Commit Graph

  • 8c9e97e65a Do not export KRBCCNAME if the default path is used (#1199363) Jakub Jelen 2017-09-11 15:54:31 +02:00
  • ce1afcf244 initial commit of tests from upstreamfirst project Mike Gahagan 2017-09-29 12:58:09 -04:00
  • ef66c0c677 openssh-7.5p1-5 + 0.10.3-2 Jakub Jelen 2017-08-14 09:45:09 +02:00
  • 0ce6c7b710 Another approach for crypto policies (#1479271) Jakub Jelen 2017-08-09 15:14:13 +02:00
  • 970a418151 Do not talk about SSHv1 in Summary Jakub Jelen 2017-08-09 15:15:11 +02:00
  • 6a05936971 Revert "server crypto policy" Jakub Jelen 2017-08-09 14:58:13 +02:00
  • fffad0579c openssh-7.5p1-4 + 0.10.3-2 Jakub Jelen 2017-08-02 13:46:00 +02:00
  • 722f82b9ab Remove openssh-clients-ssh1 subpackage (#1474942) Jakub Jelen 2017-08-01 19:00:24 +02:00
  • 1d8ffcfe05 Preprocess the configuration files to include crypto policies. Jakub Jelen 2017-07-11 15:41:09 +02:00
  • be108c2c82 - Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild Fedora Release Engineering 2017-07-27 01:53:26 +00:00
  • 64a3610c1f perl dependency renamed to perl-interpreter <https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules> Petr Písař 2017-07-12 14:20:53 +02:00
  • 2ea24bb006 openssh-7.5p1-2 + 0.10.3-2 Jakub Jelen 2017-06-30 12:44:10 +02:00
  • 9dbec70c9c Sync FIPS patch with RHEL Jakub Jelen 2017-06-30 12:18:02 +02:00
  • cdc7ba7293 get rid of unconditional goto in RSA1 code Jakub Jelen 2017-06-19 18:23:59 +02:00
  • f07a0866e1 Avoid double-free in the openssl-1.1.0 patch Jakub Jelen 2017-06-15 13:41:24 +02:00
  • eb751fd1d3 In FIPS mode do not append bogus comma after the kex list Jakub Jelen 2017-04-26 14:26:25 +02:00
  • 204765aba1 openssh-7.5p1-2 + 0.10.3-2 Jakub Jelen 2017-03-22 14:19:10 +01:00
  • c2f63ba00b Revert the chroot magic Jakub Jelen 2017-03-23 14:47:08 +01:00
  • 93868f39a9 Remove RestartPreventExitStatus which can break on slow networks Jakub Jelen 2017-03-22 18:00:17 +01:00
  • fb74d1ec96 Add missing header on s390 (#1434341) Jakub Jelen 2017-03-21 14:24:03 +01:00
  • 09320cf61a Fix typo in sandbox code, that got out after release Jakub Jelen 2017-03-21 10:12:44 +01:00
  • 17b491b307 openssh-7.5p1-1 + 0.10.3-2 Jakub Jelen 2017-03-20 15:55:43 +01:00
  • fd58b9eabb Add new DH kex into the FIPS-allowed list Jakub Jelen 2017-03-08 14:37:07 +01:00
  • 7b666e5764 openssh-7.4p1-4 + 0.10.3-1 Jakub Jelen 2017-02-28 15:13:40 +01:00
  • a9ad706d82 Coverity reports applied Jakub Jelen 2017-03-03 15:51:39 +01:00
  • f499c489fd Do not leave service in auto-restarting mode in case of configuration failure Jakub Jelen 2017-03-01 18:35:45 +01:00
  • b83281f89d Avoid sending SD_NOTIFY from wrong processes (#1427526) Jakub Jelen 2017-02-28 15:13:24 +01:00
  • ab7f9474c7 openssh-7.4p1-3 + 0.10.3-1 Jakub Jelen 2017-02-20 13:32:23 +01:00
  • 3448f25d85 Typo Jakub Jelen 2017-02-21 19:25:41 +01:00
  • b92d3c8ae0 Reference upstream bug Jakub Jelen 2017-02-20 15:24:15 +01:00
  • 4e7cdec7ef Add systemd stuff to keep track of service Jakub Jelen 2017-02-20 13:31:29 +01:00
  • 140ef5a0f5 Properly report errors from included files (#1408558) Jakub Jelen 2017-02-20 13:22:04 +01:00
  • a97eeb671c ppc architecture is gone for years Jakub Jelen 2017-02-16 10:46:10 +01:00
  • 4cf8f1aa09 Cleaner linking ldap-helper (circular dependencies) Jakub Jelen 2017-02-14 10:29:34 +01:00
  • 465b6e6b82 Check seteuid return values in all cases Jakub Jelen 2017-02-07 15:34:01 +01:00
