Commit Graph

  • 576cdf728b Fix memory leak from upstream Jakub Jelen 2015-03-30 10:55:01 +0200
  • b8a0f7a5ea Fix handling SELinux context in MLS systems Jakub Jelen 2015-03-30 10:54:24 +0200
  • 23bc31b25a Remove krb5-config workaround for #1203900 Jakub Jelen 2015-03-30 10:52:52 +0200
  • af7be11f1d Regression: solve sshd segfaults if other instance already running Jakub Jelen 2015-03-28 00:48:10 +0100
  • e5b15a7419 6.8p1-2 + 0.9.3-5 Jakub Jelen 2015-03-26 13:27:21 +0100
  • d94cf27456 Fix buffer handling in GSS after rebase Jakub Jelen 2015-03-26 12:38:43 +0100
  • 07756a2278 Fix reintroduced upstrem bug #1878 Jakub Jelen 2015-03-26 09:47:46 +0100
  • 12cf3e4d35 Update audit patch after rebase with more sanity checks Jakub Jelen 2015-03-26 09:44:58 +0100
  • aa8fb3e1cc rebuild 6.8p1-1.1 + 0.9.3-5 Jakub Jelen 2015-03-24 11:04:38 +0100
  • 1330ede7ff rebuild 6.8p1-1.1 + 0.9.3-5 Jakub Jelen 2015-03-24 10:59:16 +0100
  • e3688f35e1 release 6.8p1-1 + 0.9.3-5 Jakub Jelen 2015-03-23 08:27:16 +0100
  • d276698802 Workaround krb5-config bug (#1204646) Jakub Jelen 2015-03-23 15:29:06 +0100
  • acf98854ca Resolve segfault with auditing commands (#1203900) Jakub Jelen 2015-03-20 15:06:06 +0100
  • 114dfef6d3 Make pam_ssh_agent compile with current ssh Jakub Jelen 2015-03-24 08:24:27 +0100
  • 132f8f8686 6.8p1-1 + 0.9.3-5 Jakub Jelen 2015-03-20 14:56:04 +0100
  • 7b82d087e1 6.7p1-11 + 0.9.3-4 Jakub Jelen 2015-03-12 11:42:21 +0100
  • c31740f8ea Fix tmpfiles to be more consistent with other config files in package (#1196807) Jakub Jelen 2015-03-12 11:45:45 +0100
  • 558fb7b2f4 Add sftp option to force mode of created files Jakub Jelen 2015-03-11 17:16:54 +0100
  • c8062c4be3 Fix auditing when using combination of ForceCommand and PTY Jakub Jelen 2015-03-10 09:14:44 +0100
  • 3bc8b8b1ac Ability to specify an arbitrary LDAP filter in ldap.conf for ssh-ldap-helper Jakub Jelen 2015-03-10 09:10:39 +0100
  • 68fa4fb961 architecture dependent comments for seccomp filter (#1195065) Jakub Jelen 2015-03-10 07:12:13 +0100
  • 7aa6321a86 6.7p1-10 + 0.9.3-4 Jakub Jelen 2015-03-02 08:05:11 +0100
  • 766438b1d5 Add tmpfiles.d entries (#1196807) Jakub Jelen 2015-03-01 21:35:30 +0100
  • c8b4078a3f 6.7p1-9 + 0.9.3-4 Jakub Jelen 2015-02-27 18:44:47 +0100
  • bc083eb557 Adjust seccomp fiter for primary architectures and solve aarch64 issue (#1197051) Jakub Jelen 2015-02-26 15:52:20 +0100
  • cbda6f57fb Solve issue with ssh-copy-id and keys without trailing newline (#1093168) Jakub Jelen 2015-02-25 10:45:30 +0100
  • 5f3c83fd09 6.7p1-8 + 0.9.3-4 Jakub Jelen 2015-02-24 10:10:07 +0100
  • 6656486e18 Add AArch64 support for seccomp_filter sandbox (#1195065) Marcin Juszkiewicz 2015-02-23 17:36:03 +0100
  • e0f867b153 6.7p1-7 + 0.9.3-4 Jakub Jelen 2015-02-23 12:43:25 +0100
  • e3a6256653 Fix build issue without getuid32 Jakub Jelen 2015-02-23 12:41:59 +0100
  • c13a4b7170 6.7p1-6 + 0.9.3-4 Jakub Jelen 2015-02-23 12:15:58 +0100
  • d5a8001387 Fix seccomp filter for ix68 (#1194401), fix previous commit Jakub Jelen 2015-02-23 11:51:23 +0100
  • b9846a816d fix if statement Peter Robinson 2015-02-22 17:36:25 +0000
  • 74e740c136 Only use seccomp for sandboxing on supported platforms Peter Robinson 2015-02-22 17:28:16 +0000
  • c6945293fd 6.7p1-4 + 0.9.3-4 Jakub Jelen 2015-02-20 13:26:42 +0100
  • 77f453b74d cleanup working directory, spec file and unused patches after rebase Jakub Jelen 2015-02-20 15:04:36 +0100
