<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>OpenSSH | Dev</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/openssh/dev/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>12 Feb  2012 11:52:57 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | OpenSSH | Dev</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/openssh/dev/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>PATCH: multiple BindAddress</title>
<description>Hello all, I recently have a problem with multiple addresses and address families. Problem is simple, i have some hosts with IPv4 access only and some</description>
<pubDate>12 Feb  2012 07:22:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53370</link>
</item><item>
<title>openssh client on Windows 7 key auth issue</title>
<description>Dear All, could anybody be so kind and explain me such situation: I set up OpenSSH client on Windows 7. Then I generated keys pair by &amp;#039;ssh-keygen -t</description>
<pubDate>10 Feb  2012 08:51:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53366</link>
</item><item>
<title>Restrict commands available in an SFTP session</title>
<description>Hello, i am using SFTP with CHROOT. I want to allow my users that they can upload  and download with the sftp server, but they should never do an MK</description>
<pubDate>09 Feb  2012 05:08:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53361</link>
</item><item>
<title>Having issues with remote command execution - ssh -t host &amp;#039;sudo command&amp;#039;</title>
<description>I&amp;#039;ve been trying to find an answer on other sites however I could not resolve my problem. spec: os: ubuntu 10.0, OpenSSH_5.5p1 Debian-4ubuntu4, OpenS</description>
<pubDate>08 Feb  2012 15:11:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53357</link>
</item><item>
<title>Suggestion for openssh</title>
<description>Hi! I do not know if it&amp;#039;s the ideal place, but I&amp;#039;m sending some suggestion. Always use openssh and its enormous features. - I needed to create an en</description>
<pubDate>07 Feb  2012 04:04:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53350</link>
</item><item>
<title>Potential memory leak in sshd [detected by melton]</title>
<description>Hi all, After the memory leaks (bug 1967 &amp;lt;https://bugzilla.mindrot.org/show_bug.cgi?id=1967&amp;gt;) I reported in bugzilla are fixed, I also applied melto</description>
<pubDate>03 Feb  2012 17:55:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53319</link>
</item><item>
<title>PATCH: Fix memory leak in sshd</title>
<description>Hello, The below patch fixes a memory leak I noticed in monitor_read_load() when the child&amp;#039;s log pipe is closed. Thanks, Zev Weiss -- diff --git a/</description>
<pubDate>28 Jan  2012 01:30:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53301</link>
</item><item>
<title>PATCH: Support for encrypted host keys</title>
<description>Hello all, I recently found myself wanting to run sshd with passphrase-protected host keys rather than the usual unencrypted format, and was somewhat</description>
<pubDate>28 Jan  2012 01:25:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53300</link>
</item><item>
<title>PermitOpen None diff</title>
<description>Hi, I was wondering if this diff would make it into the next release: https://bugzilla.mindrot.org/show_bug.cgi?id=1949 Thanks, //Logan C-x-C-c --</description>
<pubDate>26 Jan  2012 05:29:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53298</link>
</item><item>
<title>Server/Client Alive mechanism issues</title>
<description>Hello, I have a bandwidth-constrained connection that I&amp;#039;d like to run rsync over through an SSH tunnel. I also want to detect any network drops prett</description>
<pubDate>25 Jan  2012 09:26:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53292</link>
</item><item>
<title>Solaris BSM audit support</title>
<description>Does anyone know if openssh has removed the experimental designation for BSM audit support for Solaris systems? If so, which release, please. Thanks.</description>
<pubDate>24 Jan  2012 12:22:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53291</link>
</item><item>
<title>Patterns in HostName ?</title>
<description>I have a Unix host that&amp;#039;s DHCPd, so resolv.conf is rewritten. Because of company policies, it&amp;#039;s not allowed to change the client dhcp config to overr</description>
<pubDate>23 Jan  2012 07:46:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53286</link>
</item><item>
<title>Regarding Pubkey Enumeration</title>
<description>HD Moore from MetaSploit has noted that, given a pubkey (and not the corresponding private key, as might be found in authorized_keys), he can determin</description>
<pubDate>20 Jan  2012 01:18:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53269</link>
</item><item>
<title>Donation of 10 ePass2003 to the OpenSSH project</title>
<description>Dear all, There were a lot of discussions about smartcards and tokens, and we would like to make a simple offer: donate to each OpenSSH developer an</description>
