[27571] in Kerberos

home help back first fref pref prev next nref lref last post

GSSAPI Key Exchange Patch for OpenSSH 4.6p1

daemon@ATHENA.MIT.EDU (Simon Wilkinson)
Tue Mar 13 12:20:48 2007

Mime-Version: 1.0 (Apple Message framework v752.3)
Message-Id: <67AAD2C2-DFD0-4F21-9495-BF1A5DF0A178@inf.ed.ac.uk>
From: Simon Wilkinson <sxw@inf.ed.ac.uk>
Date: Mon, 12 Mar 2007 21:49:18 +0000
To: openssh-unix-dev@mindrot.org
Cc: heimdal-discuss@sics.se, kerberos@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: kerberos-bounces@mit.edu

Hi,

I'm pleased to announce the availability of my GSSAPI Key Exchange  
patch for OpenSSH 4.6p1.

This patch adds support for the RFC4462 GSSAPI key exchange  
mechanisms to OpenSSH, along with some minor fixes for the GSSAPI  
code that is already in the tree.

The patch implements:
   *) gss-group1-sha1-*, gss-group14-sha1-* and gss-gex-sha1-* key  
exchange mechanisms. (#1242)
   *) Support for the null host key type (#1242)
   *) Support for CCAPI credentials caches on Mac OS X (#1245)
   *) Support for better error handling when an authentication  
exchange fails due to server misconfiguration (#1244)
   *) Better error reporting when using a GSSAPI library which  
supports multiple mechanisms (#1220)
   *) Support for GSSAPI connections to hosts behind a round-robin  
load balancer (#1008)
   *) Support for GSSAPI connections to multi-homed hosts, where each  
interface has a unique name (#928)
   *) Cleanup of GSSAPI code seperation between client and server.  
(#1225)

(bugzilla.mindrot.org bug numbers are in brackets)

The only change since the last release is a minor code fix.

As usual, the code is available from
http://www.sxw.org.uk/computing/patches/openssh.html

Cheers,

Simon.

________________________________________________
Kerberos mailing list           Kerberos@mit.edu
https://mailman.mit.edu/mailman/listinfo/kerberos

home help back first fref pref prev next nref lref last post