diff options
| author | Ed Maste <emaste@FreeBSD.org> | 2021-09-08 01:05:51 +0000 |
|---|---|---|
| committer | Ed Maste <emaste@FreeBSD.org> | 2021-09-08 01:05:51 +0000 |
| commit | 19261079b74319502c6ffa1249920079f0f69a72 (patch) | |
| tree | a07fb2205e0cea7dee1ffbcc945d9d5b97124714 /secure | |
| parent | c5128c48df3c2f3828432aff2ea536bb9c887e14 (diff) | |
| parent | 66719ee573ac2290622db642f6e89ab35b179f3d (diff) | |
openssh: update to OpenSSH v8.7p1
Some notable changes, from upstream's release notes:
- sshd(8): Remove support for obsolete "host/port" syntax.
- ssh(1): When prompting whether to record a new host key, accept the key
fingerprint as a synonym for "yes".
- ssh-keygen(1): when acting as a CA and signing certificates with an RSA
key, default to using the rsa-sha2-512 signature algorithm.
- ssh(1), sshd(8), ssh-keygen(1): this release removes the "ssh-rsa"
(RSA/SHA1) algorithm from those accepted for certificate signatures.
- ssh-sk-helper(8): this is a new binary. It is used by the FIDO/U2F
support to provide address-space isolation for token middleware
libraries (including the internal one).
- ssh(1): this release enables UpdateHostkeys by default subject to some
conservative preconditions.
- scp(1): this release changes the behaviour of remote to remote copies
(e.g. "scp host-a:/path host-b:") to transfer through the local host
by default.
- scp(1): experimental support for transfers using the SFTP protocol as
a replacement for the venerable SCP/RCP protocol that it has
traditionally used.
Additional integration work is needed to support FIDO/U2F in the base
system.
Deprecation Notice
------------------
OpenSSH will disable the ssh-rsa signature scheme by default in the
next release.
Reviewed by: imp
MFC after: 1 month
Relnotes: Yes
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D29985
Diffstat (limited to 'secure')
| -rw-r--r-- | secure/lib/libssh/Makefile | 19 | ||||
| -rw-r--r-- | secure/usr.bin/scp/Makefile | 2 | ||||
| -rw-r--r-- | secure/usr.bin/ssh-add/Makefile | 2 | ||||
| -rw-r--r-- | secure/usr.bin/ssh-keygen/Makefile | 3 | ||||
| -rw-r--r-- | secure/usr.sbin/sshd/Makefile | 2 |
5 files changed, 15 insertions, 13 deletions
diff --git a/secure/lib/libssh/Makefile b/secure/lib/libssh/Makefile index aa3dc27fb526..b97bd7f2693f 100644 --- a/secure/lib/libssh/Makefile +++ b/secure/lib/libssh/Makefile @@ -10,20 +10,21 @@ SRCS= ssh_api.c ssherr.c sshbuf.c sshkey.c sshbuf-getput-basic.c \ SRCS+= authfd.c authfile.c \ canohost.c channels.c cipher.c cipher-aes.c cipher-aesctr.c \ cipher-ctr.c cleanup.c \ - compat.c crc32.c fatal.c hostfile.c \ - log.c match.c moduli.c nchan.c packet.c opacket.c \ - readpass.c ttymodes.c xmalloc.c addrmatch.c \ - atomicio.c dispatch.c mac.c uuencode.c misc.c utf8.c \ + compat.c fatal.c hostfile.c \ + log.c match.c moduli.c nchan.c packet.c \ + readpass.c ttymodes.c xmalloc.c addr.c addrmatch.c \ + atomicio.c dispatch.c mac.c misc.c utf8.c \ monitor_fdpass.c rijndael.c ssh-dss.c ssh-ecdsa.c