Commit graph

79 commits

Author SHA1 Message Date
Alex Dupre
2c07ef369c Remove OpenSC support. This port should be updated to support PKCS#11. 2010-12-27 09:58:51 +00:00
Philip M. Gollucci
4e2a10c5ee Add the sftpfilecontrol patch as an OPTION (WITH_FILECONTROL)
See http://sftpfilecontrol.sourceforge.net/  for details.

PR:             ports/146338
Submitted by:   Steve Wills <steve@mouf.net>
2010-08-31 02:46:44 +00:00
Doug Barton
1d6b4b3f91 Begin the process of deprecating sysutils/rc_subr by
s#. %%RC_SUBR%%#. /etc/rc.subr#
2010-03-27 00:15:24 +00:00
Pav Lucistnik
adcf823bcf - Unbreak KERBEROS option
- Add option for OpenBSD support
- Fix crash in sftp listing

PR:		ports/138409 (cumulative patch)
Submitted by:	Denis Barov <dindin@dindin.ru> (maintainer)
Feature safe:	yes
2009-09-18 14:05:52 +00:00
Philip M. Gollucci
cb484f5f5e - security/openssh-portable: update HPN and LPK patches to newer versions
- still broken on -CURRENT

PR:             ports/135407
Submitted by:   Denis Barov <dindin@dindin.ru> (maintainer)
2009-06-21 20:36:15 +00:00
Norikatsu Shigemura
4de2c64b49 Fix HPN crash issue by using aes128-ctr, aes192-ctr and aes256-ctr.
Approved by:	pav
2009-05-17 03:00:11 +00:00
Pav Lucistnik
73a15551c8 - Update to 5.2p1
- Assign maintainership to the submitter

PR:		ports/134160
Submitted by:	Denis Barov <dindin@dindin.ru>
2009-05-15 11:00:27 +00:00
Pav Lucistnik
47c045b38c - Add vendor patch for lpk patch that fixes runtime on amd64
PR:		ports/129092
Submitted by:	Jui-Nan Lin <jnlin@csie.nctu.edu.tw>
Approved by:	maintainer timeout (mnag; 4 months)
2009-03-24 17:33:41 +00:00
Pav Lucistnik
159053be31 - Update to 5.1p1
PR:		ports/128679
Submitted by:	Sunpoet Po-Chuan Hsieh <sunpoet@sunpoet.net>
Approved by:	maintainer timeout (mnag; 4 months)
2009-03-24 17:26:18 +00:00
Marcus Alves Grando
061f2c543f - Update to 5.0p1
- Port LPK patch to 5.0p1 and add to files dir
- Remove USE_PERL_BUILD since doesn't need [1]
- Update KERB_GSSAPI to 5.0p1
- Update HPN patch to 5.0p1 13v3
- Respect LOCALBASE on configure_args of LPK [2]
- Change MASTER_SITE of snapshot
- portlint(1)

PR:		121826 [2]
Submitted by:	Andrew Kolchoogin <andrew___rinet.ru> [2]
Reported by:	Björn König <bkoenig___alpha-tierchen.d [1]
2008-04-19 13:46:24 +00:00
Marcus Alves Grando
651b04a669 - Update to 4.7p1
- Update HPN patch to 4.7p1-hpn12v18
- Mark as BROKEN WITH_KERB_GSSAPI while developer release a new patch
2007-09-08 01:18:31 +00:00
Marcus Alves Grando
a33136265a - Enable ssl-engine
- Update gsskex patch to 4.6p1-gsskex-20070312
- Update lpk patch to 4.6p1-0.3.9
- Update hpn patch to 4.6p1-hpn12v17
- Fix challenge-response issue
- Bump PORTREVISION

