summaryrefslogtreecommitdiff
path: root/security
AgeCommit message (Collapse)AuthorFilesLines
2000-08-11When looking for -lcrypto, test linking with:jlam2-1/+76
-lcrypto NetBSD-1.5* -lcrypto -lrsaref OpenSSL and USE_RSAREF2=NO -lcrypto -lRSAglue -lrsaref OpenSSL and USE_RSAREF2=YES and use the first set of libraries which work. Closes the following PRs: 9820, 10268, 10681.
2000-08-11Add and enable ssh-askpassjlam1-1/+2
2000-08-11ssh-askpass - X11-based passphrase dialog for OpenSSHjlam7-0/+51
2000-08-11Set location of ssh-askpass to be ${X11PREFIX}/bin/ssh-askpass.jlam3-5/+20
Closes PR#10774.
2000-08-11add some comment on license change.itojun1-1/+5
we need stick to 1.2.27 (use openssh).
2000-08-10Comment out Kerberos 5 support, for now.thorpej2-14/+16
2000-08-10Don't syslog krb5_init_context() failure. It can happen ifthorpej2-7/+17
Kerberos is simply not configured on the system.
2000-08-10Make this work with Heimdal Kerberos 5. Requires fleshed-out MCCthorpej3-5/+48
support in Heimdal.
2000-08-09Remove a commend/if clause which turns out to not actuallythorpej1-4/+1
be true.
2000-08-09Add master site on ftp.openssh.com.wiz1-1/+4
Add note why we have both openssh.com entries.
2000-08-06master site moved stuffhubertf1-15/+15
2000-08-05mention license change issue in 1.2.27 -> 1.2.28.itojun1-1/+5
2000-08-04Fix a bug where the parser would fail if a keylength was notthorpej2-1/+39
explicitly specified in a Phase-1 proposal statement. Patch sent to sakane@kame.net.
2000-08-03Update nessus to 1.0.4.frueauf8-17/+43
What is new in Nessus 1.0.4 : changes by Christoph Puppe (pluto at defcom-sec.com) : added "Sort by Port" to the report window. Reports are sorted first by holes, then by warnings, then by notes. Previous version only sorted by holes. changes by Renaud Deraison (renaud at nessus.org) : ftp related checks : the user can now supply a login/password for the ftp checks, and relies on the ftp banner if nessusd can't log into the ftp server (requested by Jens.Oeser at connector.de). libnessus : ftp_log_in() would sometime fail against some ftp servers better handling of large reports on the client side tests are saved on the server side and can be restored. Note that this is experimental and disabled by default. Do ./configure --enable-save-sessions to enable this feature, and read doc/session_saving.txt for details. better handling of targets with multiple web servers running continue to launch the DoS if the state of the remote host can not be determined fixed a bug in smb_login_as_users.nasl, and improved smb_accessible_shares.nasl added checks for unpassworded MySQLs and PostgreSQL databases nessusd uses less memory changes by Pavel Kankovsky (peak at argo.troja.mff.cuni.cz) : fixed a possible deadlock in the nessusd internal communication fixed a problem in the client that would make it crash if it received a malformed message from the server the client would not detect the death of the server when run in batch mode possible header confusion (with regex.h) fixed possible signal deadlock when exiting fixed Other changes : fixed a problem in the function is_cgi_installed() that may sometime not work against odd clients (Thomas Reinke (reinke at e-softinc.com)) fixed a bug in snmp_default_communities.nasl (Lionel Cons (lionel.cons at cern.ch)) fixed showmount.nasl (Paul Ewing Jr. (ewing at ima.umn.edu)) typo in showmount.nasl would prevent it to work over udp (ctor at krixor.xy.org)
2000-07-31The gettext package gained a shared library. For all packages whichjlam1-2/+2
link against libintl.so, update the dependency on gettext to >=0.10.35nb1.
2000-07-30update to latest (7/31), to sync with /usr/include/netinet6/ipsec.h change.itojun4-17/+17
- improvements in multiple address case - sync with improvements in INET2000 bakeoff
2000-07-30Add libnasl, nessus-core, nessus-libraries and nessus-plugins tofrueauf1-1/+5
the SUBDIR entries.
