1. 20 Mar, 2014 1 commit
    • Simon Wilkinson's avatar
      GSSAPI key exchange support · 9dfcd1a0
      Simon Wilkinson authored
      This patch has been rejected upstream: "None of the OpenSSH developers are
      in favour of adding this, and this situation has not changed for several
      years.  This is not a slight on Simon's patch, which is of fine quality, but
      just that a) we don't trust GSSAPI implementations that much and b) we don't
      like adding new KEX since they are pre-auth attack surface.  This one is
      particularly scary, since it requires hooks out to typically root-owned
      system resources."
      
      However, quite a lot of people rely on this in Debian, and it's better to
      have it merged into the main openssh package rather than having separate
      -krb5 packages (as we used to have).  It seems to have a generally good
      security history.
      
      Bug: https://bugzilla.mindrot.org/show_bug.cgi?id=1242
      Last-Updated: 2014-03-19
      
      Patch-Name: gssapi.patch
      9dfcd1a0
  2. 21 Feb, 2014 1 commit
    • Tim Rice's avatar
      20140221 · 03ae081a
      Tim Rice authored
       - (tim) [configure.ac]  Fix cut-and-paste error. Patch from Bryan Drewery.
      03ae081a
  3. 13 Feb, 2014 1 commit
  4. 04 Feb, 2014 1 commit
    • Damien Miller's avatar
      - tedu@cvs.openbsd.org 2014/01/31 16:39:19 · 1d2c4564
      Damien Miller authored
           [auth2-chall.c authfd.c authfile.c bufaux.c bufec.c canohost.c]
           [channels.c cipher-chachapoly.c clientloop.c configure.ac hostfile.c]
           [kexc25519.c krl.c monitor.c sandbox-systrace.c session.c]
           [sftp-client.c ssh-keygen.c ssh.c sshconnect2.c sshd.c sshlogin.c]
           [openbsd-compat/explicit_bzero.c openbsd-compat/openbsd-compat.h]
           replace most bzero with explicit_bzero, except a few that cna be memset
           ok djm dtucker
      1d2c4564
  5. 30 Jan, 2014 1 commit
  6. 29 Jan, 2014 2 commits
  7. 28 Jan, 2014 1 commit
  8. 25 Jan, 2014 5 commits
  9. 23 Jan, 2014 1 commit
  10. 22 Jan, 2014 2 commits
  11. 21 Jan, 2014 1 commit
  12. 18 Jan, 2014 1 commit
    • Darren Tucker's avatar
      - (dtucker) [configure.ac] On Cygwin the getopt variables (like optargs, · fdce3731
      Darren Tucker authored
         optind) are defined in getopt.h already.  Unfortunately they are defined as
         "declspec(dllimport)" for historical reasons, because the GNU linker didn't
         allow auto-import on PE/COFF targets way back when.  The problem is the
         dllexport attributes collide with the definitions in the various source
         files in OpenSSH, which obviousy define the variables without
         declspec(dllimport).  The least intrusive way to get rid of these warnings
         is to disable warnings for GCC compiler attributes when building on Cygwin.
         Patch from vinschen at redhat.com.
      fdce3731
  13. 17 Jan, 2014 6 commits
  14. 16 Jan, 2014 1 commit
  15. 19 Dec, 2013 1 commit
  16. 07 Dec, 2013 2 commits
  17. 05 Dec, 2013 1 commit
  18. 09 Nov, 2013 3 commits
  19. 08 Nov, 2013 1 commit
  20. 07 Nov, 2013 2 commits
  21. 03 Nov, 2013 1 commit
  22. 04 Aug, 2013 1 commit
  23. 11 Jun, 2013 1 commit
  24. 05 Jun, 2013 1 commit
  25. 04 Jun, 2013 1 commit