add skey openssh

This commit is contained in:
burakerturk
2015-07-16 02:47:42 +03:00
parent 72afa0ce95
commit 5139510106
23 changed files with 6350 additions and 2 deletions
+191
View File
@@ -36515,6 +36515,108 @@ uses SIMD instructions (MMX, SSE2, etc.) to accelerate baseline JPEG compression
</Update>
</History>
</SpecFile>
<SpecFile>
<Source>
<Name>openssh</Name>
<Homepage>http://www.openssh.com/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>BSD</License>
<IsA>app:console</IsA>
<IsA>service</IsA>
<PartOf>server</PartOf>
<Summary xml:lang="en">Port of OpenBSD&apos;s free SSH release</Summary>
<Summary xml:lang="tr">OpenBSD&apos;den aktarılmış SSH sürümü</Summary>
<Description xml:lang="fr">OpenSSH est une version libre des outils de connexion SSH sur lesquels les utilisateurs techniquement chevronnés s&apos;appuient. Les utilisateurs de telnet, rlogin et ftp ne se rendent peut être pas compte que les mots de passe sont transmis sur internet en clair. OpenSSH crypte tout le trafic (y compris les mots de passe) pour éliminer les écoutes passives, les détournements de connexion et autres attaques.</Description>
<Description xml:lang="en">OpenSSH is a FREE version of the SSH connectivity tools that technical users of the Internet rely on. Users of telnet, rlogin, and ftp may not realize that their password is transmitted across the Internet unencrypted, but it is. OpenSSH encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other attacks.</Description>
<Description xml:lang="tr">OpenSSH teknik internet kullanıcıların güvendikleri SSH bağlanırlık araçlarının Özgür (free) sürümüdür.telnet, rlogin ve ftp kullanıcıları parolalarının internetten şifresiz olarak aktarıldığını anlayamayabilirler ancak aktarılmaktadır.OpenSSH eavesdropping (iletişim kanalını dinleme), connection hijacking (bağlantı çalma) ve diğer atakları önlemek için tüm bağlantı trafiğini (parolalar dahil) şifrelemektedir.</Description>
<Archive type="targz" sha1sum="cdbc51e46a902b30d263b05fdc71340920e91c92">http://ftp.icm.edu.pl/pub/OpenBSD/OpenSSH/portable/openssh-6.8p1.tar.gz</Archive>
<BuildDependencies>
<Dependency>libedit-devel</Dependency>
<Dependency>zlib-devel</Dependency>
<Dependency>openssl-devel</Dependency>
<Dependency>mit-kerberos</Dependency>
<Dependency>skey-devel</Dependency>
<Dependency>pam-devel</Dependency>
<Dependency>e2fsprogs-devel</Dependency>
</BuildDependencies>
<SourceURI>server/openssh/pspec.xml</SourceURI>
</Source>
<Package>
<Name>openssh</Name>
<RuntimeDependencies>
<Dependency>libedit</Dependency>
<Dependency>zlib</Dependency>
<Dependency>openssl</Dependency>
<Dependency>mit-kerberos</Dependency>
<Dependency>skey</Dependency>
<Dependency>pam</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="executable">/usr/libexec</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="data">/usr/share/openssh</Path>
<Path fileType="data">/var/empty</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="doc">/usr/share/doc</Path>
</Files>
<Provides>
<COMAR script="service.py">System.Service</COMAR>
</Provides>
<AdditionalFiles>
<AdditionalFile target="/etc/pam.d/sshd" permission="0644" owner="root">sshd.pam</AdditionalFile>
</AdditionalFiles>
</Package>
<History>
<Update release="6">
<Date>2015-04-23</Date>
<Version>6.8_p1</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="5">
<Date>2014-12-13</Date>
<Version>6.7_p1</Version>
<Comment>Version bump.</Comment>
<Name>Yusuf Aydemir</Name>
<Email>yusuf.aydemir@pisilinux.org</Email>
</Update>
<Update release="4">
<Date>2014-05-21</Date>
<Version>6.6_p1</Version>
<Comment>Rebuild</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="3">
<Date>2014-05-10</Date>
<Version>6.6_p1</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="2">
<Date>2013-11-22</Date>
<Version>6.4_p1</Version>
<Comment>Version bump</Comment>
<Name>Aydın Demirel</Name>
<Email>aydin.demirel@pisilinux.org</Email>
</Update>
<Update release="1" type="security">
<Date>2012-10-30</Date>
<Version>6.1_p1</Version>
<Comment>First release</Comment>
<Name>Osman Erkan</Name>
<Email>osman.erkan@pisilinux.org</Email>
</Update>
</History>
</SpecFile>
<SpecFile>
<Source>
<Name>ConsoleKit2</Name>
@@ -37427,6 +37529,95 @@ uses SIMD instructions (MMX, SSE2, etc.) to accelerate baseline JPEG compression
</Update>
</History>
</SpecFile>
<SpecFile>
<Source>
<Name>skey</Name>
<Homepage>http://www.openbsd.org/faq/faq8.html#SKey</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>BSD</License>
<IsA>app:console</IsA>
<IsA>library</IsA>
<PartOf>util.crypt</PartOf>
<Summary xml:lang="en">Linux Port of OpenBSD Single-key Password System</Summary>
<Summary xml:lang="tr">Linux için OpenBSD tek anahtarlı parola sistemi</Summary>
<Description xml:lang="en">skey is an S/Key implementation ported from OpenBSD. S/Key provides One Time Password functionality, and can be used to increase system security.</Description>
