Jakub Jelen
5878ebb50e
Most of the coverity patch applied upstream, context changes for rebase
2016-08-04 10:59:59 +02:00
Jakub Jelen
70c2ac20bd
CVE-2016-6210 is fixed upstream
2016-08-04 10:59:59 +02:00
Jakub Jelen
13a7aaf5e3
CVE-2015-8325 and certificate regression are fixed upstream
2016-08-04 10:59:59 +02:00
Jakub Jelen
38e1dfa80d
Upstream bug #2477 applied
2016-08-04 10:59:59 +02:00
Jakub Jelen
4bd77fcccc
seccomp for secondary architecures patch already upstream ( #2590 )
2016-08-04 10:59:59 +02:00
Jakub Jelen
05bc93847e
Bug #2281 resolved upstream
2016-08-04 10:59:59 +02:00
Jakub Jelen
178ce15f5a
UTF-8 banners resolved by upstream bug #2058
2016-08-04 10:59:59 +02:00
Jakub Jelen
14320ca590
The upstream bug #2257 is fixed
2016-08-04 10:59:59 +02:00
Jakub Jelen
82bfd19e51
openssh-7.2p2-11 + 0.10.2-3
2016-07-26 15:41:29 +02:00
Jakub Jelen
6a7dd92929
Remove legacy sshd-keygen ( #1359762 )
...
Revert "Add legacy sshd-keygen for anaconda (#1331077 )"
This reverts commit 0b5300a59c
.
2016-07-26 15:41:29 +02:00
Jakub Jelen
793bc4b1cc
Remove slogin symlinks ( #1359762 )
...
Revert "Restore slogin symlinks"
This reverts commit e762f7265e
.
2016-07-26 15:41:29 +02:00
Jakub Jelen
b4df5ebb8d
Rework SELinux context handling with chroot using libcap-ng ( #1357860 )
2016-07-26 15:40:30 +02:00
Jakub Jelen
9dc741314f
openssh-7.2p2-10 + 0.10.2-3
2016-07-18 13:55:58 +02:00
Jakub Jelen
1057900209
Prevent user enumeration via timing channel (CVE-2016-6210)
2016-07-18 13:30:52 +02:00
Jakub Jelen
209c7a8aea
Expose more information to PAM
2016-07-18 13:30:51 +02:00
Jakub Jelen
9864973c69
Make closefrom() ignore softlinks to the /dev/ devices on s390
2016-07-18 12:26:15 +02:00
Jakub Jelen
a49441fa52
openssh-7.2p2-9 + 0.10.2-3
2016-07-01 09:07:18 +02:00
Jakub Jelen
a8068249cb
Bad condition for UseLogin check ( #1350347 )
2016-06-27 10:33:57 +02:00
Jakub Jelen
5a67d51d0f
openssh-7.2p2-8 + 0.10.2-3
2016-06-24 12:07:22 +02:00
Jakub Jelen
8cf031f736
pam_ssh_agent_auth: Fix conflict bewteen two getpwuid() calls ( #1349551 )
2016-06-24 12:07:22 +02:00
Jakub Jelen
d8ffa911e3
SFTP server forced permissions should restore umask
2016-06-24 12:07:22 +02:00
Jakub Jelen
f22e5dcaeb
pselect6 is already in upstream seccomp filter
2016-06-24 12:07:22 +02:00
Jakub Jelen
186bf3858e
UseLogin yes is not supported in Fedora
2016-06-24 12:07:22 +02:00
Jakub Jelen
c06fe506bc
seccomp filter for MIPS ( #1195065 )
2016-06-24 12:07:22 +02:00
Petr Písař
ad928ac7d1
Mandatory Perl build-requires added < https://fedoraproject.org/wiki/Changes/Build_Root_Without_Perl >
2016-06-24 10:03:17 +02:00
Jakub Jelen
ba8f38935c
openssh-7.2p2-7
2016-06-06 16:39:35 +02:00
Jakub Jelen
f6a096caf2
Build seccomp filter on ppc64(le) architecture ( #1195065 )
2016-06-06 16:39:35 +02:00
Jakub Jelen
1144aef1d1
Comments for patches, merge ssh_config from localdomain to redhat patch (ssh_config related)
2016-06-06 16:39:17 +02:00
Jakub Jelen
84d3989ec8
Coverity -> FIPS patch
2016-06-03 12:54:03 +02:00
Jakub Jelen
31536c7ac6
Move linux_seed() header from coverity to entropy patch
2016-06-03 12:54:03 +02:00
Jakub Jelen
f2868287aa
rebase x11 patch to clean up coverity patch
2016-06-03 10:44:32 +02:00
Jakub Jelen
ea9421342e
Coverity: dereference in pam_ssh_agent_auth
...
