summaryrefslogtreecommitdiff
path: root/debian
AgeCommit message (Collapse)Author
2010-03-31Remove SSHD_OOM_ADJUST configuration. sshd now unconditionally makesColin Watson
itself non-OOM-killable, and doesn't require configuration to avoid log spam in virtualisation containers (closes: #555625).
2010-03-31ssh-vulnkey.patch: update another call to auth_key_is_revokedColin Watson
2010-03-31* New upstream release (LP: #535029).Colin Watson
- After a transition period of about 10 years, this release disables SSH protocol 1 by default. Clients and servers that need to use the legacy protocol must explicitly enable it in ssh_config / sshd_config or on the command-line. - Remove the libsectok/OpenSC-based smartcard code and add support for PKCS#11 tokens. This support is enabled by default in the Debian packaging, since it now doesn't involve additional library dependencies (closes: #231472, LP: #16918). - Add support for certificate authentication of users and hosts using a new, minimal OpenSSH certificate format (closes: #482806). - Added a 'netcat mode' to ssh(1): "ssh -W host:port ...". - Add the ability to revoke keys in sshd(8) and ssh(1). (For the Debian package, this overlaps with the key blacklisting facility added in openssh 1:4.7p1-9, but with different file formats and slightly different scopes; for the moment, I've roughly merged the two.) - Various multiplexing improvements, including support for requesting port-forwardings via the multiplex protocol (closes: #360151). - Allow setting an explicit umask on the sftp-server(8) commandline to override whatever default the user has (closes: #496843). - Many sftp client improvements, including tab-completion, more options, and recursive transfer support for get/put (LP: #33378). The old mget/mput commands never worked properly and have been removed (closes: #270399, #428082). - Do not prompt for a passphrase if we fail to open a keyfile, and log the reason why the open failed to debug (closes: #431538). - Prevent sftp from crashing when given a "-" without a command. Also, allow whitespace to follow a "-" (closes: #531561).
2010-03-31handle merge history from previous tarball branchColin Watson
2010-03-29Hardcode the location of xauth to /usr/bin/xauth rather thanColin Watson
/usr/bin/X11/xauth (thanks, Aron Griffis; closes: #575725, LP: #8440). xauth no longer depends on x11-common, so we're no longer guaranteed to have the /usr/bin/X11 symlink available. I was taking advantage of the /usr/bin/X11 symlink to smooth X's move to /usr/bin, but this is far enough in the past now that it's probably safe to just use /usr/bin.
2010-03-17Fix substitution of ETC_PAM_D_SSH, following the rename in 1:4.7p1-4.Colin Watson
2010-03-08Drop compatibility with the old gssapi mechanism used in ssh-krb5 <<Colin Watson
3.8.1p1-1. Simon Wilkinson refused this patch since the old gssapi mechanism was removed due to a serious security hole, and since these versions of ssh-krb5 are no longer security-supported by Debian I don't think there's any point keeping client compatibility for them.
2010-03-01mark quilt-setup target as phonyColin Watson
2010-03-01commentary from Jonathan (original patch author) on syslog-level-silent.patchColin Watson
2010-03-01existing upstream bug reference for quieter-signals.patchColin Watson
2010-03-01forwarded lintian-symlink-pickiness.patchColin Watson
2010-03-01Include debian/ssh-askpass-gnome.png in the Debian tarball now thatColin Watson
we're using a source format that permits this, rather than messing around with uudecode.
2010-03-01forwarded old-gssapi.patchColin Watson
2010-03-01forwarded gssapi-compat.patchColin Watson
2010-03-01forwarded doc-hash-tab-completion.patchColin Watson
2010-03-01forwarded selinux-fix-chroot-directory.patchColin Watson
2010-03-01update Last-Update fieldsColin Watson
2010-03-01forwarded gnome-ssh-askpass2-link.patchColin Watson
2010-03-01forwarded doc-connection-sharing.patchColin Watson
2010-03-01forwarded ssh-copy-id-status-check.patchColin Watson
2010-03-01forwarded config-guess-sub.patchColin Watson
2010-03-01forwarded hurd-epfnosupport.patchColin Watson
2010-03-01forwarded authorized-keys-man-symlink.patchColin Watson
2010-03-01ssh-vulnkey.patch: fix offsetsColin Watson
2010-03-01Fix 'debian/rules quilt-setup' to avoid writing .orig files if someColin Watson
patches apply with offsets.
2010-02-28releasing version 1:5.3p1-3Colin Watson
2010-02-28Update copyright years for GSSAPI patch.Colin Watson
2010-02-28remove trailing whitespaceColin Watson
2010-02-28Remove obsolete header from README.Debian dating from when peopleColin Watson
expected non-free SSH.
2010-02-28more conventional signature styleColin Watson
2010-02-28Remove documentation of building for Debian 3.0 in README.Debian.Colin Watson
Support for this was removed in 1:4.7p1-2.
2010-02-28forwarded gssapi-dump.patchColin Watson
2010-02-28Add GSSAPIStoreCredentialsOnRekey to 'sshd -T' configuration dump.Colin Watson
2010-02-28* Update README.source to match, and add a 'quilt-setup' target toColin Watson
debian/rules for the benefit of those checking out the package from revision control. * All patches are now maintained separately and tagged according to DEP-3.
2010-02-28DEP-3 tagging of all remaining patchesColin Watson
2010-02-28DEP-3 tagging of versioning and file system layoutColin Watson
2010-02-28better patch nameColin Watson
2010-02-28DEP-3 tagging of remaining miscellaneous bug fixesColin Watson
2010-02-27DEP-3 tagging for message adjustments, and start on miscellaneous bug fixesColin Watson
2010-02-27DEP-3 tagging of autotools, SELinux, key blacklisting, and keepalive patchesColin Watson
2010-02-27DEP-3 tagging of GSSAPI patches; split old-gssapi.patch more appropriatelyColin Watson
2010-02-27Convert to source format 3.0 (quilt).Colin Watson
2010-02-22releasing version 1:5.3p1-2Colin Watson
2010-02-22run dh_installexamples after dh_linkColin Watson
2010-01-31Honour DEB_BUILD_OPTIONS=nocheck.Colin Watson
2010-01-31Use dh_lintian.Colin Watson
2010-01-31Install upstream sshd_config as an example (closes: #415008).Colin Watson
2010-01-31fix typo in 1:5.3p1-1 changelogColin Watson
2010-01-31Link with -Wl,--as-needed (closes: #560155).Colin Watson
2010-01-26releasing version 1:5.3p1-1Colin Watson