ssh-rsa.c dh.c \ msg.c progressmeter.c dns.c entropy.c umac.c umac128.c \ ssh-pkcs11.c smult_curve25519_ref.c \ - poly1305.c chacha.c cipher-chachapoly.c \ + poly1305.c chacha.c cipher-chachapoly.c cipher-chachapoly-libcrypto.c \ ssh-ed25519.c digest-openssl.c digest-libc.c hmac.c \ sc25519.c ge25519.c fe25519.c ed25519.c verify.c hash.c \ kex.c kexdh.c kexgex.c kexecdh.c kexc25519.c \ - kexdhc.c kexgexc.c kexecdhc.c kexc25519c.c \ - kexdhs.c kexgexs.c kexecdhs.c kexc25519s.c \ - platform-pledge.c platform-tracing.c platform-misc.c + kexgexc.c kexgexs.c \ + kexsntrup761x25519.c sntrup761.c kexgen.c \ + sftp-realpath.c platform-pledge.c platform-tracing.c platform-misc.c \ + sshbuf-io.c PACKAGE= ssh # gss-genr.c should be in $SRCS but causes linking problems, so it is @@ -34,7 +35,7 @@ SRCS+= bcrypt_pbkdf.c blowfish.c bsd-misc.c bsd-signal.c explicit_bzero.c \ fmt_scaled.c freezero.c glob.c \ libressl-api-compat.c \ openssl-compat.c port-net.c \ - realpath.c recallocarray.c strtonum.c timingsafe_bcmp.c vis.c xcrypt.c + recallocarray.c strtonum.c timingsafe_bcmp.c vis.c xcrypt.c .if ${MK_LDNS} == "no" SRCS+= getrrsetbyname.c diff --git a/secure/usr.bin/scp/Makefile b/secure/usr.bin/scp/Makefile index 34469a443287..a4e55c1bf86b 100644 --- a/secure/usr.bin/scp/Makefile +++ b/secure/usr.bin/scp/Makefile @@ -3,7 +3,7 @@ .include <src.opts.mk> PROG= scp -SRCS= scp.c +SRCS= scp.c sftp-common.c sftp-client.c sftp-glob.c progressmeter.c PACKAGE= ssh CFLAGS+=-I${SSHDIR} -include ssh_namespace.h SRCS+= ssh_namespace.h diff --git a/secure/usr.bin/ssh-add/Makefile b/secure/usr.bin/ssh-add/Makefile index acce73d3841d..c76e50a4a91a 100644 --- a/secure/usr.bin/ssh-add/Makefile +++ b/secure/usr.bin/ssh-add/Makefile @@ -3,7 +3,7 @@ .include <src.opts.mk> PROG= ssh-add -SRCS+= ssh-add.c +SRCS+= ssh-add.c ssh-sk-client.c PACKAGE= ssh CFLAGS+=-I${SSHDIR} -include ssh_namespace.h SRCS+= ssh_namespace.h diff --git a/secure/usr.bin/ssh-keygen/Makefile b/secure/usr.bin/ssh-keygen/Makefile index d6b5616dfc0a..eec0b23e1b3f 100644 --- a/secure/usr.bin/ssh-keygen/Makefile +++ b/secure/usr.bin/ssh-keygen/Makefile @@ -3,7 +3,8 @@ .include <src.opts.mk> PROG= ssh-keygen -SRCS= ssh-keygen.c +# XXX ssh-sk-client.c in libssh maybe? +SRCS= ssh-keygen.c sshsig.c ssh-sk-client.c PACKAGE= ssh CFLAGS+=-I${SSHDIR} -include ssh_namespace.h SRCS+= ssh_namespace.h diff --git a/secure/usr.sbin/sshd/Makefile b/secure/usr.sbin/sshd/Makefile index f5a4d94a62e6..b374e737a139 100644 --- a/secure/usr.sbin/sshd/Makefile +++ b/secure/usr.sbin/sshd/Makefile @@ -15,7 +15,7 @@ SRCS= sshd.c auth-rhosts.c auth-passwd.c \ monitor.c monitor_wrap.c auth-krb5.c \ auth2-gss.c gss-serv.c gss-serv-krb5.c \ loginrec.c auth-pam.c auth-shadow.c auth-sia.c md5crypt.c \ - sftp-server.c sftp-common.c \ + srclimit.c sftp-server.c sftp-common.c \ sandbox-null.c sandbox-rlimit.c sandbox-systrace.c sandbox-darwin.c \ sandbox-seccomp-filter.c sandbox-capsicum.c sandbox-pledge.c \ sandbox-solaris.c uidswap.c |
