Dmitry Belyavskiy
6fcc31aa4a
Enable GSS KEX in FIPS mode
2025-08-28 14:07:02 +02:00
Fedora Release Engineering
f6e9920c49
Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild
2025-07-24 23:40:26 +00:00
Dmitry Belyavskiy
8476fdfee5
OpenSSH part of support of ephemeral authorized keys
...
Needs a SELinux counterpart
2025-06-27 10:39:00 +02:00
Allison Karlitskaya
555ff68c37
Update sshd@.service to follow upstream
...
In particular, this adds in the support for ephemeral ssh keys provided
by credentials (passed from container managers or VM hypervisors). This
was introduced upstream by 071155a1fbac ("ssh-generator: support
ssh.ephemeral-key.all-users").
This change alone isn't enough to get this working. We now get this
SELinux denial:
type=AVC msg=audit(1750939616.931:111): avc: denied { read } for pid=1159 comm="sshd-session" name="ssh.ephemeral-authorized_keys-all" dev="tmpfs" ino=2 scontext=system_u:system_r:sshd_t:s0-s0:c0.c1023 tcontext=system_u:object_r:init_var_run_t:s0 tclass=file permissive=0
I have tested this with `setenforce 0`, however, and it works.
Resolves: rhbz#2374928
2025-06-26 14:22:07 +02:00
Dmitry Belyavskiy
f42621e54e
Support authentication indicators in GSSAPI
2025-06-09 15:17:04 +02:00
Dmitry Belyavskiy
4d148ba0d3
Apply patches forgot at the previous respin
2025-06-09 15:15:42 +02:00
Dmitry Belyavskiy
e0b2e06f74
Switch to systemd-socket activation for ssh-agent
...
Resolves: rhbz#2181353
2025-05-19 10:28:13 +02:00
Dmitry Belyavskiy
367846c9c6
Ignore too short hostkeys in known_hosts file
...
(https://github.com/openssh/openssh-portable/pull/567 )
2025-05-19 10:16:23 +02:00
Dmitry Belyavskiy
b5114ee608
Provide better diagnostics for non-supported private keys
...
(https://github.com/openssh/openssh-portable/pull/564 )
2025-05-19 10:15:02 +02:00
Dmitry Belyavskiy
6330768ca8
Rebasing to 10.0p1
2025-05-16 16:00:40 +02:00
Dmitry Belyavskiy
dd7f8b6993
Require OpenSSL 3.5 to support PQ crypto
...
Also suppress systemd warning on restart sshd
2025-04-17 12:07:36 +02:00
Zbigniew Jędrzejewski-Szmek
9ef6367bc1
Drop /usr/local/sbin from the default path too
...
On systems with merged sbin, both /usr/local/sbin and /usr/sbin are symlinks,
so /usr/local/sbin should be dropped from the default path too.
2025-03-18 21:32:06 +01:00
Dmitry Belyavskiy
db6cd22c3f
Usability adjustments
...
- Remove /usr/sbin from the default path
Resolves: rhbz#2352387
- Export and accept COLORTERM
Resolves: rhbz#2352653
2025-03-18 16:28:02 +01:00
Dmitry Belyavskiy
691ab72ad8
Update ssh-keysign permission for RPM linter
2025-03-06 12:15:40 +01:00
Dmitry Belyavskiy
300222035e
Use OpenSSL ML-KEM implementation instead of the native one
2025-03-05 15:04:36 +01:00
Dmitry Belyavskiy
ea9f68c171
Some minor fixes from Rocky Linux
...
https://www.openwall.com/lists/oss-security/2025/02/22/1
2025-02-25 12:34:18 +01:00
Dmitry Belyavskiy
03a941c079
Fixes for CVE-2025-26465, CVE-2025-26466
...
and also some minor regressions
2025-02-18 15:05:43 +01:00
Björn Esser
d195a5f6f7
Add explicit BR: libxcrypt-devel
...
Signed-off-by: Björn Esser <besser82@fedoraproject.org>
2025-02-01 19:56:17 +01:00
FeRD (Frank Dana)
4329e4cd9e
Update redhat sshd config
...
The ChallengeResponseAuthentication setting was deprecated in
favor of KbdInteractiveAuthentication, in OpenSSH 8.7.
2025-01-29 04:41:26 -05:00
Dmitry Belyavskiy
4446a8fec2
Fix regression of Match directive processing
...
Resolves: rhbz#2341769
2025-01-27 13:44:40 +01:00
Dmitry Belyavskiy
18a4ac4c5c
Fix regression of Match directive processing
...