2000-07-30Update nessus to 1.0.3.frueauf11-346/+68
Main change is the splitup into libnasl, nessus-libraries, nessus-core and nessus-plugins. Too many changes come with 1.0.3, but most noteable the number of checked security vulnerabilities increased and got updated. This is based on work Hubert Feyrer did on some former version.
2000-07-30Initial import of nessus-plugins 1.0.3, the Plugins for the Nessus Networkfrueauf5-0/+489
Security Scanner. Based on work Hubert Feyrer did on some former version.
2000-07-30Initial import of nessus-libraries 1.0.3, the Libs required by the Nessusfrueauf9-0/+104
Network security scanner. Based on work Hubert Feyrer did on some former version.
2000-07-30Initial import of nessus-core 1.0.3, the Core module of the Nessus Networkfrueauf8-0/+77
Security Scanner. Based on work from Hubert Feyrer for some former version.
2000-07-30Initial import of libnasl, a Nessus Attack Scripting Language library.frueauf5-0/+29
Based on work Hubert Feyrer did for some former version.
2000-07-28It's openssl>=0.9.5a, not openssl>=0.9.5.jlam1-3/+3
2000-07-27Add and enable pksjlam1-1/+2
2000-07-27pks - PGP Key Serverjlam13-0/+309
Taken from PR#10394 by Dave Burgess <burgess@neonramp.com> with modifications.
2000-07-26Make it work on Solaris.veego4-5/+13
2000-07-25Address concern raised in pkg/10268, part 3, by telling user how to getjlam1-5/+12
a working /dev/urandom if it's found not to work.
2000-07-25This produces some funny errors:hubertf1-2/+2
RESTRICT="foo; bar" Fix by s/;/,/
2000-07-24Make all the installed /usr/pkg/etc/rc.d/sshd.sh files match.jlam3-22/+96
Also default to "start" command if run with no arguments.
2000-07-24Add german mirror to master site list.tron1-2/+3
2000-07-22INSTALL file containing post-install code factored from package Makefilejlam1-0/+48
and PLIST.
2000-07-22Update openssh to 2.1.1p4.jlam8-84/+124
Package changes: * Factor out common post-install code from PLIST and package Makefile into files/INSTALL. * Enhance files/sshd.sh to handle start/stop/restart/status. * Check for usable installed version of OpenSSL. This bit possibly closes the following PRs: 10404, 10501, 10593 Changes from 2.1.1p3: * allow multiple whitespace but only one '=' between tokens * close can fail on AFS * allow leading whitespace in configuration files * Always create ~/.ssh with mode 700
2000-07-20Do not use NO_PACKAGE and NO_CDROM to denote restricted packages. Use therh2-6/+10
appropriate variables instead.
2000-07-20fix illegal name/version differenthubertf1-2/+3
2000-07-18update to 20000719a.itojun2-4/+4
changes: basically, result from TAHI 2nd interop test (www.tahi.org) - phase 1/2 SA removal corrections - remove possible memory leak - no notify message on information exchange - correct isakmp payload manipulation on duplicated payload types
2000-07-18update from racoon 20000701a tree to 20000716a tree.itojun2-4/+4
changes: - RFC2367 conformance for SADB_[AE]ALG_xxx. - implement initial contact - runs in background by default - delete notification - improve error handling
2000-07-17Add patch to make gnupg work on macppc/ELF.wiz2-1/+21
Patch provided by Gabriel Rosenkoetter <gr@eclipsed.net>.
