summaryrefslogtreecommitdiff
Commit message (Collapse)AuthorAgeFilesLines
* - stevesk@cvs.openbsd.org 2006/07/03 08:54:20djm2006-07-105-6/+11
| | | | | [includes.h ssh.c sshconnect.c sshd.c] move #include "version.h" out of includes.h; ok markus@
* - stevesk@cvs.openbsd.org 2006/07/02 23:01:55djm2006-07-103-5/+10
| | | | | [clientloop.c ssh.1] use -KR[bind_address:]port here; ok djm@
* - stevesk@cvs.openbsd.org 2006/07/02 22:45:59djm2006-07-108-8/+22
| | | | | | [groupaccess.c groupaccess.h includes.h session.c sftp-common.c sshpty.c] move #include <grp.h> out of includes.h (portable needed uidswap.c too)
* - stevesk@cvs.openbsd.org 2006/07/02 18:36:47djm2006-07-103-4/+7
| | | | | | [gss-serv-krb5.c gss-serv.c] no "servconf.h" needed here (gss-serv-krb5.c change not applied, portable needs the server options)
* - stevesk@cvs.openbsd.org 2006/07/02 17:12:58djm2006-07-105-29/+72
| | | | | | [ssh.1 ssh.c ssh_config.5 sshd_config.5] more details and clarity for tun(4) device forwarding; ok and help jmc@
* - djm@cvs.openbsd.org 2006/06/26 10:36:15djm2006-07-102-6/+14
| | | | | | [clientloop.c] mention optional bind_address in runtime port forwarding setup command-line help. patch from santhi.amirta AT gmail.com
* - OpenBSD CVS Syncdjm2006-07-102-4/+10
| | | | | | - djm@cvs.openbsd.org 2006/06/14 10:50:42 [sshconnect.c] limit the number of pre-banner characters we will accept; ok markus@
* - (dtucker) [INSTALL] New autoconf version: 2.60.dtucker2006-07-102-3/+6
|
* - (dtucker) [INSTALL] A bit more info on autoconf.dtucker2006-07-062-3/+5
|
* - (dtucker) [configure.ac] Try AIX blibpath test in different order whendtucker2006-07-062-4/+14
| | | | | compiling with gcc. gcc 4.1.x will accept (but ignore) -b flags so configure would not select the correct libpath linker flags.
* whitespacedjm2006-07-051-2/+1
|
* whitespacedjm2006-07-051-1/+2
|
* - (dtucker) [ssh-rand-helper.c] Don't exit if mkdir fails because thedtucker2006-07-052-3/+7
| | | | target already exists.
* - (dtucker) [INSTALL] Bug #1202: Note when autoconf is required and whichdtucker2006-06-302-2/+14
| | | | version.
* - (dtucker) [openbsd-compat/getrrsetbyname.c] Undef _res before defining it,dtucker2006-06-302-1/+6
| | | | prevents warnings on platforms where _res is in the system headers.
* - (dtucker) [openbsd-compat/openbsd-compat.h] SNPRINTF_CONST for snprintfdtucker2006-06-302-3/+7
| | | | declaration too. Patch from russ at sludge.net.
* - (dtucker) [configure.ac] Bug #1203: Add missing '[', which causes problemsdtucker2006-06-272-3/+8
| | | | with autoconf 2.60. Patch from vapier at gentoo.org.
* - (dtucker) [channels.c serverloop.c] Apply the bug #1102 workaround to ptysdtucker2006-06-243-4/+11
| | | | only, otherwise sshd can hang exiting non-interactive sessions.
* - (dtucker) [serverloop.c] Get ifdef/ifndef the right way around for the bugdtucker2006-06-242-3/+5
| | | | #1102 workaround.
* - (dtucker) [configure.ac] Bug #1193: Define PASSWD_NEEDS_USERNAME on Solaris.dtucker2006-06-242-3/+10
| | | | | Works around limitation in Solaris' passwd program for changing passwords where the username is longer than 8 characters. ok djm@
* - (dtucker) [channels.c configure.ac serverloop.c] Bug #1102: Around AIXdtucker2006-06-234-3/+26
| | | | | | | | | 4.3.3 ML3 or so, the AIX pty layer starting passing zero-length writes on the pty slave as zero-length reads on the pty master, which sshd interprets as the descriptor closing. Since most things don't do zero length writes this rarely matters, but occasionally it happens, and when it does the SSH pty session appears to hang, so we add a special case for this condition. ok djm@
* - (dtucker) [README.platform configure.ac openbsd-compat/port-tun.c] Adddtucker2006-06-235-9/+38
| | | | | tunnel support for Mac OS X/Darwin via a third-party tun driver. Patch from reyk@, tested by anil@
* - (djm) [getput.h] This file has been replaced by functions in misc.cdjm2006-06-132-59/+2
|
* - djm@cvs.openbsd.org 2006/06/13 01:18:36djm2006-06-132-2/+8
| | | | | | | | [ssh-agent.c] always use a format string, even when printing a constant - djm@cvs.openbsd.org 2006/06/13 02:17:07 [ssh-agent.c] revert; i am on drugs. spotted by alexander AT beard.se
* - markus@cvs.openbsd.org 2006/06/08 14:45:49djm2006-06-136-9/+48
| | | | | [readpass.c sshconnect.c sshconnect2.c uidswap.c uidswap.h] do not set the gid, noted by solar; ok djm
