Go to file
Dominique Leuenberger b2b28a4fe4 Accepting request 923951 from network
- Version upgrade to 8.8p1
  * No changes for askpass, see main package changelog for
    details

- Version update to 8.8p1:
  = Security
  * sshd(8) from OpenSSH 6.2 through 8.7 failed to correctly initialise
    supplemental groups when executing an AuthorizedKeysCommand or
    AuthorizedPrincipalsCommand, where a AuthorizedKeysCommandUser or
    AuthorizedPrincipalsCommandUser directive has been set to run the
    command as a different user. Instead these commands would inherit
    the groups that sshd(8) was started with.
    Depending on system configuration, inherited groups may allow
    AuthorizedKeysCommand/AuthorizedPrincipalsCommand helper programs to
    gain unintended privilege.
    Neither AuthorizedKeysCommand nor AuthorizedPrincipalsCommand are
    enabled by default in sshd_config(5).
  = Potentially-incompatible changes
  * This release disables RSA signatures using the SHA-1 hash algorithm
    by default. This change has been made as the SHA-1 hash algorithm is
    cryptographically broken, and it is possible to create chosen-prefix
    hash collisions for <USD$50K.
    For most users, this change should be invisible and there is
    no need to replace ssh-rsa keys. OpenSSH has supported RFC8332
    RSA/SHA-256/512 signatures since release 7.2 and existing ssh-rsa keys
    will automatically use the stronger algorithm where possible.
    Incompatibility is more likely when connecting to older SSH
    implementations that have not been upgraded or have not closely tracked
    improvements in the SSH protocol. For these cases, it may be necessary
    to selectively re-enable RSA/SHA1 to allow connection and/or user

OBS-URL: https://build.opensuse.org/request/show/923951
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssh?expand=0&rev=154
2021-10-11 14:48:36 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssh?expand=0&rev=1 2007-01-07 16:26:05 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssh?expand=0&rev=1 2007-01-07 16:26:05 +00:00
cavs_driver-ssh.pl Accepting request 642573 from home:scarabeus_iv:branches:network 2018-10-17 08:57:56 +00:00
openssh-7.7p1-cavstest-ctr.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-cavstest-kdf.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-disable_openssl_abi_check.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-eal3.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-enable_PAM_by_default.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-fips_checks.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-fips.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-host_ident.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-hostname_changes_when_forwarding_X.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-IPv6_X_forwarding.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-ldap.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-no_fork-no_pid_file.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-pam_check_locks.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-pts_names_formatting.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-remove_xauth_cookies_on_exit.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-seccomp_ipc_flock.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-seccomp_stat.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-send_locale.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-sftp_force_permissions.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-sftp_print_diagnostic_messages.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-systemd-notify.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-X11_trusted_forwarding.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.7p1-X_forward_with_disabled_ipv6.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.9p1-keygen-preserve-perms.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-7.9p1-revert-new-qos-defaults.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.0p1-gssapi-keyex.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.1p1-audit.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.1p1-ed25519-use-openssl-rng.patch Accepting request 849311 from home:hpjansson:branches:network 2020-11-22 16:59:16 +00:00
openssh-8.1p1-seccomp-clock_gettime64.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.1p1-seccomp-clock_nanosleep_time64.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.1p1-seccomp-clock_nanosleep.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.1p1-use-openssl-kdf.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.4p1-pam_motd.patch Accepting request 898969 from home:kukuk:branches:network 2021-06-23 18:30:23 +00:00
openssh-8.4p1-ssh_config_d.patch Accepting request 867202 from home:kukuk:branches:network 2021-01-27 19:14:20 +00:00
openssh-8.4p1-vendordir.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.8p1.tar.gz Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-8.8p1.tar.gz.asc Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-askpass-gnome.changes Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-askpass-gnome.spec Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-fips-ensure-approved-moduli.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-link-with-sk.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-reenable-dh-group14-sha1-default.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh-whitelist-syscalls.patch Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
openssh.changes - openssh.keyring: rotated to new key from https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc 2021-10-07 15:19:27 +00:00
openssh.keyring - openssh.keyring: rotated to new key from https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/RELEASE_KEY.asc 2021-10-07 15:19:27 +00:00
openssh.spec Accepting request 922068 from home:hpjansson:branches:network 2021-10-07 08:06:58 +00:00
README.FIPS Accepting request 432093 from home:pcerny:factory 2016-09-30 20:34:19 +00:00
README.kerberos Accepting request 642573 from home:scarabeus_iv:branches:network 2018-10-17 08:57:56 +00:00
README.SUSE Accepting request 873406 from home:jsegitz:branches:network 2021-04-17 14:22:02 +00:00
ssh-askpass Accepting request 718210 from home:Vogtinator:branches:network 2019-07-24 12:05:07 +00:00
ssh.reg OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssh?expand=0&rev=1 2007-01-07 16:26:05 +00:00
sshd-gen-keys-start Accepting request 914000 from home:kukuk:tiu 2021-09-01 18:03:45 +00:00
sshd.fw OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssh?expand=0&rev=7 2007-07-27 00:01:43 +00:00
sshd.pamd Accepting request 898969 from home:kukuk:branches:network 2021-06-23 18:30:23 +00:00
sshd.service - Mention upstream bugs on multiple local patches 2018-10-19 13:24:01 +00:00
sysconfig.ssh Accepting request 738490 from home:hpjansson:branches:network 2019-10-15 07:47:08 +00:00
sysusers-sshd.conf Accepting request 866259 from home:hpjansson:branches:network 2021-01-24 18:19:54 +00:00

There are following changes in default settings of ssh client and server:

* Accepting and sending of locale environment variables in protocol 2 is
  enabled.

* PAM authentication is enabled and mostly even required, do not turn it off.

* DSA authentication is enabled by default for maximum compatibility.
  NOTE: do not use DSA authentication since it is being phased out for a reason
  - the size of DSA keys is limited by the standard to 1024 bits which cannot
  be considered safe any more.

* Accepting all RFC4419 specified DH group parameters. See KexDHMin in
  ssh_config and sshd_config manual pages.

For more information on differences in SUSE OpenSSH package see README.FIPS