Reported by:	Stefan Lambrev [1], ale@ [1]
2007-08-30 15:40:39 +00:00
Marcus Alves Grando
1b02a74de9 - Update OpenSSH to 4.6p1
- Update GSSKEX patch to 20061220
- Update HPN patch to hpn12v16
- Update LPK patch to 0.3.8
2007-03-12 22:13:18 +00:00
Marcus Alves Grando
d5aa31b5f3 - Fix CHROOT patch using chroot() before setusercontext() and add strerror() in message if chroot() fail.
Notified by:	Chris Gardner <chris_g_g___hotmail.com>
2006-11-10 14:28:42 +00:00
Marcus Alves Grando
ec6c3d3ee3 - Update to 4.5p1
- patch-sshd.c unconditionally includes <gssapi.h>. Include "ssh-gss.h" instead. [1]

PR:		104481 [1]
Submitted by:	Mark Andrews <Mark_Andrews___isc.org> [1]
2006-11-10 13:11:49 +00:00
Marcus Alves Grando
a99bc1ea54 - Add OPTION to enable Kerberos/GSSAPI patch [1]
- Add OPTION to enable LPK patch (ldap stored public key) [2]

PR:		86384 [1], 103399 [2]
Submitted by:	Garrett Wollman <wollman___khavrinen.csail.mit.edu> [1], Dmitriy Kirhlarov <dkirhlarov___oilspace.com> [2]
2006-10-07 21:06:55 +00:00
Marcus Alves Grando
5ef0f821ec - Update to 4.4p1.
- Disable temporary HPN patch until HPN release new version.
- Fix rc.d script path in sshd.8
- Add FreeBSD-${PKGNAME} in SSH_VERSION and SSH_RELEASE like src does.
- Sync patches with src.

Security:	CVE-2006-4924, CVE-2006-5051
2006-10-01 02:15:00 +00:00
Simon L. B. Nielsen
5d8b44f097 Add optional OpenSC PIN patch which make it possible for OpenSSH to ask
for a PIN when using an OpenSC smartcard.

Approved by:		mnag (maintainer)
Patch obtained from:	http://bugzilla.mindrot.org/show_bug.cgi?id=608
2006-08-09 12:49:15 +00:00
Marcus Alves Grando
1468fb643a - Fix order in rc.d script. Because of pidfile are empty, reload [2] and restart [1]
commands kill all connections.
- Separate keygen part and create keygen command.
- Bump PORTREVISION

PR:		93228 [1]
Reported by:	DanGer on #bsdports [2]
2006-02-21 19:28:37 +00:00
Marcus Alves Grando
b62a23c6c7 - Update to 4.3p1
- Use DISTVERSION
- Add most configuration in OPTIONS
- Enable support to libedit in sftp [1]
- Add OPTIONS to HPN patches [2]
- Add new rc.d script [3]
- New rc.d script are responsible to check configuration and create host keys
- Using USE_RC_SUBR
- Modify pkg-message to reflect new rc.d script
- Fix pkg-plist

Reviewd by:	dougb [3]
Submitted by:	vs [1], brooks [2]
Tested by:	me, John E Hein
2006-02-07 20:07:54 +00:00
Renato Botelho
509cdc26e4 - Update to 4.2p1
PR:		ports/85578
Submitted by:	Marcus Grando <marcus@corp.grupos.com.br>
2005-09-01 19:24:36 +00:00
Michael Johnson
0ec6f79d45 - Update to 4.0p1
PR:		ports/79029
Submitted by:	Dimitry Andric <dimitry@andric.com>
2005-03-20 01:00:03 +00:00
Pav Lucistnik
e13125d765 - sshd child process crashes when user with expired password logs in.
Fix unitialized pointer in our local patch.

PR:		ports/75204
Submitted by:	Andriy Gapon <avg@icyb.net.ua>
2004-12-18 19:16:09 +00:00
Dirk Meyer
3c2373bc49 - new option WITH_OPENSSH_CHROOT
Submitted by:	KANAI Makoto
2004-10-12 04:43:52 +00:00
Dirk Meyer
cdfe97f541 - cleanup patches
(only context changed)
2004-10-12 04:42:53 +00:00
Dirk Meyer
7fbc51cf8f - update to 3.9p1
set PORTVERSION 3.9.0.1 to avoid another
bump of PORTEPOCH if 3.9.1p1 come out.

