summaryrefslogtreecommitdiff
path: root/usr.bin/ssh
AgeCommit message (Collapse)Author
2009-10-28tweak previous;Jason McIntyre
2009-10-28Allow to set the rdomain in ssh/sftp/scp/sshd and ssh-keyscan.Reyk Floeter
ok markus@
2009-10-24Request roaming to be enabled if UseRoaming is true and the serverAndreas Gunnarsson
supports it. ok markus@
2009-10-24Do the actual suspend/resume in the client. This won't be useful untilAndreas Gunnarsson
the server side supports roaming. Most code from Martin Forssen, maf at appgate dot com. Some changes by me and markus@ ok markus@
2009-10-24Define the KEX messages used when resuming a suspended connection.Andreas Gunnarsson
ok markus@
2009-10-24Dummy implementation of wait_for_roaming_reconnect() for the server side.Andreas Gunnarsson
It doesn't do anything yet but is needed for upcoming changes in roaming_common.c ok markus@
2009-10-24client_loop() must detect if the session has been suspended and resumed,Andreas Gunnarsson
and take appropriate action in that case. From Martin Forssen, maf at appgate dot com ok markus@
2009-10-24Let the client detect if the server supports roaming by lookingAndreas Gunnarsson
for the resume@appgate.com kex algorithm. ok markus@
2009-10-24Declarations needed for upcoming changes.Andreas Gunnarsson
ok markus@
2009-10-24ssh-keygen now uses AES-128 for private keysDarren Tucker
2009-10-23disallow a hostile server from checking jpake auth by sending anDamien Miller
out-of-sequence success message. (doesn't affect code enabled by default)
2009-10-22switch from 3DES to AES-128 for encryption of passphrase-protectedDamien Miller
SSH protocol 2 private keys; ok several
2009-10-22write UNIX-domain in a more consistent way; while here, replace aIgor Sobrado
few remaining ".Tn UNIX" macros with ".Ux" ones. pointed out by ratchov@, thanks! ok jmc@
2009-10-22use the UNIX-related macros (.At and .Ux) where appropriate.Igor Sobrado
ok jmc@
2009-10-17sort flags.Igor Sobrado
2009-10-11mention the host name that we are looking for in check_host_in_hostfile()Damien Miller
2009-10-11d_type isn't portable so use lstat to get dirent modes. Suggested by andDarren Tucker
"looks sane" deraadt@
2009-10-08some tweaks now that protocol 1 is not offered by default; ok markusJason McIntyre
2009-10-08disable protocol 1 by default (after a transition period of about 10 years)Markus Friedl
ok deraadt
2009-10-06bz#1596: fflush(NULL) before exec() to ensure that everying (motdDamien Miller
in particular) has made it out before the streams go away.
2009-10-01fix a castAlexander von Gernler
ok djm@ markus@
2009-09-01fix a race condition in ssh-agent that could result in a wedged orDamien Miller
spinning agent: don't read off the end of the allocated fd_sets, and don't issue blocking read/write on agent sockets - just fall back to select() on retriable read/write errors. bz#1633 reported and tested by "noodle10000 AT googlemail.com"; ok dtucker@ markus@
2009-08-31document -e and -h; prodded by jmc@Damien Miller
2009-08-31check correct variable for error message, spotted by martynas@Damien Miller
2009-08-27Do not fall back to adding keys without contraints (ssh-add -c / -t ...)Damien Miller
when the agent refuses the constrained add request. This was a useful migration measure back in 2002 when constraints were new, but just adds risk now. bz #1612, report and patch from dkg AT fifthhorseman.net; ok markus@
2009-08-27allow setting an explicit umask on the commandline to override whateverDamien Miller
default the user has. bz#1229; ok dtucker@ deraadt@ markus@
2009-08-27force use of correct hash function for random-art signature displayDamien Miller
as it was inheriting the wrong one when bubblebabble signatures were activated; bz#1611 report and patch from fwojcik+openssh AT besh.com; ok markus@
2009-08-27allow setting an explicit umask on the commandline to override whateverDamien Miller
default the user has. bz#1229; ok dtucker@ deraadt@ markus@
2009-08-20subsystem_flag is defined in ssh.c so it's extern; ok djmDarren Tucker
2009-08-19ether -> either;Jason McIntyre
2009-08-18fix "get" command usage, spotted by jmc@Damien Miller
2009-08-18recursive transfer support for get/put and on the commandlineDamien Miller
work mostly by carlosvsilvapt@gmail.com for the Google Summer of Code with some tweaks by me; "go for it" deraadt@
2009-08-16Add PubkeyAuthentication to the list allowed in a Match block (bz #1577)Darren Tucker
2009-08-15remove unused define. markus@ ok.Federico G. Schwindt
2009-08-14make the "get_handle: ..." error messages vaguely useful by allowingDamien Miller
callers to specify their own error message strings.
2009-08-13sync synopsis and usage();Jason McIntyre
2009-08-13Swizzle options: "-P sftp_server_path" moves to "-D sftp_server_path",Damien Miller
add "-P port" to match scp(1). Fortunately, the -P option is only really used by our regression scripts. part of larger patch from carlosvsilvapt@gmail.com for his Google Summer of Code work; ok deraadt markus
2009-08-12sort options;Jason McIntyre
2009-08-12support most of scp(1)'s commandline arguments in sftp(1), as a firstDamien Miller
step towards making sftp(1) a drop-in replacement for scp(1). One conflicting option (-P) has not been changed, pending further discussion. Patch from carlosvsilvapt@gmail.com as part of his work in the Google Summer of Code
2009-07-05only send SSH2_MSG_DISCONNECT if we're in compat20; from dtucker@Kevin Steves
ok deraadt@ markus@
2009-07-02allow for long home dir paths (bz #1615). ok deraadtDarren Tucker
2009-06-30crank version; ok deraadtMarkus Friedl
2009-06-27Add client option UseRoaming. It doesn't do anything yet but willAndreas Gunnarsson
control whether the client tries to use roaming if enabled on the server. From Martin Forssen. ok markus@
2009-06-27It may be necessary to retransmit some data when resuming, so add itAndreas Gunnarsson
to a buffer when roaming is enabled. Most of this code was written by Martin Forssen, maf at appgate dot com. ok markus@
2009-06-27packet_bacup_state() and packet_restore_state() will be used toAndreas Gunnarsson
temporarily save the current state ren resuming a suspended connection. ok markus@
2009-06-22alphabetize includes; reduces diff vs portable and style(9). ok stevesk djmDarren Tucker
2009-06-21Add tags for the benefit of the sync scriptsDarren Tucker
2009-06-21abort if key_sign fails, preventing possible null deref. Based on reportDarren Tucker
from Paolo Ganci, ok markus@ djm@
2009-06-13Use debug3() instead of debug(), requested by markus@Andreas Gunnarsson
ok dtucker@
2009-06-12Move some more statics into session_stateAndreas Gunnarsson
ok markus@ djm@