  • bdb932c46a new pam_ssh_agent_auth-0.10.3 release Jakub Jelen 2017-02-07 15:33:15 +01:00
  • 26cec0607f openssh-7.4p1-2 + 0.10.2-5 Jakub Jelen 2017-02-06 09:47:28 +01:00
  • 640dfa350e Set environment variable to avoid race condition with systemd (#1415218) Jakub Jelen 2017-02-06 09:41:32 +01:00
  • 4a6ef41937 Do not overwrite N and E for RSA-certs in ssh-agent (#1416584) Jakub Jelen 2017-02-03 11:06:19 +01:00
  • 28ff3aa1c5 Correct path to crypto policies Jakub Jelen 2017-01-06 13:00:16 +01:00
  • b19926d292 openssh-7.4p1-1 + 0.10.2-5 Jakub Jelen 2017-01-03 14:30:38 +01:00
  • 58f79a27c3 Whitelist /usr/lib64/ for PKCS#11 modules Jakub Jelen 2017-01-03 10:43:15 +01:00
  • 6cf9b8e61b rebase to openssh-7.4p1-1 Jakub Jelen 2017-01-02 15:42:13 +01:00
  • 4189cebf7a Cache supported OIDS for GSSAPI kex (#1395288) Jakub Jelen 2017-01-02 14:42:38 +01:00
  • dd8e5419eb Fix use-after-free error (#1409433) Jakub Jelen 2017-01-02 14:23:54 +01:00
  • 38869a3406 Prevent hangs with long MOTD (filling buffers and blocking) Jakub Jelen 2016-12-15 14:29:36 +01:00
  • d8c2e8dc88 openssh-7.3p1-7 + 0.10.2-4 Jakub Jelen 2016-12-08 13:57:03 +01:00
  • 162941961a Move MAX_DISPLAYS to a configuration option Jakub Jelen 2016-12-08 13:51:28 +01:00
  • 4ce5741703 Properly deserialize received RSA certificates in ssh-agent (#1402029) Jakub Jelen 2016-12-08 13:50:08 +01:00
  • 172540fc87 7.2p2-14 + 0.10.2-3 f24 Jakub Jelen 2016-11-16 12:49:53 +01:00
  • c79ade1296 GSSAPI requires futex syscall in privsep child (#1395288) Jakub Jelen 2016-11-16 08:38:35 +01:00
  • 567d83cf01 When doing chroot * we should not drop any capabilities for root * we should not clear bounding capabilities for other users * we should probably retain the supplement groups Jakub Jelen 2016-10-21 14:50:42 +02:00
  • 7bccf7e6e0 openssh-7.3p1-6 + 0.10.2-4 Jakub Jelen 2016-11-16 11:07:41 +01:00
  • ef1da17783 GSSAPI requires futex syscall in privsep child (#1395288) Jakub Jelen 2016-11-16 08:38:35 +01:00
  • ccf623128a Fix changelog Jakub Jelen 2016-11-07 09:33:43 +01:00
  • 2a8bce34e4 openssh-7.3p1-5 + 0.10.2-4 Jakub Jelen 2016-10-27 18:26:25 +02:00
  • aacf0d429a OpenSSL 1.1.0 compat Jakub Jelen 2016-10-22 22:47:27 +02:00
  • ecc9f8d02b When doing chroot * we should not drop any capabilities for root * we should not clear bounding capabilities for other users * we should probably retain the supplement groups Jakub Jelen 2016-10-21 14:50:42 +02:00
  • c9d9fe9b0f Recommend crypto-policies for a client package Jakub Jelen 2016-10-11 10:29:50 +02:00
  • e7932f4770 openssh-7.2p2-6 + 0.10.2-3 f23 Jakub Jelen 2016-09-30 15:09:07 +02:00
  • 5f3ebc826d Fix NULL derefence (#1380297) https://anongit.mindrot.org/openssh.git/patch/?id=28652bca29046f62c7045e933e6b931de1d16737 Jakub Jelen 2016-09-29 11:15:13 +02:00
  • 0408223488 openssh-7.2p2-12 + 0.10.2-3 Jakub Jelen 2016-09-30 13:19:39 +02:00
  • fcaf20b6d9 Fix NULL derefence (#1380297) https://anongit.mindrot.org/openssh.git/patch/?id=28652bca29046f62c7045e933e6b931de1d16737 Jakub Jelen 2016-09-29 11:15:13 +02:00
  • d924bc6892 openssh-7.3p1-4 + 0.10.2-4 Jakub Jelen 2016-09-29 11:17:14 +02:00
  • 639ae2c73c Include client Crypto Policy (#1225752) Jakub Jelen 2016-09-29 11:26:06 +02:00
  • ae831ab305 Fix NULL derefence (#1380297) https://anongit.mindrot.org/openssh.git/patch/?id=28652bca29046f62c7045e933e6b931de1d16737 Jakub Jelen 2016-09-29 11:15:13 +02:00
