summaryrefslogtreecommitdiff
path: root/usr.bin/ssh
AgeCommit message (Collapse)Author
2015-04-29Allow ListenAddress, Port and AddressFamily in any order. bz#68,Darren Tucker
ok djm@, jmc@ (for the man page bit).
2015-04-28enviroment -> environment: apologies to darren for not spotting that firstJason McIntyre
time round...
2015-04-28Fix typo in previousDarren Tucker
2015-04-28Document that the TERM environment variable is not subject to SendEnvDarren Tucker
and AcceptEnv. bz#2386, based loosely on a patch from jjelen at redhat, help and ok jmc@
2015-04-27Make sshd default to PermitRootLogin=no;Damien Miller
ok deraadt@ rpe@
2015-04-27more OPENSSL=no fixes; ok dtucker@Damien Miller
2015-04-27fix compilation with OPENSSL=no; ok dtucker@Damien Miller
2015-04-27Include stdio.h for FILE (used in sshkey.h) so it compiles with OPENSSL=no.Darren Tucker
2015-04-27allow "sshd -f none" to skip reading the config file, much likeDamien Miller
"ssh -F none" does. ok dtucker
2015-04-24combine -Dd onto one line and update usage();Jason McIntyre
2015-04-24add ssh-agent -D to leave ssh-agent in foreground without enablingDamien Miller
debug mode; bz#2381 ok dtucker@
2015-04-242*len -> use xreallocarray()Theo de Raadt
ok djm
2015-04-24rename xrealloc() to xreallocarray() since it follows that form.Theo de Raadt
ok djm
2015-04-23Two small fixes for sshd -T: ListenAddress'es are added to a list head soDarren Tucker
reverse the order when printing them to ensure the behaviour remains the same, and print StreamLocalBindMask as octal with leading zero. ok deraadt@
2015-04-23Check for and reject missing arguments for VersionAddendum and ForceCommand.Darren Tucker
bz#2281, patch from plautrba at redhat com, ok djm@
2015-04-22unknown certificate extensions are non-fatal, so don't fatalDamien Miller
when they are encountered; bz#2387 reported by Bob Van Zant; ok dtucker@
2015-04-21Add back a backslash removed in rev 1.42 so KEX_SERVER_ENCRYPT willJonathan Gray
include aes again. ok deraadt@
2015-04-17s/recommended/required/ that private keys be og-rDamien Miller
this wording change was made a while ago but got accidentally reverted
2015-04-17don't try to cleanup NULL KEX proposals in kex_prop_free();Damien Miller
found by Jukka Taimisto and Markus Hietava
2015-04-17use error/logit/fatal instead of fprintf(stderr, ...) and exit(0),Damien Miller
fix a few errors that were being printed to stdout instead of stderr and a few non-errors that were going to stderr instead of stdout bz#2325; ok dtucker
2015-04-17debug log missing DISPLAY environment when X11 forwardingDamien Miller
requested; bz#1682 ok dtucker@
2015-04-17don't call record_login() in monitor when UseLogin is enabled;Damien Miller
bz#278 reported by drk AT sgi.com; ok dtucker
2015-04-17Add some missing options to sshd -T and fix the output of VersionAddendumDarren Tucker
HostCertificate. bz#2346, patch from jjelen at redhat com, ok djm.
2015-04-16Document "none" for PidFile XAuthLocation TrustedUserCAKeys and RevokedKeys.Darren Tucker
bz#2382, feedback from jmc@, ok djm@
2015-04-15Plug leak of address passed to logging. bz#2373, patch from jjelen at redhat,Darren Tucker
ok markus@
2015-04-14Output remote username in debug output since with Host and Match it's notDarren Tucker
always obvious what it will be. bz#2368, ok djm@
2015-04-13deprecate ancient, pre-RFC4419 and undocumentedDamien Miller
SSH2_MSG_KEX_DH_GEX_REQUEST_OLD message; ok markus@ deraadt@ "seems reasonable" dtucker@
2015-04-10Don't send hostkey advertisments (hostkeys-00@openssh.com) to currentDarren Tucker
versions of Tera Term as they can't handle them. Newer versions should be OK. Patch from Bryan Drewery and IWAMOTO Kouichi, ok djm@
2015-04-10include port number if a non-default one has been specified;Damien Miller
based on patch from Michael Handler
2015-04-07treat Protocol=1,2|2,1 as Protocol=2 when compiled without SSH1Damien Miller
support; ok dtucker@ millert@
2015-04-05Do not use int for sig_atomic_t; spotted by christos@netbsd; ok markus@Miod Vallat
2015-04-03correct return value in pubkey parsing, spotted by Ben HawkesDamien Miller
ok markus@
2015-03-31downgrade error() for known_hosts parse errors to debug() to quietDamien Miller
warnings from ssh1 keys present when compiled !ssh1. also identify ssh1 keys when scanning, even when compiled !ssh1 ok markus@ miod@
2015-03-31fd leak for !ssh1 case; found by unittests; ok markus@Damien Miller
2015-03-31don't fatal when a !ssh1 sshd is reexeced from a w/ssh1 listener;Damien Miller
reported by miod@; ok miod@ markus@
2015-03-31Comments are only supported for RSA1 keys. If a user tried to add one andTobias Stoeckmann
entered his passphrase, explicitly clear it before exit. This is done in all other error paths, too. ok djm
2015-03-30ssh-askpass(1) is the default, overridden by SSH_ASKPASS;Jason McIntyre
diff originally from jiri b;
2015-03-30fix uninitialised memory read when parsing a config file consistingDamien Miller
of a single nul byte. Found by hanno AT hboeck.de using AFL; ok dtucker
2015-03-26sigp and lenp are not optional in ssh_agent_sign(); ok djm@Markus Friedl
2015-03-26don't try to load .ssh/identity by default if SSH1 is disabled; ok markus@Christian Weisgerber
2015-03-26ban all-zero curve25519 keys as recommended by latestDamien Miller
CFRG curves draft; ok markus
2015-03-26relax bits needed check to allow diffie-hellman-group1-sha1 keyDamien Miller
exchange to complete for chacha20-poly1305 was selected as symmetric cipher; ok markus
2015-03-25ignore v1 errors on ssh-add -D; only try v2 keys on -l/-L (unless WITH_SSH1)Markus Friedl
ok djm@
2015-03-25unbreak ssh_agent_sign (lenp vs *lenp)Markus Friedl
2015-03-24don't leak 'setp' on error; noted by Nicholas Lemonias; ok djm@Markus Friedl
2015-03-24consistent check for NULL as noted by Nicholas Lemonias; ok djm@Markus Friedl
2015-03-24correct fmt-string for size_t as noted by Nicholas Lemonias; ok djm@Markus Friedl
2015-03-24promote chacha20-poly1305@openssh.com to be the default cipher;Damien Miller
ok markus
2015-03-24Compile-time disable SSH protocol 1. You can turn it back on usingDamien Miller
the Makefile.inc knob if you need it to talk to ancient devices.
2015-03-24fix double-negative error message "ssh1 is not unsupported"Damien Miller