Commit graph

  • 92f788e684 CVE-2025-61985: Reject URL-strings with NULL characters f42 Zoltan Fridrich 2026-01-08 14:40:44 +01:00
  • e3ef73c545 CVE-2025-61984: Reject usernames with control characters Zoltan Fridrich 2026-01-08 14:35:24 +01:00
  • be36f8dbd6 Rebase to OpenSSH 10.2p1 rawhide main Dmitry Belyavskiy 2025-12-17 15:38:20 +01:00
  • 84bc3aa057
    Do not fail sshd-auth with gssapi-keyex and no hostkeys Pavol Žáčik 2025-12-10 12:25:47 +01:00
  • c32475ebd9
    Do not fail sshd-auth with gssapi-keyex and no hostkeys f43 Pavol Žáčik 2025-12-10 12:47:55 +01:00
  • c3d6c51bfc Remove redundant SELinux patches Dmitry Belyavskiy 2025-12-02 14:05:50 +01:00
  • ef51fad482 Implement mlkem768nistp256-sha256 and mlkem1024nistp384-sha384 KEX methods Dmitry Belyavskiy 2025-11-03 13:44:22 +01:00
  • fa07fe987f Minor cleanup Dmitry Belyavskiy 2025-09-15 15:45:42 +02:00
  • 6fcc31aa4a Enable GSS KEX in FIPS mode Dmitry Belyavskiy 2025-08-28 14:07:02 +02:00
  • f6e9920c49 Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild Fedora Release Engineering 2025-07-24 23:40:26 +00:00
  • 8476fdfee5 OpenSSH part of support of ephemeral authorized keys Dmitry Belyavskiy 2025-06-27 10:39:00 +02:00
  • 555ff68c37 Update sshd@.service to follow upstream Allison Karlitskaya 2025-06-26 13:52:50 +02:00
  • f42621e54e Support authentication indicators in GSSAPI Dmitry Belyavskiy 2025-06-09 15:17:04 +02:00
  • 4d148ba0d3 Apply patches forgot at the previous respin Dmitry Belyavskiy 2025-06-09 15:15:42 +02:00
  • e0b2e06f74 Switch to systemd-socket activation for ssh-agent Dmitry Belyavskiy 2025-05-19 10:28:13 +02:00
  • d40c8a38aa CVE-2025-32728: Fix logic error in DisableForwarding option f41 Zoltan Fridrich 2025-05-19 10:25:55 +02:00
  • 367846c9c6 Ignore too short hostkeys in known_hosts file Dmitry Belyavskiy 2025-05-19 10:16:23 +02:00
  • b5114ee608 Provide better diagnostics for non-supported private keys Dmitry Belyavskiy 2025-05-19 10:15:02 +02:00
  • f1c4103d37 CVE-2025-32728: Fix logic error in DisableForwarding option Zoltan Fridrich 2025-05-19 10:09:46 +02:00
  • 6330768ca8 Rebasing to 10.0p1 Dmitry Belyavskiy 2025-05-16 14:45:32 +02:00
  • dd7f8b6993 Require OpenSSL 3.5 to support PQ crypto Dmitry Belyavskiy 2025-04-17 12:07:36 +02:00
  • 9cfcf4fc06 Remove /usr/sbin and /usr/local/sbin from the default PATH Dmitry Belyavskiy 2025-03-26 16:25:16 +01:00
  • 9ef6367bc1 Drop /usr/local/sbin from the default path too Zbigniew Jędrzejewski-Szmek 2025-03-18 21:32:06 +01:00
  • db6cd22c3f Usability adjustments Dmitry Belyavskiy 2025-03-18 16:28:02 +01:00
  • 691ab72ad8 Update ssh-keysign permission for RPM linter Dmitry Belyavskiy 2025-03-06 12:15:40 +01:00
  • 300222035e Use OpenSSL ML-KEM implementation instead of the native one Dmitry Belyavskiy 2025-03-05 15:04:36 +01:00
  • ea9f68c171 Some minor fixes from Rocky Linux Dmitry Belyavskiy 2025-02-25 12:34:18 +01:00
  • 9fce7969ae Fixes for CVE-2025-26465, CVE-2025-26466 f40 Dmitry Belyavskiy 2025-02-18 15:05:43 +01:00
  • 2608e2de3a Fixes for CVE-2025-26465, CVE-2025-26466 Dmitry Belyavskiy 2025-02-18 15:05:43 +01:00
  • 36962d5dd4 Fixes for CVE-2025-26465, CVE-2025-26466 Dmitry Belyavskiy 2025-02-18 15:05:43 +01:00
  • 03a941c079 Fixes for CVE-2025-26465, CVE-2025-26466 Dmitry Belyavskiy 2025-02-18 15:05:43 +01:00
  • 10d332fff3 Drop call to %sysusers_create_compat Zbigniew Jędrzejewski-Szmek 2025-02-11 17:44:45 +01:00