<pubDate>20 Jan  2012 01:08:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53268</link>
</item><item>
<title>ChrootDirectory per SSH Subsystem?</title>
<description>Hi, According to the sshd_config manual page the option ChrootDirectory can be used to force a chroot:ed environment for the SSHD server. But as I un</description>
<pubDate>19 Jan  2012 05:38:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53252</link>
</item><item>
<title>sftp-server vs. internal-sftp</title>
<description>Hi guys,   Given that internal-sftp is the only way to support chrooted users, is there any particular reason why sftp-server is still the default</description>
<pubDate>16 Jan  2012 16:10:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53251</link>
</item><item>
<title>X.509 certificate integration continue with PKCS11 and FIPS capable OpenSSL</title>
<description>Hello list members, I would like to inform that version 7.1 of X.509 certificate support) is ready. The just published update from &amp;quot;Integration&amp;quot; se</description>
<pubDate>15 Jan  2012 11:38:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53250</link>
</item><item>
<title>[PATCH 1/1] Ported gnome-ssh-askpass2 to gtk3.</title>
<description>Hello List, This is for the portable release. I wanted gnome-ssh-askpass to be a gtk+3 app, so I made a quick port. Mark ---  contrib/Makefile</description>
<pubDate>13 Jan  2012 02:48:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53248</link>
</item><item>
<title>Request for obfuscating the handshake</title>
<description>Dear OpenSSH team, First of all thanks a lot for your good work on developing such a usable peace of software. Nice job. As you may know, we have som</description>
<pubDate>12 Jan  2012 10:58:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53240</link>
</item><item>
<title>scp should not report 100% until the last byte is transferred</title>
<description>Hello, just my opinion, but yesterday I run into a case, where after 7 hours of transferring a file (a little bit greater than 1 GB) the scp reporte</description>
<pubDate>12 Jan  2012 00:46:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53236</link>
</item><item>
<title>Full replay logs of OpenSSH sessions</title>
<description>Hi all, I am not 100% sure if this is a -dev or a -user topic, but I am leaning towards the former. Feel free to cuss at me and tell me to ask -user,</description>
<pubDate>11 Jan  2012 04:02:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53231</link>
</item><item>
<title>Configuration file TCPKeepAlive option does not work reliably</title>
<description>Hi! There are configuration knobs (TCPKeepAlive) to enable/disable the use of TCP keepalives both in the ssh client and server. Unfortunately some UN</description>
<pubDate>10 Jan  2012 07:34:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53228</link>
</item><item>
<title>Interop problem with IPSSH-6.6.0, CR/NL?</title>
<description>I have a curious problem connecting with OpenSSH (5.1p1 on FreeBSD, 6.0-beta on OpenBSD) to some managed switches running &amp;quot;IPSSH-6.6.0&amp;quot;. When I conne</description>
<pubDate>04 Jan  2012 13:59:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53219</link>
</item><item>
<title>ECDSA, SSHFP, and &amp;quot;Error calculating host key fingerprint.&amp;quot;</title>
<description>When connecting to a host that provides an ECDSA host key and the client has &amp;quot;VerifyHostKeyDNS&amp;quot; set to &amp;#039;yes&amp;#039; or &amp;#039;ask&amp;#039; SSH outputs a mysterious and und</description>
<pubDate>03 Jan  2012 16:56:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53216</link>
</item><item>
<title>A probable useful feature</title>
<description>Hi, As I mentioned in the following post : http://www.linuxquestions.org/questions/linux-security-4/exclude-a-from-being-logged-in-var-log-wtmp-9208</description>
<pubDate>31 Dec  2011 01:40:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53211</link>
</item><item>
<title>sshd: Allow more directives in Match-Block</title>
<description>Hi, I think, there are some more directives, which could be allowed in the Match block in the sshd_config. For myself, i needed PrintMotd, PrintLast</description>
<pubDate>20 Dec  2011 07:23:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53199</link>
</item><item>
<title>ssh-copy-id -p port option</title>
<description>Hi. I would like to add an option [-p port] to ssh-copy-id. If this option is given then ssh-copy-id calls ssh with -p port to connect to non-standa</description>
<pubDate>20 Dec  2011 06:31:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53198</link>
</item><item>
<title>Retrieving authorized_keys via remote script</title>
<description>Here&amp;#039;s a simple patch which retrieves authorized_keys via exec&amp;#039;ing a program, rather than reading a flat file. I added a simple option, AuthorizedKe</description>
