summaryrefslogtreecommitdiff
path: root/ChangeLog
Commit message (Collapse)AuthorAgeFilesLines
* - jmc@cvs.openbsd.org 2005/03/01 15:47:14Damien Miller2005-03-021-1/+4
| | | | | [ssh-keyscan.1 ssh-keyscan.c] sort options and sync usage();
* - jmc@cvs.openbsd.org 2005/03/01 15:05:00Damien Miller2005-03-021-1/+4
| | | | | [ssh-keygen.1] whitespace;
* - jmc@cvs.openbsd.org 2005/03/01 14:59:49Damien Miller2005-03-021-1/+5
| | | | | | [sshd.8] new sentence, new line; whitespace;
* - jmc@cvs.openbsd.org 2005/03/01 14:55:23Damien Miller2005-03-021-1/+5
| | | | | | [ssh_config.5] do not mark up punctuation; whitespace;
* - jmc@cvs.openbsd.org 2005/03/01 14:47:58Damien Miller2005-03-021-1/+8
| | | | | | [ssh.1] remove some unneccesary macros; do not mark up punctuation;
* - djm@cvs.openbsd.org 2005/03/01 10:42:49Damien Miller2005-03-011-1/+5
| | | | | | [ssh-keygen.1 ssh-keygen.c ssh_config.5] add tools for managing known_hosts files with hashed hostnames, including hashing existing files and deleting hosts by name; ok markus@ deraadt@
* - djm@cvs.openbsd.org 2005/03/01 10:41:28Damien Miller2005-03-011-1/+4
| | | | | [ssh-keyscan.1 ssh-keyscan.c] option to hash hostnames output by ssh-keyscan; ok markus@ deraadt@
* - djm@cvs.openbsd.org 2005/03/01 10:40:27Damien Miller2005-03-011-1/+7
| | | | | | | | [hostfile.c hostfile.h readconf.c readconf.h ssh.1 ssh_config.5] [sshconnect.c sshd.8] add support for hashing host names and addresses added to known_hosts files, to improve privacy of which hosts user have been visiting; ok markus@ deraadt@
* - djm@cvs.openbsd.org 2005/03/01 10:09:52Damien Miller2005-03-011-1/+9
| | | | | | | | | | [auth-options.c channels.c channels.h clientloop.c compat.c compat.h] [misc.c misc.h readconf.c readconf.h servconf.c ssh.1 ssh.c ssh_config.5] [sshd_config.5] bz#413: allow optional specification of bind address for port forwardings. Patch originally by Dan Astorian, but worked on by several people Adds GatewayPorts=clientspecified option on server to allow remote forwards to bind to client-specified ports.
* - djm@cvs.openbsd.org 2005/02/28 00:54:10Damien Miller2005-03-011-1/+5
| | | | | | [ssh_config.5] bz#849: document timeout on untrusted x11 forwarding sessions. Reported by orion AT cora.nwra.com; ok markus@
* - jmc@cvs.openbsd.org 2005/02/25 10:55:13Damien Miller2005-03-011-1/+5
| | | | | | [sshd.8] add /etc/motd and $HOME/.hushlogin to FILES; from michael knudsen;
* - djm@cvs.openbsd.org 2005/02/20 22:59:06Damien Miller2005-03-011-1/+6
| | | | | | | [sftp.c] turn on ssh batch mode when in sftp batch mode, patch from jdmossh AT nand.net; ok markus@
* - djm@cvs.openbsd.org 2005/02/18 03:05:53Damien Miller2005-03-011-1/+4
| | | | | [canohost.c] better error messages for getnameinfo failures; ok dtucker@
* - otto@cvs.openbsd.org 2005/02/16 09:56:44Damien Miller2005-03-011-1/+7
| | | | | [ssh.c] Better diagnostic if an identity file is not accesible. ok markus@ djm@
* - (dtucker) [Makefile.in] Add a install-nosysconf target for installing theDarren Tucker2005-02-261-1/+4
| | | | | binaries without the config files. Primarily useful for packaging. Patch from phil at usc.edu. ok djm@
* - (dtucker) [acconfig.h configure.ac openbsd-compat/bsd-misc.{c,h}]Darren Tucker2005-02-261-1/+4
| | | | | Remove SETGROUPS_NOOP, was only used by Cygwin, which doesn't need it any more. Patch from vinschen at redhat.com.
* - (dtucker) [openbsd-compat/bsd-openpty.c openbsd-compat/inet_ntop.c]Darren Tucker2005-02-261-2/+6
| | | | Remove two obsolete Cygwin #ifdefs. Patch from vinschen at redhat.com.
* - (djm) [configure.ac] in_addr_t test needs sys/types.h tooDamien Miller2005-02-241-1/+4
|
* - (dtucker) [uidswap.c] Skip uid restore test on Cygwin. Patch fromDarren Tucker2005-02-221-1/+5
| | | | vinschen at redhat.com.
* - (dtucker) [configure.ac] Missing comma in AIX section, somehow causesDarren Tucker2005-02-201-1/+3
| | | | unrelated platforms to be configured incorrectly.
* - (dtucker) [LICENCE Makefile.in README.platform audit-bsm.c configure.acDarren Tucker2005-02-201-1/+7
| | | | | | defines.h] Bug #125: Add *EXPERIMENTAL* BSM audit support. Configure --with-audit=bsm to enable. Patch originally from Sun Microsystems, parts by John R. Jackson. ok djm@
* - (dtucker) [configure.ac openbsd-compat/port-aix.{c,h}] Silence some moreDarren Tucker2005-02-161-1/+3
| | | | compiler warnings on AIX.
