriptions to avoid relying on previous experience with | Colin Watson | |
rsh, based on suggestions from Reuben Thomas (closes: #512198). | |||
2010-01-02 | Remove init script stop link in rc1, as killprocs handles it already. | Colin Watson | |
2010-01-02 | Cope with insserv reordering of init script links. | Colin Watson | |
2010-01-02 | fix gssapi-keyex and gssapi methods following JPAKE | Colin Watson | |
2010-01-02 | Remove ssh/new_config, only needed for direct upgrades from potato which | Colin Watson | |
are no longer particularly feasible anyway (closes: #420682). | |||
2010-01-02 | Update OpenSSH FAQ to revision 1.110. | Colin Watson | |
2010-01-02 | fix build with GSSAPI disabled | Colin Watson | |
2010-01-02 | yet another report of this | Colin Watson | |
2010-01-02 | Use hardening-includes for hardening logic (thanks, Kees Cook; closes: | Colin Watson | |
#561887). | |||
2010-01-02 | Don't duplicate backslashes when displaying server banner (thanks, | Colin Watson | |
Michał Górny; closes: #505378, LP: #425346). | |||
2010-01-02 | Initialise sc to NULL in ssh_selinux_getctxbyname (thanks, Václav Ovsík; | Colin Watson | |
closes: #498684). | |||
2010-01-02 | Make ChrootDirectory work with SELinux (thanks, Russell Coker; closes: | Colin Watson | |
#556644). | |||
2010-01-02 | more bug fix notes | Colin Watson | |
2010-01-02 | merge from gssapi branch | Colin Watson | |
2010-01-02 | autoconf | Colin Watson | |
2010-01-01 | * New upstream release (closes: #536182). Yes, I know 5.3p1 has been out | Colin Watson | |
for a while, but there's no GSSAPI patch available for it yet. - Change the default cipher order to prefer the AES CTR modes and the revised "arcfour256" mode to CBC mode ciphers that are susceptible to CPNI-957037 "Plaintext Recovery Attack Against SSH". - Add countermeasures to mitigate CPNI-957037-style attacks against the SSH protocol's use of CBC-mode ciphers. Upon detection of an invalid packet length or Message Authentication Code, ssh/sshd will continue reading up to the maximum supported packet length rather than immediately terminating the connection. This eliminates most of the known differences in behaviour that leaked information about the plaintext of injected data which formed the basis of this attack (closes: #506115, LP: #379329). - ForceCommand directive now accepts commandline arguments for the internal-sftp server (closes: #524423, LP: #362511). - Add AllowAgentForwarding to available Match keywords list (closes: #540623). - Make ssh(1) send the correct channel number for SSH2_MSG_CHANNEL_SUCCESS and SSH2_MSG_CHANNEL_FAILURE messages to avoid triggering 'Non-public channel' error messages on sshd(8) in openssh-5.1. - Avoid printing 'Non-public channel' warnings in sshd(8), since the ssh(1) has sent incorrect channel numbers since ~2004 (this reverts a behaviour introduced in openssh-5.1; closes: #496017). * Update to GSSAPI patch from http://www.sxw.org.uk/computing/patches/openssh-5.2p1-gsskex-all-20090726.patch, including cascading credentials support (LP: #416958). | |||
2010-01-01 | TODO for gssapi branch handling | Colin Watson | |
2010-01-01 | import openssh-5.2p1-gsskex-all-20090726.patch | Colin Watson | |
2010-01-01 | Import 5.2p1 tarball | Colin Watson | |
2009-12-29 | no-op merge from constructed gssapi branch, to ease future upstream merges | Colin Watson | |
2009-12-29 | import openssh-5.1p1-gsskex-cjwatson-20080722.patch | Colin Watson | |
2009-12-29 | import openssh-4.7p1-gsskex-20070927.patch | Colin Watson | |
2009-12-29 | import openssh-4.6p1-gsskex-20070312.patch | Colin Watson | |
2009-12-29 | import openssh-4.3p2-gsskex-20060223.patch | Colin Watson | |
2009-12-29 | import openssh-4.2p1-gsskex-20050926-2.patch | Colin Watson | |
2009-12-29 | import openssh-4.0p1-gssapikex.patch | Colin Watson | |
2009-12-21 | pushed some previous upstream release branches to Launchpad | Colin Watson | |
2009-12-21 | Add debian/README.source with instructions on bzr handling. | Colin Watson | |
2009-12-21 | move local ignores to .bzrignore and resync .cvsignore files with upstream | Colin Watson | |
2009-12-21 | Moved to bzr.debian.org; add Vcs-Bzr and Vcs-Browser control fields. | Colin Watson | |
2009-11-12 | Use x11.pc when compiling/linking gnome-ssh-askpass2 (closes: #555951). | Colin Watson | |
2009-10-05 | releasing version 1:5.1p1-8 | Colin Watson | |
2009-10-04 | Pass $SSHD_OPTS when checking configuration too (thanks, "sobtwmxt"; | Colin Watson | |
closes: #548662). | |||
2009-09-30 | Fix grammar in if-up script (closes: #549128). | Colin Watson | |
2009-09-26 | - (djm) Release 5.3p1 | Damien Miller | |
2009-09-26 | - (djm) [packet.c] Restore EWOULDBLOCK handling that got lost somewhere | Damien Miller | |
2009-09-26 | - (djm) [README] update relnotes URL | Damien Miller | |
2009-09-26 | - (djm) [contrib/caldera/openssh.spec contrib/redhat/openssh.spec] | Damien Miller | |
[contrib/suse/openssh.spec] Update for release | |||
2009-09-17 | Build-depend on libselinux1-dev on sh4 too (thanks, Nobuhiro Iwamatsu; | Colin Watson | |
closes: #547103). | |||
2009-09-11 | - (dtucker) [configure.ac] Change the -lresolv check so it works on Mac OS X | Darren Tucker | |
10.6 (which doesn't have BIND8_COMPAT and thus uses res_9_query). Patch from jbasney at ncsa uiuc edu. | |||
2009-09-09 | - (djm) [serverloop.c] Fix test for server-assigned remote forwarding port | Damien Miller | |
(-R 0:...); bz#1578, spotted and fix by gavin AT emf.net; ok dtucker@ | |||
2009-09-01 | - (dtucker) [configure.ac] Bug #1639: use AC_PATH_PROG to search the path for | Darren Tucker | |
krb5-config if it's not in the location specified by --with-kerberos5. Patch from jchadima at redhat. | |||
2009-08-29 | - (dtucker) [README.platform] Add text about development packages, based on | Darren Tucker | |
text from Chris Pepper in bug #1631. | |||
2009-08-28 | Build with just -fPIC on mips/mipsel, not -fPIE as well (thanks, LIU Qi; | Colin Watson | |
closes: #538313). | |||
2009-08-28 | - (dtucker) [configure.ac] Fix the syntax of the Solaris tcgetattr entry. | Darren Tucker | |
2009-08-28 | - (dtucker) [clientloop.c configure.ac defines.h] Make the client's IO buffer | Darren Tucker | |
size a compile-time option and set it to 64k on Cygwin, since Corinna reports that it makes a significant difference to performance. ok djm@ | |||
2009-08-28 | - (dtucker) [channels.c configure.ac] Bug #1528: skip the tcgetattr call on | Darren Tucker | |
the pty master on Solaris, since it never succeeds and can hang if large amounts of data is sent to the slave (eg a copy-paste). Based on a patch originally from Doke Scott, ok djm@ |