<pubDate>14 Dec  2011 16:23:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53175</link>
</item><item>
<title>ssh-agent and IdentityFile</title>
<description>I&amp;#039;ve noticed that the ssh-agent applies any keys it already has passwords for (via ssh-add) first, overriding the ssh config files for preferred ident</description>
<pubDate>13 Dec  2011 14:52:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53171</link>
</item><item>
<title>ssh-keygen -K option</title>
<description>Hi there,    I&amp;#039;m in the process of generating a moduli file under Linux with 5.9p1 version which in fact takes quite some time for the big primes t</description>
<pubDate>10 Dec  2011 04:18:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53155</link>
</item><item>
<title>Proposal for SFTP extension to include user name and group name in file attributes</title>
<description>Hello, I&amp;#039;ve gathered from searching Bugzilla[1][2] that a patch to update OpenSSH&amp;#039;s SFTP implementation to support version 4 or above of the protocol</description>
<pubDate>09 Dec  2011 11:53:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53151</link>
</item><item>
<title>Converting SSH2 keys for use in OpenSSH</title>
<description>I have a couple of keys generated using the F-Secure SSH2 client. I have converted those keys using &amp;quot;ssh-keygen -i -f samplekey.txt &amp;gt;&amp;gt; ~/.ssh/authoriz</description>
<pubDate>07 Dec  2011 16:54:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53148</link>
</item><item>
<title>AllowUsers</title>
<description>Hi guys, i think, that we have found an issue in the config &amp;quot;sshd_config&amp;quot;. The correct way is, to set AllowUsers in the config like this:  &amp;gt; AllowU</description>
<pubDate>05 Dec  2011 11:38:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53141</link>
</item><item>
<title>Bad protocol version identification from UNKNOWN (patch)</title>
<description>I was just helping someone track down why they were getting a &amp;quot;Bad protocol version identification&amp;quot; error for sshd, and I noticed that it was logging</description>
<pubDate>01 Dec  2011 08:17:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53096</link>
</item><item>
<title>Server moved</title>
<description>Hi, The server move was completed over the weekend. Please let me know if anything is broken. -d _______________________________________________ ope</description>
<pubDate>27 Nov  2011 15:23:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53082</link>
</item><item>
<title>Feature request: LDAP public keys</title>
<description>Hello, Are there any plans to include this feature in future releases? There&amp;#039;s a project running for this, patches are available. http://code.google.</description>
<pubDate>23 Nov  2011 03:52:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53075</link>
</item><item>
<title>user creation before authentication</title>
<description>Hi, I am working on the following SSH solution and I need some help: 1. User ssh against my node where he/she does not have an account 2. Firstly the</description>
<pubDate>22 Nov  2011 06:57:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53072</link>
</item><item>
<title>ssh-keygen -r should support SSHFP records for ECDSA (or at least return non-zero error code on failure)</title>
<description>hi folks: it looks like ssh-keygen -r can&amp;#039;t export SSHFP records for ECDSA keys: 0 dkg@pip:/tmp/cdtemp.oiRYAS$ ssh-keygen -f foobar -t ecdsa -q -P &amp;#039;</description>
<pubDate>21 Nov  2011 07:29:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53070</link>
</item><item>
<title>list/bugzilla downtime</title>
<description>Hi, The mailing lists and bugzilla are going to be down for a bit while I move the server to a new, better connected and cheaper to operate home. I&amp;#039;</description>
<pubDate>20 Nov  2011 20:16:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53067</link>
</item><item>
<title>Wrong permissions for $HOME</title>
<description>Hi, today me and a friend of mine spent several hours figuring out why ssh still asked for a password after we set up public key authentication. We h</description>
<pubDate>18 Nov  2011 10:02:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53060</link>
</item><item>
<title>Is there a documentation of the key file formats?</title>
<description>Hello, part of a usual OpenSSH installation are quite some files containing key material, like private keys (id_rsa, id_dsa, id_ecdsa) and the corres</description>
<pubDate>14 Nov  2011 09:40:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53056</link>
</item><item>
<title>SCP fails to locate remote file: &amp;#039;-- &amp;lt;filename&amp;gt;&amp;#039;</title>
<description>I am not sure if many people have run into this, but recently working  with some non-standard SSH capable devices, Routers, Firewalls and  Switches,</description>
<pubDate>11 Nov  2011 08:57:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53051</link>
</item><item>
<title>Strange behaviour of ssh</title>
<description>Hello together! I&amp;#039;ve Debian 6.0.3 with OpenSSH_5.5p1 and problem with the execution of remote commands via ssh. It seems as if the first command isn&amp;#039;</description>
<pubDate>07 Nov  2011 03:28:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53042</link>
</item><item>
<title>PermitOpen none option diff</title>
<description>Hi, After reading the previous thread. I decided to give it a try. http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=543683 Here&amp;#039;s the diff (written</description>
<pubDate>06 Nov  2011 05:03:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53041</link>
</item><item>
<title>FW: Help with CA Certificates for user authentication?</title>
<description>My apologies to the list for inadvertently taking this offline. As info: -----Original Message----- From: Iain Morgan [mailto:Iain.Morgan@nasa.gov]</description>
<pubDate>05 Nov  2011 04:42:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53039</link>
</item><item>
<title>Help with CA Certificates for user authentication?</title>
<description>As background, I read: http://therowes.net/~greg/2011/03/23/ssh-trusted-ca-key/ http://www.ibm.com/developerworks/aix/library/au-sshsecurity/ http://</description>
<pubDate>02 Nov  2011 23:50:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/53012</link>
</item><item>
<title>ssh-agent use in different security domains</title>
<description>Consider this topology         domain1-server1   domain2-server2               |               |   laptop -</description>
<pubDate>25 Oct  2011 00:57:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52980</link>
</item><item>
<title>problem using sshd inside a LXC container</title>
<description>Currently I have a RH6.1 host with selinux enabled On this I am running a LXC container with ubuntu (without selinux) with OpenSSH_5.3p1 Debian-3ubunt</description>
<pubDate>24 Oct  2011 04:38:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52973</link>
</item><item>
<title>[patch/cygwin] don&amp;#039;t require doc files</title>
<description>Hi, could somebody with checkin rights please apply the below patch? It only changes the Cygwin specific installation so that it doesn&amp;#039;t bail out if</description>
<pubDate>24 Oct  2011 03:40:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52974</link>
</item><item>
<title>problem with a tty</title>
<description>hello everyone I&amp;#039;m writing an application which execute ssh, I communicate with a ssh process by stdin/stdout. Everything works fine, but lately I&amp;#039;ve</description>
<pubDate>24 Oct  2011 01:11:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52972</link>
</item><item>
<title>Creating a reverse socket often (not always) fails.</title>
<description>Hi, I&amp;#039;m a little stuck on getting reverse connection working reliably from embedded devices running dropbear 0.51 to Ubuntu 8.x openssh. Connecting t</description>
<pubDate>21 Oct  2011 20:39:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52968</link>
</item><item>
<title>Handing connection depending on the client computer public key fingerprint</title>
<description>Hello,  I try to find a way to handle SSH connections differently depending if it comes from a &amp;#039;trusted&amp;quot; computer or from an unknown computer (for in</description>
<pubDate>21 Oct  2011 13:40:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52966</link>
</item><item>
<title>Determining the port assigned by -R 0</title>
<description>It&amp;#039;s difficult to programmatically determine the port dynamically assigned by -R 0. The port is output in plain (and presumably localized) text, but</description>
<pubDate>14 Oct  2011 13:55:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52931</link>
</item><item>
<title>[PATCH] Fix control persist and stdio forward interaction</title>
<description>As reported earlier at https://lists.mindrot.org/pipermail/openssh-unix-dev/2011-March/029441.html there is some strange interaction between Control</description>
<pubDate>13 Oct  2011 02:18:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52924</link>
</item><item>
<title>scp with different users</title>
<description>This may be a dumb question, but is there any reason why  scp a@b:c d: fails, where  scp a@b:c .  scp c d: succeeds? I get &amp;quot;Host key verification</description>
<pubDate>10 Oct  2011 12:36:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52914</link>
</item><item>
<title>Channel life span</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, Basic context for my questions: Client (ssh) and server side (sshd) where the client use -L optio</description>
<pubDate>10 Oct  2011 09:38:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52912</link>
</item><item>
<title>Restricting users using one port</title>
<description>I have ssh running on port 22 and (say) port 33333. Port 22 is restricted at layer 3 so not much can get to it. Port 33333 is open to the world. I on</description>