  • 08cb909f5d Move cavs tests into subpackage -cavs (#1194320) Jakub Jelen 2015-02-20 13:24:42 +0100
  • 2f556360f6 6.7p1-3 + 0.9.3-4 Jakub Jelen 2015-02-11 13:40:30 +0100
  • 6df422d544 Fix ssh-copy-id on non-sh shells (#1045191) Jakub Jelen 2015-02-18 16:01:02 +0100
  • bb3e880c01 Add SSH KDF CAVS test driver for future FIPS validation (#1193045) Jakub Jelen 2015-02-17 12:44:33 +0100
  • 14c675f3a5 Use global hardening specification instead of hardening made by openssh. Jakub Jelen 2015-02-16 16:10:19 +0100
  • 0a4ac4f4d3 Enable seccomp sandboxing after resolving problems with audit patch (#1062953) Jakub Jelen 2015-02-11 10:29:14 +0100
  • b552eb6714 Make output of sshd -T more consistent, using upstream patch (#1187521) Jakub Jelen 2015-02-03 14:06:59 +0100
  • 580f986839 Update coverity patch after rebase to 6.7 Jakub Jelen 2015-01-30 14:27:43 +0100
  • 6c6416dc9d 6.7p1-2 + 0.9.3-4 Jakub Jelen 2015-01-27 14:10:18 +0100
  • 021326a6ae Fix audit patch after rebase to 6.7 Jakub Jelen 2015-01-27 11:41:18 +0100
  • 9b4e25cce0 temporarily disable audit patch causing segmentation faults Petr Lautrbach 2015-01-20 17:08:25 +0100
  • f29c8784c6 restore tcp wrappers support, based on Debian patch https://lists.mindrot.org/pipermail/openssh-unix-dev/2014-April/032497.html Petr Lautrbach 2015-01-20 17:06:46 +0100
  • 1900351913 6.7p1-1 + 0.9.3-4 Petr Lautrbach 2015-01-20 13:18:45 +0100
  • b457c98bec use upstream FigerPrintHash for fingerprint - 56d1c83cdd1ac76f1c6bd41e01e80dad834f3994 Petr Lautrbach 2014-12-22 13:29:43 +0100
  • 98584338a4 fix direction in CRYPTO_SESSION audit message Petr Lautrbach 2015-01-16 16:20:11 +0100
  • 3ffcb799b3 Fix changelog entry Jakub Jelen 2015-01-15 14:27:12 +0100
  • 2109ab67c2 6.6.1p1-11 + 0.9.3-3 Jakub Jelen 2015-01-14 14:22:30 +0100
  • 140e5ca05d add new option GSSAPIEnablek5users and disable using ~/.k5users by default CVE-2014-9278 (#1170745) Petr Lautrbach 2015-01-14 15:24:52 +0100
  • 9080a85b54 Update vendor-patchlevel string Jakub Jelen 2015-01-14 14:17:28 +0100
  • f92cd01d62 Update ldap extension to resolve #981058 Jakub Jelen 2015-01-09 18:50:03 +0100
  • e581af0a84 Add missing documentation link to systemd service files (RHBZ#1181593) Jakub Jelen 2015-01-13 17:48:55 +0100
  • b9d68e7db4 Fix config parser for ip:port values (#1130733) Jakub Jelen 2015-01-12 10:56:26 +0100
  • fd06d69c6a Fix confusing error message in scp (#1142223) Jakub Jelen 2015-01-14 13:33:57 +0100
  • 62986c5e87 6.6.1p1-10 + 0.9.3-3 Petr Lautrbach 2014-12-19 10:24:59 +0100
  • 7a7b8f0984 log via monitor in chroots without /dev/log Petr Lautrbach 2014-12-19 10:14:36 +0100
  • 720cf82ef2 record pfs= field in CRYPTO_SESSION audit event Petr Lautrbach 2014-12-15 18:59:39 +0100
  • cf5c1140f2 increase size of AUDIT_LOG_SIZE to 256 Petr Lautrbach 2014-12-11 14:11:31 +0100
  • 276c16ce71 6.6.1p1-9 + 0.9.3-3 Petr Lautrbach 2014-12-03 18:18:19 +0100
  • 56a647f5e3 the .local domain example should be in ssh_config, not in sshd_config Petr Lautrbach 2014-12-03 18:08:20 +0100
  • 08fe9e8e47 use different values for DH for Cisco servers (#1026430) Petr Lautrbach 2014-12-01 16:48:15 +0100
  • 823364a11e 6.6.1p1-8 + 0.9.3-3 Petr Lautrbach 2014-11-13 22:21:52 +0100
  • 44f0ac8d08 fix several coverity issues Resolves: rhbz#1139794 Petr Lautrbach 2014-11-13 16:43:15 +0100
  • 57666dc3be fix gsskex patch to correctly handle MONITOR_REQ_GSSSIGN request (#1118005) Petr Lautrbach 2014-11-12 17:02:36 +0100
  • a1e1ac2bfc 6.6.1p1-7 + 0.9.3-3 Petr Lautrbach 2014-11-07 12:53:03 +0100