2000-07-17Add Solaris support.veego2-5/+21
2000-07-16Man page is not distributed by itself anymore. (undo last commit, fix itwiz2-7/+2
correctly)
2000-07-16Corrected distfile name (two places) so package builds.mason1-3/+3
2000-07-15No '-' in pkg version!hubertf1-2/+2
2000-07-15Set maintainer to wiz@netbsd.org.wiz1-2/+2
2000-07-15Update gnupg to 1.0.2. NetBSD changes had been mailed to author andwiz6-56/+17
have been integrated. Relevant Changes: * Fixed expiration handling of encryption keys. * Add an experimental feature to do unattended key generation. * The user is now asked for the reason of revocation as required by the new OpenPGP draft. * There is a ~/.gnupg/random_seed file now which saves the state of the internal RNG and increases system performance somewhat. This way the full entropy source is only used in cases were it is really required. Use the option --no-random-seed-file to disable this feature. * New options --ignore-time-conflict and --lock-never. * Encryption is now much faster: About 2 times for 1k bit keys and 8 times for 4k keys. * New encryption keys are generated in a way which allows a much faster decryption. * New command --export-secret-subkeys which outputs the _primary_ key with it's secret parts deleted. This is useful for automated decryption/signature creation as it allows to keep the real secret primary key offline and thereby protecting the key certificates and allowing to create revocations for the subkeys. See the FAQ for a procedure to install such secret keys. * Keygeneration now writes to the first writeable keyring or as default to the one in the homedirectory. Prior versions ignored all --keyring options. * New option --command-fd to take user input from a file descriptor; to be used with --status-fd by software which uses GnuPG as a backend. * There is a new status PROGRESS which is used to show progress during key generation. * Support for the new MDC encryption packets. To create them either --force-mdc must be use or cipher algorithm with a blocksize other than 64 bits is to be used. --openpgp currently disables MDC packets entirely. This option should not yet be used. * New option --no-auto-key-retrieve to disable retrieving of a missing public key from a keyerver, when a keyerver has been set. * Danish, Esperanto, Japanese, Dutch, and Swedish translations
2000-07-15update to 2.1.1p3.itojun11-141/+9
depend on openssl >= 0.9.5. see PR 10593. --- 2.1.1p2 -> 2.1.1p3 20000712 - (djm) Remove -lresolve for Reliant Unix - (djm) OpenBSD CVS Updates: - deraadt@cvs.openbsd.org 2000/07/11 02:11:34 [session.c sshd.c ] make MaxStartups code still work with -d; djm - deraadt@cvs.openbsd.org 2000/07/11 13:17:45 [readconf.c ssh_config] disable FallBackToRsh by default - (djm) Replace in_addr_t with u_int32_t in bsd-inet_aton.c. Report from Ben Lindstrom <mouring@pconline.com> - (djm) Make building of X11-Askpass and GNOME-Askpass optional in RPM spec file. - (djm) Released 2.1.1p3 20000711 - (djm) Fixup for AIX getuserattr() support from Tom Bertelson <tbert@abac.com> - (djm) ReliantUNIX support from Udo Schweigert <ust@cert.siemens.de> - (djm) NeXT: dirent structures to get scp working from Ben Lindstrom <mouring@pconline.com> - (djm) Fix broken inet_ntoa check and ut_user/ut_name confusion, report from Jim Watt <jimw@peisj.pebio.com> - (djm) Replaced bsd-snprintf.c with one from Mutt source tree, it is known to compile on more platforms (incl NeXT). - (djm) Added bsd-inet_aton and configure support for NeXT - (djm) Misc NeXT fixes from Ben Lindstrom <mouring@pconline.com> - (djm) OpenBSD CVS updates: - markus@cvs.openbsd.org 2000/06/26 03:22:29 [authfd.c] cleanup, less cut&paste - markus@cvs.openbsd.org 2000/06/26 15:59:19 [servconf.c servconf.h session.c sshd.8 sshd.c] MaxStartups: limit number of unauthenticated connections, work by theo and me - deraadt@cvs.openbsd.org 2000/07/05 14:18:07 [session.c] use no_x11_forwarding_flag correctly; provos ok - provos@cvs.openbsd.org 2000/07/05 15:35:57 [sshd.c] typo - aaron@cvs.openbsd.org 2000/07/05 22:06:58 [scp.1 ssh-agent.1 ssh-keygen.1 sshd.8] Insert more missing .El directives. Our troff really should identify