<pubDate>09 Oct  2011 01:15:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52909</link>
</item><item>
<title>[PATCH] add log= directive to authorized_hosts</title>
<description>Attached is a patch which adds a log= directive to authorized_keys. The text in the log=&amp;quot;text&amp;quot; directive is appended to the log line, so you can easil</description>
<pubDate>08 Oct  2011 07:05:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52904</link>
</item><item>
<title>Detect PID of sshd processes used by one public key; detect -R allocated port on the server</title>
<description>I have a situation where a number of potentially hostile clients ssh to a host I control, each ssh&amp;#039;ing in as the same user, and each forwarding a remo</description>
<pubDate>08 Oct  2011 02:01:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52898</link>
</item><item>
<title>OpenSSH hanging</title>
<description>Hi there,  I&amp;#039;m having some strange behaviour from OpenSSH  It presents itself when using the &amp;quot;ssh -t&amp;quot; / pseudo terminal.  We are using this feat</description>
<pubDate>06 Oct  2011 15:58:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52896</link>
</item><item>
<title>Information on command execution in sshd</title>
<description>Hi, I was going through the code of open ssh server part ( code for sshd ). My query is when user gives any command ( for example unix command &amp;quot;ls&amp;quot;)</description>
<pubDate>02 Oct  2011 05:22:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52878</link>
</item><item>
<title>Interop problem with old dropbear and new openssh</title>
<description>Hi, I have a router running an old version of OpenWRT with an old version of dropbear (Dropbear sshd v0.44test3). It has been working for many year</description>
<pubDate>30 Sep  2011 14:45:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52869</link>
</item><item>
<title>openssh remote port forwarding and permitopen</title>
<description>I have an application where a lot of end user CPE devices ssh in automatically to a central server, and are authenticated by public key, to do remote</description>
<pubDate>30 Sep  2011 08:22:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52862</link>
</item><item>
<title>sizeof(char)</title>
<description>I was scanning through my config.h and noticed something that startled me a bit. The configure script actually checks what sizeof(char) is, and defin</description>
<pubDate>28 Sep  2011 17:32:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52858</link>
</item><item>
<title>Fingerprint mismatch upon cvs update</title>
<description>Hello, a moment ago i got this: : @@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@ : @  WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED</description>
<pubDate>28 Sep  2011 04:29:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52856</link>
</item><item>
<title>Support for ecc</title>
<description>Hi All, I think I know the answer. However, I would like to confirm my understanding. Does openssh support the usage of ecc keys? Any plan for suppo</description>
<pubDate>25 Sep  2011 22:23:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52849</link>
</item><item>
<title>sshd 5.6p1 does not accept connections in fips mode</title>
<description>Hi, I was trying to run sshd after applying the fips patches mentioned in  http://www.gossamer-threads.com/lists/engine?do=post_attachment;postatt_</description>
<pubDate>25 Sep  2011 15:10:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52848</link>
</item><item>
<title>which sftp protocol is openssh or sftp-server using or support?</title>
<description>Hi, After reading the source code of openssh and man page of sftp. In sftp.h it define 27 /* 28 * draft-ietf-secsh-filexfer-01.txt 29 */ 30 31 /*</description>
<pubDate>21 Sep  2011 18:34:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52782</link>
</item><item>
<title>Different HostKeys for different hostnames or IPs in the same sshd?..</title>
<description>Hello! Like many organizations, we have &amp;quot;disaster-recovery&amp;quot; location, where separate servers are running ready to take up important services should</description>
<pubDate>20 Sep  2011 13:12:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52768</link>
</item><item>
<title>weird make errors on portable snapshots</title>
<description>When doing a make with the portable developer version, I came across this error:  ssh/ssh_host_ecdsa_key|/opt/etc/ssh_host_ecdsa_key|g&amp;#039; -e &amp;#039;s|/etc/s</description>
<pubDate>16 Sep  2011 09:42:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52746</link>
</item><item>
<title>sftp memory leak patch</title>
<description>Hi, I was wondering if there were issues with this diff: https://bugzilla.mindrot.org/show_bug.cgi?id=1921 -- `` Real men run current !&amp;#039;&amp;#039; ________</description>
<pubDate>11 Sep  2011 02:04:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52703</link>
</item><item>
