/[base]/head/crypto/openssh/servconf.c
ViewVC logotype

Log of /head/crypto/openssh/servconf.c

Parent Directory Parent Directory | Revision Log Revision Log


Links to HEAD: (view) (download) (annotate)
Sticky Revision:

Revision 251088 - (view) (download) (annotate) - [select for diffs]
Modified Wed May 29 00:19:58 2013 UTC (9 years, 9 months ago) by des
File length: 62147 byte(s)
Diff to previous 248619
Revert a local change that sets the default for UsePrivilegeSeparation to
"sandbox" instead of "yes".  In sandbox mode, the privsep child is unable
to load additional libraries and will therefore crash when trying to take
advantage of crypto offloading on CPUs that support it.


Revision 248619 - (view) (download) (annotate) - [select for diffs]
Modified Fri Mar 22 17:55:38 2013 UTC (10 years ago) by des
File length: 62140 byte(s)
Diff to previous 240075
Upgrade to OpenSSH 6.2p1.  The most important new features are support
for a key revocation list and more fine-grained authentication control.


Revision 240075 - (view) (download) (annotate) - [select for diffs]
Modified Mon Sep 3 16:51:41 2012 UTC (10 years, 6 months ago) by des
File length: 60055 byte(s)
Diff to previous 231584
Upgrade OpenSSH to 6.1p1.


Revision 231584 - (view) (download) (annotate) - [select for diffs]
Modified Mon Feb 13 11:59:59 2012 UTC (11 years, 1 month ago) by ed
File length: 56256 byte(s)
Diff to previous 226046
Polish diff against upstream.

- Revert unneeded whitespace changes.
- Revert modifications to loginrec.c, as the upstream version already
  does the right thing.
- Fix indentation and whitespace of local changes.

Approved by:	des
MFC after:	1 month


Revision 226046 - (view) (download) (annotate) - [select for diffs]
Modified Wed Oct 5 22:08:17 2011 UTC (11 years, 5 months ago) by des
File length: 56278 byte(s)
Diff to previous 224638
Upgrade to OpenSSH 5.9p1.

MFC after:	3 months


Revision 224638 - (view) (download) (annotate) - [select for diffs]
Modified Wed Aug 3 19:14:22 2011 UTC (11 years, 7 months ago) by brooks
File length: 56170 byte(s)
Diff to previous 221420
Add support for dynamically adjusted buffers to allow the full use of
the bandwidth of long fat pipes (i.e. 100Mbps+ trans-oceanic or
trans-continental links).  Bandwidth-delay products up to 64MB are
supported.

Also add support (not compiled by default) for the None cypher.  The
None cypher can only be enabled on non-interactive sessions (those
without a pty where -T was not used) and must be enabled in both
the client and server configuration files and on the client command
line.  Additionally, the None cypher will only be activated after
authentication is complete.  To enable the None cypher you must add
-DNONE_CIPHER_ENABLED to CFLAGS via the make command line or in
/etc/make.conf.

This code is a style(9) compliant version of these features extracted
from the patches published at:

http://www.psc.edu/networking/projects/hpn-ssh/

Merging this patch has been a collaboration between me and Bjoern.

Reviewed by:	bz
Approved by:	re (kib), des (maintainer)


Revision 221420 - (view) (download) (annotate) - [select for diffs]
Modified Wed May 4 07:34:44 2011 UTC (11 years, 10 months ago) by des
File length: 54350 byte(s)
Diff to previous 215116
Upgrade to OpenSSH 5.8p2.


Revision 215116 - (view) (download) (annotate) - [select for diffs]
Modified Thu Nov 11 11:46:19 2010 UTC (12 years, 4 months ago) by des
File length: 52861 byte(s)
Diff to previous 207319
Upgrade to OpenSSH 5.6p1.


Revision 207319 - (view) (download) (annotate) - [select for diffs]
Modified Wed Apr 28 10:36:33 2010 UTC (12 years, 10 months ago) by des
File length: 52326 byte(s)
Diff to previous 204917
Upgrade to OpenSSH 5.5p1.


Revision 204917 - (view) (download) (annotate) - [select for diffs]
Modified Tue Mar 9 19:16:43 2010 UTC (13 years ago) by des
File length: 52041 byte(s)
Diff to previous 197679
Upgrade to OpenSSH 5.4p1.

MFC after:	1 month


Revision 197679 - (view) (download) (annotate) - [select for diffs]
Modified Thu Oct 1 17:12:52 2009 UTC (13 years, 5 months ago) by des
File length: 50519 byte(s)
Diff to previous 192595
Upgrade to OpenSSH 5.3p1.