these and spit out a warning. - todd@cvs.openbsd.org 2000/07/06 21:55:04 [auth-rsa.c auth2.c ssh-keygen.c] clean code is good code - deraadt@cvs.openbsd.org 2000/07/07 02:14:29 [serverloop.c] sense of port forwarding flag test was backwards - provos@cvs.openbsd.org 2000/07/08 17:17:31 [compat.c readconf.c] replace strtok with strsep; from David Young <dyoung@onthejob.net> - deraadt@cvs.openbsd.org 2000/07/08 19:21:15 [auth.h] KNF - ho@cvs.openbsd.org 2000/07/08 19:27:33 [compat.c readconf.c] Better conditions for strsep() ending. - ho@cvs.openbsd.org 2000/07/10 10:27:05 [readconf.c] Get the correct message on errors. (niels@ ok) - ho@cvs.openbsd.org 2000/07/10 10:30:25 [cipher.c kex.c servconf.c] strtok() --> strsep(). (niels@ ok) - (djm) Fix problem with debug mode and MaxStartups - (djm) Don't generate host keys when $(DESTDIR) is set (e.g. during RPM builds) - (djm) Add strsep function from OpenBSD libc for systems that lack it 20000709 - (djm) Only enable PAM_TTY kludge for Linux. Problem report from Kevin Steves <stevesk@sweden.hp.com> - (djm) Match prototype and function declaration for rresvport_af. Problem report from Niklas Edmundsson <nikke@ing.umu.se> - (djm) Missing $(DESTDIR) on host-key target causing problems with RPM builds. Problem report from Gregory Leblanc <GLeblanc@cu-portland.edu> - (djm) Replace ut_name with ut_user. Patch from Jim Watt <jimw@peisj.pebio.com> - (djm) Fix pam sprintf fix - (djm) Cleanup entropy collection code a little more. Split initialisation from seeding, perform intialisation immediatly at start, be careful with uids. Based on problem report from Jim Watt <jimw@peisj.pebio.com> - (djm) More NeXT compatibility from Ben Lindstrom <mouring@pconline.com> Including sigaction() et al. replacements - (djm) AIX getuserattr() session initialisation from Tom Bertelson <tbert@abac.com> 20000708 - (djm) Fix bad fprintf format handling in auth-pam.c. Patch from Aaron Hopkins <aaron@die.net> - (djm) Fix incorrect configure handling of --with-rsh-path option. Fix from Lutz Jaenicke <Lutz.Jaenicke@aet.TU-Cottbus.DE> - (djm) Fixed undefined variables for OSF SIA. Report from Baars, Henk <Hendrik.Baars@nl.origin-it.com> - (djm) Handle EWOULDBLOCK returns from read() and write() in atomicio.c Fix from Marquess, Steve Mr JMLFDC <Steve.Marquess@DET.AMEDD.ARMY.MIL> - (djm) Don't use inet_addr. 20000702 - (djm) Fix brace mismatch from Corinna Vinschen <vinschen@cygnus.com> - (djm) Stop shadow expiry checking from preventing logins with NIS. Based on fix from HARUYAMA Seigo <haruyama@nt.phys.s.u-tokyo.ac.jp> - (djm) Use standard OpenSSL functions in auth-skey.c. Patch from Chris, the Young One <cky@pobox.com> - (djm) Fix scp progress meter on really wide terminals. Based on patch from James H. Cloos Jr. <cloos@jhcloos.com> 20000701 - (djm) Fix Tru64 SIA problems reported by John P Speno <speno@isc.upenn.edu> - (djm) Login fixes from Tom Bertelson <tbert@abac.com> - (djm) Replace "/bin/sh" with _PATH_BSHELL. Report from Corinna Vinschen <vinschen@cygnus.com> - (djm) Replace "/usr/bin/login" with LOGIN_PROGRAM - (djm) Added check for broken snprintf() functions which do not correctly terminate output string and attempt to use replacement. - (djm) Released 2.1.1p2
2000-07-14Introduce the mk.conf definition for PRIV_CONF_DIR, which defaults toagc2-4/+15
${LOCALBASE}/etc, and is the parent directory of the priv package's user configuration data. Modify Makefile to pick up this definition, and pass it on as an argument to the configure script. Modify the PLIST to include this location, and pre-process the PLIST at install time to set the correct location.
2000-07-14Set the correct maintainer for this package.agc1-2/+2
2000-07-14Create the ${PREFIX}/etc/priv directory when the package is installed,agc1-1/+2
pointed out by hubertf.
2000-07-14Add and enable priv.agc1-1/+2
2000-07-14Initial import of priv-1.0-beta, a utility to execute commands as aagc5-0/+41
different user, into the NetBSD packages collection.
2000-07-14Add a patch so that the 64-bit size (from the stat buffer) is printed usingagc2-1/+22
the correct printf-format. From LeRoy Miller (root@gcc.ansic.net) in PR pkg/10478.