summaryrefslogtreecommitdiffstats
path: root/authfd.h (unfollow)
Commit message (Collapse)AuthorFilesLines
2007-06-12 - markus@cvs.openbsd.org 2007/06/11 09:14:00Darren Tucker2-4/+10
[channels.h] increase default channel windows; ok djm
2007-06-11 - markus@cvs.openbsd.org 2007/06/11 08:04:44Damien Miller2-3/+9
[channels.c] send 'window adjust' messages every tree packets and do not wait until 50% of the window is consumed. ok djm dtucker
2007-06-11 - (dtucker) [includes.h] Bug #1243: HAVE_PATHS -> HAVE_PATHS_H. ShouldDarren Tucker2-2/+5
prevent warnings about redefinitions of various things in paths.h. Spotted by cartmanltd at hotmail.com.
2007-06-11 - (dtucker) [openbsd-compat/bsd-misc.c] According to the spec the "remainder"Darren Tucker2-2/+6
argument to nanosleep may be NULL. Currently this never happens in OpenSSH, but check anyway in case this changes or the code gets used elsewhere.
2007-06-11 - (djm) [configure.ac umac.c] If platform doesn't provide swap32(3), thenDamien Miller3-10/+12
fallback to provided bit-swizzing functions
2007-06-11 - jmc@cvs.openbsd.org 2007/06/08 07:48:09Damien Miller2-4/+11
[sshd_config.5] oops, here too: put the MAC list into a display, like we do for ciphers, since groff has trouble with wide lines;
2007-06-11 - jmc@cvs.openbsd.org 2007/06/08 07:43:46Damien Miller2-4/+11
[ssh_config.5] put the MAC list into a display, like we do for ciphers, since groff has trouble handling wide lines;
2007-06-11 - pvalchev@cvs.openbsd.org 2007/06/08 04:40:40Damien Miller2-2/+9
[ssh_config] Add a "MACs" line after "Ciphers" with the default MAC algorithms, to ease people who want to tweak both (eg. for performance reasons). ok deraadt@ djm@ dtucker@
2007-06-11 - pvalchev@cvs.openbsd.org 2007/06/07 19:37:34Damien Miller14-58/+1512
[kex.h mac.c mac.h monitor_wrap.c myproposal.h packet.c ssh.1] [ssh_config.5 sshd.8 sshd_config.5] Add a new MAC algorithm for data integrity, UMAC-64 (not default yet, must specify umac-64@openssh.com). Provides about 20% end-to-end speedup compared to hmac-md5. Represents a different approach to message authentication to that of HMAC that may be beneficial if HMAC based on one of its underlying hash algorithms is found to be vulnerable to a new attack. http://www.ietf.org/rfc/rfc4418.txt in conjunction with and OK djm@
2007-06-11 - (djm) Bugzilla #1306: silence spurious error messages from hang-on-exitDamien Miller2-6/+9
fix; tested by dtucker@ and jochen.kirn AT gmail.com
2007-06-11spacingDamien Miller1-2/+3
2007-06-05 - (dtucker) [mdoc2man.awk] Add support for %R references, used for RFCs.Darren Tucker2-3/+11
2007-06-05 - (dtucker) [mdoc2man.awk] Remove trailing "$" from Mdocdate regex soDarren Tucker2-3/+5
mindrot's cvs doesn't expand it on us.
2007-06-05 - (dtucker) [mdoc2man.awk] Teach it to deal with $Mdocdate tags thatDarren Tucker2-1/+12
OpenBSD's cvs now adds.