Revision 192595 - (view) (download) (annotate) - [select for diffs]
Modified Fri May 22 18:46:28 2009 UTC (13 years, 10 months ago) by des
File length: 50526 byte(s)
Diff to previous 181111
Upgrade to OpenSSH 5.2p1.

MFC after:	3 months


Revision 181111 - (view) (download) (annotate) - [select for diffs]
Modified Fri Aug 1 02:48:36 2008 UTC (14 years, 7 months ago) by des
File length: 49681 byte(s)
Diff to previous 181097
Upgrade to OpenSSH 5.1p1.

I have worked hard to reduce diffs against the vendor branch.  One
notable change in that respect is that we no longer prefer DSA over
RSA - the reasons for doing so went away years ago.  This may cause
some surprises, as ssh will warn about unknown host keys even for
hosts whose keys haven't changed.

MFC after:	6 weeks


Revision 181097 - (view) (download) (annotate) - [select for diffs]
Modified Fri Aug 1 01:13:41 2008 UTC (14 years, 7 months ago) by des
File length: 41805 byte(s)
Diff to previous 162856
Consistently set svn:eol-style.


Revision 162856 - (view) (download) (annotate) - [select for diffs]
Modified Sat Sep 30 13:38:06 2006 UTC (16 years, 5 months ago) by des
File length: 41805 byte(s)
Diff to previous 157019
Merge conflicts.

MFC after:	1 week


Revision 157019 - (view) (download) (annotate) - [select for diffs]
Modified Wed Mar 22 20:41:37 2006 UTC (17 years ago) by des
File length: 32041 byte(s)
Diff to previous 149753
Merge conflicts.


Revision 149753 - (view) (download) (annotate) - [select for diffs]
Modified Sat Sep 3 07:04:25 2005 UTC (17 years, 6 months ago) by des
File length: 31191 byte(s)
Diff to previous 147005
Resolve conflicts.


Revision 147005 - (view) (download) (annotate) - [select for diffs]
Modified Sun Jun 5 15:46:09 2005 UTC (17 years, 9 months ago) by des
File length: 30374 byte(s)
Diff to previous 137019
Resolve conflicts.


Revision 137019 - (view) (download) (annotate) - [select for diffs]
Modified Thu Oct 28 16:11:31 2004 UTC (18 years, 5 months ago) by des
File length: 29713 byte(s)
Diff to previous 126277
Resolve conflicts


Revision 126277 - (view) (download) (annotate) - [select for diffs]
Modified Thu Feb 26 10:52:33 2004 UTC (19 years, 1 month ago) by des
File length: 28373 byte(s)
Diff to previous 126271
Resolve conflicts.


Revision 126271 - (view) (download) (annotate) - [select for diffs]
Modified Thu Feb 26 10:24:07 2004 UTC (19 years, 1 month ago) by des
File length: 27880 byte(s)
Diff to previous 126009
Pull asbesthos underpants on and disable protocol version 1 by default.


Revision 126009 - (view) (download) (annotate) - [select for diffs]
Modified Thu Feb 19 15:53:31 2004 UTC (19 years, 1 month ago) by des
File length: 27892 byte(s)
Diff to previous 124279
Turn non-PAM password authentication off by default when USE_PAM is
defined.  Too many users are getting bitten by it.


Revision 124279 - (view) (download) (annotate) - [select for diffs]
Modified Fri Jan 9 08:07:12 2004 UTC (19 years, 2 months ago) by des
File length: 27824 byte(s)
Diff to previous 124211
Egg on my face: UsePAM was off by default.

Pointed out by:	Sean McNeil <sean@mcneil.com>


Revision 124211 - (view) (download) (annotate) - [select for diffs]
Modified Wed Jan 7 11:16:27 2004 UTC (19 years, 2 months ago) by des
File length: 27824 byte(s)
Diff to previous 113911
Resolve conflicts and remove obsolete files.

Sponsored by:	registrar.no


Revision 113911 - (view) (download) (annotate) - [select for diffs]
Modified Wed Apr 23 17:13:13 2003 UTC (19 years, 11 months ago) by des
File length: 28974 byte(s)
Diff to previous 106130
Resolve conflicts.


Revision 106130 - (view) (download) (annotate) - [select for diffs]
Modified Tue Oct 29 10:16:02 2002 UTC (20 years, 5 months ago) by des
File length: 28921 byte(s)
Diff to previous 99063
Resolve conflicts.


