📄 changelog
字号:
discard remaining bytes of current request; ok provos@ - markus@cvs.openbsd.org 2002/06/06 17:30:11 [sftp-server.c] use get_int() macro (hide iqueue) - (bal) Missed msg.[ch] in merge. Required for ssh-keysign. - (bal) Forgot to add msg.c Makefile.in. - (bal) monitor_mm.c typos. - (bal) Refixed auth2.c. It was never fully commited while spliting out authentication to different files. - (bal) ssh-keysign should build and install correctly now. Phase two would be to clean out any dead wood and disable ssh setuid on install. - (bal) Reverse logic, use __func__ first since it's C9920020604 - (stevesk) [channels.c] bug #164 patch from YOSHIFUJI Hideaki (changed setsockopt from debug to error for now).20020527 - (tim) [configure.ac.orig monitor_fdpass.c] Enahnce msghdr tests to address build problem on Irix reported by Dave Love <d.love@dl.ac.uk>. Back out last monitor_fdpass.c changes that are no longer needed with new tests. Patch tested on Irix by Jan-Frode Myklebust <janfrode@parallab.uib.no>20020522 - (djm) Fix spelling mistakes, spotted by Solar Designer i <solar@openwall.com> - Sync scard/ (not sure when it drifted) - (djm) OpenBSD CVS Sync: [auth.c] Fix typo/thinko. Pass in as to auth_approval(), not NULL. Closes PR 2659. - Crank version - Crank RPM spec versions20020521 - (stevesk) [sshd.c] bug 245; disable setsid() for now - (stevesk) [sshd.c] #ifndef HAVE_CYGWIN for setgroups()20020517 - (tim) [configure.ac] remove extra MD5_MSG="no" line.20020515 - (bal) CVS ID fix up on auth-passwd.c - (bal) OpenBSD CVS Sync - deraadt@cvs.openbsd.org 2002/05/07 19:54:36 [ssh.h] use ssh uid - deraadt@cvs.openbsd.org 2002/05/08 21:06:34 [ssh.h] move to sshd.sshd instead - stevesk@cvs.openbsd.org 2002/05/11 20:24:48 [ssh.h] typo in comment - itojun@cvs.openbsd.org 2002/05/13 02:37:39 [auth-skey.c auth2.c] less warnings. skey_{respond,query} are public (in auth.h) - markus@cvs.openbsd.org 2002/05/13 20:44:58 [auth-options.c auth.c auth.h] move the packet_send_debug handling from auth-options.c to auth.c; ok provos@ - millert@cvs.openbsd.org 2002/05/13 15:53:19 [sshd.c] Call setsid() in the child after sshd accepts the connection and forks. This is needed for privsep which calls setlogin() when it changes uids. Without this, there is a race where the login name of an existing connection, as returned by getlogin(), may be changed to the privsep user (sshd). markus@ OK - markus@cvs.openbsd.org 2002/05/13 21:26:49 [auth-rhosts.c] handle debug messages during rhosts-rsa and hostbased authentication; ok provos@ - mouring@cvs.openbsd.org 2002/05/15 15:47:49 [kex.c monitor.c monitor_wrap.c sshd.c] 'monitor' variable clashes with at least one lame platform (NeXT). i Renamed to 'pmonitor'. provos@ - deraadt@cvs.openbsd.org 2002/05/04 02:39:35 [servconf.c sshd.8 sshd_config] enable privsep by default; provos ok - millert@cvs.openbsd.org 2002/05/06 23:34:33 [ssh.1 sshd.8] Kill/adjust r(login|exec)d? references now that those are no longer in the tree. - markus@cvs.openbsd.org 2002/05/15 21:02:53 [servconf.c sshd.8 sshd_config] disable privsep and enable setuid for the 3.2.2 release - (bal) Fixed up PAM case. I think. - (bal) Clarified openbsd-compat/*-cray.* Licence provided by Wendy - (bal) OpenBSD CVS Sync - markus@cvs.openbsd.org 2002/05/15 21:05:29 [version.h] enter OpenSSH_3.2.2 - (bal) Caldara, Suse, and Redhat openssh.specs updated.20020514 - (stevesk) [README.privsep] PAM+privsep works with Solaris 8. - (tim) [sshpty.c] set tty modes when allocating old style bsd ptys to match what newer style ptys have when allocated. Based on a patch by Roger Cornelius <rac@tenzing.org> - (tim) [README.privsep] UnixWare 7 and OpenUNIX 8 work. - (tim) [README.privsep] remove reference to UnixWare 7 and OpenUNIX 8 from PAM-enabled pragraph. UnixWare has no PAM. - (tim) [contrib/caldera/openssh.spec] update version.20020513 - (stevesk) add initial