<title>SSH Compression - Block Deduplication</title>
<description>Hello, I did a search against the list archive and didn&amp;#039;t see any comments on the topic of using deduplication as a compression algorithm. This is</description>
<pubDate>09 Sep  2011 10:03:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52692</link>
</item><item>
<title>Announce: X.509 certificates support v7.0 for OpenSSH version 5.9p1</title>
<description>Hi All, Version 7.0 of &amp;quot;X.509 certificates support in OpenSSH&amp;quot; is ready for immediate download. This version allow client to use certificates and k</description>
<pubDate>08 Sep  2011 09:39:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52678</link>
</item><item>
<title>Dynamic port remote listener - a BUG?</title>
<description>Hello, Today I tried using &amp;quot;dynamically assigned&amp;quot; port for remote listener, by requesting listener on port 0. This is supposed to create a listener o</description>
<pubDate>08 Sep  2011 08:24:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52687</link>
</item><item>
<title>ssh_SSLeay_add_all_algorithms()</title>
<description>I am confused on how ssh_SSLeay_add_all_algorithms() get used in the ssh applications for openssh-5.7p1 and later releases. I don&amp;#039;t see any of the app</description>
<pubDate>08 Sep  2011 06:33:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52674</link>
</item><item>
<title>cipher_get_keycontext() and cipher_set_keycontext() copying OpenSSL RC4 cryptographic state</title>
<description>These two functions in cipher.c (I have looked at openssh5.8p1 &amp;amp; openssh5.9p1) copy the internal cryptographic state of an OpenSSL RC4 encryption/decr</description>
<pubDate>07 Sep  2011 07:34:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52673</link>
</item><item>
<title>mac_int() does not call HMAC_CTX_init()</title>
<description>Last year I sent the email below describing a bug in openssh 5.6p1. I just noticed this bug still exists in 5.9p1. Probably my earlier email was trea</description>
<pubDate>06 Sep  2011 07:36:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52652</link>
</item><item>
<title>error in openssh-5.9p1 release</title>
<description>Hi, Some of the more observant of you have noticed that the just-released OpenSSH-5.9p1 identifies itself as OpenSSH-5.9p2. Don&amp;#039;t be worried - it is</description>
<pubDate>06 Sep  2011 05:16:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52649</link>
</item><item>
<title>Announce: OpenSSH 5.9 released</title>
<description>OpenSSH 5.9 has just been released. It will be available from the mirrors listed at http://www.openssh.com/ shortly. OpenSSH is a 100% complete SSH p</description>
<pubDate>05 Sep  2011 22:29:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52645</link>
</item><item>
<title>scp fails after sending command: scp -v -t</title>
<description>I encounter a strange problem with scp / sftp: I travel quite a bit. Normally I never have had any problems using ssh / scp / sftp to connect from my</description>
<pubDate>03 Sep  2011 08:43:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52470</link>
</item><item>
<title>problems building openssh-5.8p1 on qnx</title>
<description>I am having trouble figuring out how to build openssh-5.8p1 for QNX 6.5. I am trying to build on linux, cross-compiling for armv7. If I configure like</description>
<pubDate>02 Sep  2011 04:33:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52462</link>
</item><item>
<title>pkcs and host keys</title>
<description>Hi Damien, I see in your asia bsdcon presentation you mentioned the possibility of storing host keys in PKCS #11. I&amp;#039;m interested in using a usb rsa</description>
<pubDate>01 Sep  2011 20:22:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52460</link>
</item><item>
<title>Auth forwarding socket for single auth</title>
<description>Hi all, authentication forwarding depends much on the environment it is used in, but generally on shared hosts it is considered insecure, as this doc</description>
<pubDate>29 Aug  2011 08:50:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52452</link>
</item><item>
<title>Unable to execute the commands at remote machine after RSA handshake</title>
<description>HI,      I am succeeded to do the password less authonitication but unable to execute the command and get the command OUTPUT/ERROR message. Below</description>
<pubDate>26 Aug  2011 05:45:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52437</link>
</item><item>
<title>Add missing -o options in ssh(1) manual</title>
<description>A few options appear to be missing from the list in ssh&amp;#039;s manual. The one I didn&amp;#039;t add is EnableSSHKeysign, whose description implies it is only effec</description>
<pubDate>25 Aug  2011 12:31:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52434</link>
</item><item>
<title>Fwd: PAM module: To analyse if user is using password or passwordless authentication</title>