Revision 99063 - (view) (download) (annotate) - [select for diffs]
Modified Sat Jun 29 11:48:59 2002 UTC (20 years, 9 months ago) by des
File length: 28672 byte(s)
Diff to previous 99048
Resolve conflicts.

Sponsored by:	DARPA, NAI Labs


Revision 99048 - (view) (download) (annotate) - [select for diffs]
Modified Sat Jun 29 10:51:56 2002 UTC (20 years, 9 months ago) by des
File length: 28670 byte(s)
Diff to previous 99047
Apply FreeBSD's configuration defaults.

Sponsored by:	DARPA, NAI Labs


Revision 99047 - (view) (download) (annotate) - [select for diffs]
Modified Sat Jun 29 10:49:57 2002 UTC (20 years, 9 months ago) by des
File length: 28242 byte(s)
Diff to previous 98941
Add the VersionAddendum configuration variable.

Sponsored by:	DARPA, NAI Labs


Revision 98941 - (view) (download) (annotate) - [select for diffs]
Modified Thu Jun 27 22:42:11 2002 UTC (20 years, 9 months ago) by des
File length: 27966 byte(s)
Diff to previous 98684
Forcibly revert to mainline.


Revision 98684 - (view) (download) (annotate) - [select for diffs]
Modified Sun Jun 23 16:09:08 2002 UTC (20 years, 9 months ago) by des
File length: 27658 byte(s)
Diff to previous 95456
Resolve conflicts.  Known issues:

 - sshd fails to set TERM correctly.
 - privilege separation may break PAM and is currently turned off.
 - man pages have not yet been updated

I will have these issues resolved, and privilege separation turned on by
default, in time for DP2.

Sponsored by:	DARPA, NAI Labs


Revision 95456 - (view) (download) (annotate) - [select for diffs]
Modified Thu Apr 25 16:53:25 2002 UTC (20 years, 11 months ago) by des
File length: 27077 byte(s)
Diff to previous 95431
Back out previous commit.


Revision 95431 - (view) (download) (annotate) - [select for diffs]
Modified Thu Apr 25 05:59:53 2002 UTC (20 years, 11 months ago) by jkh
File length: 27077 byte(s)
Diff to previous 95119
Change default challenge/response behavior of sshd by popular demand.
This brings us into sync with the behavior of sshd on other Unix platforms.

Submitted by:	Joshua Goodall <joshua@roughtrade.net>


Revision 95119 - (view) (download) (annotate) - [select for diffs]
Modified Sat Apr 20 09:26:43 2002 UTC (20 years, 11 months ago) by ache
File length: 27077 byte(s)
Diff to previous 94511
1) Surprisingly, "CheckMail" handling code completely removed from this
version, so documented "CheckMail" option exists but does nothing.
Bring it back to life adding code back.

2) Cosmetique. Reduce number of args in do_setusercontext()


Revision 94511 - (view) (download) (annotate) - [select for diffs]
Modified Fri Apr 12 15:52:10 2002 UTC (20 years, 11 months ago) by des
File length: 27050 byte(s)
Diff to previous 94464
Back out previous backout.  It seems I was right to begin with, and DSA is
preferrable to RSA (not least because the SECSH draft standard requires
DSA while RSA is only recommended).


Revision 94464 - (view) (download) (annotate) - [select for diffs]
Modified Thu Apr 11 22:04:40 2002 UTC (20 years, 11 months ago) by des
File length: 27142 byte(s)
Diff to previous 94438
Knowledgeable persons assure me that RSA is preferable to DSA and that we
should transition away from DSA.


Revision 94438 - (view) (download) (annotate) - [select for diffs]
Modified Thu Apr 11 16:08:02 2002 UTC (20 years, 11 months ago) by des
File length: 27050 byte(s)
Diff to previous 93216
Do not attempt to load an ssh2 RSA host key by default.


Revision 93216 - (view) (download) (annotate) - [select for diffs]
Modified Tue Mar 26 12:27:43 2002 UTC (21 years ago) by nectar
File length: 27142 byte(s)
Diff to previous 93155
REALLY correct typo this time.

Noticed by:	roam


Revision 93155 - (view) (download) (annotate) - [select for diffs]
Modified Mon Mar 25 14:55:41 2002 UTC (21 years ago) by nectar
File length: 27142 byte(s)
Diff to previous 92708
Fix typo (missing paren) affecting KRB4 && KRB5 case.

Approved by:	des


Revision 92708 - (view) (download) (annotate) - [select for diffs]
Modified Tue Mar 19 16:44:11 2002 UTC (21 years ago) by des
File length: 27141 byte(s)
Diff to previous 92559
Unbreak for KRB4 ^ KRB5 case.

