add skey openssh
This commit is contained in:
@@ -0,0 +1,61 @@
|
||||
#!/usr/bin/python
|
||||
# -*- coding: utf-8 -*-
|
||||
#
|
||||
# Licensed under the GNU General Public License, version 3.
|
||||
# See the file http://www.gnu.org/licenses/gpl.txt
|
||||
|
||||
from pisi.actionsapi import autotools
|
||||
from pisi.actionsapi import pisitools
|
||||
from pisi.actionsapi import shelltools
|
||||
from pisi.actionsapi import get
|
||||
|
||||
WorkDir = "openssh-%s" % get.srcVERSION().replace("_","")
|
||||
|
||||
def setup():
|
||||
shelltools.export("CFLAGS","%s -fpie" % get.CFLAGS())
|
||||
shelltools.export("LDFLAGS","%s -pie" % get.LDFLAGS())
|
||||
|
||||
#pisitools.dosed("pathnames.h", "/usr/X11R6/bin/xauth", r"/usr/bin/xauth")
|
||||
#pisitools.dosed("sshd_config", "(?m)^(^#UsePAM ).*", r"UsePAM yes")
|
||||
#pisitools.dosed("sshd_config", "(?m)^(^#PasswordAuthentication ).*", r"PasswordAuthentication no")
|
||||
#pisitools.dosed("sshd_config", "(?m)^(^#X11Forwarding ).*", r"X11Forwarding yes")
|
||||
#pisitools.dosed("sshd_config", "(?m)^(^#UseDNS ).*", r"UseDNS no")
|
||||
#pisitools.dosed("sshd_config", "(?m)^(^#PermitRootLogin ).*", r"PermitRootLogin no")
|
||||
|
||||
autotools.autoreconf("-fi")
|
||||
|
||||
# Kerberos support is a must, libedit is optional
|
||||
# Update configure parameters when both are ready
|
||||
autotools.configure("--sysconfdir=/etc/ssh \
|
||||
--libexecdir=/usr/libexec/openssh \
|
||||
--datadir=/usr/share/openssh \
|
||||
--disable-strip \
|
||||
--with-pam \
|
||||
--with-skey \
|
||||
--with-libedit \
|
||||
--with-kerberos5 \
|
||||
--with-tcp-wrappers \
|
||||
--with-md5-passwords \
|
||||
--with-ipaddr-display \
|
||||
--with-privsep-user=sshd \
|
||||
--with-privsep-path=/var/empty \
|
||||
--without-zlib-version-check \
|
||||
--without-ssl-engine")
|
||||
|
||||
def build():
|
||||
autotools.make()
|
||||
|
||||
def install():
|
||||
autotools.rawInstall("DESTDIR=%s" % get.installDIR())
|
||||
|
||||
# fixes #10992
|
||||
pisitools.dobin("contrib/ssh-copy-id")
|
||||
pisitools.doman("contrib/ssh-copy-id.1")
|
||||
|
||||
shelltools.chmod("%s/etc/ssh/sshd_config" % get.installDIR(), 0600)
|
||||
# special request by merensan
|
||||
shelltools.echo("%s/etc/ssh/ssh_config" % get.installDIR(), "ServerAliveInterval 5")
|
||||
|
||||
pisitools.dodir("/var/empty/sshd")
|
||||
|
||||
pisitools.dodoc("ChangeLog", "CREDITS", "OVERVIEW", "README*", "TODO", "sshd_config")
|
||||
@@ -0,0 +1,46 @@
|
||||
# -*- coding: utf-8 -*-
|
||||
from comar.service import *
|
||||
|
||||
serviceType = "server"
|
||||
serviceDesc = _({"en": "Secure Shell Server",
|
||||
"tr": "Güvenli Kabuk Sunucusu"
|
||||
})
|
||||
|
||||
MSG_ERR_NEEDCONF = _({"en": "You need /etc/ssh/sshd_config to run sshd.",
|
||||
"tr": "Sshd'yi çalıştırabilmek için /etc/ssh/sshd_config'e ihtiyaç var.",
|
||||
})
|
||||
|
||||
PID_FILE = "/run/sshd.pid"
|
||||
RSA1_KEY = "/etc/ssh/ssh_host_key"
|
||||
RSA_KEY = "/etc/ssh/ssh_host_rsa_key"
|
||||
DSA_KEY = "/etc/ssh/ssh_host_dsa_key"
|
||||
|
||||
def check_config():
|
||||
import os
|
||||
if not os.path.exists("/etc/ssh/sshd_config"):
|
||||
fail(MSG_ERR_NEEDCONF)
|
||||
if not os.path.exists(RSA1_KEY):
|
||||
# Default is 2048 bits, and is considered sufficient.
|
||||
run("/usr/bin/ssh-keygen", "-t", "rsa1",
|
||||
"-f", "/etc/ssh/ssh_host_key", "-N", "")
|
||||
if not os.path.exists(DSA_KEY):
|
||||
run("/usr/bin/ssh-keygen", "-t", "dsa",
|
||||
"-f", "/etc/ssh/ssh_host_dsa_key", "-N", "")
|
||||
if not os.path.exists(RSA_KEY):
|
||||
run("/usr/bin/ssh-keygen", "-t", "rsa",
|
||||
"-f", "/etc/ssh/ssh_host_rsa_key", "-N", "")
|
||||
|
||||
@synchronized
|
||||
def start():
|
||||
check_config()
|
||||
startService(command="/usr/sbin/sshd",
|
||||
pidfile=PID_FILE,
|
||||
donotify=True)
|
||||
|
||||
@synchronized
|
||||
def stop():
|
||||
stopService(pidfile=PID_FILE,
|
||||
donotify=True)
|
||||
|
||||
def status():
|
||||
return isServiceRunning(PID_FILE)
|
||||
@@ -0,0 +1,171 @@
|
||||
Hi,
|
||||
|
||||
So I screwed up when writing the support for the curve25519 KEX method
|
||||
that doesn't depend on OpenSSL's BIGNUM type - a bug in my code left
|
||||
leading zero bytes where they should have been skipped. The impact of
|
||||
this is that OpenSSH 6.5 and 6.6 will fail during key exchange with a
|
||||
peer that implements curve25519-sha256@libssh.org properly about 0.2%
|
||||
of the time (one in every 512ish connections).
|
||||
|
||||
We've fixed this for OpenSSH 6.7 by avoiding the curve25519-sha256
|
||||
key exchange for previous versions, but I'd recommend distributors
|
||||
of OpenSSH apply this patch so the affected code doesn't become
|
||||
too entrenched in LTS releases.
|
||||
|
||||
The patch fixes the bug and makes OpenSSH identify itself as 6.6.1 so as
|
||||
to distinguish itself from the incorrect versions so the compatibility
|
||||
code to disable the affected KEX isn't activated.
|
||||
|
||||
I've committed this on the 6.6 branch too.
|
||||
|
||||
Apologies for the hassle.
|
||||
|
||||
-d
|
||||
|
||||
Index: version.h
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/version.h,v
|
||||
retrieving revision 1.82
|
||||
diff -u -p -r1.82 version.h
|
||||
--- version.h 27 Feb 2014 23:01:54 -0000 1.82
|
||||
+++ version.h 20 Apr 2014 03:35:15 -0000
|
||||
@@ -1,6 +1,6 @@
|
||||
/* $OpenBSD: version.h,v 1.70 2014/02/27 22:57:40 djm Exp $ */
|
||||
|
||||
-#define SSH_VERSION "OpenSSH_6.6"
|
||||
+#define SSH_VERSION "OpenSSH_6.6.1"
|
||||
|
||||
#define SSH_PORTABLE "p1"
|
||||
#define SSH_RELEASE SSH_VERSION SSH_PORTABLE
|
||||
Index: compat.c
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/compat.c,v
|
||||
retrieving revision 1.82
|
||||
retrieving revision 1.85
|
||||
diff -u -p -r1.82 -r1.85
|
||||
--- compat.c 31 Dec 2013 01:25:41 -0000 1.82
|
||||
+++ compat.c 20 Apr 2014 03:33:59 -0000 1.85
|
||||
@@ -95,6 +95,9 @@ compat_datafellows(const char *version)
|
||||
{ "Sun_SSH_1.0*", SSH_BUG_NOREKEY|SSH_BUG_EXTEOF},
|
||||
{ "OpenSSH_4*", 0 },
|
||||
{ "OpenSSH_5*", SSH_NEW_OPENSSH|SSH_BUG_DYNAMIC_RPORT},
|
||||
+ { "OpenSSH_6.6.1*", SSH_NEW_OPENSSH},
|
||||
+ { "OpenSSH_6.5*,"
|
||||
+ "OpenSSH_6.6*", SSH_NEW_OPENSSH|SSH_BUG_CURVE25519PAD},
|
||||
{ "OpenSSH*", SSH_NEW_OPENSSH },
|
||||
{ "*MindTerm*", 0 },
|
||||
{ "2.1.0*", SSH_BUG_SIGBLOB|SSH_BUG_HMAC|
|
||||
@@ -251,7 +254,6 @@ compat_cipher_proposal(char *cipher_prop
|
||||
return cipher_prop;
|
||||
}
|
||||
|
||||
-
|
||||
char *
|
||||
compat_pkalg_proposal(char *pkalg_prop)
|
||||
{
|
||||
@@ -263,5 +265,18 @@ compat_pkalg_proposal(char *pkalg_prop)
|
||||
if (*pkalg_prop == '\0')
|
||||
fatal("No supported PK algorithms found");
|
||||
return pkalg_prop;
|
||||
+}
|
||||
+
|
||||
+char *
|
||||
+compat_kex_proposal(char *kex_prop)
|
||||
+{
|
||||
+ if (!(datafellows & SSH_BUG_CURVE25519PAD))
|
||||
+ return kex_prop;
|
||||
+ debug2("%s: original KEX proposal: %s", __func__, kex_prop);
|
||||
+ kex_prop = filter_proposal(kex_prop, "curve25519-sha256@libssh.org");
|
||||
+ debug2("%s: compat KEX proposal: %s", __func__, kex_prop);
|
||||
+ if (*kex_prop == '\0')
|
||||
+ fatal("No supported key exchange algorithms found");
|
||||
+ return kex_prop;
|
||||
}
|
||||
|
||||
Index: compat.h
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/compat.h,v
|
||||
retrieving revision 1.42
|
||||
retrieving revision 1.43
|
||||
diff -u -p -r1.42 -r1.43
|
||||
--- compat.h 31 Dec 2013 01:25:41 -0000 1.42
|
||||
+++ compat.h 20 Apr 2014 03:25:31 -0000 1.43
|
||||
@@ -59,6 +59,7 @@
|
||||
#define SSH_BUG_RFWD_ADDR 0x02000000
|
||||
#define SSH_NEW_OPENSSH 0x04000000
|
||||
#define SSH_BUG_DYNAMIC_RPORT 0x08000000
|
||||
+#define SSH_BUG_CURVE25519PAD 0x10000000
|
||||
|
||||
void enable_compat13(void);
|
||||
void enable_compat20(void);
|
||||
@@ -66,6 +67,7 @@ void compat_datafellows(const char *
|
||||
int proto_spec(const char *);
|
||||
char *compat_cipher_proposal(char *);
|
||||
char *compat_pkalg_proposal(char *);
|
||||
+char *compat_kex_proposal(char *);
|
||||
|
||||
extern int compat13;
|
||||
extern int compat20;
|
||||
Index: sshd.c
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/sshd.c,v
|
||||
retrieving revision 1.448
|
||||
retrieving revision 1.453
|
||||
diff -u -p -r1.448 -r1.453
|
||||
--- sshd.c 26 Feb 2014 23:20:08 -0000 1.448
|
||||
+++ sshd.c 20 Apr 2014 03:28:41 -0000 1.453
|
||||
@@ -2462,6 +2438,9 @@ do_ssh2_kex(void)
|
||||
if (options.kex_algorithms != NULL)
|
||||
myproposal[PROPOSAL_KEX_ALGS] = options.kex_algorithms;
|
||||
|
||||
+ myproposal[PROPOSAL_KEX_ALGS] = compat_kex_proposal(
|
||||
+ myproposal[PROPOSAL_KEX_ALGS]);
|
||||
+
|
||||
if (options.rekey_limit || options.rekey_interval)
|
||||
packet_set_rekey_limits((u_int32_t)options.rekey_limit,
|
||||
(time_t)options.rekey_interval);
|
||||
Index: sshconnect2.c
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/sshconnect2.c,v
|
||||
retrieving revision 1.197
|
||||
retrieving revision 1.199
|
||||
diff -u -p -r1.197 -r1.199
|
||||
--- sshconnect2.c 4 Feb 2014 00:20:16 -0000 1.197
|
||||
+++ sshconnect2.c 20 Apr 2014 03:25:31 -0000 1.199
|
||||
@@ -195,6 +196,8 @@ ssh_kex2(char *host, struct sockaddr *ho
|
||||
}
|
||||
if (options.kex_algorithms != NULL)
|
||||
myproposal[PROPOSAL_KEX_ALGS] = options.kex_algorithms;
|
||||
+ myproposal[PROPOSAL_KEX_ALGS] = compat_kex_proposal(
|
||||
+ myproposal[PROPOSAL_KEX_ALGS]);
|
||||
|
||||
if (options.rekey_limit || options.rekey_interval)
|
||||
packet_set_rekey_limits((u_int32_t)options.rekey_limit,
|
||||
Index: bufaux.c
|
||||
===================================================================
|
||||
RCS file: /var/cvs/openssh/bufaux.c,v
|
||||
retrieving revision 1.62
|
||||
retrieving revision 1.63
|
||||
diff -u -p -r1.62 -r1.63
|
||||
--- bufaux.c 4 Feb 2014 00:20:15 -0000 1.62
|
||||
+++ bufaux.c 20 Apr 2014 03:24:50 -0000 1.63
|
||||
@@ -1,4 +1,4 @@
|
||||
-/* $OpenBSD: bufaux.c,v 1.56 2014/02/02 03:44:31 djm Exp $ */
|
||||
+/* $OpenBSD: bufaux.c,v 1.57 2014/04/16 23:22:45 djm Exp $ */
|
||||
/*
|
||||
* Author: Tatu Ylonen <ylo@cs.hut.fi>
|
||||
* Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
|
||||
@@ -372,6 +372,9 @@ buffer_put_bignum2_from_string(Buffer *b
|
||||
|
||||
if (l > 8 * 1024)
|
||||
fatal("%s: length %u too long", __func__, l);
|
||||
+ /* Skip leading zero bytes */
|
||||
+ for (; l > 0 && *s == 0; l--, s++)
|
||||
+ ;
|
||||
p = buf = xmalloc(l + 1);
|
||||
/*
|
||||
* If most significant bit is set then prepend a zero byte to
|
||||
_______________________________________________
|
||||
openssh-unix-dev mailing list
|
||||
openssh-unix-dev@mindrot.org
|
||||
https://lists.mindrot.org/mailman/listinfo/openssh-unix-dev
|
||||
@@ -0,0 +1,8 @@
|
||||
#%PAM-1.0
|
||||
|
||||
auth include system-auth
|
||||
auth required pam_shells.so
|
||||
auth required pam_nologin.so
|
||||
account include system-auth
|
||||
password include system-auth
|
||||
session include system-auth
|
||||
@@ -0,0 +1,104 @@
|
||||
<?xml version="1.0" ?>
|
||||
<!DOCTYPE PISI SYSTEM "http://www.pisilinux.org/projeler/pisi/pisi-spec.dtd">
|
||||
<PISI>
|
||||
<Source>
|
||||
<Name>openssh</Name>
|
||||
<Homepage>http://www.openssh.com/</Homepage>
|
||||
<Packager>
|
||||
<Name>PisiLinux Community</Name>
|
||||
<Email>admins@pisilinux.org</Email>
|
||||
</Packager>
|
||||
<License>BSD</License>
|
||||
<IsA>app:console</IsA>
|
||||
<IsA>service</IsA>
|
||||
<Summary>Port of OpenBSD's free SSH release</Summary>
|
||||
<Description>OpenSSH is a FREE version of the SSH connectivity tools that technical users of the Internet rely on. Users of telnet, rlogin, and ftp may not realize that their password is transmitted across the Internet unencrypted, but it is. OpenSSH encrypts all traffic (including passwords) to effectively eliminate eavesdropping, connection hijacking, and other attacks.</Description>
|
||||
<Archive sha1sum="cdbc51e46a902b30d263b05fdc71340920e91c92" type="targz">http://ftp.icm.edu.pl/pub/OpenBSD/OpenSSH/portable/openssh-6.8p1.tar.gz</Archive>
|
||||
<BuildDependencies>
|
||||
<Dependency>libedit-devel</Dependency>
|
||||
<Dependency>zlib-devel</Dependency>
|
||||
<Dependency>openssl-devel</Dependency>
|
||||
<Dependency>mit-kerberos</Dependency>
|
||||
<Dependency>skey-devel</Dependency>
|
||||
<Dependency>pam-devel</Dependency>
|
||||
<Dependency>e2fsprogs-devel</Dependency>
|
||||
</BuildDependencies>
|
||||
<Patches>
|
||||
<!-- <Patch>curve25519pad.patch</Patch> -->
|
||||
</Patches>
|
||||
</Source>
|
||||
|
||||
<Package>
|
||||
<Name>openssh</Name>
|
||||
<RuntimeDependencies>
|
||||
<Dependency>libedit</Dependency>
|
||||
<Dependency>zlib</Dependency>
|
||||
<Dependency>openssl</Dependency>
|
||||
<Dependency>mit-kerberos</Dependency>
|
||||
<Dependency>skey</Dependency>
|
||||
<Dependency>pam</Dependency>
|
||||
</RuntimeDependencies>
|
||||
<Files>
|
||||
<Path fileType="config">/etc</Path>
|
||||
<Path fileType="executable">/usr/bin</Path>
|
||||
<Path fileType="executable">/usr/sbin</Path>
|
||||
<Path fileType="executable">/usr/libexec</Path>
|
||||
<Path fileType="library">/usr/lib</Path>
|
||||
<Path fileType="data">/usr/share/openssh</Path>
|
||||
<Path fileType="data">/var/empty</Path>
|
||||
<Path fileType="man">/usr/share/man</Path>
|
||||
<Path fileType="doc">/usr/share/doc</Path>
|
||||
</Files>
|
||||
<AdditionalFiles>
|
||||
<AdditionalFile owner="root" permission="0644" target="/etc/pam.d/sshd">sshd.pam</AdditionalFile>
|
||||
</AdditionalFiles>
|
||||
<Provides>
|
||||
<COMAR script="service.py">System.Service</COMAR>
|
||||
</Provides>
|
||||
</Package>
|
||||
|
||||
<History>
|
||||
<Update release="6">
|
||||
<Date>2015-04-23</Date>
|
||||
<Version>6.8_p1</Version>
|
||||
<Comment>Version bump.</Comment>
|
||||
<Name>Ertuğrul Erata</Name>
|
||||
<Email>ertugrulerata@gmail.com</Email>
|
||||
</Update>
|
||||
<Update release="5">
|
||||
<Date>2014-12-13</Date>
|
||||
<Version>6.7_p1</Version>
|
||||
<Comment>Version bump.</Comment>
|
||||
<Name>Yusuf Aydemir</Name>
|
||||
<Email>yusuf.aydemir@pisilinux.org</Email>
|
||||
</Update>
|
||||
<Update release="4">
|
||||
<Date>2014-05-21</Date>
|
||||
<Version>6.6_p1</Version>
|
||||
<Comment>Rebuild</Comment>
|
||||
<Name>Ertuğrul Erata</Name>
|
||||
<Email>ertugrulerata@gmail.com</Email>
|
||||
</Update>
|
||||
<Update release="3">
|
||||
<Date>2014-05-10</Date>
|
||||
<Version>6.6_p1</Version>
|
||||
<Comment>Version bump.</Comment>
|
||||
<Name>Ertuğrul Erata</Name>
|
||||
<Email>ertugrulerata@gmail.com</Email>
|
||||
</Update>
|
||||
<Update release="2">
|
||||
<Date>2013-11-22</Date>
|
||||
<Version>6.4_p1</Version>
|
||||
<Comment>Version bump</Comment>
|
||||
<Name>Aydın Demirel</Name>
|
||||
<Email>aydin.demirel@pisilinux.org</Email>
|
||||
</Update>
|
||||
<Update release="1" type="security">
|
||||
<Date>2012-10-30</Date>
|
||||
<Version>6.1_p1</Version>
|
||||
<Comment>First release</Comment>
|
||||
<Name>Osman Erkan</Name>
|
||||
<Email>osman.erkan@pisilinux.org</Email>
|
||||
</Update>
|
||||
</History>
|
||||
</PISI>
|
||||
@@ -0,0 +1,9 @@
|
||||
<?xml version="1.0" ?>
|
||||
<PISI>
|
||||
<Source>
|
||||
<Name>openssh</Name>
|
||||
<Summary xml:lang="tr">OpenBSD'den aktarılmış SSH sürümü</Summary>
|
||||
<Description xml:lang="tr">OpenSSH teknik internet kullanıcıların güvendikleri SSH bağlanırlık araçlarının Özgür (free) sürümüdür.telnet, rlogin ve ftp kullanıcıları parolalarının internetten şifresiz olarak aktarıldığını anlayamayabilirler ancak aktarılmaktadır.OpenSSH eavesdropping (iletişim kanalını dinleme), connection hijacking (bağlantı çalma) ve diğer atakları önlemek için tüm bağlantı trafiğini (parolalar dahil) şifrelemektedir.</Description>
|
||||
<Description xml:lang="fr">OpenSSH est une version libre des outils de connexion SSH sur lesquels les utilisateurs techniquement chevronnés s'appuient. Les utilisateurs de telnet, rlogin et ftp ne se rendent peut être pas compte que les mots de passe sont transmis sur internet en clair. OpenSSH crypte tout le trafic (y compris les mots de passe) pour éliminer les écoutes passives, les détournements de connexion et autres attaques.</Description>
|
||||
</Source>
|
||||
</PISI>
|
||||
Reference in New Issue
Block a user