| Commit message (Collapse) | Author | Age | Files | Lines |
| |
|
|
|
|
| |
and {ssh,sshd}_config.
|
| |
|
|
|
|
|
| |
cleanup. A round-trip (./freebsd-pre-merge.sh ; ./freebsd-post-merge.sh)
now results in an unchanged working copy.
|
|
|
|
|
| |
Security: SA-16:07.openssh
Security: CVE-2016-0777
|
|
|
|
|
|
| |
PR: 204769
Submitted by: David Binderman <dcb314@hotmail.com>
MFC after: 1 week
|
|
|
|
| |
of ssh-askpass and xauth, breaking X11 forwarding.
|
| |
|
| |
|
| |
|
| |
|
| |
|
| |
|
|
|
|
|
| |
there is (currently) no way to make Subversion generate correct $Mdocdate$
tags, but perhas we can teach mandoc to read Subversion's %d format.
|
|
|
|
|
|
|
|
|
|
| |
from OpenSSH-portable master.
Git revisions: 45b0eb752c94954a6de046bfaaf129e518ad4b5b
5e75f5198769056089fb06c4d738ab0e5abc66f7
d4697fe9a28dab7255c60433e4dd23cf7fce8a8b
Reviewed by: des
Security: FreeBSD-SA-15:22.openssh
|
|
|
|
|
|
| |
Security: CVE-2014-2653
Security: CVE-2015-5600
Security: FreeBSD-SA-15:16.openssh
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
Re-apply r99054 by des in 2002. This was accidentally dropped
by the update to OpenSSH 6.5p1 (r261320).
This change is actually taken from r387082 of
ports/security/openssh-portable/files/patch-ssh.c
PR: 198043
Differential Revision: https://reviews.freebsd.org/D3103
Reviewed by: des
Approved by: kib (mentor)
MFC after: 3 days
Relnotes: yes
Sponsored by: Dell Inc.
|
|
|
|
|
|
| |
the current set, it is good hygiene to change them once in a while.
MFC after: 1 week
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| |
The use of CHAN_TCP_WINDOW_DEFAULT here was fixed in upstream OpenSSH
in CVS 1.4810, git 5baa170d771de9e95cf30b4c469ece684244cf3e:
- dtucker@cvs.openbsd.org 2007/12/28 22:34:47
[clientloop.c]
Use the correct packet maximum sizes for remote port and agent forwarding.
Prevents the server from killing the connection if too much data is queued
and an excessively large packet gets sent. bz #1360, ok djm@.
The change was lost due to the the way the original upstream HPN patch
modified this code. It was re-adding the original OpenSSH code and never
was properly fixed to use the new value.
MFC after: 2 weeks
|
|
|
|
|
| |
PR: 193127
MFC after: 2 weeks
|
|
|
|
|
|
| |
avoid confusion.
Sponsored by: Multiplay
|
| |
|
| |
|
|\ |
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
$FreeBSD$ tags and man page dates.
Add a post-merge script which reapplies these changes.
Run both scripts to normalize the existing code base. As a result, many
files which should have had $FreeBSD$ tags but didn't now have them.
Partly rewrite the upgrade instructions and remove the now outdated
list of tricks.
|
| |
| |
| |
| |
| |
| |
| | |
auditdistd is not updated as I will make the change upstream and then do a
vendor import sometime in the next week or two.
MFC after: 3 weeks
|
| |
| |
| |
| | |
Approved by: des
|
| | |
|
|\ \
| |/ |
|
| |
| |
| |
| |
| |
| |
| |
| | |
Upgrade to OpenSSH 6.4p1.
Bump VersionAddendum.
Approved by: des
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
repeat performance by introducing a script that runs configure with and
without Kerberos, diffs the result and generates krb5_config.h, which
contains the preprocessor macros that need to be defined in the Kerberos
case and undefined otherwise.
Approved by: re (marius)
|
|\ \
| |/
| |
| |
| |
| |
| | |
didn't use them. This will make future merges from the vendor tree much
easier.
Approved by: re (gjb)
|
|\ \
| |/
| |
| | |
Approved by: re (gjb)
|
| |
| |
| |
| |
| |
| |
| |
| | |
LDNS. With that setting, OpenSSH will silently accept host keys that
match verified SSHFP records. If an SSHFP record exists but could not
be verified, OpenSSH will print a message and prompt the user as usual.
Approved by: re (blanket)
|
|\ \
| |/
| |
| |
| |
| |
| |
| |
| | |
branch but never merged to head. They were inadvertantly left out when
6.1p1 was merged to head. It didn't make any difference at the time,
because they were unused, but one of them is required for DNS-based host
key verification.
Approved by: re (blanket)
|
| |
| |
| |
| | |
MFC after: 3 days
|
| |
| |
| |
| | |
"sandbox" to "yes", but did not update the documentation to match.
|
| |
| |
| |
| |
| |
| | |
"sandbox" instead of "yes". In sandbox mode, the privsep child is unable
to load additional libraries and will therefore crash when trying to take
advantage of crypto offloading on CPUs that support it.
|
| |
| |
| |
| | |
the issues that affected us.
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
and the update to 6.1 added SSH_BUG_DYNAMIC_RPORT with the
same value.
Fix the HPN SSH_BUG_LARGEWINDOW bit so it is unique.
Approved by: des
MFC after: 2 weeks
|
| |
| |
| |
| | |
PR: bin/178060
|
| | |
|
| | |
|
| | |
|
| | |
|
| | |
|
|\ \
| |/
| |
| | |
for a key revocation list and more fine-grained authentication control.
|
| |
| |
| |
| |
| |
| |
| |
| |
| |
| |
| | |
has been deprecated for a while, some people still use it and were
unpleasantly surprised by this change.
I may revert this commit at a later date if I can come up with a way
to give users who still have authorized_keys2 files sufficient advance
warning.
MFC after: ASAP
|
| |
| |
| |
| |
| |
| |
| |
| |
| | |
own umask setting (from ~/.login.conf) unless running with the user's UID.
Therefore, we need to call it again with LOGIN_SETUMASK after changing UID.
PR: bin/176740
Submitted by: John Marshall <john.marshall@riverwillow.com.au>
MFC after: 1 week
|
| |
| |
| |
| | |
behave the way OpenSSH expects.
|