Sponsored by:	DARPA, NAI Labs


Revision 92559 - (view) (download) (annotate) - [select for diffs]
Modified Mon Mar 18 10:09:43 2002 UTC (21 years ago) by des
File length: 26744 byte(s)
Diff to previous 76262
Fix conflicts.


Revision 76262 - (view) (download) (annotate) - [select for diffs]
Modified Fri May 4 04:14:23 2001 UTC (21 years, 10 months ago) by green
File length: 25873 byte(s)
Diff to previous 76227
Fix conflicts for OpenSSH 2.9.


Revision 76227 - (view) (download) (annotate) - [select for diffs]
Modified Thu May 3 00:29:28 2001 UTC (21 years, 10 months ago) by green
File length: 21827 byte(s)
Diff to previous 73400
Add a "VersionAddendum" configuration setting for sshd which allows
anyone to easily change the part of the OpenSSH version after the main
version number.  The FreeBSD-specific version banner could be disabled
that way, for example:

# Call ourselves plain OpenSSH
VersionAddendum


Revision 73400 - (view) (download) (annotate) - [select for diffs]
Modified Sun Mar 4 02:22:04 2001 UTC (22 years ago) by assar
File length: 21613 byte(s)
Diff to previous 72586
Add code for being compatible with ssh.com's krb5 authentication.
It is done by using the same ssh messages for v4 and v5 authentication
(since the ssh.com does not now anything about v4) and looking at the
contents after unpacking it to see if it is v4 or v5.
Based on code from Björn Grönvall <bg@sics.se>

PR:		misc/20504


Revision 72586 - (view) (download) (annotate) - [select for diffs]
Modified Sun Feb 18 01:33:31 2001 UTC (22 years, 1 month ago) by ps
File length: 21338 byte(s)
Diff to previous 72020
Make ConnectionsPerPeriod non-fatal for real.


Revision 72020 - (view) (download) (annotate) - [select for diffs]
Modified Sun Feb 4 20:15:53 2001 UTC (22 years, 1 month ago) by green
File length: 21314 byte(s)
Diff to previous 70990
MFF: Make ConnectionsPerPeriod usage a warning, not fatal.


Revision 70990 - (view) (download) (annotate) - [select for diffs]
Modified Sat Jan 13 07:57:43 2001 UTC (22 years, 2 months ago) by green
File length: 21314 byte(s)
Diff to previous 69591
/Really/ deprecate ConnectionsPerPeriod, ripping out the code for it
and giving a dire error to its lingering users.


Revision 69591 - (view) (download) (annotate) - [select for diffs]
Modified Tue Dec 5 02:55:12 2000 UTC (22 years, 3 months ago) by green
File length: 21760 byte(s)
Diff to previous 65674
Update to OpenSSH 2.3.0 with FreeBSD modifications.  OpenSSH 2.3.0
new features description elided in favor of checking out their
website.

Important new FreeBSD-version stuff: PAM support has been worked
in, partially from the "Unix" OpenSSH version, and a lot due to the
work of Eivind Eklend, too.

This requires at least the following in pam.conf:

sshd    auth    sufficient      pam_skey.so
sshd    auth    required        pam_unix.so                     try_first_pass
sshd    session required        pam_permit.so

Parts by:	Eivind Eklend <eivind@FreeBSD.org>


Revision 65674 - (view) (download) (annotate) - [select for diffs]
Modified Sun Sep 10 09:35:38 2000 UTC (22 years, 6 months ago) by kris
File length: 21124 byte(s)
Diff to previous 65357
Resolve conflicts and update for OpenSSH 2.2.0

Reviewed by:	gshapiro, peter, green


Revision 65357 - (view) (download) (annotate) - [select for diffs]
Modified Sat Sep 2 03:49:22 2000 UTC (22 years, 6 months ago) by kris
File length: 18753 byte(s)
Diff to previous 65022
Turn on X11Forwarding by default on the server. Any risk is to the client,
where it is already disabled by default.

Reminded by:	peter


Revision 65022 - (view) (download) (annotate) - [select for diffs]
Modified Wed Aug 23 09:47:25 2000 UTC (22 years, 7 months ago) by kris
File length: 18753 byte(s)
Diff to previous 63249
Increase the default value of LoginGraceTime from 60 seconds to 120
seconds.