<description>I am writing a PAM module for ssh service. I would like to know how can I determine within the PAM module if user is using password or password-less (</description>
<pubDate>25 Aug  2011 03:52:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52432</link>
</item><item>
<title>OpenSSH on ULTRIX</title>
<description>Hi, not sure if this is considered news, but I have been able to build OpenSSH 5.8p2 on mips-dec-ultrix4.5. On my system I have ULTRIX 4.5 with the l</description>
<pubDate>22 Aug  2011 04:17:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52427</link>
</item><item>
<title>authorized_credentials patch.</title>
<description>Gives GSSAPI-MIC the same options capability currently provided for public key logins by the AuthorizedKeysFile. Uses krb5_principal_match() to supp</description>
<pubDate>20 Aug  2011 12:52:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52420</link>
</item><item>
<title>secureshell@securityfocus.com list dead?</title>
<description>Hello, anybody knows what happened to the ssh user mailing list on secureshell@securityfocus.com? it seems to be dead for more than two months now. I</description>
<pubDate>18 Aug  2011 12:17:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52417</link>
</item><item>
<title>RSA_public_decrypt and FIPS</title>
<description>Does anyone knows if there is a patch for OpenSSH in order to make it work with 0.9.8r OpenSSL in FIPS Mode ? I&amp;#039;m having problem with the RSA_public_d</description>
<pubDate>18 Aug  2011 09:47:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52416</link>
</item><item>
<title>Re: openssh-unix-dev Digest, Vol 100, Issue 3</title>
<description>Works on my netbsd tinkerbox. NetBSD 5.0.2 NetBSD 5.0.2 (GENERIC) It uses rlimit. Privsep sandbox style: rlimit I also get warnings during make.</description>
<pubDate>17 Aug  2011 04:11:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52404</link>
</item><item>
<title>MaxSessions option in sshd_config</title>
<description>Hi, I need information regarding MaxSessions option in sshd_config. As i understand, it defines the maximum number of channels that can be opened at</description>
<pubDate>16 Aug  2011 08:51:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52391</link>
</item><item>
<title>Call for testing: OpenSSH-5.9</title>
<description>Hi, OpenSSH 5.9 is almost ready for release, so we would appreciate testing on as many platforms and systems as possible. This release contains a cou</description>
<pubDate>13 Aug  2011 17:30:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52382</link>
</item><item>
<title>configure bug for HAVE_RES_EXTERN check</title>
<description>The code used in configure.ac to check for struct __res_state _res is an extern, can fail. I&amp;#039;m porting the code to UWIN, (Unix on Windows, available a</description>
<pubDate>08 Aug  2011 11:17:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52357</link>
</item><item>
<title>Typo in sftp.1 manpage</title>
<description>Hello, Just found a typo in sftp.1 manpage: s/ether/either/ Regards -- ^L. _______________________________________________ openssh-unix-dev mailin</description>
<pubDate>07 Aug  2011 05:39:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52346</link>
</item><item>
<title>How does one download SSHredder?</title>
<description>Hi, In doing some google search on SSH security verification came across mention of program called SSHredder. ( http://developers.slashdot.org/story/</description>
<pubDate>05 Aug  2011 11:56:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52331</link>
</item><item>
<title>Typo in a manpage</title>
<description>Hello, There&amp;#039;s a typo in moduli.5 manpage. I&amp;#039;m not quite sure it needs a patch. Anyway, the fix is: s/primaility/primality/ Regards -- ^L. ______</description>
<pubDate>05 Aug  2011 10:03:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52332</link>
</item><item>
<title>Anti-MITMA method of Samy Kamkar</title>
<description>Hi, I wonder if OpenSSH has the following method against MITMA already implemented or not: &amp;quot; Anti-MITMA: Preventing Man in the Middle Attacks Code a</description>
<pubDate>03 Aug  2011 16:05:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52326</link>
</item><item>
<title>OpenSSH and FIPS 140-2</title>
<description>Does anyone knows why in some OpenSSH patches for FIPS we have something like: SSLeay_add_all_algorithms(); if (FIPS_mode() &amp;amp;&amp;amp; !FIPSCHECK_verify(NULL</description>
<pubDate>03 Aug  2011 09:31:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52325</link>
</item><item>
<title>Adding fflush() to ssh-agent so its output can be redirected to a file</title>
<description>Without this patch &amp;quot;ssh-agent -d &amp;gt; ~/ssh-agent.sh&amp;quot; will produce a zero byte file. Obviously a corner case, but for what I&amp;#039;m doing it&amp;#039;s a show-stopper,</description>
<pubDate>01 Aug  2011 21:36:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/openssh/dev/52319</link>
</item>
</channel>
</rss>