  • d195a5f6f7
    Add explicit BR: libxcrypt-devel Björn Esser 2025-02-01 19:56:17 +01:00
  • 4329e4cd9e Update redhat sshd config FeRD (Frank Dana) 2025-01-29 04:41:26 -05:00
  • 064da31af6 Fix regression of Match directive processing Dmitry Belyavskiy 2025-01-27 13:42:31 +01:00
  • 4446a8fec2 Fix regression of Match directive processing Dmitry Belyavskiy 2025-01-27 13:44:40 +01:00
  • 18a4ac4c5c Fix regression of Match directive processing Dmitry Belyavskiy 2025-01-27 13:42:31 +01:00
  • 50fa131d40 Remove pam-ssh-agent subcomponent Dmitry Belyavskiy 2025-01-27 11:10:48 +01:00
  • 7551e56471 Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild Fedora Release Engineering 2025-01-17 21:50:57 +00:00
  • 25272c68ef Rebasing to OpenSSH 9.9p1 Dmitry Belyavskiy 2025-01-17 12:49:45 +01:00
  • 9bab787a28 Fix MLKEM for BE platforms Dmitry Belyavskiy 2024-10-28 17:41:21 +01:00
  • 82b86d60c5 Eliminate memory leaks Dmitry Belyavskiy 2024-10-16 15:43:14 +02:00
  • 5f1bef2988 Memory management improvements Dmitry Belyavskiy 2024-10-16 15:14:16 +02:00
  • ceb1e2f209 Merge gssapi patches Zoltan Fridrich 2024-10-15 16:40:22 +02:00
  • 0fd6584c66 Gssapi-keyex: fix issues found by static analysis Zoltan Fridrich 2024-10-15 14:38:14 +02:00
  • 7f540abac3 Avoid warning when OPTIONS var is not set by environment file Nils Kattenbeck 2024-10-14 17:01:30 +00:00
  • 10c69e8578 Avoid warning when OPTIONS var is not set by environment file Nils Kattenbeck 2024-10-14 17:01:01 +00:00
  • e0b8822dc8 Avoid warning when OPTIONS var is not set by environment file Nils Kattenbeck 2024-10-14 16:58:19 +00:00
  • 2c05d86713 Use FIPS KEX defaults in FIPS mode Dmitry Belyavskiy 2024-10-11 14:43:34 +02:00
  • b3639c9616 Separate ssh-keysign to a dedicated package Dmitry Belyavskiy 2024-10-11 14:42:24 +02:00
  • 2b8473c18a Update version of pam_ssh_agent_auth Dmitry Belyavskiy 2024-10-10 15:55:43 +02:00
  • ddef24ba7e Rebasing to OpenSSH 9.9p1 Dmitry Belyavskiy 2024-10-09 12:52:03 +02:00
  • c1ec7304ff Use GEF to audit sshd GOT for signs of tampering Gordon Messmer 2024-04-04 14:38:30 -07:00
  • f1b4e2eb0a
    Update to OpenSSH 9.9 (rhbz#2230781) Daniel Milnes 2024-09-22 18:01:05 +01:00
  • 64631599fc Merge gssapi-keyex patches Zoltan Fridrich 2024-09-16 12:28:25 +02:00
  • 23b9423768 Synchronize patches from Red Hat Dmitry Belyavskiy 2024-09-03 18:15:29 +02:00
  • adab98c5ba Synchronize patches from Red Hat Dmitry Belyavskiy 2024-09-03 16:12:58 +02:00
  • 28a28238b3 Sshd now proposes to enter password again when a non-existing user is specified Dmitry Belyavskiy 2024-08-05 12:49:38 +02:00
  • 01d59dc323
    Start sshd after network-online.target Koichiro Iwao 2024-07-26 15:46:53 +09:00
  • dd27043411 Change default key type in FIPS mode Dmitry Belyavskiy 2024-07-26 17:01:14 +02:00
  • 0943a793b6 Minor stuff Dmitry Belyavskiy 2024-07-24 14:31:43 +02:00
  • ff8756ae7b Make test pass again Dmitry Belyavskiy 2024-07-23 16:20:17 +02:00
  • 207f4964a4 proper struct for gss_keyex authmethod Dmitry Belyavskiy 2024-07-22 17:36:13 +02:00
  • b46d13eb96 listening_for_clients - comment out Dmitry Belyavskiy 2024-07-12 15:16:09 +02:00
  • 1f22cfd0dd Eliminate reexec_flag Dmitry Belyavskiy 2024-07-12 13:38:48 +02:00
  • cae81de8e8 Eliminating PRIVSEP because of OpenSSH architecture changes Dmitry Belyavskiy 2024-07-12 13:20:45 +02:00
