Secure Shell Client and Server (Remote Login Program)

Edit Package openssh

Devel package for openssh

Refresh
Refresh
Source Files
Filename Size Changed
README.FIPS 0000003276 3.2 KB
README.SUSE 0000000690 690 Bytes
README.kerberos 0000000528 528 Bytes
cavs_driver-ssh.pl 0000005408 5.28 KB
openssh-7.7p1-IPv6_X_forwarding.patch 0000001228 1.2 KB
openssh-7.7p1-X11_trusted_forwarding.patch 0000001739 1.7 KB
openssh-7.7p1-X_forward_with_disabled_ipv6.patch 0000000829 829 Bytes
openssh-7.7p1-cavstest-ctr.patch 0000007984 7.8 KB
openssh-7.7p1-cavstest-kdf.patch 0000014404 14.1 KB
openssh-7.7p1-disable_openssl_abi_check.patch 0000001544 1.51 KB
openssh-7.7p1-eal3.patch 0000000845 845 Bytes
openssh-7.7p1-enable_PAM_by_default.patch 0000000681 681 Bytes
openssh-7.7p1-fips.patch 0000024472 23.9 KB
openssh-7.7p1-fips_checks.patch 0000011794 11.5 KB
openssh-7.7p1-host_ident.patch 0000000774 774 Bytes
openssh-7.7p1-hostname_changes_when_forwarding_X.patch 0000002583 2.52 KB
openssh-7.7p1-ldap.patch 0000086759 84.7 KB
openssh-7.7p1-no_fork-no_pid_file.patch 0000000644 644 Bytes
openssh-7.7p1-pam_check_locks.patch 0000004810 4.7 KB
openssh-7.7p1-pts_names_formatting.patch 0000001043 1.02 KB
openssh-7.7p1-remove_xauth_cookies_on_exit.patch 0000001294 1.26 KB
openssh-7.7p1-seccomp_ipc_flock.patch 0000001431 1.4 KB
openssh-7.7p1-seccomp_stat.patch 0000000610 610 Bytes
openssh-7.7p1-send_locale.patch 0000001404 1.37 KB
openssh-7.7p1-sftp_force_permissions.patch 0000004188 4.09 KB
openssh-7.7p1-sftp_print_diagnostic_messages.patch 0000001776 1.73 KB
openssh-7.7p1-systemd-notify.patch 0000002569 2.51 KB
openssh-7.9p1-keygen-preserve-perms.patch 0000001304 1.27 KB
openssh-7.9p1-revert-new-qos-defaults.patch 0000002921 2.85 KB
openssh-8.0p1-gssapi-keyex.patch 0000124024 121 KB
openssh-8.1p1-audit.patch 0000070750 69.1 KB
openssh-8.1p1-ed25519-use-openssl-rng.patch 0000001840 1.8 KB
openssh-8.1p1-seccomp-clock_gettime64.patch 0000000844 844 Bytes
openssh-8.1p1-seccomp-clock_nanosleep.patch 0000000472 472 Bytes
openssh-8.1p1-seccomp-clock_nanosleep_time64.patch 0000000837 837 Bytes
openssh-8.1p1-use-openssl-kdf.patch 0000003878 3.79 KB
openssh-8.4p1-pam_motd.patch 0000000843 843 Bytes
openssh-8.4p1-ssh_config_d.patch 0000001291 1.26 KB
openssh-8.4p1-vendordir.patch 0000007113 6.95 KB
openssh-8.9p1.tar.gz 0001820282 1.74 MB
openssh-8.9p1.tar.gz.asc 0000000833 833 Bytes
openssh-askpass-gnome.changes 0000011444 11.2 KB
openssh-askpass-gnome.spec 0000002134 2.08 KB
openssh-fips-ensure-approved-moduli.patch 0000001788 1.75 KB
openssh-reenable-dh-group14-sha1-default.patch 0000001502 1.47 KB
openssh-whitelist-syscalls.patch 0000000927 927 Bytes
openssh.changes 0000232360 227 KB
openssh.keyring 0000022720 22.2 KB
openssh.spec 0000018516 18.1 KB
ssh-askpass 0000000479 479 Bytes
ssh.reg 0000000500 500 Bytes
sshd-gen-keys-start 0000000225 225 Bytes
sshd.fw 0000000135 135 Bytes
sshd.pamd 0000000425 425 Bytes
sshd.service 0000000394 394 Bytes
sysconfig.ssh 0000000221 221 Bytes
sysusers-sshd.conf 0000000064 64 Bytes
Revision 237 (latest revision is 268)
Dirk Mueller's avatar Dirk Mueller (dirkmueller) accepted request 960041 from Hans Petter Jansson's avatar Hans Petter Jansson (hpjansson) (revision 237)
- Version update to 8.9p1:
  = Security
  * sshd(8): fix an integer overflow in the user authentication path
    that, in conjunction with other logic errors, could have yielded
    unauthenticated access under difficult to exploit conditions.
    This situation is not exploitable because of independent checks in
    the privilege separation monitor. Privilege separation has been
    enabled by default in since openssh-3.2.2 (released in 2002) and
    has been mandatory since openssh-7.5 (released in 2017). Moreover,
    portable OpenSSH has used toolchain features available in most
    modern compilers to abort on signed integer overflow since
    openssh-6.5 (released in 2014).
    Thanks to Malcolm Stagg for finding and reporting this bug.
  = Potentially-incompatible changes
  * sshd(8), portable OpenSSH only: this release removes in-built
