Age | Commit message (Collapse) | Author | |
---|---|---|---|
2013-05-22 | Remove ancient commented-out code. | Colin Watson | |
2013-05-22 | Fix dh_builddeb invocation so that we really use xz compression for | Colin Watson | |
binary packages, as intended since 1:6.1p1-2. | |||
2013-05-22 | Bracket our session stack with calls to pam_selinux close/open (thanks, | Colin Watson | |
Laurent Bigonville; closes: #679458). | |||
2013-05-22 | Use the pam_loginuid session module (thanks, Laurent Bigonville; closes: | Colin Watson | |
#677440, LP: #1067779). | |||
2013-05-22 | * Remove the check for vulnerable host keys; this was first added five | Colin Watson | |
years ago, and everyone should have upgraded through a version that applied these checks by now. The ssh-vulnkey tool and the blacklisting support in sshd are still here, at least for the moment. * This removes the last of our uses of debconf (closes: #221531). | |||
2013-05-22 | Drop now-unused Lintian override. | Colin Watson | |
2013-05-22 | Switch to new unified layout for Upstart jobs as documented in | Colin Watson | |
https://wiki.ubuntu.com/UpstartCompatibleInitScripts: the init script checks for a running Upstart, and we now let dh_installinit handle most of the heavy lifting in maintainer scripts. Ubuntu users should be essentially unaffected except that sshd may no longer start automatically in chroots if the running Upstart predates 0.9.0; but the main goal is simply not to break when openssh-server is installed in a chroot. | |||
2013-05-22 | Replace old manual conffile handling code with dpkg-maintscript-helper, | Colin Watson | |
via dh_installdeb. | |||
2013-05-22 | close bug | Colin Watson | |
2013-05-22 | Add #DEBHELPER# tokens to openssh-client.postinst and | Colin Watson | |
openssh-server.postinst. | |||
2013-05-22 | Clarify changelog: upgrades -> direct upgrades. | Colin Watson | |
2013-05-22 | Remove lots of maintainer script support for upgrades from pre-etch | Colin Watson | |
(three releases before current stable). | |||
2013-05-22 | Another unregistration. | Colin Watson | |
2013-05-21 | Remove support for upgrading from ssh-nonfree. | Colin Watson | |
2013-05-21 | Remove ssh/use_old_init_script, which was a workaround for a very old | Colin Watson | |
bug in /etc/init.d/ssh. If anyone has ignored this for >10 years then they aren't going to be convinced now. | |||
2013-05-21 | Drop conffile handling for upgrades from pre-split ssh package; this was | Colin Watson | |
originally added in 1:4.3p2-7 / 1:4.3p2-8, and contained a truly ghastly hack around a misbehaviour in sarge's dpkg. Since this is now four Debian releases ago, we can afford to drop this and simplify the packaging. | |||
2013-05-21 | Change start condition of Upstart job to be just the standard "runlevel | Colin Watson | |
[2345]", rather than "filesystem or runlevel [2345]"; the latter makes it unreasonably difficult to ensure that urandom starts before ssh, and is not really necessary since one of static-network-up and failsafe-boot is guaranteed to happen and will trigger entry to the default runlevel, and we don't care about ssh starting before the network (LP: #1098299). | |||
2013-05-16 | releasing version 1:6.2p2-1 | Colin Watson | |
2013-05-16 | * New upstream release (http://www.openssh.com/txt/release-6.2p2): | Colin Watson | |
- Only warn for missing identity files that were explicitly specified (closes: #708275). - Fix bug in contributed contrib/ssh-copy-id script that could result in "rm *" being called on mktemp failure (closes: #708419). | |||
2013-05-13 | releasing version 1:6.2p1-3 | Colin Watson | |
2013-05-13 | Renumber Debian-specific additions to enum monitor_reqtype so that they | Colin Watson | |
fit within a single byte (thanks, Jason Conti; LP: #1179202). | |||