  • b38789c6ac Rebase to OpenSSH 9.8p1 Dmitry Belyavskiy 2024-07-10 18:19:23 +02:00
  • 1b1292d3a5 DSA keys are no longer supported, due to the use of SHA1. Gordon Messmer 2024-07-22 13:43:22 -07:00
  • b7ff239418 Rate limit service restarts to prevent intermittent test failures. Gordon Messmer 2024-07-04 09:50:01 -07:00
  • 2d59c1dbf2 Collect all logs after pam_ssh_agent_auth and port-forward tests Gordon Messmer 2024-07-03 22:46:52 -07:00
  • 787ce2c24d Collect logs after sudo attempt in pam_ssh_agent_auth Gordon Messmer 2024-07-02 15:15:49 -07:00
  • 80da2c7159 Remove unused rhts-environment.sh Cristian Le 2024-07-03 10:46:07 +02:00
  • f8918df60f Migrate sti tests to tmt Cristian Le 2024-07-02 09:42:19 +02:00
  • 31a40d987f Temporary fix for https://pagure.io/releng/issue/12187 Gordon Messmer 2024-07-03 10:47:20 -07:00
  • fe837a3014 Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild Fedora Release Engineering 2024-07-18 21:00:36 +00:00
  • 98e71e9408 fixup! Rebase to OpenSSH 9.8p1 rebase_98 Dmitry Belyavskiy 2024-07-11 17:10:20 +02:00
  • 56e7243e57 Rebase to OpenSSH 9.8p1 Dmitry Belyavskiy 2024-07-10 18:19:23 +02:00
  • 2177f2909a Temporary fix for https://pagure.io/releng/issue/12187 Gordon Messmer 2024-07-03 10:47:20 -07:00
  • 0a7b686893
    Remove unused rhts-environment.sh Cristian Le 2024-07-03 10:46:07 +02:00
  • 9a37672985
    Migrate sti tests to tmt Cristian Le 2024-07-02 09:42:19 +02:00
  • da739e684b DO NOT MERGE: try restoring the filesystem rpm before running tests Gordon Messmer 2024-07-02 11:22:06 -07:00
  • bd0d70b915 DO NOT MERGE: collect filesystem info to troubleshoot test failures Gordon Messmer 2024-07-02 10:48:15 -07:00
  • 996eee0135 DO NOT MERGE: get logs after sudo attempt Gordon Messmer 2024-07-02 10:11:27 -07:00
  • 364af7f74f DO NOT MERGE: check pam update with sed Gordon Messmer 2024-07-02 09:45:32 -07:00
  • d523236d89 DO NOT MERGE: test key type change Gordon Messmer 2024-07-02 08:30:09 -07:00
  • 2b3c43fd47 Rewriting OpenSSH GSS KEX to use new packet API Zoltan Fridrich 2024-05-27 12:00:57 +02:00
  • c58fea86cd Version bump Dmitry Belyavskiy 2024-07-02 11:12:42 +02:00
  • dcbca7b947 Patch 9.6p1 for CVE-2024-6387 Gordon Messmer 2024-07-01 20:49:16 -07:00
  • cbeb03a371 Version bump Dmitry Belyavskiy 2024-07-02 09:22:24 +02:00
  • 69c52aa299 Shorten paths used for parallel tests to fix BZ#2295117 Gordon Messmer 2024-07-01 20:23:20 -07:00
  • f124af09d8
    Backport CVE-2024-6387 fix to F40 Daniel Milnes 2024-07-01 22:04:00 +01:00
  • 89cb13be8c
    Remove the ObscureKeystrokeTiming bug as it doesn't impact OpenSSH 9.3 f39 Daniel Milnes 2024-07-01 22:32:20 +01:00
  • ce2bc3d4bb
    Backport CVE-2024-6387 fix to F39 Daniel Milnes 2024-07-01 22:04:00 +01:00
  • d73d06ac75 Add patch to fix CVE-2024-6387 U2FsdGVkX1 2024-07-01 08:40:42 -04:00
  • b77eafa86b Make default key sizes configurable in sshd-keygen Zoltan Fridrich 2024-05-09 16:30:24 +02:00
  • dc8423673e Correctly audit hostname and IP address Zoltan Fridrich 2024-05-09 16:29:32 +02:00
  • 53eafa2b19 Use OpenSSL SSH KDF implementation - s390x fixup Dmitry Belyavskiy 2024-04-24 15:13:42 +02:00
  • 855a9d9c41 Use OpenSSL SSH KDF implementation Dmitry Belyavskiy 2024-04-24 12:00:24 +02:00
  • 80ba97c338 Bump spec Dmitry Belyavskiy 2024-04-17 10:44:40 +02:00
  • b001382b22 Drop %attr for a symlink Zbigniew Jędrzejewski-Szmek 2024-04-16 22:35:55 +02:00