    support for MD5-hashed passwords. If you require these on your
    system then we recommend linking against libxcrypt or similar.
  * This release modifies the FIDO security key middleware interface
    and increments SSH_SK_VERSION_MAJOR.
  = New features
  * ssh(1), sshd(8), ssh-add(1), ssh-agent(1): add a system for
    restricting forwarding and use of keys added to ssh-agent(1)
    A detailed description of the feature is available at
    https://www.openssh.com/agent-restrict.html and the protocol
    extensions are documented in the PROTOCOL and PROTOCOL.agent
    files in the source release.
  * ssh(1), sshd(8): add the sntrup761x25519-sha512@openssh.com hybrid
    ECDH/x25519 + Streamlined NTRU Prime post-quantum KEX to the
    default KEXAlgorithms list (after the ECDH methods but before the
    prime-group DH ones). The next release of OpenSSH is likely to
    make this key exchange the default method.
  * ssh-keygen(1): when downloading resident keys from a FIDO token,
    pass back the user ID that was used when the key was created and
    append it to the filename the key is written to (if it is not the
    default). Avoids keys being clobbered if the user created multiple
    resident keys with the same application string but different user
    IDs.
  * ssh-keygen(1), ssh(1), ssh-agent(1): better handling for FIDO keys
    on tokens that provide user verification (UV) on the device itself,
    including biometric keys, avoiding unnecessary PIN prompts.
  * ssh-keygen(1): add "ssh-keygen -Y match-principals" operation to
    perform matching of principals names against an allowed signers
    file. To be used towards a TOFU model for SSH signatures in git.
  * ssh-add(1), ssh-agent(1): allow pin-required FIDO keys to be added
    to ssh-agent(1). $SSH_ASKPASS will be used to request the PIN at
    authentication time.
  * ssh-keygen(1): allow selection of hash at sshsig signing time
    (either sha512 (default) or sha256).
  * ssh(1), sshd(8): read network data directly to the packet input
    buffer instead of indirectly via a small stack buffer. Provides a
    modest performance improvement.
  * ssh(1), sshd(8): read data directly to the channel input buffer,
    providing a similar modest performance improvement.
  * ssh(1): extend the PubkeyAuthentication configuration directive to
    accept yes|no|unbound|host-bound to allow control over one of the
    protocol extensions used to implement agent-restricted keys.
  = Bugfixes
  * sshd(8): document that CASignatureAlgorithms, ExposeAuthInfo and
    PubkeyAuthOptions can be used in a Match block. PR277.
  * sshd(8): fix possible string truncation when constructing paths to
    .rhosts/.shosts files with very long user home directory names.
  * ssh-keysign(1): unbreak for KEX algorithms that use SHA384/512
    exchange hashes
  * ssh(1): don't put the TTY into raw mode when SessionType=none,
    avoids ^C being unable to kill such a session. bz3360
  * scp(1): fix some corner-case bugs in SFTP-mode handling of
    ~-prefixed paths.
  * ssh(1): unbreak hostbased auth using RSA keys. Allow ssh(1) to
    select RSA keys when only RSA/SHA2 signature algorithms are
    configured (this is the default case). Previously RSA keys were
    not being considered in the default case.
  * ssh-keysign(1): make ssh-keysign use the requested signature
    algorithm and not the default for the key type. Part of unbreaking
    hostbased auth for RSA/SHA2 keys.
  * ssh(1): stricter UpdateHostkey signature verification logic on
    the client- side. Require RSA/SHA2 signatures for RSA hostkeys
    except when RSA/SHA1 was explicitly negotiated during initial
    KEX; bz3375
  * ssh(1), sshd(8): fix signature algorithm selection logic for
    UpdateHostkeys on the server side. The previous code tried to
    prefer RSA/SHA2 for hostkey proofs of RSA keys, but missed some
    cases. This will use RSA/SHA2 signatures for RSA keys if the
    client proposed these algorithms in initial KEX. bz3375
  * All: convert all uses of select(2)/pselect(2) to poll(2)/ppoll(2).
    This includes the mainloops in ssh(1), ssh-agent(1), ssh-agent(1)