README.privsep - (stevesk) [configure.ac] nicer message: --with-privsep-user=user - (djm) Add --with-superuser-path=xxx configure option to specify what $PATH the superuser receives. - (djm) Bug #231: UsePrivilegeSeparation turns off Banner. - (djm) Add --with-privsep-path configure option - (djm) Update RPM spec file: different superuser path, use /var/empty/sshd for privsep - (djm) Bug #234: missing readpassphrase declaration and defines - (djm) Add INSTALL warning about SSH protocol 1 blowfish w/ OpenSSL < 0.9.620020511 - (tim) [configure.ac] applied a rework of djm's OpenSSL search cleanup patch. Now only searches system and /usr/local/ssl (OpenSSL's default install path) Others must use --with-ssl-dir=.... - (tim) [monitor_fdpass.c] fix for systems that have both HAVE_ACCRIGHTS_IN_MSGHDR and HAVE_CONTROL_IN_MSGHDR. Ie. sys/socket.h has #define msg_accrights msg_control20020510 - (stevesk) [auth.c] Shadow account and expiration cleanup. Now check for root forced expire. Still don't check for inactive. - (djm) Rework RedHat RPM files. Based on spec from Nalin Dahyabhai <nalin@redhat.com> and patches from Pekka Savola <pekkas@netcore.fi> - (djm) Try to drop supplemental groups at daemon startup. Patch from RedHat - (bal) Back all the way out of auth-passwd.c changes. Breaks too many things that don't set pw->pw_passwd.20020509 - (tim) [Makefile.in] Unbreak make -f Makefile.in distprep20020508 - (tim) [openbsd-compat/bsd-arc4random.c] fix logic on when seed_rng() is called. Report by Chris Maxwell <maxwell@cs.dal.ca> - (tim) [Makefile.in configure.ac] set SHELL variable in Makefile - (djm) Disable PAM kbd-int auth if privsep is turned on (it doesn't work)20020507 - (tim) [configure.ac openbsd-compat/bsd-misc.c openbsd-compat/bsd-misc.h] Add truncate() emulation to address Bug 20820020506 - (djm) Unbreak auth-passwd.c for PAM and SIA - (djm) Unbreak PAM auth for protocol 1. Report from Pekka Savola <pekkas@netcore.fi> - (djm) Don't reinitialise PAM credentials before we have started PAM. Report from Pekka Savola <pekkas@netcore.fi> 20020506 - (bal) Fixed auth-passwd.c to resolve PermitEmptyPassword issue 20020501 - (djm) Import OpenBSD regression tests. Requires BSD make to run - (djm) Fix readpassphase compilation for systems which have it20020429 - (tim) [contrib/caldera/openssh.spec] update fixUP to reflect changes in sshd_config. - (tim) [contrib/cygwin/README] remove reference to regex. patch from Corinna Vinschen <vinschen@redhat.com>20020426 - (djm) Bug #137, #209: fix make problems for scard/Ssh.bin, do uudecode during distprep only - (djm) Disable PAM password expiry until a complete fix for bug #188 exists - (djm) Bug #180: Set ToS bits on IPv4-in-IPv6 mapped addresses. Based on patch from openssh@misc.tecq.org20020425 - (stevesk) [defines.h] remove USE_TIMEVAL; unused - (stevesk) [acconfig.h auth-passwd.c configure.ac sshd.c] HP-UX 10.26 support. bug #184. most from dcole@keysoftsys.com.20020424 - (djm) OpenBSD CVS Sync - markus@cvs.openbsd.org 2002/04/23 12:54:10 [version.h] 3.2.1 - djm@cvs.openbsd.org 2002/04/23 22:16:29 [sshd.c] Improve error message; ok markus@ stevesk@20020423 - (stevesk) [acconfig.h configure.ac session.c] LOGIN_NO_ENDOPT for HP-UX - (stevesk) [acconfig.h] NEED_IN_SYSTM_H unused - (markus) OpenBSD CVS Sync - markus@cvs.openbsd.org 2002/04/23 12:58:26 [radix.c] send complete ticket; semerad@ss1000.ms.mff.cuni.cz - (djm) Trim ChangeLog to include only post-3.1 changes - (djm) Update RPM spec file versions - (djm) Redhat spec enables KrbV by default - (djm) Applied OpenSC smartcard updates from Markus & Antti Tapaninen <aet@cc.hut.fi> - (djm) Define BROKEN_REALPATH for AIX, patch from Antti Tapaninen <aet@cc.hut.fi> - (djm) Bug #214: Fix utmp for Irix (don't strip "tty"). Patch from Kevin Taylor <no@nowhere.org> (??) via Philipp Grau <phgrau@zedat.fu-berlin.de> - (djm) Bug #213: Simplify CMSG_ALIGN