PR:		20488
Submitted by:	rwatson


Revision 63249 - (view) (download) (annotate) - [select for diffs]
Modified Sun Jul 16 05:53:14 2000 UTC (22 years, 8 months ago) by peter
File length: 18752 byte(s)
Diff to previous 62944
Forced commit.  This is to try and help folks that used the international
crypto repo and have slightly different files but with the same version.
cvsup in 'checkout mode' has no trouble with this, but cvs can get really
silly about it.


Revision 62944 - (view) (download) (annotate) - [select for diffs]
Modified Tue Jul 11 09:54:24 2000 UTC (22 years, 8 months ago) by peter
File length: 18752 byte(s)
Diff to previous 62943
Sync sshd_config with sshd and manapage internal defaults (Checkmail = yes)


Revision 62943 - (view) (download) (annotate) - [select for diffs]
Modified Tue Jul 11 09:52:14 2000 UTC (22 years, 8 months ago) by peter
File length: 18752 byte(s)
Diff to previous 62942
Sync LoginGraceTime with sshd_config = 60 seconds by default, not 600.


Revision 62942 - (view) (download) (annotate) - [select for diffs]
Modified Tue Jul 11 09:50:15 2000 UTC (22 years, 8 months ago) by peter
File length: 18753 byte(s)
Diff to previous 61320
Fix out-of-sync defaults.  PermitRootLogin is supposed to be 'no' but
sshd's internal default was 'yes'.  (if some cracker managed to trash
/etc/ssh/sshd_config, then root logins could be reactivated)

Approved by: kris


Revision 61320 - (view) (download) (annotate) - [select for diffs]
Modified Tue Jun 6 06:16:55 2000 UTC (22 years, 9 months ago) by green
File length: 18754 byte(s)
Diff to previous 61212
Allow "DenyUsers" to function.


Revision 61212 - (view) (download) (annotate) - [select for diffs]
Modified Sat Jun 3 09:58:15 2000 UTC (22 years, 9 months ago) by kris
File length: 18703 byte(s)
Diff to previous 60576
Resolve conflicts


Revision 60576 - (view) (download) (annotate) - [select for diffs]
Modified Mon May 15 05:24:25 2000 UTC (22 years, 10 months ago) by kris
File length: 18553 byte(s)
Diff to previous 58585
Resolve conflicts and update for FreeBSD.


Revision 58585 - (view) (download) (annotate) - [select for diffs]
Modified Sun Mar 26 07:37:48 2000 UTC (23 years ago) by kris
File length: 16592 byte(s)
Diff to previous 58463
Resolve conflicts.


Revision 58463 - (view) (download) (annotate) - [select for diffs]
Modified Wed Mar 22 09:36:35 2000 UTC (23 years ago) by sheldonh
File length: 16592 byte(s)
Diff to previous 57565
IgnoreUserKnownHosts is a boolean flag, not an integer value.

The fix submitted in the attributed PR is identical to the one
adopted by OpenBSD.

PR:		17027
Submitted by:	David Malone <dwmalone@maths.tcd.ie>
Obtained from:	OpenBSD


Revision 57565 - (view) (download) (annotate) - [select for diffs]
Modified Mon Feb 28 19:03:50 2000 UTC (23 years, 1 month ago) by markm
File length: 16591 byte(s)
Diff to previous 57432
1) Add kerberos5 functionality.
   by Daniel Kouril <kouril@informatics.muni.cz>
2) Add full LOGIN_CAP capability
   by Andrey Chernov


Revision 57432 - (view) (download) (annotate) - [select for diffs]
Modified Thu Feb 24 15:29:42 2000 UTC (23 years, 1 month ago) by markm
File length: 16010 byte(s)
Diff to previous 57430
Add the patches fom ports (QV: ports/security/openssh/patches/patch-*)


Revision 57430 - (view) (download) (annotate) - [select for diffs]
Modified Thu Feb 24 14:29:47 2000 UTC (23 years, 1 month ago) by markm
File length: 15334 byte(s)
Copied from: vendor-crypto/openssh/dist/crypto/openssh/servconf.c revision 57429
Diff to previous 57429
This commit was generated by cvs2svn to compensate for changes in r57429,
which included commits to RCS files with non-trunk default branches.


Revision 57429 - (view) (download) (annotate) - [select for diffs]
Added Thu Feb 24 14:29:47 2000 UTC (23 years, 1 month ago) by markm
Original Path: vendor-crypto/openssh/dist/crypto/openssh/servconf.c
File length: 15334 byte(s)
Vendor import of OpenSSH.


This form allows you to request diffs between any two revisions of this file. For each of the two "sides" of the diff, enter a numeric revision.

  Diffs between and
  Type of Diff should be a

  ViewVC Help
Powered by ViewVC 1.1.27