- new option OPENSSH_SNAPSHOT
2004-08-18 11:35:53 +00:00
Dirk Meyer
d35031ac66 - update to 3.8p1 2004-02-25 12:32:57 +00:00
Dirk Meyer
12fc4ace75 - fix Usage 2003-12-04 03:24:09 +00:00
Dirk Meyer
709dd56c79 - GSSAPI patch improved for kerbers5 and hemidal
Submitted by:	bg@sics.se
2003-10-10 03:52:03 +00:00
Dirk Meyer
537a93ab72 - Fix BATCH=yes patch for bento. 2003-09-28 03:07:19 +00:00
Dirk Meyer
67cde0f8e7 - update to 3.7.1p2
more regressions tests successfull
2003-09-26 18:13:52 +00:00
Dirk Meyer
91f368c344 - Security Fix in PAM handling
Obtained from:	des
2003-09-26 02:42:39 +00:00
Dirk Meyer
ae53ed442c - Security Fix obtained from OpenBSD
http://www.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/buffer.c.diff?r1=1.18&r2=1.19

Submitted by:	ash@lab.poc.net
2003-09-23 19:16:49 +00:00
Jacques Vidrine
17f5a3c9fe Add Solar Designer's additional fixes to buffer management. 2003-09-17 16:07:48 +00:00
Dirk Meyer
07a618199e - Securitry Fix revision 2
http://www.openssh.com/txt/buffer.adv
Approved by:	lioux (portmgr)
2003-09-17 12:03:12 +00:00
Jacques Vidrine
4cb3944f15 Do not record expanded size before attempting to reallocate associated
memory.

Obtained from:	OpenBSD
2003-09-16 12:43:10 +00:00
Dirk Meyer
034a5e4f4f - extend regression tests 2003-04-01 04:10:29 +00:00
Dirk Meyer
a5724cba62 - Update to 3.6p1 2003-04-01 03:02:56 +00:00
Dirk Meyer
cafc71515f - openssh-3.5p1 doesn't log utmp for IPv6 connection correctly
Submitted by:	ume
2003-01-02 04:21:59 +00:00
Dirk Meyer
0a7cc8117d - cleanup of mor patches
- fix Makefile to avoid key-generation on bento.
2002-10-26 03:56:53 +00:00
Dirk Meyer
80bc17d33a Update to 3.5p1 2002-10-17 04:40:20 +00:00
Dirk Meyer
25fa2627ff Craete moduli on bento. 2002-09-17 05:24:37 +00:00
Dirk Meyer
58d5d9a297 add bugfix from CURRENT 2002-08-06 19:31:25 +00:00
Dirk Meyer
cbf06429f9 Fix resolver problem with privilege-separation.
PR:		39953
2002-07-27 06:20:28 +00:00
Dirk Meyer
9d5e8cafdc - add pam_cleanup from CURRENT
- Fix build problems < 4.0
PR:		40576
2002-07-24 20:47:22 +00:00
Dirk Meyer
e36257ada7 Add bits for regression tests
Fix build for /var/empty is schg and have open permissions.
2002-07-22 05:28:52 +00:00
Dirk Meyer
1c0df50961 - Fix Problem with HAVE_HOST_IN_UTMP
- update monitor.c

PR:		40576
Submitted by:	lxv@a-send-pr.sink.omut.org
2002-07-15 20:08:01 +00:00
Dirk Meyer
f61d0ce158 merge PAM buffer management from current. 2002-07-07 18:55:26 +00:00
Dirk Meyer
5e5d96c36b 'PermitRootLogin no' is the new default for the OpenSSH port.
This now matches the PermitRootLogin configuration of OpenSSH in
the base system.  Please be aware of this when upgrading your
OpenSSH port, and if truly necessary, re-enable remote root login
by readjusting this option in your sshd_config.

Users are encouraged to create single-purpose users with ssh keys
and very narrowly defined sudo privileges instead of using root
for automated tasks.

- PKGNAMESUFFIX for GSSAPI set.
- Merged some patches from current to improve PAM.
- Fix BATCH=yes for bento.
2002-07-04 18:29:18 +00:00
Dirk Meyer
2d15acdaf5 Cleanup patch to avoid conflicts with GSSAPI patches 2002-07-01 19:37:55 +00:00