2007-06-05 - djm@cvs.openbsd.org 2007/06/05 06:52:37Darren Tucker7-25/+49
[kex.c monitor_wrap.c packet.c mac.h kex.h mac.c] Preserve MAC ctx between packets, saving 2xhash calls per-packet. Yields around a 12-16% end-to-end speedup for arcfour256/hmac-md5 patch from markus@ tested dtucker@ and myself, ok markus@ and me (I'm committing at his request)
2007-06-05 - djm@cvs.openbsd.org 2007/06/02 09:04:58Darren Tucker2-3/+8
[bufbn.c] memory leak on error path; from arnaud.lacombe.1 AT ulaval.ca
2007-06-05 - djm@cvs.openbsd.org 2007/05/31 23:34:29Darren Tucker2-3/+5
[packet.c] gc unreachable code; spotted by Tavis Ormandy
2007-06-05 - jmc@cvs.openbsd.org 2007/05/31 19:20:16Darren Tucker13-25/+30
[scp.1 ssh_config.5 sftp-server.8 ssh-agent.1 sshd_config.5 sftp.1 ssh-keygen.1 ssh-keyscan.1 ssh-add.1 sshd.8 ssh.1 ssh-keysign.8] convert to new .Dd format; (We will need to teach mdoc2man.awk to understand this too.)
2007-06-05 - djm@cvs.openbsd.org 2007/05/30 05:58:13Darren Tucker2-8/+16
[kex.c] tidy: KNF, ARGSUSED and u_int
2007-06-05 - djm@cvs.openbsd.org 2007/05/22 10:18:52Darren Tucker2-2/+9
[sshd.c] zap double include; from p_nowaczyk AT o2.pl (not required in -portable, Id sync only)
2007-05-20 - (dtucker) [auth-pam.c] Return empty string if fgets fails inDarren Tucker2-2/+5
sshpam_tty_conv. Patch from ldv at altlinux.org.
2007-05-20 - (dtucker) [auth-pam.c] malloc+memset -> calloc. Patch fromDarren Tucker2-5/+5
ldv at altlinux.org.
2007-05-20 - jolan@cvs.openbsd.org 2007/05/17 23:53:41Darren Tucker2-2/+6
[sshconnect2.c] djm owes me a vb and a tism cd for breaking ssh compilation
2007-05-20 - djm@cvs.openbsd.org 2007/05/17 20:52:13Darren Tucker2-2/+8
[monitor.c] pass received SIGINT from monitor to postauth child so it can clean up properly. bz#1196, patch from senthilkumar_sen AT hotpop.com; ok markus@
2007-05-20 - djm@cvs.openbsd.org 2007/05/17 20:48:13Darren Tucker2-4/+19
[sshconnect2.c] fall back to gethostname() when the outgoing connection is not on a socket, such as is the case when ProxyCommand is used. Gives hostbased auth an opportunity to work; bz#616, report and feedback stuart AT kaloram.com; ok markus@
2007-05-20 - djm@cvs.openbsd.org 2007/05/17 07:55:29Darren Tucker2-7/+27
[sftp-server.c] bz#1286 stop reading and processing commands when input or output buffer is nearly full, otherwise sftp-server would happily try to grow the input/output buffers past the maximum supported by the buffer API and promptly fatal() based on patch from Thue Janus Kristensen; feedback & ok dtucker@
2007-05-20 - djm@cvs.openbsd.org 2007/05/17 07:50:31Darren Tucker2-2/+8
[log.c] save and restore errno when logging; ok deraadt@
2007-05-20 - dtucker@cvs.openbsd.org 2007/04/23 10:15:39Darren Tucker2-3/+5
[servconf.c] Remove debug() left over from development. ok deraadt@
2007-05-20 - stevesk@cvs.openbsd.org 2007/04/18 01:12:43Darren Tucker2-5/+14
[sftp-server.c] cast "%llu" format spec to (unsigned long long); do not assume a u_int64_t arg is the same as 'unsigned long long'. from Dmitry V. Levin <ldv@altlinux.org> ok markus@ 'Yes, that looks correct' millert@
2007-05-20 - stevesk@cvs.openbsd.org 2007/04/14 22:01:58Darren Tucker2-4/+8
[auth2.c] remove unused macro; from Dmitry V. Levin <ldv@altlinux.org>
2007-05-1020070509Tim Rice2-3/+7
- (tim) [configure.ac] Bug #1287: Add missing test for ucred.h.
2007-04-29trim pastoDarren Tucker1-4/+1
2007-04-29 - (dtucker) [configure.ac defines.h] Have configure check for offsetofDarren Tucker3-5/+11
to prevent redefinition warnings.