  • 739842b137 Make the code build without SELinux and without Audit Jakub Jelen 2016-09-15 16:36:04 +02:00
  • 0a605f4d31 openssh-7.3p1-3 + 0.10.2-4 Jakub Jelen 2016-08-15 12:20:15 +02:00
  • 38d533a5e1 Proper content of the included configuration files Jakub Jelen 2016-08-15 12:18:50 +02:00
  • 73953d29f1 openssh-7.3p1-2 + 0.10.2-4 Jakub Jelen 2016-08-09 10:32:01 +02:00
  • 24cd5a4d34 openssh-7.2p2-12 + 0.10.2-3 Jakub Jelen 2016-08-09 08:45:07 +02:00
  • 793e7839fc CVE-2016-6515: Denial of service via very long passwords (#1364936) Jakub Jelen 2016-08-09 08:43:37 +02:00
  • 88f3a752ae openssh-7.3p1-1. + 0.10.2-4 Jakub Jelen 2016-08-09 08:24:35 +02:00
  • 90ffc35e29 Correct permissions on the ssh_config directory (#1365270) Jakub Jelen 2016-08-09 08:23:44 +02:00
  • 7ea4bdf410 forgotten sources Jakub Jelen 2016-08-05 15:49:56 +02:00
  • a711d3c82f openssh-7.3p1-1 + 0.10.2-4 Jakub Jelen 2016-07-26 12:31:13 +02:00
  • 6454089e75 Create include directory with example content (redhat modifications) Jakub Jelen 2016-08-04 10:57:32 +02:00
  • 334feb284c Do not build ssh-keycat with sshd LIBS Jakub Jelen 2016-08-02 12:53:25 +02:00
  • b165161da2 When we don't listen for the clients, num_listen_socks is -1 Jakub Jelen 2016-07-26 15:14:46 +02:00
  • 6da7f4d0ed Drop SCP progressmeter patch because of reworked UTF-8 API (tracked upstream #2434) Jakub Jelen 2016-07-26 10:55:37 +02:00
  • b487a6d746 Move old canohost.h API to shared place, so it can be used by audit and gssapi (states) Jakub Jelen 2016-07-26 10:54:13 +02:00
  • 5878ebb50e Most of the coverity patch applied upstream, context changes for rebase Jakub Jelen 2016-07-25 16:21:15 +02:00
  • 70c2ac20bd CVE-2016-6210 is fixed upstream Jakub Jelen 2016-07-25 15:29:47 +02:00
  • 13a7aaf5e3 CVE-2015-8325 and certificate regression are fixed upstream Jakub Jelen 2016-07-25 15:23:16 +02:00
  • 38e1dfa80d Upstream bug #2477 applied Jakub Jelen 2016-07-25 15:22:09 +02:00
  • 4bd77fcccc seccomp for secondary architecures patch already upstream (#2590) Jakub Jelen 2016-07-25 15:02:45 +02:00
  • 05bc93847e Bug #2281 resolved upstream Jakub Jelen 2016-07-25 14:56:34 +02:00
  • 178ce15f5a UTF-8 banners resolved by upstream bug #2058 Jakub Jelen 2016-07-25 14:54:30 +02:00
  • 14320ca590 The upstream bug #2257 is fixed Jakub Jelen 2016-07-25 14:38:39 +02:00
  • 986af88658 openssh-7.2p2-5 + 0.10.2-3 Jakub Jelen 2016-07-27 12:38:04 +02:00
  • 5d464e8b62 Rework SELinux context handling with chroot using libcap-ng (#1357860) Jakub Jelen 2016-07-20 16:18:46 +02:00
  • 5a28bb2729 openssh-7.2p2-11 + 0.10.2-3 Jakub Jelen 2016-07-26 16:39:52 +02:00
  • 82bfd19e51 openssh-7.2p2-11 + 0.10.2-3 Jakub Jelen 2016-07-26 13:01:28 +02:00
  • 6a7dd92929 Remove legacy sshd-keygen (#1359762) Revert "Add legacy sshd-keygen for anaconda (#1331077)" Jakub Jelen 2016-07-26 12:57:48 +02:00
  • 793bc4b1cc Remove slogin symlinks (#1359762) Revert "Restore slogin symlinks" Jakub Jelen 2016-07-26 12:56:55 +02:00
  • b4df5ebb8d Rework SELinux context handling with chroot using libcap-ng (#1357860) Jakub Jelen 2016-07-20 16:18:46 +02:00
  • 2762c74636 openssh-7.2p2-4 + 0.10.2-3 Jakub Jelen 2016-07-18 15:03:33 +02:00
  • 920d3a7915 Prevent user enumeration via timing channel (CVE-2016-6210) Jakub Jelen 2016-07-18 13:30:36 +02:00
  • 9dc741314f openssh-7.2p2-10 + 0.10.2-3 Jakub Jelen 2016-07-18 13:55:58 +02:00
  • 1057900209 Prevent user enumeration via timing channel (CVE-2016-6210) Jakub Jelen 2016-07-18 13:30:36 +02:00