<Description xml:lang="tr">skey, OpenBSD&apos;den Linux&apos;a aktarılan S/Key sistemidir. S/Key sistemi Tek Seferlik Parola özelilği ile sistem güvenliğini arttırmak için kullanılabilir.</Description>
<Archive type="tarbz2" sha1sum="d55fb286098900cdf3eb6b174a720a06c722312a">http://source.pisilinux.org/1.0/skey-1.1.5.tar.bz2</Archive>
<BuildDependencies>
<Dependency>cracklib-devel</Dependency>
<Dependency>zlib-devel</Dependency>
<Dependency>perl</Dependency>
</BuildDependencies>
<Patches>
<Patch level="1">skey-1.1.5-gentoo.diff</Patch>
<Patch level="1">skey-login_name_max.diff</Patch>
<Patch>skey-1.1.5-fPIC.patch</Patch>
<Patch>skey-1.1.5-bind-now.patch</Patch>
<Patch level="1">skey-1.1.5-otp.diff</Patch>
<Patch level="1">skey-1.1.5-binary-search.patch</Patch>
<Patch level="1">confdir.patch</Patch>
<Patch level="1">zeroed_entries.patch</Patch>
<Patch level="1">default_hash.patch</Patch>
<Patch level="1">fix_library_info.patch</Patch>
</Patches>
<SourceURI>util/crypt/skey/pspec.xml</SourceURI>
</Source>
<Package>
<Name>skey</Name>
<RuntimeDependencies>
<Dependency>cracklib</Dependency>
<Dependency>zlib</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc/skey</Path>
<Path fileType="library">/lib</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="doc">/usr/share/doc/skey</Path>
<Path fileType="man">/usr/share/man</Path>
</Files>
</Package>
<Package>
<Name>skey-devel</Name>
<Summary xml:lang="en">Development files for skey</Summary>
<Summary xml:lang="tr">skey için geliştirme dosyaları</Summary>
<PartOf>system.devel</PartOf>
<RuntimeDependencies>
<Dependency release="3">skey</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
<Path fileType="man">/usr/share/man/man3</Path>
</Files>
</Package>
<History>
<Update release="3">
<Date>2014-05-21</Date>
<Version>1.1.5</Version>
<Comment>Rebuild.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="2">
<Date>2014-05-11</Date>
<Version>1.1.5</Version>
<Comment>Release bump.</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2010-10-11</Date>
<Version>1.1.5</Version>
<Comment>First release</Comment>
<Name>Pisi Linux Admins</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</SpecFile>
<SpecFile>
<Source>
<Name>ibus</Name>
+1 -1
View File
@@ -1 +1 @@
1c0684ec1c4864118d5c3f330e65e2927d033b5e
e71d198707ff47d47ce52f748d0f840759c93459
BIN
View File
Binary file not shown.
+1 -1
View File
@@ -1 +1 @@
e2f4786f8ff3cde55c63b109fb9b52c49b45da3b
e1eb011d34cd99766706520be34a79527c587363
+61
View File
@@ -0,0 +1,61 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/licenses/gpl.txt
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
from pisi.actionsapi import get
WorkDir = "openssh-%s" % get.srcVERSION().replace("_","")
def setup():
shelltools.export("CFLAGS","%s -fpie" % get.CFLAGS())
shelltools.export("LDFLAGS","%s -pie" % get.LDFLAGS())
#pisitools.dosed("pathnames.h", "/usr/X11R6/bin/xauth", r"/usr/bin/xauth")
#pisitools.dosed("sshd_config", "(?m)^(^#UsePAM ).*", r"UsePAM yes")
#pisitools.dosed("sshd_config", "(?m)^(^#PasswordAuthentication ).*", r"PasswordAuthentication no")
#pisitools.dosed("sshd_config", "(?m)^(^#X11Forwarding ).*", r"X11Forwarding yes")
#pisitools.dosed("sshd_config", "(?m)^(^#UseDNS ).*", r"UseDNS no")
#pisitools.dosed("sshd_config", "(?m)^(^#PermitRootLogin ).*", r"PermitRootLogin no")
autotools.autoreconf("-fi")
# Kerberos support is a must, libedit is optional
# Update configure parameters when both are ready
autotools.configure("--sysconfdir=/etc/ssh \
--libexecdir=/usr/libexec/openssh \
--datadir=/usr/share/openssh \
--disable-strip \
--with-pam \
--with-skey \
--with-libedit \
--with-kerberos5 \
--with-tcp-wrappers \
--with-md5-passwords \
--with-ipaddr-display \
--with-privsep-user=sshd \
--with-privsep-path=/var/empty \
--without-zlib-version-check \
--without-ssl-engine")
def build():
autotools.make()
def install():
autotools.rawInstall("DESTDIR=%s" % get.installDIR())
# fixes #10992
pisitools.dobin("contrib/ssh-copy-id")
pisitools.doman("contrib/ssh-copy-id.1")
shelltools.chmod("%s/etc/ssh/sshd_config" % get.installDIR(), 0600)
# special request by merensan
shelltools.echo("%s/etc/ssh/ssh_config" % get.installDIR(), "ServerAliveInterval 5")
pisitools.dodir("/var/empty/sshd")
pisitools.dodoc("ChangeLog", "CREDITS", "OVERVIEW", "README*", "TODO", "sshd_config")
+46
View File
@@ -0,0 +1,46 @@
# -*- coding: utf-8 -*-
from comar.service import *
serviceType = "server"
serviceDesc = _({"en": "Secure Shell Server",
"tr": "Güvenli Kabuk Sunucusu"
})
MSG_ERR_NEEDCONF = _({"en": "You need /etc/ssh/sshd_config to run sshd.",
"tr": "Sshd'yi çalıştırabilmek için /etc/ssh/sshd_config'e ihtiyaç var.",
})
PID_FILE = "/run/sshd.pid"
RSA1_KEY = "/etc/ssh/ssh_host_key"
RSA_KEY = "/etc/ssh/ssh_host_rsa_key"
DSA_KEY = "/etc/ssh/ssh_host_dsa_key"
def check_config():
import os
if not os.path.exists("/etc/ssh/sshd_config"):
fail(MSG_ERR_NEEDCONF)
if not os.path.exists(RSA1_KEY):
# Default is 2048 bits, and is considered sufficient.
run("/usr/bin/ssh-keygen", "-t", "rsa1",
"-f", "/etc/ssh/ssh_host_key", "-N", "")
if not os.path.exists(DSA_KEY):
run("/usr/bin/ssh-keygen", "-t", "dsa",
"-f", "/etc/ssh/ssh_host_dsa_key", "-N", "")
if not os.path.exists(RSA_KEY):
run("/usr/bin/ssh-keygen", "-t", "rsa",
"-f", "/etc/ssh/ssh_host_rsa_key", "-N", "")
@synchronized
def start():
check_config()
startService(command="/usr/sbin/sshd",
pidfile=PID_FILE,
donotify=True)
@synchronized
def stop():
stopService(pidfile=PID_FILE,
donotify=True)
def status():
return isServiceRunning(PID_FILE)
+171
View File
@@ -0,0 +1,171 @@
Hi,
So I screwed up when writing the support for the curve25519 KEX method
that doesn't depend on OpenSSL's BIGNUM type - a bug in my code left
leading zero bytes where they should have been skipped. The impact of
this is that OpenSSH 6.5 and 6.6 will fail during key exchange with a
peer that implements curve25519-sha256@libssh.org properly about 0.2%
of the time (one in every 512ish connections).
We've fixed this for OpenSSH 6.7 by avoiding the curve25519-sha256
key exchange for previous versions, but I'd recommend distributors
of OpenSSH apply this patch so the affected code doesn't become
too entrenched in LTS releases.
The patch fixes the bug and makes OpenSSH identify itself as 6.6.1 so as
to distinguish itself from the incorrect versions so the compatibility
code to disable the affected KEX isn't activated.
I've committed this on the 6.6 branch too.
Apologies for the hassle.
-d
Index: version.h
===================================================================
RCS file: /var/cvs/openssh/version.h,v
retrieving revision 1.82
diff -u -p -r1.82 version.h
--- version.h 27 Feb 2014 23:01:54 -0000 1.82
+++ version.h 20 Apr 2014 03:35:15 -0000
@@ -1,6 +1,6 @@
/* $OpenBSD: version.h,v 1.70 2014/02/27 22:57:40 djm Exp $ */
-#define SSH_VERSION "OpenSSH_6.6"
+#define SSH_VERSION "OpenSSH_6.6.1"
#define SSH_PORTABLE "p1"
#define SSH_RELEASE SSH_VERSION SSH_PORTABLE
Index: compat.c
===================================================================
RCS file: /var/cvs/openssh/compat.c,v
retrieving revision 1.82
retrieving revision 1.85
diff -u -p -r1.82 -r1.85
--- compat.c 31 Dec 2013 01:25:41 -0000 1.82
+++ compat.c 20 Apr 2014 03:33:59 -0000 1.85
@@ -95,6 +95,9 @@ compat_datafellows(const char *version)
{ "Sun_SSH_1.0*", SSH_BUG_NOREKEY|SSH_BUG_EXTEOF},
{ "OpenSSH_4*", 0 },
{ "OpenSSH_5*", SSH_NEW_OPENSSH|SSH_BUG_DYNAMIC_RPORT},
+ { "OpenSSH_6.6.1*", SSH_NEW_OPENSSH},
+ { "OpenSSH_6.5*,"
+ "OpenSSH_6.6*", SSH_NEW_OPENSSH|SSH_BUG_CURVE25519PAD},
{ "OpenSSH*", SSH_NEW_OPENSSH },
{ "*MindTerm*", 0 },
{ "2.1.0*", SSH_BUG_SIGBLOB|SSH_BUG_HMAC|
@@ -251,7 +254,6 @@ compat_cipher_proposal(char *cipher_prop
return cipher_prop;
}
-
char *
compat_pkalg_proposal(char *pkalg_prop)
{
@@ -263,5 +265,18 @@ compat_pkalg_proposal(char *pkalg_prop)
if (*pkalg_prop == '\0')
fatal("No supported PK algorithms found");
return pkalg_prop;
+}
+
+char *
+compat_kex_proposal(char *kex_prop)
+{
+ if (!(datafellows & SSH_BUG_CURVE25519PAD))
+ return kex_prop;
+ debug2("%s: original KEX proposal: %s", __func__, kex_prop);
+ kex_prop = filter_proposal(kex_prop, "curve25519-sha256@libssh.org");
+ debug2("%s: compat KEX proposal: %s", __func__, kex_prop);
+ if (*kex_prop == '\0')
+ fatal("No supported key exchange algorithms found");
+ return kex_prop;
}
Index: compat.h
===================================================================
RCS file: /var/cvs/openssh/compat.h,v
retrieving revision 1.42
retrieving revision 1.43
diff -u -p -r1.42 -r1.43
--- compat.h 31 Dec 2013 01:25:41 -0000 1.42
+++ compat.h 20 Apr 2014 03:25:31 -0000 1.43
@@ -59,6 +59,7 @@
#define SSH_BUG_RFWD_ADDR 0x02000000
#define SSH_NEW_OPENSSH 0x04000000
#define SSH_BUG_DYNAMIC_RPORT 0x08000000
+#define SSH_BUG_CURVE25519PAD 0x10000000
void enable_compat13(void);
void enable_compat20(void);
@@ -66,6 +67,7 @@ void compat_datafellows(const char *
int proto_spec(const char *);
char *compat_cipher_proposal(char *);
char *compat_pkalg_proposal(char *);
+char *compat_kex_proposal(char *);
extern int compat13;
extern int compat20;
Index: sshd.c
===================================================================
RCS file: /var/cvs/openssh/sshd.c,v
retrieving revision 1.448
retrieving revision 1.453
diff -u -p -r1.448 -r1.453
--- sshd.c 26 Feb 2014 23:20:08 -0000 1.448
+++ sshd.c 20 Apr 2014 03:28:41 -0000 1.453
@@ -2462,6 +2438,9 @@ do_ssh2_kex(void)
if (options.kex_algorithms != NULL)
myproposal[PROPOSAL_KEX_ALGS] = options.kex_algorithms;
+ myproposal[PROPOSAL_KEX_ALGS] = compat_kex_proposal(
+ myproposal[PROPOSAL_KEX_ALGS]);
+
if (options.rekey_limit || options.rekey_interval)
packet_set_rekey_limits((u_int32_t)options.rekey_limit,
(time_t)options.rekey_interval);
Index: sshconnect2.c
===================================================================
RCS file: /var/cvs/openssh/sshconnect2.c,v
retrieving revision 1.197
retrieving revision 1.199
diff -u -p -r1.197 -r1.199
--- sshconnect2.c 4 Feb 2014 00:20:16 -0000 1.197
+++ sshconnect2.c 20 Apr 2014 03:25:31 -0000 1.199
@@ -195,6 +196,8 @@ ssh_kex2(char *host, struct sockaddr *ho
}
if (options.kex_algorithms != NULL)
myproposal[PROPOSAL_KEX_ALGS] = options.kex_algorithms;
+ myproposal[PROPOSAL_KEX_ALGS] = compat_kex_proposal(
+ myproposal[PROPOSAL_KEX_ALGS]);
if (options.rekey_limit || options.rekey_interval)
packet_set_rekey_limits((u_int32_t)options.rekey_limit,
Index: bufaux.c
===================================================================
RCS file: /var/cvs/openssh/bufaux.c,v
retrieving revision 1.62
retrieving revision 1.63
diff -u -p -r1.62 -r1.63
--- bufaux.c 4 Feb 2014 00:20:15 -0000 1.62
+++ bufaux.c 20 Apr 2014 03:24:50 -0000 1.63
@@ -1,4 +1,4 @@
-/* $OpenBSD: bufaux.c,v 1.56 2014/02/02 03:44:31 djm Exp $ */
+/* $OpenBSD: bufaux.c,v 1.57 2014/04/16 23:22:45 djm Exp $ */
/*
* Author: Tatu Ylonen <ylo@cs.hut.fi>
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -372,6 +372,9 @@ buffer_put_bignum2_from_string(Buffer *b
if (l > 8 * 1024)
fatal("%s: length %u too long", __func__, l);
+ /* Skip leading zero bytes */
+ for (; l > 0 && *s == 0; l--, s++)
+ ;
p = buf = xmalloc(l + 1);
/*
* If most significant bit is set then prepend a zero byte to
_______________________________________________
openssh-unix-dev mailing list
openssh-unix-dev@mindrot.org
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev
+8
View File
@@ -0,0 +1,8 @@
#%PAM-1.0
auth include system-auth
auth required pam_shells.so
auth required pam_nologin.so
account include system-auth
password include system-auth
session include system-auth
+104
View File
@@ -0,0 +1,104 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>openssh</Name>
<Homepage>http://www.openssh.com/</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>BSD</License>
<IsA>app:console</IsA>
<IsA>service</IsA>
<Summary>Port of OpenBSD's free SSH release</Summary>
<Description>OpenSSH is a FREE version of the SSH connectivity tools that technical users of the Internet rely on. Users of telnet, rlogin, and ftp may not realize that their password is transmitted across the Internet unencrypted, but it is. OpenSSH encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other attacks.</Description>
<Archive sha1sum="cdbc51e46a902b30d263b05fdc71340920e91c92" type="targz">http://ftp.icm.edu.pl/pub/OpenBSD/OpenSSH/portable/openssh-6.8p1.tar.gz</Archive>
<BuildDependencies>
<Dependency>libedit-devel</Dependency>
<Dependency>zlib-devel</Dependency>
<Dependency>openssl-devel</Dependency>
<Dependency>mit-kerberos</Dependency>
<Dependency>skey-devel</Dependency>
<Dependency>pam-devel</Dependency>
<Dependency>e2fsprogs-devel</Dependency>
</BuildDependencies>
<Patches>
<!-- <Patch>curve25519pad.patch</Patch> -->
</Patches>
</Source>
<Package>
<Name>openssh</Name>
<RuntimeDependencies>
<Dependency>libedit</Dependency>
<Dependency>zlib</Dependency>
<Dependency>openssl</Dependency>
<Dependency>mit-kerberos</Dependency>
<Dependency>skey</Dependency>
<Dependency>pam</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="executable">/usr/libexec</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="data">/usr/share/openssh</Path>
<Path fileType="data">/var/empty</Path>
<Path fileType="man">/usr/share/man</Path>
<Path fileType="doc">/usr/share/doc</Path>
</Files>
<AdditionalFiles>
<AdditionalFile owner="root" permission="0644" target="/etc/pam.d/sshd">sshd.pam</AdditionalFile>
</AdditionalFiles>
<Provides>
<COMAR script="service.py">System.Service</COMAR>
</Provides>
</Package>
<History>
<Update release="6">
<Date>2015-04-23</Date>
<Version>6.8_p1</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="5">
<Date>2014-12-13</Date>
<Version>6.7_p1</Version>
<Comment>Version bump.</Comment>
<Name>Yusuf Aydemir</Name>
<Email>yusuf.aydemir@pisilinux.org</Email>
</Update>
<Update release="4">
<Date>2014-05-21</Date>
<Version>6.6_p1</Version>
<Comment>Rebuild</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="3">
<Date>2014-05-10</Date>
<Version>6.6_p1</Version>
<Comment>Version bump.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="2">
<Date>2013-11-22</Date>
<Version>6.4_p1</Version>
<Comment>Version bump</Comment>
<Name>Aydın Demirel</Name>
<Email>aydin.demirel@pisilinux.org</Email>
</Update>
<Update release="1" type="security">
<Date>2012-10-30</Date>
<Version>6.1_p1</Version>
<Comment>First release</Comment>
<Name>Osman Erkan</Name>
<Email>osman.erkan@pisilinux.org</Email>
</Update>
</History>
</PISI>
+9
View File
@@ -0,0 +1,9 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>openssh</Name>
<Summary xml:lang="tr">OpenBSD'den aktarılmış SSH sürümü</Summary>
<Description xml:lang="tr">OpenSSH teknik internet kullanıcıların güvendikleri SSH bağlanırlık araçlarının Özgür (free) sürümüdür.telnet, rlogin ve ftp kullanıcıları parolalarının internetten şifresiz olarak aktarıldığını anlayamayabilirler ancak aktarılmaktadır.OpenSSH eavesdropping (iletişim kanalını dinleme), connection hijacking (bağlantı çalma) ve diğer atakları önlemek için tüm bağlantı trafiğini (parolalar dahil) şifrelemektedir.</Description>
<Description xml:lang="fr">OpenSSH est une version libre des outils de connexion SSH sur lesquels les utilisateurs techniquement chevronnés s'appuient. Les utilisateurs de telnet, rlogin et ftp ne se rendent peut être pas compte que les mots de passe sont transmis sur internet en clair. OpenSSH crypte tout le trafic (y compris les mots de passe) pour éliminer les écoutes passives, les détournements de connexion et autres attaques.</Description>
</Source>
</PISI>
+72
View File
@@ -0,0 +1,72 @@
#!/usr/bin/python
# -*- coding: utf-8 -*-
#
# Licensed under the GNU General Public License, version 3.
# See the file http://www.gnu.org/copyleft/gpl.txt.
#
# Note that we fiddle with permissions of everything to make sure not to make a security hole
#
from pisi.actionsapi import autotools
from pisi.actionsapi import pisitools
from pisi.actionsapi import shelltools
from pisi.actionsapi import libtools
from pisi.actionsapi import get
def setup():
shelltools.export("SENDMAIL", "/usr/sbin/sendmail")
shelltools.export("CFLAGS", "%s -DSKEY_HASH_DEFAULT=1" % get.CFLAGS())
autotools.configure("--sysconfdir=/etc/skey")
def build():
autotools.make()
def install():
### Runtime
for i in ["skey", "skeyinit", "skeyinfo"]:
pisitools.dobin(i)
for i in ["otp-md4", "otp-sha1", "otp-md5"]:
pisitools.dosym("skey", "/usr/bin/%s" % i)
pisitools.insinto("/usr/sbin", "skeyprune.pl", "skeyprune")
pisitools.insinto("/usr/bin", "skeyaudit.sh", "skeyaudit")
# these must be suid root so users can generate their passwords, fperms u+s,og-r
for i in ["skeyinit", "skeyinfo", "skeyaudit"]:
shelltools.chmod("%s/usr/bin/%s" % (get.installDIR(), i), 4755)
shelltools.chmod("%s/usr/bin/skey" % get.installDIR(), 0755)
shelltools.chmod("%s/usr/sbin/skeyprune" % get.installDIR(), 0755)
### Developement
pisitools.insinto("/usr/include", "skey.h")
for i in ["libskey.so.1.1.5", "libskey.so.1", "libskey.so"]:
# dolib borks with symlinks
# pisitools.dolib(i, destinationDirectory="/lib")
pisitools.insinto("/lib", i)
shelltools.chmod("%s/lib/%s" % (get.installDIR(), i), 0755)
#libtools.gen_usr_ldscript("libskey.so")
pisitools.dosym("../../lib/libskey.so", "/usr/lib/libskey.so")
### Config
# only root needs to have access to these files. fperms g-rx,o-rx /etc/skey
pisitools.dodir("/etc/skey")
shelltools.chmod("%s/etc/skey" % get.installDIR(), 0700)
# skeyinit will not function if this file is not present. these permissions are applied by the skey system if missing.
shelltools.touch("%s/etc/skey/skeykeys" % get.installDIR())
shelltools.chmod("%s/etc/skey/skeykeys" % get.installDIR(), 0600)
### Docs
for i in ["skey.1", "skeyaudit.1", "skeyinfo.1", "skeyinit.1", "skey.3", "skeyprune.8"]:
pisitools.doman(i)
pisitools.dodoc("CHANGES", "README")
+12
View File
@@ -0,0 +1,12 @@
diff -Nur skey-1.1.5-old//skeyprune.pl skey-1.1.5/skeyprune.pl
--- skey-1.1.5-old//skeyprune.pl 2010-09-12 15:03:35.695999732 +0300
+++ skey-1.1.5/skeyprune.pl 2010-09-12 15:06:03.817000568 +0300
@@ -14,7 +14,7 @@
die "Usage: $0 [days]\n" if $#ARGC > 0;
# Pathnames
-$keyfile = '/etc/skeykeys';
+$keyfile = '/etc/skey/skeykeys';
$temp = "$keyfile.tmp$$";
# Quick mapping of month name -> number
+12
View File
@@ -0,0 +1,12 @@
diff -Nur skey-1.1.5-old//skeyinit.1 skey-1.1.5/skeyinit.1
--- skey-1.1.5-old//skeyinit.1 2010-09-12 15:03:35.695999732 +0300
+++ skey-1.1.5/skeyinit.1 2010-09-12 15:10:43.478000350 +0300
@@ -47,7 +47,7 @@
(default is 100).
.It Fl t Ar hash
Selects the hash algorithm to use.
-Available choices are md4 (the default), md5 or sha1.
+Available choices are md4, md5 (the default) or sha1.
.It Ar user
The username to be changed/added.
By default the current user is operated on, only root may
@@ -0,0 +1,15 @@
diff -Nur skey-1.1.5-old//skey.3 skey-1.1.5/skey.3
--- skey-1.1.5-old//skey.3 2010-09-12 15:03:35.696999758 +0300
+++ skey-1.1.5/skey.3 2010-09-12 15:12:24.658996394 +0300
@@ -245,10 +245,8 @@
.Bl -tag -width /usr/lib/libskey_p.a -compact
.It Pa /usr/lib/libskey.a
static skey library
-.It Pa /usr/lib/libskey.so
+.It Pa /lib/libskey.so
dynamic skey library
-.It Pa /usr/lib/libskey_p.a
-static skey library compiled for profiling
.El
.Sh SEE ALSO
.Xr skey 1 ,
@@ -0,0 +1,34 @@
--- skey-1.1.5-orig/put.c 2008-09-21 10:12:06.000000000 +0200
+++ skey-1.1.5/put.c 2008-09-21 10:19:54.000000000 +0200
@@ -2206,27 +2206,17 @@
{
int i, j;
- for (;;) {
+ while (low <= high) {
i = (low + high) / 2;
if ((j = strncmp(w, Wp[i], 4)) == 0)
return i; /* Found it */
- if (high == low + 1)
- {
- /* Avoid effects of integer truncation in /2 */
- if (strncmp(w, Wp[high], 4) == 0)
- return high;
- else
- return -1;
- }
-
- if (low >= high)
- return -1; /* I don't *think* this can happen... */
if (j < 0)
- high = i; /* Search lower half */
+ high = i - 1; /* Search lower half */
else
- low = i; /* Search upper half */
+ low = i + 1; /* Search upper half */
}
+ return -1;
}
static void insert(char *s, int x, int start, int length)
@@ -0,0 +1,15 @@
--- Makefile.in.orig 2005-08-19 18:14:48.000000000 -0400
+++ Makefile.in 2005-08-19 18:15:45.000000000 -0400
@@ -67,10 +67,10 @@
${CC} -o $@ ${SKEYOBJS} ${LDFLAGS} -lskey ${LIBS}
skeyinit: libskey.so ${SKEYINITOBJS}
- ${CC} -o $@ ${SKEYINITOBJS} ${LDFLAGS} -lskey ${LIBS}
+ ${CC} -o $@ ${SKEYINITOBJS} ${LDFLAGS} -lskey ${LIBS} -Wl,-z,now
skeyinfo: libskey.so ${SKEYINFOOBJS}
- ${CC} -o $@ ${SKEYINFOOBJS} ${LDFLAGS} -lskey ${LIBS}
+ ${CC} -o $@ ${SKEYINFOOBJS} ${LDFLAGS} -lskey ${LIBS} -Wl,-z,now
${MANPAGES} ${SCRIPTS}::
${FIXPATHSCMD} ${srcdir}/$@
@@ -0,0 +1,12 @@
--- Makefile.in 2004-02-25 10:16:15.219448392 +0000
+++ Makefile.in 2004-02-25 10:16:39.087583762 +0000
@@ -50,6 +50,9 @@
${LIBOBJS}: config.h
+${LIBOBJS}: %.o: %.c
+ ${CC} ${CFLAGS} -fPIC -c $< -o $@
+
libskey.a: ${LIBOBJS}
${AR} rv $@ ${LIBOBJS}
${RANLIB} $@
File diff suppressed because it is too large Load Diff
+59
View File
@@ -0,0 +1,59 @@
diff -Nur skey-1.1.5.orig/skey.c skey-1.1.5/skey.c
--- skey-1.1.5.orig/skey.c 2004-11-12 23:09:02.382529123 +0100
+++ skey-1.1.5/skey.c 2004-11-12 23:23:09.864378849 +0100
@@ -46,6 +46,17 @@
char passwd[SKEY_MAX_PW_LEN+1], key[SKEY_BINKEY_SIZE];
char buf[33], *seed, *slash, *t;
+ /* If we were called as otp-METHOD, set algorithm based on that */
+ if ((slash = strrchr(argv[0], '/')))
+ slash++;
+ else
+ slash = argv[0];
+ if (strncmp(slash, "otp-", 4) == 0) {
+ slash += 4;
+ if (skey_set_algorithm(slash) == NULL)
+ errx(1, "Unknown hash algorithm %s", slash);
+ }
+
while ((i = getopt(argc, argv, "fn:p:t:x")) != -1) {
switch(i) {
case 'f':
diff -Nur skey-1.1.5.orig/skey.1 skey-1.1.5/skey.1
--- skey-1.1.5.orig/skey.1 2004-11-12 23:09:02.375530148 +0100
+++ skey-1.1.5/skey.1 2004-11-12 23:41:43.298268426 +0100
@@ -6,7 +6,7 @@
.Dt SKEY 1
.Os
.Sh NAME
-.Nm skey
+.Nm skey, otp-md4, otp-md5, otp-sha1
.Nd respond to an OTP challenge
.Sh SYNOPSIS
.Nm
@@ -27,13 +27,24 @@
.Pp
.Em S/Key
uses 64 bits of information, transformed by the
-.Tn MD4
+.Tn MD5
algorithm into 6 English words.
The user supplies the words to authenticate himself to programs like
.Xr login 1
or
.Xr ftpd 8 .
.Pp
+When
+.Nm skey
+is invoked as
+.Nm otp-method ,
+.Nm skey
+will use
+.Ar method
+as the hash function where
+.Ar method
+is currently one of md4, md5, or sha1.
+.Pp
Example use of the
.Em S/Key
program
@@ -0,0 +1,15 @@
diff -ruN skey-1.1.5.orig/skeyinit.c skey-1.1.5/skeyinit.c
--- skey-1.1.5.orig/skeyinit.c 2003-11-12 21:26:49.000000000 +0000
+++ skey-1.1.5/skeyinit.c 2003-11-12 21:28:24.000000000 +0000
@@ -62,6 +62,11 @@
#define SKEY_NAMELEN 4
#endif
+/* #33315 */
+#ifndef LOGIN_NAME_MAX
+#define LOGIN_NAME_MAX 256
+#endif
+
int main __P((int, char **));
int main(int argc, char **argv)
@@ -0,0 +1,12 @@
diff -Nur skey-1.1.5-old//skeyprune.pl skey-1.1.5/skeyprune.pl
--- skey-1.1.5-old//skeyprune.pl 2010-09-12 15:07:36.778000090 +0300
+++ skey-1.1.5/skeyprune.pl 2010-09-12 15:08:05.152998914 +0300
@@ -37,7 +37,7 @@
while (<OLD>) {
# Ignore commented out entries
- if ( ! /^#[^\s#]+\s+(MD[0-9]+\s+)?[0-9]+\s+[A-z0-9_-]+\s+[a-f0-9]+\s+(Jan|Feb|Mar|Apr|May|Ju[nl]|Aug|Sep|Oct|Nov|Dec)\s+[0-9]+,\s*[0-9]+\s+[0-9]+:[0-9]+:[0-9]+$/ ) {
+ if ( ! /^#[^\s#]+\s+(MD[0-9]+\s+)?[0-9]+\s+[A-z0-9_-]+\s+[a-f0-9]+\s+(Jan|Feb|Mar|Apr|May|Ju[nl]|Aug|Sep|Oct|Nov|Dec)\s+[0-9]+,\s*[0-9]+\s+[0-9]+:[0-9]+:[0-9]+$/i ) {
/((Jan|Feb|Mar|Apr|May|Ju[nl]|Aug|Sep|Oct|Nov|Dec)\s+[0-9]+,\s*[0-9]+\s+[0-9]+:[0-9]+:[0-9]+)$/;
# Prune out old entries if asked to
+107
View File
@@ -0,0 +1,107 @@
<?xml version="1.0" ?>
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
<PISI>
<Source>
<Name>skey</Name>
<Homepage>http://www.openbsd.org/faq/faq8.html#SKey</Homepage>
<Packager>
<Name>PisiLinux Community</Name>
<Email>admins@pisilinux.org</Email>
</Packager>
<License>BSD</License>
<IsA>app:console</IsA>
<IsA>library</IsA>
<Summary>Linux Port of OpenBSD Single-key Password System</Summary>
<Description>skey is an S/Key implementation ported from OpenBSD. S/Key provides One Time Password functionality, and can be used to increase system security.</Description>
<Archive sha1sum="d55fb286098900cdf3eb6b174a720a06c722312a" type="tarbz2">http://source.pisilinux.org/1.0/skey-1.1.5.tar.bz2</Archive>
<BuildDependencies>
<Dependency>cracklib-devel</Dependency>
<Dependency>zlib-devel</Dependency>
<Dependency>perl</Dependency>
</BuildDependencies>
<Patches>
<!-- Backports from NETBSD, shadow cracklib support etc. -->
<Patch level="1">skey-1.1.5-gentoo.diff</Patch>
<!-- Glibc does not define LOGIN_NAME_MAX -->
<Patch level="1">skey-login_name_max.diff</Patch>
<!-- Build enhancements -->
<Patch>skey-1.1.5-fPIC.patch</Patch>
<Patch>skey-1.1.5-bind-now.patch</Patch>
<!-- Allow invokation as otp-foo -->
<Patch level="1">skey-1.1.5-otp.diff</Patch>
<!-- Fix binary search -->
<Patch level="1">skey-1.1.5-binary-search.patch</Patch>
<!-- sed -i -e 's:/etc/skeykeys:/etc/skey/skeykeys:g' skeyprune.pl skeyprune.8 -->
<Patch level="1">confdir.patch</Patch>
<!-- Make sure to use case insensitive check for zeroed entries
sed -i -e 's:\(if ( ! /.*/\):\1i:g' skeyprune.pl -->
<Patch level="1">zeroed_entries.patch</Patch>
<!-- sed -i 's#\(md4\) \((the default)\), \(md5\) or \(sha1.\)#\1, \3 \2 or \4#g' skeyinit.1 -->
<Patch level="1">default_hash.patch</Patch>
<!-- sed -i 's:/usr\(/lib/libskey.so\):\1:;/It.*libskey_p/{N;d;}' skey.3 -->
<Patch level="1">fix_library_info.patch</Patch>
</Patches>
</Source>
<Package>
<Name>skey</Name>
<RuntimeDependencies>
<Dependency>cracklib</Dependency>
<Dependency>zlib</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="config">/etc/skey</Path>
<Path fileType="library">/lib</Path>
<Path fileType="executable">/usr/bin</Path>
<Path fileType="library">/usr/lib</Path>
<Path fileType="executable">/usr/sbin</Path>
<Path fileType="doc">/usr/share/doc/skey</Path>
<Path fileType="man">/usr/share/man</Path>
</Files>
</Package>
<Package>
<Name>skey-devel</Name>
<PartOf>system.devel</PartOf>
<Summary>Development files for skey</Summary>
<RuntimeDependencies>
<Dependency release="current">skey</Dependency>
</RuntimeDependencies>
<Files>
<Path fileType="header">/usr/include</Path>
<Path fileType="man">/usr/share/man/man3</Path>
</Files>
</Package>
<History>
<Update release="3">
<Date>2014-05-21</Date>
<Version>1.1.5</Version>
<Comment>Rebuild.</Comment>
<Name>Ertuğrul Erata</Name>
<Email>ertugrulerata@gmail.com</Email>
</Update>
<Update release="2">
<Date>2014-05-11</Date>
<Version>1.1.5</Version>
<Comment>Release bump.</Comment>
<Name>Marcin Bojara</Name>
<Email>marcin@pisilinux.org</Email>
</Update>
<Update release="1">
<Date>2010-10-11</Date>
<Version>1.1.5</Version>
<Comment>First release</Comment>
<Name>Pisi Linux Admins</Name>
<Email>admins@pisilinux.org</Email>
</Update>
</History>
</PISI>
+13
View File
@@ -0,0 +1,13 @@
<?xml version="1.0" ?>
<PISI>
<Source>
<Name>skey</Name>
<Summary xml:lang="tr">Linux için OpenBSD tek anahtarlı parola sistemi</Summary>
<Description xml:lang="tr">skey, OpenBSD'den Linux'a aktarılan S/Key sistemidir. S/Key sistemi Tek Seferlik Parola özelilği ile sistem güvenliğini arttırmak için kullanılabilir.</Description>
</Source>
<Package>
<Name>skey-devel</Name>
<Summary xml:lang="tr">skey için geliştirme dosyaları</Summary>
</Package>
</PISI>