Resolves: rhbz#2341769
2025-01-27 13:42:31 +01:00
Dmitry Belyavskiy
50fa131d40
Remove pam-ssh-agent subcomponent
...
Resolves: rhbz#2338440
2025-01-27 11:10:48 +01:00
Fedora Release Engineering
7551e56471
Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild
2025-01-17 21:50:57 +00:00
Dmitry Belyavskiy
9bab787a28
Fix MLKEM for BE platforms
2024-10-28 17:41:21 +01:00
Dmitry Belyavskiy
5f1bef2988
Memory management improvements
2024-10-16 15:14:16 +02:00
Zoltan Fridrich
0fd6584c66
Gssapi-keyex: fix issues found by static analysis
...
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2024-10-15 14:38:14 +02:00
Nils Kattenbeck
7f540abac3
Avoid warning when OPTIONS var is not set by environment file
2024-10-14 17:01:30 +00:00
Nils Kattenbeck
10c69e8578
Avoid warning when OPTIONS var is not set by environment file
2024-10-14 17:01:01 +00:00
Nils Kattenbeck
e0b8822dc8
Avoid warning when OPTIONS var is not set by environment file
2024-10-14 16:58:19 +00:00
Dmitry Belyavskiy
2c05d86713
Use FIPS KEX defaults in FIPS mode
2024-10-11 15:07:02 +02:00
Dmitry Belyavskiy
b3639c9616
Separate ssh-keysign to a dedicated package
2024-10-11 15:07:02 +02:00
Dmitry Belyavskiy
2b8473c18a
Update version of pam_ssh_agent_auth
2024-10-10 15:55:43 +02:00
Dmitry Belyavskiy
ddef24ba7e
Rebasing to OpenSSH 9.9p1
2024-10-10 11:36:06 +02:00
Zoltan Fridrich
64631599fc
Merge gssapi-keyex patches
...
Signed-off-by: Zoltan Fridrich <zfridric@redhat.com>
2024-09-16 12:28:25 +02:00
Dmitry Belyavskiy
adab98c5ba
Synchronize patches from Red Hat
2024-09-03 16:12:58 +02:00
Dmitry Belyavskiy
28a28238b3
Sshd now proposes to enter password again when a non-existing user is specified
2024-08-05 12:49:38 +02:00
Dmitry Belyavskiy
dd27043411
Change default key type in FIPS mode
2024-07-26 17:01:14 +02:00
Dmitry Belyavskiy
0943a793b6
Minor stuff
2024-07-24 14:31:43 +02:00
Dmitry Belyavskiy
ff8756ae7b
Make test pass again
2024-07-24 13:57:59 +02:00
Dmitry Belyavskiy
207f4964a4
proper struct for gss_keyex authmethod
2024-07-24 13:57:59 +02:00
Dmitry Belyavskiy
b46d13eb96
listening_for_clients - comment out
2024-07-24 13:57:59 +02:00
Dmitry Belyavskiy
1f22cfd0dd
Eliminate reexec_flag
2024-07-24 13:57:59 +02:00
Dmitry Belyavskiy
cae81de8e8
Eliminating PRIVSEP because of OpenSSH architecture changes
2024-07-24 13:57:59 +02:00
Dmitry Belyavskiy
b38789c6ac
Rebase to OpenSSH 9.8p1
2024-07-24 13:57:59 +02:00
Gordon Messmer
1b1292d3a5
DSA keys are no longer supported, due to the use of SHA1.
2024-07-22 13:43:22 -07:00
Gordon Messmer
b7ff239418
Rate limit service restarts to prevent intermittent test failures.
2024-07-22 09:24:02 -07:00
Gordon Messmer
2d59c1dbf2
Collect all logs after pam_ssh_agent_auth and port-forward tests
2024-07-22 09:24:02 -07:00
Gordon Messmer
787ce2c24d
Collect logs after sudo attempt in pam_ssh_agent_auth
2024-07-22 09:24:02 -07:00
Cristian Le
80da2c7159
Remove unused rhts-environment.sh
...
Looking at the source, there doesn't seem to be any functions/variables used from there
https://github.com/beaker-project/rhts/blob/master/bin/rhts-environment.sh
Signed-off-by: Cristian Le <cristian.le@mpsd.mpg.de>
2024-07-22 09:24:02 -07:00
Cristian Le
f8918df60f
Migrate sti tests to tmt
2024-07-22 09:24:02 -07:00