  • 65a6cd2d8c correct the calculation of bytes for authctxt->krb5_ccname <ams@corefiling.com> (#1161073) Petr Lautrbach 2014-11-07 12:52:06 +0100
  • 3b7c8620a1 6.6.1p1-6 + 0.9.3-3 Petr Lautrbach 2014-11-04 19:09:42 +0100
  • 5296a797aa privsep_preauth: use SELinux context from selinux-policy (#1008580) Petr Lautrbach 2014-10-14 13:10:45 +0200
  • 414bfae1bc change audit trail - do not use (invalid user) - change acct for an unknown user "(unknown)" - don't send login audit event in getpwnamallow() Petr Lautrbach 2014-11-03 16:30:07 +0100
  • 30c06a07fb fix kuserok patch which checked for the existence of .k5login unconditionally and hence prevented other mechanisms to be used properly Petr Lautrbach 2014-10-24 20:10:20 +0200
  • 1ba984dcf2 revert the default of KerberosUseKuserok back to yes (#1153076) Petr Lautrbach 2014-10-24 19:59:55 +0200
  • 0f0e055d6a Ignore SIGXFSZ in postauth monitor https://bugzilla.mindrot.org/show_bug.cgi?id=2263 Petr Lautrbach 2014-09-29 08:37:05 +0200
  • 4b24967a9c fix parsing of empty arguments in sshd_conf https://bugzilla.mindrot.org/show_bug.cgi?id=2281 Petr Lautrbach 2014-09-25 11:45:47 +0200
  • c8fc193f3d sshd-keygen - don't generate DSA and ED25519 host keys in FIPS mode Stanislav Zidek 2014-09-23 10:59:03 +0200
  • afde9f8153 6.6.1p1-5 + 0.9.3-3 Petr Lautrbach 2014-09-08 10:35:57 +0200
  • ce2d80b4e7 don't consider a partial success as a failure Petr Lautrbach 2014-09-04 16:33:25 +0200
  • 163064841f apply RFC3454 stringprep to banners when possible https://bugzilla.mindrot.org/show_bug.cgi?id=2058 Petr Lautrbach 2014-09-03 15:44:40 +0200
  • c16b7033ca change the rsa key generation error message due to FIPS restrictions in openssl Petr Lautrbach 2014-09-02 15:41:49 +0200
  • 0a3f4e122d set a client's address right after a connection is set http://bugzilla.mindrot.org/show_bug.cgi?id=2257 Petr Lautrbach 2014-09-01 17:35:01 +0200
  • 662c5a05b3 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild Peter Robinson 2014-08-17 14:08:07 +0000
  • e336e33a32 fix license handling Tom Callaway 2014-07-18 19:28:30 -0400
  • 8ff21c966a 6.6.1p1-3 + 0.9.3-2 Petr Lautrbach 2014-07-18 08:38:51 +0200
  • 817071dc4d standardise on NI_MAXHOST for gethostname() string lengths (#1051490) Petr Lautrbach 2014-07-17 14:26:49 +0200
  • cef0d582b6 6.6.1p1-2 + 0.9.3-2 Petr Lautrbach 2014-07-14 12:35:16 +0200
  • d8b90ac6f8 minor spec file cleanup Petr Lautrbach 2014-07-09 21:40:06 +0200
  • 8028159313 fix and rebase fips patch to 6.6.1p1 Petr Lautrbach 2014-07-09 21:16:53 +0200
  • 9f526c6f31 cleanup and remove FIPS code from audit patch Petr Lautrbach 2014-07-09 21:08:53 +0200
  • 5160c9c8f3 rebase audit patch for 6.6.1p1 Petr Lautrbach 2014-07-08 15:52:24 +0200
  • 26621fa3b8 Add pam_reauthorize.so to sshd.pam (#1115977) Stef Walter 2014-07-03 13:58:57 +0200
  • 86f29c353e bring back openssh-5.5p1-x11.patch Petr Lautrbach 2014-07-03 16:42:56 +0200
  • 5fcfcac428 drop openssh-5.8p2-remove-stale-control-socket.patch Petr Lautrbach 2014-07-03 16:23:00 +0200
  • 8b5feef2c8 bring back the openssh-5.8p2-sigpipe.patch Petr Lautrbach 2014-07-03 16:14:38 +0200
  • d1b0938acc - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild Dennis Gilmore 2014-06-07 12:01:42 -0500
  • 7463b66c25 add missing patches and remove unused patches Petr Lautrbach 2014-06-04 10:26:18 +0200
  • 3e1dd6c5fd add forgotten openssh-6.6p1-gsskex.patch Petr Lautrbach 2014-06-04 10:17:31 +0200