2013-05-09 | releasing version 1:6.2p1-2 | Colin Watson | |
2013-05-09 | Fix consolekit mismerges in monitor.c and monitor_wrap.c. | Colin Watson | |
2013-05-09 | * Fix build failure on Ubuntu: | Colin Watson | |
- Include openbsd-compat/sys-queue.h from consolekit.c. | |||
2013-05-07 | releasing version 1:6.2p1-1 | Colin Watson | |
2013-05-07 | Move platform_sys_dir_uid to misc.c to fix linking following ↵ | Colin Watson | |
user-group-modes.patch. | |||
2013-05-07 | * New upstream release (http://www.openssh.com/txt/release-6.2). | Colin Watson | |
- Add support for multiple required authentication in SSH protocol 2 via an AuthenticationMethods option (closes: #195716). - Fix Sophie Germain formula in moduli(5) (closes: #698612). - Update ssh-copy-id to Phil Hands' greatly revised version (closes: #99785, #322228, #620428; LP: #518883, #835901, #1074798). | |||
2013-05-06 | Use dh-autoreconf. | Colin Watson | |
2013-03-25 | releasing version 1:6.1p1-4 | Colin Watson | |
2013-03-25 | Add ssh-agent upstart user job. This implements something similar to | Stéphane Graber | |
the 90x11-common_ssh-agent Xsession script. That is, start ssh-agent and set the appropriate environment variables (closes: #703906). | |||
2013-03-25 | debian/openssh-server.sshd.pam: Explicitly state that ~/.pam_environment | Gunnar Hjalmarsson | |
should be read, and move the pam_env calls from "auth" to "session" so that it's also read when $HOME is encrypted (LP: #952185). | |||
2013-02-08 | releasing version 1:6.1p1-3 | Colin Watson | |
2013-02-08 | CVE-2010-5107: Improve DoS resistance by changing default of MaxStartups | Colin Watson | |
to 10:30:100 (closes: #700102). | |||
2012-12-19 | Give ssh and ssh-krb5 versioned dependencies on openssh-client and | Colin Watson | |
openssh-server, to try to reduce confusion when people run 'apt-get install ssh' or similar and expect that to upgrade everything relevant. | |||
2012-11-26 | releasing version 1:6.1p1-2 | Colin Watson | |
2012-11-26 | Simplify --with-consolekit handling. | Colin Watson | |
2012-11-26 | Install apport hooks. | Colin Watson | |
2012-11-26 | Add mention of ssh-keygen in ssh connect warning (Scott Moser). | Colin Watson | |
2012-11-26 | Tweak sshd(8) to refer to ssh's Upstart job as well as its init script. | Colin Watson | |
2012-11-26 | Merge Upstart job scripting support from Ubuntu, to handle the Upstart job ↵ | Colin Watson | |
being primary there. | |||
2012-11-25 | Only build with -j if DEB_BUILD_OPTIONS=parallel=* is used (closes: | Colin Watson | |
#694282). | |||
2012-11-01 | Add an Upstart job (not currently used by default in Debian). | Colin Watson | |
2012-10-31 | Drop openssh-blacklist and openssh-blacklist-extra to Suggests. It's | Colin Watson | |
been long enough since the relevant vulnerability that we shouldn't need these installed by default nowadays. | |||
2012-10-31 | * Merge from Ubuntu: | Colin Watson | |
- Add support for registering ConsoleKit sessions on login. (This is currently enabled only when building for Ubuntu.) | |||
2012-09-28 | Use xz compression for binary packages. | Colin Watson | |
2012-09-07 | releasing version 1:6.1p1-1 | Colin Watson | |
2012-09-07 | Consolidate the two "Miscellaneous bug fixes" sections of debian/patches/series. | Colin Watson | |
2012-09-07 | * New upstream release (http://www.openssh.com/txt/release-6.1). | Colin Watson | |
- Enable pre-auth sandboxing by default for new installs. - Allow "PermitOpen none" to refuse all port-forwarding requests (closes: #543683). | |||
2012-08-24 | releasing version 1:6.0p1-3 | Colin Watson | |
2012-08-24 | Add ncurses-term to openssh-server's Recommends, since it's often needed | Colin Watson | |
to support unusual terminal emulators on clients (closes: #675362). |