Compare commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
e8121e2215 | ||
|
|
aa080fd376 | ||
|
|
a0e7f10508 | ||
|
|
314c1be7e2 | ||
|
|
f99940bb9f | ||
|
|
52582a9535 | ||
|
|
7bb9f1cbf8 | ||
|
|
da11f7bb52 | ||
|
|
c99ee82478 | ||
|
|
bc9f9699ec | ||
|
|
6a2798f655 | ||
|
|
4cc0fae3a9 | ||
|
|
303fa18d3e | ||
|
|
8c4d25fd31 | ||
|
|
da221e306f | ||
|
|
e4b1734886 | ||
|
|
310c18b342 |
@@ -1,16 +1,68 @@
|
||||
20050919
|
||||
- (tim) [aclocal.m4 configure.ac] Delete acconfig.h and add templates to
|
||||
AC_DEFINE and AC_DEFINE_UNQUOTED to quiet autoconf 2.59 warning messages.
|
||||
ok dtucker@
|
||||
20051102
|
||||
- (dtucker) [openbsd-compat/bsd-misc.c] Bug #1108: fix broken strdup().
|
||||
Reported by olavi at ipunplugged.com and antoine.brodin at laposte.net
|
||||
via FreeBSD.
|
||||
|
||||
20050912
|
||||
- (tim) [configure.ac] Bug 1078. Fix --without-kerberos5. Reported by
|
||||
Mike Frysinger.
|
||||
20051030
|
||||
- (djm) [contrib/suse/openssh.spec contrib/suse/rc.
|
||||
sshd contrib/suse/sysconfig.ssh] Bug #1106: Updated SuSE spec and init
|
||||
20051025
|
||||
- (dtucker) [configure.ac] Relocate LLONG_MAX calculation to after the
|
||||
sizeof(long long) checks, to make fixing bug #1104 easier (no changes
|
||||
yet).
|
||||
- (dtucker) [configure.ac] Bug #1104: Tru64's printf family doesn't
|
||||
understand "%lld", even though the compiler has "long long", so handle
|
||||
it as a special case. Patch tested by mcaskill.scott at epa.gov.
|
||||
|
||||
20050908
|
||||
- (tim) [defines.h openbsd-compat/port-uw.c] Add long password support to
|
||||
OpenServer 6 and add osr5bigcrypt support so when someone migrates
|
||||
passwords between UnixWare and OpenServer they will still work. OK dtucker@
|
||||
20051017
|
||||
- (dtucker) [configure.ac] Bug #1097: Fix configure for cross-compiling.
|
||||
/etc/default/login report and testing from aabaker at iee.org, corrections
|
||||
from tim@.
|
||||
|
||||
20051008
|
||||
- (dtucker) [configure.ac] Bug #1098: define $MAIL for HP-UX; report from
|
||||
brian.smith at agilent com.
|
||||
|
||||
20051005
|
||||
- (dtucker) [configure.ac sshd.8] Enable locked account check (a prepended
|
||||
"*LOCKED*" string) for FreeBSD. Patch jeremie at le-hen.org and
|
||||
senthilkumar_sen at hotpop.com.
|
||||
|
||||
20051003
|
||||
- (dtucker) OpenBSD CVS Sync
|
||||
- [email protected] 2005/09/07 08:53:53
|
||||
[channels.c]
|
||||
enforce chanid != NULL; ok djm
|
||||
- [email protected] 2005/09/09 19:18:05
|
||||
[clientloop.c]
|
||||
typo; from mark at mcs.vuw.ac.nz, bug #1082
|
||||
- [email protected] 2005/09/19 11:37:34
|
||||
[ssh_config.5 ssh.1]
|
||||
mention ability to specify bind_address for DynamicForward and -D options;
|
||||
bz#1077 spotted by Haruyama Seigo
|
||||
- [email protected] 2005/09/19 11:47:09
|
||||
[sshd.c]
|
||||
stop connection abort on rekey with delayed compression enabled when
|
||||
post-auth privsep is disabled (e.g. when root is logged in); ok dtucker@
|
||||
- [email protected] 2005/10/03 07:44:42
|
||||
[canohost.c]
|
||||
Relocate check_ip_options call to prevent logging of garbage for
|
||||
connections with IP options set. bz#1092 from David Leonard,
|
||||
"looks good" deraadt@
|
||||
|
||||
20050930
|
||||
- (dtucker) [openbsd-compat/openbsd-compat.h] Bug #1096: Add prototype
|
||||
for strtoll. Patch from o.flebbe at science-computing.de.
|
||||
- (dtucker) [monitor.c] Bug #1087: Send loginmsg to preauth privsep
|
||||
child during PAM account check without clearing it. This restores the
|
||||
post-login warnings such as LDAP password expiry. Patch from Tomas Mraz
|
||||
with help from several others.
|
||||
- (dtucker) [auth-pam.c] Bug #1028: send final non-query messages from
|
||||
PAM via keyboard-interactive. Patch tested by the folks at Vintela.
|
||||
|
||||
20050922
|
||||
- (dtucker) [configure.ac] Use -R linker flag for libedit too; patch from
|
||||
skeleten at shillest.net.
|
||||
|
||||
20050901
|
||||
- (djm) Update RPM spec file versions
|
||||
@@ -3003,4 +3055,4 @@
|
||||
- (djm) Trim deprecated options from INSTALL. Mention UsePAM
|
||||
- (djm) Fix quote handling in sftp; Patch from admorten AT umich.edu
|
||||
|
||||
$Id: ChangeLog,v 1.3891 2005/09/19 16:36:55 tim Exp $
|
||||
$Id: ChangeLog,v 1.3887.2.15 2005/11/01 22:06:50 dtucker Exp $
|
||||
|
||||
+12
-2
@@ -47,7 +47,7 @@
|
||||
|
||||
/* Based on $FreeBSD: src/crypto/openssh/auth2-pam-freebsd.c,v 1.11 2003/03/31 13:48:18 des Exp $ */
|
||||
#include "includes.h"
|
||||
RCSID("$Id: auth-pam.c,v 1.126 2005/07/17 07:18:50 djm Exp $");
|
||||
RCSID("$Id: auth-pam.c,v 1.126.2.1 2005/09/30 00:55:17 dtucker Exp $");
|
||||
|
||||
#ifdef USE_PAM
|
||||
#if defined(HAVE_SECURITY_PAM_APPL_H)
|
||||
@@ -716,8 +716,18 @@ sshpam_query(void *ctx, char **name, char **info,
|
||||
plen++;
|
||||
xfree(msg);
|
||||
break;
|
||||
case PAM_SUCCESS:
|
||||
case PAM_AUTH_ERR:
|
||||
debug3("PAM: PAM_AUTH_ERR");
|
||||
if (**prompts != NULL && strlen(**prompts) != 0) {
|
||||
*info = **prompts;
|
||||
**prompts = NULL;
|
||||
*num = 0;
|
||||
**echo_on = 0;
|
||||
ctxt->pam_done = -1;
|
||||
return 0;
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
case PAM_SUCCESS:
|
||||
if (**prompts != NULL) {
|
||||
/* drain any accumulated messages */
|
||||
debug("PAM: %s", **prompts);
|
||||
|
||||
+4
-4
@@ -12,7 +12,7 @@
|
||||
*/
|
||||
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: canohost.c,v 1.44 2005/06/17 02:44:32 djm Exp $");
|
||||
RCSID("$OpenBSD: canohost.c,v 1.45 2005/10/03 07:44:42 dtucker Exp $");
|
||||
|
||||
#include "packet.h"
|
||||
#include "xmalloc.h"
|
||||
@@ -43,9 +43,6 @@ get_remote_hostname(int sock, int use_dns)
|
||||
cleanup_exit(255);
|
||||
}
|
||||
|
||||
if (from.ss_family == AF_INET)
|
||||
check_ip_options(sock, ntop);
|
||||
|
||||
ipv64_normalise_mapped(&from, &fromlen);
|
||||
|
||||
if (from.ss_family == AF_INET6)
|
||||
@@ -55,6 +52,9 @@ get_remote_hostname(int sock, int use_dns)
|
||||
NULL, 0, NI_NUMERICHOST) != 0)
|
||||
fatal("get_remote_hostname: getnameinfo NI_NUMERICHOST failed");
|
||||
|
||||
if (from.ss_family == AF_INET)
|
||||
check_ip_options(sock, ntop);
|
||||
|
||||
if (!use_dns)
|
||||
return xstrdup(ntop);
|
||||
|
||||
|
||||
+7
-7
@@ -39,7 +39,7 @@
|
||||
*/
|
||||
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: channels.c,v 1.223 2005/07/17 07:17:54 djm Exp $");
|
||||
RCSID("$OpenBSD: channels.c,v 1.224 2005/09/07 08:53:53 markus Exp $");
|
||||
|
||||
#include "ssh.h"
|
||||
#include "ssh1.h"
|
||||
@@ -2668,6 +2668,9 @@ x11_create_display_inet(int x11_display_offset, int x11_use_localhost,
|
||||
char strport[NI_MAXSERV];
|
||||
int gaierr, n, num_socks = 0, socks[NUM_SOCKS];
|
||||
|
||||
if (chanids == NULL)
|
||||
return -1;
|
||||
|
||||
for (display_number = x11_display_offset;
|
||||
display_number < MAX_DISPLAYS;
|
||||
display_number++) {
|
||||
@@ -2749,8 +2752,7 @@ x11_create_display_inet(int x11_display_offset, int x11_use_localhost,
|
||||
}
|
||||
|
||||
/* Allocate a channel for each socket. */
|
||||
if (chanids != NULL)
|
||||
*chanids = xmalloc(sizeof(**chanids) * (num_socks + 1));
|
||||
*chanids = xmalloc(sizeof(**chanids) * (num_socks + 1));
|
||||
for (n = 0; n < num_socks; n++) {
|
||||
sock = socks[n];
|
||||
nc = channel_new("x11 listener",
|
||||
@@ -2758,11 +2760,9 @@ x11_create_display_inet(int x11_display_offset, int x11_use_localhost,
|
||||
CHAN_X11_WINDOW_DEFAULT, CHAN_X11_PACKET_DEFAULT,
|
||||
0, "X11 inet listener", 1);
|
||||
nc->single_connection = single_connection;
|
||||
if (*chanids != NULL)
|
||||
(*chanids)[n] = nc->self;
|
||||
(*chanids)[n] = nc->self;
|
||||
}
|
||||
if (*chanids != NULL)
|
||||
(*chanids)[n] = -1;
|
||||
(*chanids)[n] = -1;
|
||||
|
||||
/* Return the display number for the DISPLAY environment variable. */
|
||||
*display_numberp = display_number;
|
||||
|
||||
+2
-2
@@ -59,7 +59,7 @@
|
||||
*/
|
||||
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: clientloop.c,v 1.141 2005/07/16 01:35:24 djm Exp $");
|
||||
RCSID("$OpenBSD: clientloop.c,v 1.142 2005/09/09 19:18:05 markus Exp $");
|
||||
|
||||
#include "ssh.h"
|
||||
#include "ssh1.h"
|
||||
@@ -266,7 +266,7 @@ client_x11_get_proto(const char *display, const char *xauth_path,
|
||||
}
|
||||
}
|
||||
snprintf(cmd, sizeof(cmd),
|
||||
"%s %s%s list %s . 2>" _PATH_DEVNULL,
|
||||
"%s %s%s list %s 2>" _PATH_DEVNULL,
|
||||
xauth_path,
|
||||
generated ? "-f " : "" ,
|
||||
generated ? xauthfile : "",
|
||||
|
||||
+293
-398
File diff suppressed because it is too large
Load Diff
@@ -834,9 +834,7 @@ mm_answer_pam_account(int sock, Buffer *m)
|
||||
ret = do_pam_account();
|
||||
|
||||
buffer_put_int(m, ret);
|
||||
buffer_append(&loginmsg, "\0", 1);
|
||||
buffer_put_cstring(m, buffer_ptr(&loginmsg));
|
||||
buffer_clear(&loginmsg);
|
||||
buffer_put_string(m, buffer_ptr(&loginmsg), buffer_len(&loginmsg));
|
||||
|
||||
mm_request_send(sock, MONITOR_ANS_PAM_ACCOUNT, m);
|
||||
|
||||
|
||||
@@ -18,7 +18,7 @@
|
||||
#include "includes.h"
|
||||
#include "xmalloc.h"
|
||||
|
||||
RCSID("$Id: bsd-misc.c,v 1.27 2005/05/27 11:13:41 dtucker Exp $");
|
||||
RCSID("$Id: bsd-misc.c,v 1.27.2.1 2005/11/01 22:06:50 dtucker Exp $");
|
||||
|
||||
#ifndef HAVE___PROGNAME
|
||||
char *__progname;
|
||||
@@ -223,10 +223,7 @@ strdup(const char *str)
|
||||
len = strlen(str) + 1;
|
||||
cp = malloc(len);
|
||||
if (cp != NULL)
|
||||
if (strlcpy(cp, str, len) != len) {
|
||||
free(cp);
|
||||
return NULL;
|
||||
}
|
||||
return cp;
|
||||
return(memcpy(cp, str, len));
|
||||
return NULL;
|
||||
}
|
||||
#endif
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
/* $Id: openbsd-compat.h,v 1.30 2005/08/26 20:15:20 tim Exp $ */
|
||||
/* $Id: openbsd-compat.h,v 1.30.2.1 2005/09/29 23:55:14 dtucker Exp $ */
|
||||
|
||||
/*
|
||||
* Copyright (c) 1999-2003 Damien Miller. All rights reserved.
