Changelog for
openssh-server-7.8p1-3.fc29.x86_64.rpm :
* Mon Sep 24 2018 Jakub Jelen
- 7.8p1-3 + 0.10.3-5- Disable OpenSSH hardening flags and use the ones provided by system- Ignore unknown parts of PKCS#11 URI- Do not fail with GSSAPI enabled in match blocks (#1580017)- Fix the segfaulting cavs test (#1628962)
* Fri Aug 31 2018 Jakub Jelen - 7.8p1-2 + 0.10.3-5- New upstream release fixing CVE 2018-15473- Remove unused patches- Remove reference to unused enviornment variable SSH_USE_STRONG_RNG- Address coverity issues- Unbreak scp between two IPv6 hosts- Unbreak GSSAPI key exchange (#1624344)- Unbreak rekeying with GSSAPI key exchange (#1624344)
* Thu Aug 09 2018 Jakub Jelen - 7.7p1-6 + 0.10.3-4- Fix listing of kex algoritms in FIPS mode- Allow aes-gcm cipher modes in FIPS mode- Coverity fixes
* Fri Jul 13 2018 Fedora Release Engineering - 7.7p1-5.1- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
* Tue Jul 03 2018 Jakub Jelen - 7.7p1-5 + 0.10.3-4- Disable manual printing of motd by default (#1591381)
* Wed Jun 27 2018 Jakub Jelen - 7.7p1-4 + 0.10.3-4- Better handling of kerberos tickets storage (#1566494)- Add pam_motd to pam stack (#1591381)
* Mon Apr 16 2018 Jakub Jelen - 7.7p1-3 + 0.10.3-4- Fix tun devices and other issues fixed after release upstream (#1567775)
* Thu Apr 12 2018 Jakub Jelen - 7.7p1-2 + 0.10.3-4- Do not break quotes parsing in configuration file (#1566295)
* Wed Apr 04 2018 Jakub Jelen - 7.7p1-1 + 0.10.3-4- New upstream release (#1563223)- Add support for ECDSA keys in PKCS#11 (#1354510)- Add support for PKCS#11 URIs
* Tue Mar 06 2018 Jakub Jelen - 7.6p1-7 + 0.10.3-3- Require crypto-policies version and new path- Remove bogus NSS linking
* Thu Feb 08 2018 Fedora Release Engineering - 7.6p1-6.1- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
* Fri Jan 26 2018 Jakub Jelen - 7.6p1-6 + 0.10.3-3- Rebuild for gcc bug on i386 (#1536555)
* Thu Jan 25 2018 Florian Weimer - 7.6p1-5.2- Rebuild to work around gcc bug leading to sshd miscompilation (#1538648)
* Sat Jan 20 2018 Björn Esser - 7.6p1-5.1.1- Rebuilt for switch to libxcrypt
* Wed Jan 17 2018 Jakub Jelen - 7.6p1-5 + 0.10.3-3- Drop support for TCP wrappers (#1530163)- Do not pass hostnames to audit -- UseDNS is usually disabled (#1534577)
* Thu Dec 14 2017 Jakub Jelen - 7.6p1-4 + 0.10.3-3- Whitelist gettid() syscall in seccomp filter (#1524392)
* Mon Dec 11 2017 Jakub Jelen - 7.6p1-3 + 0.10.3-3- Do not segfault during audit cleanup (#1524233)- Avoid gcc warnings about uninitialized variables
* Wed Nov 22 2017 Jakub Jelen - 7.6p1-2 + 0.10.3-3- Do not build everything against libldap- Do not segfault for ECC keys in PKCS#11
* Thu Oct 19 2017 Jakub Jelen - 7.6p1-1 + 0.10.3-3- New upstream release OpenSSH 7.6- Addressing review remarks for OpenSSL 1.1.0 patch- Fix PermitOpen bug in OpenSSH 7.6- Drop support for ExposeAuthenticationMethods option
* Mon Sep 11 2017 Jakub Jelen - 7.5p1-6 + 0.10.3-2- Do not export KRB5CCNAME if the default path is used (#1199363)- Add enablement for openssl-ibmca and openssl-ibmpkcs11 (#1477636)- Add new GSSAPI kex algorithms with SHA-2, but leave them disabled for now- Enforce pam_sepermit for all logins in SSH (#1492313)- Remove pam_reauthorize, since it is not needed by cockpit anymore (#1492313)
* Mon Aug 14 2017 Jakub Jelen - 7.5p1-5 + 0.10.3-2- Another less-intrusive approach to crypto policy (#1479271)
* Tue Aug 01 2017 Jakub Jelen - 7.5p1-4 + 0.10.3-2- Remove SSH-1 subpackage for Fedora 27 (#1474942)- Follow system-wide crypto policy in server (#1479271)
* Thu Jul 27 2017 Fedora Release Engineering - 7.5p1-3.1- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
* Fri Jun 30 2017 Jakub Jelen - 7.5p1-2 + 0.10.3-2- Sync downstream patches with RHEL (FIPS)- Resolve potential issues with OpenSSL 1.1.0 patch
* Wed Mar 22 2017 Jakub Jelen - 7.5p1-2 + 0.10.3-2- Fix various after-release typos including failed build in s390x (#1434341)- Revert chroot magic with SELinux
* Mon Mar 20 2017 Jakub Jelen - 7.5p1-1 + 0.10.3-2- New upstream release
* Fri Mar 03 2017 Jakub Jelen - 7.4p1-4 + 0.10.3-1- Avoid sending the SD_NOTIFY messages from wrong processes (#1427526)- Address reports by coverity
* Mon Feb 20 2017 Jakub Jelen - 7.4p1-3 + 0.10.3-1- Properly report errors from included files (#1408558)- New pam_ssh_agent_auth 0.10.3 release- Switch to SD_NOTIFY to make systemd happy
* Mon Feb 06 2017 Jakub Jelen - 7.4p1-2 + 0.10.2-5- Fix ssh-agent cert signing error (#1416584)- Fix wrong path to crypto policies- Attempt to resolve issue with systemd
* Tue Jan 03 2017 Jakub Jelen - 7.4p1-1 + 0.10.2-5- New upstream release (#1406204)- Cache supported OIDs for GSSAPI key exchange (#1395288)- Fix typo causing heap corruption (use-after-free) (#1409433)- Prevent hangs with long MOTD
* Thu Dec 08 2016 Jakub Jelen - 7.3p1-7 + 0.10.2-4- Properly deserialize received RSA certificates in ssh-agent (#1402029)- Move MAX_DISPLAYS to a configuration option
* Wed Nov 16 2016 Jakub Jelen - 7.3p1-6 + 0.10.2-4- GSSAPI requires futex syscall in privsep child (#1395288)
* Thu Oct 27 2016 Jakub Jelen - 7.3p1-5 + 0.10.2-4- Build against OpenSSL 1.1.0 with compat changes- Recommend crypto-policies- Fix chroot dropping capabilities (#1386755)
* Thu Sep 29 2016 Jakub Jelen - 7.3p1-4 + 0.10.2-4- Fix NULL dereference (#1380297)- Include client Crypto Policy (#1225752)