    and sftp-server(8), as well as the sshd(8) listen loop and all
    other FD read/writability checks. On platforms with missing or
    broken poll(2)/ppoll(2) syscalls a select(2)-based compat shim is
    available.
  * ssh-keygen(1): the "-Y find-principals" command was verifying key
    validity when using ca certs but not with simple key lifetimes
    within the allowed signers file.
  * ssh-keygen(1): make sshsig verify-time argument parsing optional
  * sshd(8): fix truncation in rhosts/shosts path construction.
  * ssh(1), ssh-agent(1): avoid xmalloc(0) for PKCS#11 keyid for ECDSA
    keys (we already did this for RSA keys). Avoids fatal errors for
    PKCS#11 libraries that return empty keyid, e.g. Microchip ATECC608B
    "cryptoauthlib"; bz#3364
  * ssh(1), ssh-agent(1): improve the testing of credentials against
    inserted FIDO: ask the token whether a particular key belongs to
    it in cases where the token supports on-token user-verification
    (e.g. biometrics) rather than just assuming that it will accept it.
    Will reduce spurious "Confirm user presence" notifications for key
    handles that relate to FIDO keys that are not currently inserted in at
    least some cases. bz3366
  * ssh(1), sshd(8): correct value for IPTOS_DSCP_LE. It needs to
    allow for the preceding two ECN bits. bz#3373
  * ssh-keygen(1): add missing -O option to usage() for the "-Y sign"
    option.
  * ssh-keygen(1): fix a NULL deref when using the find-principals
    function, when matching an allowed_signers line that contains a
    namespace restriction, but no restriction specified on the
    command-line
  * ssh-agent(1): fix memleak in process_extension(); oss-fuzz
    issue #42719
  * ssh(1): suppress "Connection to xxx closed" messages when LogLevel
    is set to "error" or above. bz3378
  * ssh(1), sshd(8): use correct zlib flags when inflate(3)-ing
    compressed packet data. bz3372
  * scp(1): when recursively transferring files in SFTP mode, create the
    destination directory if it doesn't already exist to match scp(1) in
    legacy RCP mode behaviour.
  * scp(1): many improvements in error message consistency between scp(1)
    in SFTP mode vs legacy RCP mode.
  * sshd(8): fix potential race in SIGTERM handling PR289
  * ssh(1), ssh(8): since DSA keys are deprecated, move them to the
    end of the default list of public keys so that they will be tried
    last. PR295
  * ssh-keygen(1): allow 'ssh-keygen -Y find-principals' to match
    wildcard principals in allowed_signers files
  = Portability
  * ssh(1), sshd(8): don't trust closefrom(2) on Linux. glibc's
    implementation does not work in a chroot when the kernel does not
    have close_range(2). It tries to read from /proc/self/fd and when
    that fails dies with an assertion of sorts. Instead, call
    close_range(2) directly from our compat code and fall back if
    that fails.  bz#3349,
  * OS X poll(2) is broken; use compat replacement. For character-
    special devices like /dev/null, Darwin's poll(2) returns POLLNVAL
    when polled with POLLIN. Apparently this is Apple bug 3710161 -
    not public but a websearch will find other OSS projects
    rediscovering it periodically since it was first identified in
    2005.
  * Correct handling of exceptfds/POLLPRI in our select(2)-based
    poll(2)/ppoll(2) compat implementation.
  * Cygwin: correct checking of mbstowcs() return value.
  * Add a basic SECURITY.md that refers people to the openssh.com
    website.
  * Enable additional compiler warnings and toolchain hardening flags,
    including -Wbitwise-instead-of-logical, -Wmisleading-indentation,
    -fzero-call-used-regs and -ftrivial-auto-var-init.
  * HP/UX. Use compat getline(3) on HP-UX 10.x, where the libc version
    is not reliable.
- Rebased patches:
  * openssh-7.7p1-ldap.patch
  * openssh-8.0p1-gssapi-keyex.patch
  * openssh-8.1p1-audit.patch
  * openssh-8.4p1-vendordir.patch
  * openssh-reenable-dh-group14-sha1-default.patch
Comments 1

John Doe's avatar

Can you upgrade to 9.6?

openSUSE Build Service is sponsored by