|
||||
@@ -152,6 +152,10 @@ int openpty(int *, int *, char *, struct termios *, struct winsize *);
|
||||
int snprintf(char *, size_t, const char *, ...);
|
||||
#endif
|
||||
|
||||
#ifndef HAVE_STRTOLL
|
||||
long long strtoll(const char *, char **, int);
|
||||
#endif
|
||||
|
||||
#ifndef HAVE_STRTONUM
|
||||
long long strtonum(const char *, long long, long long, const char **);
|
||||
#endif
|
||||
|
||||
@@ -34,7 +34,7 @@
|
||||
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
||||
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
.\"
|
||||
.\" $OpenBSD: ssh.1,v 1.209 2005/07/06 09:33:05 dtucker Exp $
|
||||
.\" $OpenBSD: ssh.1,v 1.210 2005/09/19 11:37:34 djm Exp $
|
||||
.Dd September 25, 1999
|
||||
.Dt SSH 1
|
||||
.Os
|
||||
@@ -47,7 +47,12 @@
|
||||
.Op Fl 1246AaCfgkMNnqsTtVvXxY
|
||||
.Op Fl b Ar bind_address
|
||||
.Op Fl c Ar cipher_spec
|
||||
.Op Fl D Ar port
|
||||
.Oo Fl D\ \&
|
||||
.Sm off
|
||||
.Oo Ar bind_address : Oc
|
||||
.Ar port
|
||||
.Sm on
|
||||
.Oc
|
||||
.Op Fl e Ar escape_char
|
||||
.Op Fl F Ar configfile
|
||||
.Op Fl i Ar identity_file
|
||||
@@ -494,13 +499,20 @@ The default is
|
||||
arcfour256,arcfour,aes192-cbc,aes256-cbc,aes128-ctr,
|
||||
aes192-ctr,aes256-ctr''
|
||||
.Ed
|
||||
.It Fl D Ar port
|
||||
.It Fl D Xo
|
||||
.Sm off
|
||||
.Oo Ar bind_address : Oc
|
||||
.Ar port
|
||||
.Sm on
|
||||
.Xc
|
||||
Specifies a local
|
||||
.Dq dynamic
|
||||
application-level port forwarding.
|
||||
This works by allocating a socket to listen to
|
||||
.Ar port
|
||||
on the local side, and whenever a connection is made to this port, the
|
||||
on the local side, optionally bound to the specified
|
||||
.Ar bind_address .
|
||||
Whenever a connection is made to this port, the
|
||||
connection is forwarded over the secure channel, and the application
|
||||
protocol is then used to determine where to connect to from the
|
||||
remote machine.
|
||||
@@ -509,6 +521,30 @@ Currently the SOCKS4 and SOCKS5 protocols are supported, and
|
||||
will act as a SOCKS server.
|
||||
Only root can forward privileged ports.
|
||||
Dynamic port forwardings can also be specified in the configuration file.
|
||||
.Pp
|
||||
IPv6 addresses can be specified with an alternative syntax:
|
||||
.Sm off
|
||||
.Xo
|
||||
.Op Ar bind_address No /
|
||||
.Ar port
|
||||
.Xc
|
||||
.Sm on
|
||||
or by enclosing the address in square brackets.
|
||||
Only the superuser can forward privileged ports.
|
||||
By default, the local port is bound in accordance with the
|
||||
.Cm GatewayPorts
|
||||
setting.