* - (dtucker) [session.c] Bug #918: store credentials from gssapi-with-micDarren Tucker2005-02-161-1/+5
| | | | | | authentication early enough to be available to PAM session modules when privsep=yes. Patch from deengert at anl.gov, ok'ed in principle by Sam Hartman and similar to Debian's ssh-krb5 package.
* - (dtucker) [configure.ac] Bug #893: check for libresolv early on ReliantDarren Tucker2005-02-161-1/+4
| | | | | Unix; prevents problems relating to the location of -lresolv in the link order.
* - (dtucker) [auth-shadow.c] Prevent compiler warnings if "DAY" is definedDarren Tucker2005-02-161-1/+3
| | | | by the system headers.
* - (dtucker) [ssh-rand-helper.c] Provide seed_rng since it may be calledDarren Tucker2005-02-161-1/+3
| | | | via mkstemp in some configurations. ok djm@
* write seed to temporary file and atomically rename into place; ok dtucker@Damien Miller2005-02-161-1/+5
|
* - (dtucker) [loginrec.c] Add missing #include.Darren Tucker2005-02-151-1/+2
|
* - (dtucker) [README.platform auth.c configure.ac loginrec.cDarren Tucker2005-02-151-1/+5
| | | | | | openbsd-compat/port-aix.c openbsd-compat/port-aix.h] Bug #835: enable IPv6 on AIX where possible (see README.platform for details) and work around a misfeature of AIX's getnameinfo. ok djm@
* - (dtucker) [config.sh.in] Collect oslevel -r too.Darren Tucker2005-02-151-1/+4
|
* - (dtucker) [openbsd-compat/fake-rfc2553.h] We now need EAI_SYSTEM too.Darren Tucker2005-02-111-1/+2
|
* - (dtucker) [configure.ac] Tidy up configure --help output.Darren Tucker2005-02-111-1/+4
|
* - (dtucker) [configure.ac] Bug #919: Provide visible feedback for theDarren Tucker2005-02-101-1/+5
| | | | --disable-etc-default-login configure option.
* - (dtucker) [configure.ac session.c] Some platforms (eg some SCO) requireDarren Tucker2005-02-091-1/+4
| | | | | the username to be passed to the passwd command when changing expired passwords. ok djm@
* - (dtucker) [configure.ac] Bug #854: prepend pwd to relative --with-ssl-dirDarren Tucker2005-02-091-3/+3
| | | | paths. ok djm@
* - (dtucker) [auth-passwd.c openbsd-compat/port-aix.c] Don't callDarren Tucker2005-02-091-1/+6
| | | | | disable_forwarding() from compat library. Prevent linker errrors trying to resolve it for binaries other than sshd. ok djm@
* - dtucker@cvs.openbsd.org 2005/02/08 22:24:57Darren Tucker2005-02-091-1/+4
| | | | | [sshd.c] Provide reason in error message if getnameinfo fails; ok markus@
* - dtucker@cvs.openbsd.org 2005/01/30 11:18:08Darren Tucker2005-02-091-1/+4
| | | | | [monitor.c] Make code match intent; ok djm@
* - jmc@cvs.openbsd.org 2005/01/28 18:14:09Darren Tucker2005-02-091-1/+5
| | | | | | [ssh_config.5] wording; ok markus@
* - jmc@cvs.openbsd.org 2005/01/28 15:05:43Darren Tucker2005-02-091-1/+4
| | | | | [ssh_config.5] grammar;
* - dtucker@cvs.openbsd.org 2005/01/28 09:45:53Darren Tucker2005-02-091-1/+9
| | | | | | | [ssh_config] Make it clear that the example entries in ssh_config are only some of the commonly-used options and refer the user to ssh_config(5) for more details; ok djm@
* - (dtucker) [audit.c audit.h auth.c auth1.c auth2.c loginrec.c monitor.cDarren Tucker2005-02-081-1/+5
| | | | | | monitor_wrap.c monitor_wrap.h session.c sshd.c]: Prepend all of the audit defines and enums with SSH_ to prevent namespace collisions on some platforms (eg AIX).
* - (dtucker) [openbsd-compat/port-aix.c] Silence compiler warnings.Darren Tucker2005-02-081-1/+2
|
* - (dtucker) [regress/test-exec.sh] Bug #912: Set _POSIX2_VERSION for theDarren Tucker2005-02-081-1/+6
| | | | | regress tests so newer versions of GNU head(1) behave themselves. Patch by djm, so ok me.
* - (dtucker) [auth.c] Fix parens in audit log check.Darren Tucker2005-02-041-1/+2
|
* - (dtucker) [monitor.c] Permit INVALID_USER audit events from slave too.Darren Tucker2005-02-041-1/+4
|
* typoDarren Tucker2005-02-031-2/+2
|
* - (dtucker) [Makefile.in auth.c auth.h auth1.c auth2.c loginrec.c monitor.cDarren Tucker2005-02-031-1/+5
| | | | | | monitor.h monitor_wrap.c monitor_wrap.h session.c sshd.c] Bug #125: (first stage) Add audit instrumentation to sshd, currently disabled by default. with suggestions from and djm@
* - (dtucker) [auth.c canohost.c canohost.h configure.ac defines.h loginrec.c]Darren Tucker2005-02-021-1/+6
| | | | | | | Bug #974: Teach sshd to write failed login records to btmp for failed auth attempts (currently only for password, kbdint and C/R, only on Linux and HP-UX), based on code from login.c from util-linux. With ashok_kovai at hotmail.com, ok djm@
* - (dtucker) [session.c sshd.c] Bug #445: Propogate KRB5CCNAME if set to childDarren Tucker2005-02-021-1/+5
| | | | | | the process. Since we also unset KRB5CCNAME at startup, if it's set after authentication it must have been set by the platform's native auth system. This was already done for AIX; this enables it for the general case.