summaryrefslogtreecommitdiff
path: root/usr.bin/ssh
AgeCommit message (Collapse)Author
2013-07-02add missing library dependenciesMarkus Friedl
2013-07-02remove extra whitespaceMarkus Friedl
2013-06-27do not use Sx for sections outwith the man page - ingo informs me thatJason McIntyre
stuff like html will render with broken links; issue reported by Eric S. Raymond, via djm
2013-06-22improved time_t overflow check suggested by guenther@Damien Miller
2013-06-21make this -Wsign-compare clean after time_t conversionDamien Miller
2013-06-21sprinkle in some error() to explain moduli(5) parse failuresDamien Miller
2013-06-21explicitly mention that IdentitiesOnly can be used with IdentityFileDamien Miller
to control which keys are offered from an agent.
2013-06-21for hostbased authentication, print the client host and user onDamien Miller
the auth success/failure line; bz#2064, ok dtucker@
2013-06-20don't leak the rdata blob on errors; ok djm@Markus Friedl
2013-06-19stop doing kerberos in ssh and sshdTheo de Raadt
the code bloat makes that no longer trustworthy functionality ok guenther
2013-06-18Shuffle library link order to appease the static arch deities.Miod Vallat
2013-06-17link to the new kerberos librariesRobert Nagy
2013-06-17Handle time_t values as long long's when formatting them and whenPhilip Guenther
parsing them from remote servers. Improve error checking in parsing of 'T' lines. ok dtucker@ deraadt@
2013-06-10revert 1.203 while we investigate crashes reported by okan@Darren Tucker
2013-06-07Add an "ABANDONED" channel state and use for mux sessions that areDarren Tucker
disconnected via the ~. escape sequence. Channels in this state will be able to close if the server responds, but do not count as active channels. This means that if you ~. all of the mux clients when using ControlPersist on a broken network, the backgrounded mux master will exit when the Control Persist time expires rather than hanging around indefinitely. bz#1917, also reported and tested by tedu@. ok djm@ markus@.
2013-06-05plug another memleak. bz#1967, from Zhenbo Xu, detected by Melton, ok djmDarren Tucker
2013-06-05Fix memory leaks found by Zhenbo Xu and the Melton tool. bz#1967, ok djmDarren Tucker
2013-06-05When running sshd -D, close stderr unless we have explicitly requestingDarren Tucker
logging to stderr. From james.hunt at ubuntu.com via bz#1976, djm's patch so, err, ok dtucker.
2013-06-05fix leaks in mux error paths, from Zhenbo Xu, found by Melton. bz#1967, ok djmDarren Tucker
2013-06-04Make sftp's libedit interface marginally multibyte aware by building up theDarren Tucker
quoted string by character instead of by byte. Prevents failures when linked against a libedit built with wide character support (bz#1990). "looks ok" djm
2013-06-04use MAXPATHLEN for buffer size instead of fixed value. ok markusDarren Tucker
2013-06-03force the MAC output to be 64-bit aligned so umac won't see unalignedDarren Tucker
accesses on strict-alignment architectures. bz#2101, patch from tomas.kuthan at oracle.com, ok djm@
2013-06-02No need for the mux cleanup callback to be visible so restore it to staticDarren Tucker
and call it through the detach_user function pointer. ok djm@
2013-06-02typo in commentDarren Tucker
2013-06-02Make parent_alive_interval time_t to avoid signed/unsigned comparisonDarren Tucker
2013-06-02Add misc.h for monotim prototype.Darren Tucker
2013-06-01Update progressmeter when data is acked, not when it's sent. bz#2108, fromDarren Tucker
Debian via Colin Watson, ok djm@
2013-06-01Replace S_IWRITE, which isn't standardized, with S_IWUSR, which is. PatchDarren Tucker
from Nathan Osman via bz#2085. ok deraadt.
2013-06-01Use clock_gettime(CLOCK_MONOTONIC ...) for ssh timers so that things likeDarren Tucker
keepalives and rekeying will work properly over clock steps. Suggested by markus@, "looks good" djm@.
2013-05-31Use time_t where appropriate. ok djmDarren Tucker
2013-05-19Standardise logging of supplemental information during userauth. KeysDamien Miller
and ruser is now logged in the auth success/failure message alongside the local username, remote host/port and protocol in use. Certificates contents and CA are logged too. Pushing all logging onto a single line simplifies log analysis as it is no longer necessary to relate information scattered across multiple log entries. "I like it" markus@
2013-05-19fix failure to recognise cert-authority keys if a key of a different typeDamien Miller
appeared in authorized_keys before it; ok markus@
2013-05-17bye, bye xfree(); ok markus@Damien Miller
2013-05-16remove another now-unused variableDarren Tucker
2013-05-16remove now-unused variablesDarren Tucker
2013-05-16switch RekeyLimit traffic volume parsing to scan_scaled. ok djm@Darren Tucker
2013-05-16Fix some "unused result" warnings found via clang and -portable. ok markus@Darren Tucker
2013-05-16oops! avoid Xr to self;Jason McIntyre
2013-05-16put IgnoreUnknown in the right place;Jason McIntyre
2013-05-16add the ability to ignore specific unrecognised ssh_config options;Damien Miller
bz#866; ok markus@
2013-05-16Add RekeyLimit to sshd with the same syntax as the client allowing rekeyingDarren Tucker
based on traffic volume or time. ok djm@, help & ok jmc@ for the man page.
2013-05-16Add an optional second argument to RekeyLimit in the client to allowDarren Tucker
rekeying based on elapsed time in addition to amount of traffic. with djm@ jmc@, ok djm
2013-05-10remove unused extern optarg. ok markus@Darren Tucker
2013-05-10memleak in cert_free(), wasn't actually freeing the struct;Damien Miller
bz#2096 from shm AT digitalsun.pl
2013-05-10fix bzero(ptr_to_struct, sizeof(ptr_to_struct)); bz#2100 fromDamien Miller
Colin Watson
2013-05-06Reference the version of the sftp draft we actually implement. ok djm@Darren Tucker
2013-04-24remove extra parens noticed by nicmTed Unangst
2013-04-23use xasprintf instead of a series of strlcats and strdup. ok djmTed Unangst
2013-04-22typo in debug output: evitval->exitvalDarren Tucker
2013-04-19remove duplicated list entry pointed out by naddy@Damien Miller