SHA256
1
0
forked from pool/openssh

- Disable ssh1 protocol support as neither RH or Debian enable

this protocol by default anymore either.

OBS-URL: https://build.opensuse.org/package/show/network/openssh?expand=0&rev=154
This commit is contained in:
Tomáš Chvátal 2018-10-17 09:24:31 +00:00 committed by Git OBS Bridge
parent 7bccbbd821
commit c159d0ce66
3 changed files with 8 additions and 9 deletions

View File

@ -11,10 +11,6 @@ There are following changes in default settings of ssh client and server:
either "prohibit-password" or even better to "no" (which disables direct either "prohibit-password" or even better to "no" (which disables direct
remote root login entirely). remote root login entirely).
* SSH protocol version 1 is enabled for maximum compatibility.
NOTE: do not use protocol version 1. It is less secure then v2 and should
generally be phased out.
* DSA authentication is enabled by default for maximum compatibility. * DSA authentication is enabled by default for maximum compatibility.
NOTE: do not use DSA authentication since it is being phased out for a reason NOTE: do not use DSA authentication since it is being phased out for a reason
- the size of DSA keys is limited by the standard to 1024 bits which cannot - the size of DSA keys is limited by the standard to 1024 bits which cannot

View File

@ -1,3 +1,9 @@
-------------------------------------------------------------------
Wed Oct 17 09:22:36 UTC 2018 - Tomáš Chvátal <tchvatal@suse.com>
- Disable ssh1 protocol support as neither RH or Debian enable
this protocol by default anymore either.
------------------------------------------------------------------- -------------------------------------------------------------------
Wed Oct 17 08:42:12 UTC 2018 - Tomáš Chvátal <tchvatal@suse.com> Wed Oct 17 08:42:12 UTC 2018 - Tomáš Chvátal <tchvatal@suse.com>

View File

@ -27,8 +27,7 @@
%bcond_without susefirewall %bcond_without susefirewall
%bcond_with tirpc %bcond_with tirpc
%endif %endif
%define _fwdir %{_sysconfdir}/sysconfig/SuSEfirewall2.d %define _fwdefdir %{_sysconfdir}/sysconfig/SuSEfirewall2.d/services
%define _fwdefdir %{_fwdir}/services
%define _appdefdir %( grep "configdirspec=" $( which xmkmf ) | sed -r 's,^[^=]+=.*-I(.*)/config.*$,\\1/app-defaults,' ) %define _appdefdir %( grep "configdirspec=" $( which xmkmf ) | sed -r 's,^[^=]+=.*-I(.*)/config.*$,\\1/app-defaults,' )
%define CHECKSUM_SUFFIX .hmac %define CHECKSUM_SUFFIX .hmac
%define CHECKSUM_HMAC_KEY "HMAC_KEY:OpenSSH-FIPS@SLE" %define CHECKSUM_HMAC_KEY "HMAC_KEY:OpenSSH-FIPS@SLE"
@ -197,10 +196,8 @@ export LDFLAGS CFLAGS CXXFLAGS CPPFLAGS
--with-ldap \ --with-ldap \
--with-xauth=%{_bindir}/xauth \ --with-xauth=%{_bindir}/xauth \
--with-libedit \ --with-libedit \
--with-ssh1 \ --target=%{_target_cpu}-suse-linux
--target=%{_target_cpu}-suse-linux \
### configure end
make %{?_smp_mflags} make %{?_smp_mflags}
%install %install