* - markus@cvs.openbsd.org 2006/06/06 10:20:20djm2006-06-136-20/+29
| | | | | | [readpass.c sshconnect.c sshconnect.h sshconnect2.c uidswap.c] replace remaining setuid() calls with permanently_set_uid() and check seteuid() return values; report Marcus Meissner; ok dtucker djm
* - markus@cvs.openbsd.org 2006/06/01 09:21:48djm2006-06-132-3/+13
| | | | | | [sshd.c] call get_remote_ipaddr() early; fixes logging after client disconnects; report mpf@; ok dtucker@
* - mk@cvs.openbsd.org 2006/05/30 11:46:38djm2006-06-132-3/+7
| | | | | | [ssh-add.c] Sync usage() with man page and reality. ok deraadt dtucker
* - jmc@cvs.openbsd.org 2006/05/29 16:13:23djm2006-06-132-2/+10
| | | | | [ssh.1] add GSSAPI to the list of authentication methods supported;
* - jmc@cvs.openbsd.org 2006/05/29 16:10:03djm2006-06-132-5/+13
| | | | | [ssh_config.5] oops - previous was too long; split the list of auths up
* - dtucker@cvs.openbsd.org 2006/05/29 12:56:33djm2006-06-132-2/+8
| | | | | | [ssh_config] Add GSSAPIAuthentication and GSSAPIDelegateCredentials to examples in sample ssh_config. ok markus@
* - dtucker@cvs.openbsd.org 2006/05/29 12:54:08djm2006-06-132-3/+6
| | | | | [ssh_config.5] Add gssapi-with-mic to PreferredAuthentications default list; ok jmc
* - miod@cvs.openbsd.org 2006/05/18 21:27:25djm2006-06-133-5/+8
| | | | | [kexdhc.c kexgexc.c] paramter -> parameter
* - markus@cvs.openbsd.org 2006/05/17 12:43:34djm2006-06-136-11/+18
| | | | | [scp.c sftp.c ssh-agent.c ssh-keygen.c sshconnect.c] fix leak; coverity via Kylene Jo Hall
* - markus@cvs.openbsd.org 2006/05/16 09:00:00djm2006-06-132-2/+6
| | | | | [clientloop.c] missing free; from Kylene Hall
* - djm@cvs.openbsd.org 2006/05/08 10:49:48djm2006-06-132-2/+9
| | | | | | [sshconnect2.c] uint32_t -> u_int32_t (which we use everywhere else) (Id sync only - portable already had this)
* - (dtucker) [auth.c monitor.c] Now that we don't log from both the monitordtucker2006-05-213-40/+13
| | | | | and slave, we can remove the special-case handling in the audit hook in auth_log.
* - (dtucker) [ssh-rand-helper.c] Check return code of mkdir and fix filedtucker2006-05-172-2/+8
| | | | pointer leak. From kjhall at us.ibm.com, found by coverity.
* typodtucker2006-05-151-2/+2
|
* - (dtucker) [auth-pam.c] Bug #1188: pass result of do_pam_account back anddtucker2006-05-152-6/+19
| | | | do not allow kbdint again after the PAM account check fails. ok djm@
* - (dtucker) [defines.h] Find a value for IOV_MAX or use a conservativedtucker2006-05-152-2/+14
| | | | default. Patch originally from tim@, ok djm
* - (dtucker) [openbsd-compat/getrrsetbyname.c] Use _compat_res instead ofdtucker2006-05-152-1/+11
| | | | | | _res, prevents problems on some platforms that have _res as a global but don't have getrrsetbyname(), eg IRIX 5.3. Found and tested by georg.schwarz at freenet.de, ok djm@.
* - dtucker@cvs.openbsd.org 2006/05/06 08:35:40dtucker2006-05-062-1/+5
| | | | | [auth-krb5.c] Add $OpenBSD$ in comment here too
* - djm@cvs.openbsd.org 2006/04/01 05:37:46dtucker2006-05-062-3/+6
| | | | | [OVERVIEW] $OpenBSD$ in here too
* - djm@cvs.openbsd.org 2006/05/04 14:55:23dtucker2006-05-062-3/+23
| | | | | [dh.c] tighter DH exponent checks here too; feedback and ok markus@
* - dtucker@cvs.openbsd.org 2006/04/25 08:02:27dtucker2006-05-066-20/+35
| | | | | | | [authfile.c authfile.h sshconnect2.c ssh.c sshconnect1.c] Prevent ssh from trying to open private keys with bad permissions more than once or prompting for their passphrases (which it subsequently ignores anyway), similar to a previous change in ssh-add. bz #1186, ok djm@
* - (dtucker) [auth-pam.c groupaccess.c monitor.c monitor_wrap.c scard-opensc.cdtucker2006-05-0411-20/+31
| | | | | | | session.c ssh-rand-helper.c sshd.c openbsd-compat/bsd-cygwin_util.c openbsd-compat/setproctitle.c] Convert malloc(foo*bar) -> calloc(foo,bar) in Portable-only code; since calloc zeros, remove now-redundant memsets. Also add a couple of sanity checks. With & ok djm@
* - (dtucker) [packet.c] Remove in_systm.h since it's also in includes.hdtucker2006-05-032-2/+6
| | | | | and double including it on IRIX 5.3 causes problems. From Georg Schwarz, "no objections" tim@
* missing filedjm2006-04-231-2/+2
|
* - (djm) [auth.h dispatch.h kex.h] sprinkle in signal.h to getdjm2006-04-234-1/+9
| | | | sig_atomic_t