Secure Shell Client and Server (Remote Login Program)

Edit Package openssh

Devel package for openssh

Refresh
Refresh
Source Files
Filename Size Changed
README.FIPS 0000003276 3.2 KB
README.SUSE 0000001036 1.01 KB
README.kerberos 0000000528 528 Bytes
cavs_driver-ssh.pl 0000005408 5.28 KB
openssh-7.7p1-IPv6_X_forwarding.patch 0000001700 1.66 KB
openssh-7.7p1-X11_trusted_forwarding.patch 0000001739 1.7 KB
openssh-7.7p1-X_forward_with_disabled_ipv6.patch 0000000803 803 Bytes
openssh-7.7p1-allow_root_password_login.patch 0000002161 2.11 KB
openssh-7.7p1-cavstest-ctr.patch 0000007984 7.8 KB
openssh-7.7p1-cavstest-kdf.patch 0000014383 14 KB
openssh-7.7p1-disable_openssl_abi_check.patch 0000001421 1.39 KB
openssh-7.7p1-eal3.patch 0000001285 1.25 KB
openssh-7.7p1-enable_PAM_by_default.patch 0000001065 1.04 KB
openssh-7.7p1-fips.patch 0000024710 24.1 KB
openssh-7.7p1-fips_checks.patch 0000011686 11.4 KB
openssh-7.7p1-host_ident.patch 0000001104 1.08 KB
openssh-7.7p1-hostname_changes_when_forwarding_X.patch 0000002595 2.53 KB
openssh-7.7p1-ldap.patch 0000086133 84.1 KB
openssh-7.7p1-no_fork-no_pid_file.patch 0000000578 578 Bytes
openssh-7.7p1-pam_check_locks.patch 0000004797 4.68 KB
openssh-7.7p1-pts_names_formatting.patch 0000001499 1.46 KB
openssh-7.7p1-remove_xauth_cookies_on_exit.patch 0000001495 1.46 KB
openssh-7.7p1-seccomp_ipc_flock.patch 0000001431 1.4 KB
openssh-7.7p1-seccomp_stat.patch 0000000801 801 Bytes
openssh-7.7p1-send_locale.patch 0000001933 1.89 KB
openssh-7.7p1-sftp_force_permissions.patch 0000004188 4.09 KB
openssh-7.7p1-sftp_print_diagnostic_messages.patch 0000001777 1.74 KB
openssh-7.7p1-systemd-notify.patch 0000002569 2.51 KB
openssh-7.9p1-keygen-preserve-perms.patch 0000001268 1.24 KB
openssh-7.9p1-revert-new-qos-defaults.patch 0000002767 2.7 KB
openssh-8.0p1-gssapi-keyex.patch 0000123410 121 KB
openssh-8.1p1-audit.patch 0000071255 69.6 KB
openssh-8.1p1-ed25519-use-openssl-rng.patch 0000001840 1.8 KB
openssh-8.1p1-seccomp-clock_gettime64.patch 0000000811 811 Bytes
openssh-8.1p1-seccomp-clock_nanosleep.patch 0000000435 435 Bytes
openssh-8.1p1-seccomp-clock_nanosleep_time64.patch 0000000837 837 Bytes
openssh-8.1p1-use-openssl-kdf.patch 0000003818 3.73 KB
openssh-8.4p1.tar.gz 0001742201 1.66 MB
openssh-8.4p1.tar.gz.asc 0000000683 683 Bytes
openssh-askpass-gnome.changes 0000011210 10.9 KB
openssh-askpass-gnome.spec 0000002134 2.08 KB
openssh-fips-ensure-approved-moduli.patch 0000001739 1.7 KB
openssh.changes 0000200236 196 KB
openssh.keyring 0000013442 13.1 KB
openssh.spec 0000018088 17.7 KB
ssh-askpass 0000000479 479 Bytes
ssh.reg 0000000500 500 Bytes
sshd-gen-keys-start 0000000153 153 Bytes
sshd.fw 0000000135 135 Bytes
sshd.pamd 0000000404 404 Bytes
sshd.service 0000000394 394 Bytes
sysconfig.ssh 0000000221 221 Bytes
Revision 222 (latest revision is 268)
Hans Petter Jansson's avatar Hans Petter Jansson (hpjansson) accepted request 863944 from Dirk Mueller's avatar Dirk Mueller (dirkmueller) (revision 222)
- update to 8.4p1:
  Security
  ========
 * ssh-agent(1): restrict ssh-agent from signing web challenges for
   FIDO/U2F keys.
 * ssh-keygen(1): Enable FIDO 2.1 credProtect extension when generating
   a FIDO resident key.
 * ssh(1), ssh-keygen(1): support for FIDO keys that require a PIN for
   each use. These keys may be generated using ssh-keygen using a new
   "verify-required" option. When a PIN-required key is used, the user
   will be prompted for a PIN to complete the signature operation.
  New Features
  ------------
 * sshd(8): authorized_keys now supports a new "verify-required"
   option to require FIDO signatures assert that the token verified
   that the user was present before making the signature. The FIDO
   protocol supports multiple methods for user-verification, but
   currently OpenSSH only supports PIN verification.
 * sshd(8), ssh-keygen(1): add support for verifying FIDO webauthn
   signatures. Webauthn is a standard for using FIDO keys in web
   browsers. These signatures are a slightly different format to plain
   FIDO signatures and thus require explicit support.
 * ssh(1): allow some keywords to expand shell-style ${ENV}
   environment variables. The supported keywords are CertificateFile,
   ControlPath, IdentityAgent and IdentityFile, plus LocalForward and
   RemoteForward when used for Unix domain socket paths. bz#3140
 * ssh(1), ssh-agent(1): allow some additional control over the use of
   ssh-askpass via a new $SSH_ASKPASS_REQUIRE environment variable,
   including forcibly enabling and disabling its use. bz#69
 * ssh(1): allow ssh_config(5)'s AddKeysToAgent keyword accept a time
Comments 1

John Doe's avatar

Can you upgrade to 9.6?

openSUSE Build Service is sponsored by