2007-04-29 - (dtucker) [configure.ac defines.h] Prevent warnings about __attribute__Darren Tucker3-7/+24
__nonnull__ for versions of GCC that don't support it.
2007-04-29 - (dtucker) [configure.ac defines.h] Have configure check for MAXSYMLINKSDarren Tucker3-5/+11
so we don't get redefinition warnings.
2007-04-29 - (dtucker) [openbsd-compat/xmmap.c] Include stdlib.h for mkstemp prototype.Darren Tucker2-2/+4
2007-04-29 - (dtucker) [configure.ac openbsd-compat/getrrsetbyname.c] Bug #1299: Use theDarren Tucker3-9/+27
platform's _res if it has one. Should fix problem of DNSSEC record lookups on NetBSD as reported by Curt Sampson.
2007-04-29 - (dtucker) [auth-shadow.c loginrec.c] Include time.h for time(2) prototype.Darren Tucker3-1/+4
2007-04-29 - (dtucker) [openbsd-compat/bsd-misc.c] Include unistd.h and sys/types.hDarren Tucker2-1/+7
for select(2) prototype.
2007-04-06 - (dtucker) [INSTALL] prngd lives at sourceforge these days.Darren Tucker2-4/+5
2007-04-06 - (dtucker) [INSTALL] Update the systems that have PAM as standard. LinkDarren Tucker2-6/+13
to OpenPAM too.
2007-03-2620070326Tim Rice8-17/+28
- (tim) [auth.c configure.ac defines.h session.c openbsd-compat/port-uw.c openbsd-compat/port-uw.h openbsd-compat/xcrypt.c] Rework libiaf test/defines to account for IRIX having libiaf but not set_id(). Patch with & ok dtucker@
2007-03-25 - (dtucker) [Makefile.in configure.ac] Replace single-purpose LIBSELINUX,Darren Tucker3-18/+20
LIBWRAP and LIBPAM variables in Makefile with the general-purpose SSHDLIBS. "I like" djm@
2007-03-21 - (dtucker) [regress/agent-getpeereid.sh] Do peereid test if we haveDarren Tucker2-2/+6
HAVE_GETPEERUCRED too. Also from Jan Pechanec.
2007-03-21 - (dtucker) [configure.ac openbsd-compat/bsd-getpeereid.c] Bug #1287: UseDarren Tucker3-10/+36
getpeerucred to implement getpeereid (currently only Solaris 10 and up). Patch by Jan.Pechanec at Sun.
2007-03-21 - jmc@cvs.openbsd.org 2007/03/20 15:57:15Darren Tucker2-14/+24
[sshd.8] - let synopsis and description agree for -f - sort FILES - +.Xr ssh-keyscan 1 , from Igor Sobrado
2007-03-21 - tedu@cvs.openbsd.org 2007/03/20 03:56:12Darren Tucker3-8/+11
[readconf.c clientloop.c] remove some bogus *p tests from charles longeau ok deraadt millert
2007-03-21 - dtucker@cvs.openbsd.org 2007/03/19 12:16:42Darren Tucker2-26/+49
[ssh-agent.c] Remove the signal handler that checks if the agent's parent process has gone away, instead check when the select loop returns. Record when the next key will expire when scanning for expired keys. Set the select timeout to whichever of these two things happens next. With djm@, with & ok deraadt@ markus@
2007-03-21 - djm@cvs.openbsd.org 2007/03/19 01:01:29Darren Tucker2-3/+13
[sshd_config] Disable the legacy SSH protocol 1 for new installations via a configuration override. In the future, we will change the server's default itself so users who need the legacy protocol will need to turn it on explicitly
2007-03-21 - dtucker@cvs.openbsd.org 2007/03/09 05:20:06Darren Tucker3-7/+16
[servconf.c sshd.c] Move C/R -> kbdint special case to after the defaults have been loaded, which makes ChallengeResponse default to yes again. This was broken by the Match changes and not fixed properly subsequently. Found by okan at demirmen.com, ok djm@ "please do it" deraadt@