Upstream: https://sourceforge.net/p/pamsshagentauth/bugs/22/
2016-06-03 09:49:44 +02:00
Jakub Jelen
d78d347c11
Check for real location of .k5login file ( #1328243 )
2016-06-03 09:29:58 +02:00
Jakub Jelen
8dd0608e77
Regression in certificate-based authentication ( #1333498 )
2016-05-06 09:25:20 +02:00
Jakub Jelen
991b66246f
openssh-7.2p2-6 + 0.10.2-3
2016-04-29 13:57:45 +02:00
Jakub Jelen
0b5300a59c
Add legacy sshd-keygen for anaconda ( #1331077 )
2016-04-29 13:41:38 +02:00
Jakub Jelen
1380564732
openssh-7.2p2-5 + 0.10.2-3
2016-04-22 14:52:57 +02:00
Jakub Jelen
b7de610db3
Fix typo about sshd-keygen in sysconfig ( #1325535 )
2016-04-22 14:50:30 +02:00
Jakub Jelen
cf4e3a1844
Fix for CVE-2015-8325 ( #1328013 )
2016-04-18 12:39:11 +02:00
Jakub Jelen
58d2868dfe
openssh-7.2p2-4 + 0.10.2-3
2016-04-15 17:56:43 +02:00
Jakub Jelen
5489ace8dc
Add sshd-keygen.target to abstract key creation from sshd.service and sshd@.service ( #1325535 )
...
* PartOf is needed to trigger sshd-keygen checks for sshd.service restarts
* sshd-keygen.target makes a level of abstraction to eliminate dupplicate
dependencies on both sshd and sshd@ services
2016-04-15 17:05:32 +02:00
Jakub Jelen
461b3af818
Remove unused sshd init script
2016-04-15 17:04:59 +02:00
Jakub Jelen
32a74888d5
openssh-7.2p2-3 + 0.10.2-3
2016-04-13 13:44:58 +02:00
Jakub Jelen
00c7b75439
Make sshd-keygen comply with packaging guidelines ( #1325535 )
2016-04-13 13:42:12 +02:00
Jakub Jelen
3d2c14680b
Soft-deny socket() syscall in seccomp sandbox ( #1324493 )
...
* Used for ecdh-sha2-nistp* key exchange methods in FIPS mode
2016-04-11 16:14:25 +02:00
Jakub Jelen
0509c6c977
Remove *sha1 Kex in FIPS mode ( #1324493 )
2016-04-11 13:16:52 +02:00
Jakub Jelen
117a730ded
Remove *gcm ciphers in FIPS mode ( #1324493 )
2016-04-11 13:16:44 +02:00
Jakub Jelen
f7e56a52db
openssh-7.2p2-2 + 0.10.2-3
2016-04-06 13:01:29 +02:00
Jakub Jelen
fc0cf7f8d5
Fix GSSAPI Key Exchange for older clients ( #1323622 )
...
Failed with older clients, because server was doing signature over
different data than the verifying client. It was caused by bump of
minimal DH groups offered by server and a bug in code, which was
using max(client_min, server_min) instead of client_min as proposed
by RFC4462.
2016-04-06 12:53:37 +02:00
Jakub Jelen
bda184b249
pam_ssh_agent_auth: prevent using MD5 in Fips mode
2016-03-16 09:40:35 +01:00