|
||||
However, an explicit
|
||||
.Ar bind_address
|
||||
may be used to bind the connection to a specific address.
|
||||
The
|
||||
.Ar bind_address
|
||||
of
|
||||
.Dq localhost
|
||||
indicates that the listening port be bound for local use only, while an
|
||||
empty address or
|
||||
.Sq *
|
||||
indicates that the port should be available from all interfaces.
|
||||
.It Fl e Ar ch | ^ch | none
|
||||
Sets the escape character for sessions with a pty (default:
|
||||
.Ql ~ ) .
|
||||
|
||||
+24
-2
@@ -34,7 +34,7 @@
|
||||
.\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
|
||||
.\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
|
||||
.\"
|
||||
.\" $OpenBSD: ssh_config.5,v 1.61 2005/07/08 12:53:10 jmc Exp $
|
||||
.\" $OpenBSD: ssh_config.5,v 1.62 2005/09/19 11:37:34 djm Exp $
|
||||
.Dd September 25, 1999
|
||||
.Dt SSH_CONFIG 5
|
||||
.Os
|
||||
@@ -320,7 +320,29 @@ Specifies that a TCP/IP port on the local machine be forwarded
|
||||
over the secure channel, and the application
|
||||
protocol is then used to determine where to connect to from the
|
||||
remote machine.
|
||||
The argument must be a port number.
|
||||
.Pp
|
||||
The argument must be
|
||||
.Sm off
|
||||
.Oo Ar bind_address : Oc Ar port .
|
||||
.Sm on
|
||||
IPv6 addresses can be specified by enclosing addresses in square brackets or
|
||||
by using an alternative syntax:
|
||||
.Oo Ar bind_address Ns / Oc Ns Ar port .
|
||||
By default, the local port is bound in accordance with the
|
||||
.Cm GatewayPorts
|
||||
setting.
|
||||
However, an explicit
|
||||
.Ar bind_address
|
||||
may be used to bind the connection to a specific address.
|
||||
The
|
||||
.Ar bind_address
|
||||
of
|
||||
.Dq localhost
|
||||
indicates that the listening port be bound for local use only, while an
|
||||
empty address or
|
||||
.Sq *
|
||||
indicates that the port should be available from all interfaces.
|
||||
.Pp
|
||||
Currently the SOCKS4 and SOCKS5 protocols are supported, and
|
||||
.Nm ssh
|
||||
will act as a SOCKS server.
|
||||
|
||||
@@ -123,7 +123,10 @@ on Solaris,
|
||||
.Ql \&*
|
||||
on HP-UX, containing
|
||||
.Ql Nologin
|
||||
on Tru64 and a leading
|
||||
on Tru64,
|
||||
a leading
|
||||
.Ql \&*LOCKED\&*
|
||||
on FreeBSD and a leading
|
||||
.Ql \&!!
|
||||
on Linux). If there is a requirement to disable password authentication
|
||||
for the account while allowing still public-key, then the passwd field
|
||||
|
||||
@@ -42,7 +42,7 @@
|
||||
*/
|
||||
|
||||
#include "includes.h"
|
||||
RCSID("$OpenBSD: sshd.c,v 1.312 2005/07/25 11:59:40 markus Exp $");
|
||||
RCSID("$OpenBSD: sshd.c,v 1.314 2005/09/19 11:47:09 djm Exp $");
|
||||
|
||||
#include <openssl/dh.h>
|
||||
#include <openssl/bn.h>
|
||||
@@ -633,9 +633,8 @@ privsep_postauth(Authctxt *authctxt)
|
||||
if (authctxt->pw->pw_uid == 0 || options.use_login) {
|
||||
#endif
|
||||
/* File descriptor passing is broken or root login */
|
||||
monitor_apply_keystate(pmonitor);
|
||||
use_privsep = 0;
|
||||
return;
|
||||
goto out;
|
||||
}
|
||||
|
||||
/* Authentication complete */
|
||||
@@ -669,6 +668,7 @@ privsep_postauth(Authctxt *authctxt)
|
||||
/* Drop privileges */
|
||||
do_setusercontext(authctxt->pw);
|
||||
|
||||
out:
|
||||
/* It is safe now to apply the key state */
|
||||
monitor_apply_keystate(pmonitor);
|
||||
|
||||
|
||||
Reference in New Issue
Block a user