macros to avoid symbol clashes. Reported by Doug Manton <dmanton@emea.att.com> - (djm) Bug #222: Fix tests for getaddrinfo on OSF/1. Spotted by Robert Urban <urban@spielwiese.de> - (djm) Bug #206 - blibpath isn't always needed for AIX ld, avoid sizeof(long long int) == 4 breakage. Patch from Matthew Clarke <Matthew_Clarke@mindlink.bc.ca> - (djm) Make privsep work with PAM (still experimental) - (djm) OpenBSD CVS Sync - deraadt@cvs.openbsd.org 2002/04/20 09:02:03 [servconf.c] No, afs requires explicit enabling - markus@cvs.openbsd.org 2002/04/20 09:14:58 [bufaux.c bufaux.h] add buffer_{get,put}_short - markus@cvs.openbsd.org 2002/04/20 09:17:19 [radix.c] rewrite using the buffer_* API, fixes overflow; ok deraadt@ - stevesk@cvs.openbsd.org 2002/04/21 16:19:27 [sshd.8 sshd_config] document default AFSTokenPassing no; ok deraadt@ - stevesk@cvs.openbsd.org 2002/04/21 16:25:06 [sshconnect1.c] spelling in error message; ok markus@ - markus@cvs.openbsd.org 2002/04/22 06:15:47 [radix.c] fix check for overflow - markus@cvs.openbsd.org 2002/04/22 16:16:53 [servconf.c sshd.8 sshd_config] do not auto-enable KerberosAuthentication; ok djm@, provos@, deraadt@ - markus@cvs.openbsd.org 2002/04/22 21:04:52 [channels.c clientloop.c clientloop.h ssh.c] request reply (success/failure) for -R style fwd in protocol v2, depends on ordered replies. fixes http://bugzilla.mindrot.org/show_bug.cgi?id=215; ok provos@20020421 - (tim) [entropy.c.] Portability fix for SCO Unix 3.2v4.x (SCO OSR 3.0). entropy.c needs seteuid(getuid()) for the setuid(original_uid) to succeed. Patch by gert@greenie.muc.de. This fixes one part of Bug 20820020418 - (djm) Avoid SIGCHLD breakage when run from rsync. Fix from Sturle Sunde <sturle.sunde@usit.uio.no>20020417 - (djm) Tell users to configure /dev/random support into OpenSSL in INSTALL - (djm) Fix .Nm in mdoc2man.pl from pspencer@fields.utoronto.ca - (tim) [configure.ac] Issue warning on --with-default-path=/some_path if LOGIN_CAP is enabled. Report & testing by Tuc <tuc@ttsg.com>20020415 - (djm) Unbreak "make install". Fix from Darren Tucker <dtucker@zip.com.au> - (stevesk) bsd-cygwin_util.[ch] BSD license from Corinna Vinschen - (tim) [configure.ac] add tests for recvmsg and sendmsg. [monitor_fdpass.c] add checks for HAVE_SENDMSG and HAVE_RECVMSG for systems that HAVE_ACCRIGHTS_IN_MSGHDR but no recvmsg or sendmsg.20020414 - (djm) ssh-rand-helper improvements - Add commandline debugging options - Don't write binary data if stdout is a tty (use hex instead) - Give it a manpage - (djm) Random number collection doc fixes from Ben20020413 - (djm) Add KrbV support patch from Simon Wilkinson <simon@sxw.org.uk>20020412 - (stevesk) [auth-sia.[ch]] add BSD license from Chris Adams - (tim) [configure.ac] add <sys/types.h> to msghdr tests. Change -L to -h on testing for /bin being symbolic link - (bal) Mistaken in Cygwin scripts for ssh starting. Patch by Corinna Vinschen <vinschen@redhat.com> - (bal) disable privsep if no MAP_ANON. We can re-enable it after the release when we can do more testing.20020411 - (stevesk) [auth-sia.c] cleanup - (tim) [acconfig.h defines.h includes.h] put includes in includes.h and defines in defines.h [rijndael.c openbsd-compat/fake-socket.h openbsd-compat/inet_aton.c] include "includes.h" instead of "config.h" ok stevesk@20020410 - (stevesk) [configure.ac monitor.c] HAVE_SOCKETPAIR - (stevesk) [auth-sia.c] compile fix Chris Adams <cmadams@hiwaay.net> - (bal) OpenBSD CVS Sync - markus@cvs.openbsd.org 2002/04/10 08:21:47 [auth1.c compat.c compat.h] strip '@' from username only for KerbV and known broken clients, bug #204 - markus@cvs.openbsd.org 2002/04/10 08:56:01 [version.h] OpenSSH_3.2 - Added p1 to idenify Portable release version.20020408 - (bal) Minor OpenSC updates. Fix up header locations and update README.smartcard provided by Juha Yrj鰈
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -