Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
openSUSE:Leap:15.6:Update
openssh.33331
0002-upstream-disable-UpdateHostkeys-by-default...
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File 0002-upstream-disable-UpdateHostkeys-by-default-if.patch of Package openssh.33331
From e79957e877db42c4c68fabcf6ecff2268e53acb5 Mon Sep 17 00:00:00 2001 From: "djm@openbsd.org" <djm@openbsd.org> Date: Wed, 7 Oct 2020 02:18:45 +0000 Subject: [PATCH] upstream: disable UpdateHostkeys by default if VerifyHostKeyDNS is enabled; suggested by Mark D. Baushke OpenBSD-Commit-ID: 85a1b88592c81bc85df7ee7787dbbe721a0542bf --- readconf.c | 7 ++++--- ssh_config.5 | 8 +++++--- 2 files changed, 9 insertions(+), 6 deletions(-) diff --git a/readconf.c b/readconf.c index a4f6cba0519..8655646b47f 100644 --- a/readconf.c +++ b/readconf.c #@@ -1,4 +1,4 @@ #-/* $OpenBSD: readconf.c,v 1.337 2020/10/03 09:22:26 djm Exp $ */ #+/* $OpenBSD: readconf.c,v 1.338 2020/10/07 02:18:45 djm Exp $ */ # /* # * Author: Tatu Ylonen <ylo@cs.hut.fi> # * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland @@ -2168,9 +2168,10 @@ fill_default_options(Options * options) xstrdup(_PATH_SSH_SYSTEM_HOSTFILE2); } if (options->update_hostkeys == -1) { - if (options->num_user_hostfiles == 0 || + if (options->verify_host_key_dns <= 0 && + (options->num_user_hostfiles == 0 || (options->num_user_hostfiles == 1 && strcmp(options-> - user_hostfiles[0], _PATH_SSH_USER_HOSTFILE) == 0)) + user_hostfiles[0], _PATH_SSH_USER_HOSTFILE) == 0))) options->update_hostkeys = SSH_UPDATE_HOSTKEYS_YES; else options->update_hostkeys = SSH_UPDATE_HOSTKEYS_NO; diff --git a/ssh_config.5 b/ssh_config.5 index e085efffce7..2f1886a1b07 100644 --- a/ssh_config.5 +++ b/ssh_config.5 #@@ -33,8 +33,8 @@ # .\" (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF # .\" THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE. # .\" #-.\" $OpenBSD: ssh_config.5,v 1.334 2020/10/03 08:30:47 djm Exp $ #-.Dd $Mdocdate: October 3 2020 $ #+.\" $OpenBSD: ssh_config.5,v 1.335 2020/10/07 02:18:45 djm Exp $ #+.Dd $Mdocdate: October 7 2020 $ # .Dt SSH_CONFIG 5 # .Os # .Sh NAME @@ -1723,7 +1723,9 @@ host was already trusted or explicitly accepted by the user. .Cm UpdateHostKeys is enabled by default if the user has not overridden the default .Cm UserKnownHostsFile -setting, otherwise +setting and has not enabled +.Cm VerifyHostKeyDNS , +otherwise .Cm UpdateHostKeys will be set to .Cm no .
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor