openssh-vl.spec 25 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742
  1. %define ver 5.5p1
  2. %define rel 3%{_dist_release}
  3. # SELinux
  4. %define WITH_SELINUX 0
  5. # OpenSSH privilege separation requires a user & group ID
  6. %define sshd_uid 74
  7. %define sshd_gid 74
  8. # Version of ssh-askpass
  9. %define aversion 1.2.4.1
  10. # Do we want to disable building of gnome-askpass? (1=yes 0=no)
  11. %define no_gnome_askpass 0
  12. # Use GTK2 for gnome-ssh-askpass
  13. %define gtk2 1
  14. # Build position-independent executables (requires toolchain support)?
  15. %define pie 1
  16. # Do we want to link against a static libcrypto? (1=yes 0=no)
  17. %define static_libcrypto 0
  18. # Do we want smartcard support (1=yes 0=no)
  19. %define scard 0
  20. # Disable IPv6 (avoids DNS hangs on some glibc versions)
  21. %define noip6 0
  22. # Do we want kerberos5 support (1=yes 0=no)
  23. %define kerberos5 0
  24. # Reserve options to override askpass settings with:
  25. # rpm -ba|--rebuild --define 'skip_xxx 1'
  26. %{?skip_gnome_askpass:%define no_gnome_askpass 1}
  27. # Options for static OpenSSL link:
  28. # rpm -ba|--rebuild --define "static_openssl 1"
  29. %{?static_openssl:%define static_libcrypto 1}
  30. # Options for Smartcard support: (needs libsectok and openssl-engine)
  31. # rpm -ba|--rebuild --define "smartcard 1"
  32. %{?smartcard:%define scard 1}
  33. # Option to disable ipv6
  34. # rpm -ba|--rebuild --define "noipv6 1"
  35. %{?noipv6:%define noip6 1}
  36. # Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
  37. %define rescue 0
  38. %{?build_rescue:%define rescue 1}
  39. # Turn off some stuff for resuce builds
  40. %if %{rescue}
  41. %define kerberos5 0
  42. %endif
  43. Summary: The OpenSSH implementation of SSH.
  44. Summary(ja): OpenSSH - フリーの Secure Shell (SSH) の実装
  45. Name: openssh
  46. Version: %{ver}
  47. Release: %{rel}
  48. URL: http://www.openssh.com/portable.html
  49. Source0: ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-%{version}.tar.gz
  50. Patch0: openssh-5.5p1-vine.patch
  51. Patch2: openssh-5.3p1-skip-initial.patch
  52. Patch4: openssh-5.2p1-vendor.patch
  53. Patch5: openssh-3.9p1-noinitlog.patch
  54. Patch12: openssh-selinux.patch
  55. Patch20: openssh-3.9p1-gssapimitm.patch
  56. Patch21: openssh-3.9p1-safe-stop.patch
  57. Patch24: openssh-4.3p1-fromto-remote.patch
  58. Patch26: openssh-5.2p1-pam-no-stack.patch
  59. Patch27: openssh-5.1p1-log-in-chroot.patch
  60. Patch30: openssh-4.0p1-exit-deadlock.patch
  61. # Patch31: openssh-3.9p1-skip-used.patch
  62. Patch35: openssh-4.2p1-askpass-progress.patch
  63. # Vine Patch
  64. Patch100: openssh-norootlogin.patch
  65. Patch120: openssh-4.7p1-sshd.init.patch
  66. License: BSD
  67. Group: Applications/Internet
  68. BuildRoot: %{_tmppath}/%{name}-%{version}-buildroot
  69. Obsoletes: ssh
  70. BuildRequires: perl, openssl-devel, sharutils, tcp_wrappers
  71. BuildRequires: util-linux
  72. BuildRequires: db4-devel
  73. BuildRequires: pam-devel
  74. BuildRequires: zlib-devel
  75. %if ! %{no_gnome_askpass}
  76. BuildRequires: libX11-devel
  77. BuildRequires: gtk2-devel
  78. %endif
  79. BuildRequires: xorg-x11-xauth
  80. BuildRequires: groff
  81. BuildRequires: libedit-devel
  82. Vendor: Project Vine
  83. Distribution: Vine Linux
  84. Packager: daisuke
  85. %package clients
  86. Summary: OpenSSH clients.
  87. Summary(ja): OpenSSH Secure Shell プロトコルクライアント
  88. Requires: openssh = %{version}-%{release}
  89. Group: Applications/Internet
  90. Obsoletes: ssh-clients
  91. %package server
  92. Summary: The OpenSSH server daemon.
  93. Summary(ja): OpenSSH Secure Shell プロトコルサーバ (sshd)
  94. Group: System Environment/Daemons
  95. Obsoletes: ssh-server
  96. Requires(post): openssh = %{version}-%{release}
  97. Requires(post): chkconfig
  98. Requires(pre): shadow-utils
  99. Requires(post): initscripts >= 5.20
  100. Requires: pam
  101. %package askpass-gnome
  102. Summary: A passphrase dialog for OpenSSH, X, and GNOME.
  103. Summary(ja): OpenSSH GNOME パスフレーズ入力ダイアログ
  104. Group: Applications/Internet
  105. Requires: openssh = %{version}-%{release}
  106. Obsoletes: ssh-extras
  107. Obsoletes: openssh-askpass < 5.5p1-3vl6
  108. Provides: openssh-askpass = %{version}-%{release}
  109. %package contrib
  110. Summary: addons for OpenSSH
  111. Summary(ja): OpenSSH のためのアドオン
  112. Group: Applications/Internet
  113. Requires: openssh-clients = %{version}-%{release}
  114. %description
  115. SSH (Secure SHell) is a program for logging into and executing
  116. commands on a remote machine. SSH is intended to replace rlogin and
  117. rsh, and to provide secure encrypted communications between two
  118. untrusted hosts over an insecure network. X11 connections and
  119. arbitrary TCP/IP ports can also be forwarded over the secure channel.
  120. OpenSSH is OpenBSD's version of the last free version of SSH, bringing
  121. it up to date in terms of security and features, as well as removing
  122. all patented algorithms to separate libraries.
  123. This package includes the core files necessary for both the OpenSSH
  124. client and server. To make this package useful, you should also
  125. install openssh-clients, openssh-server, or both.
  126. #'
  127. %description -l ja
  128. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  129. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  130. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  131. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  132. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  133. な通信路の中を通すことができます。
  134. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  135. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  136. アルゴリズムは分割したライブラリにわかれています。
  137. このパッケージは OpenSSH のクライアントとサーバの両方で必要とされる
  138. コアのファイルを含んでいます。実際に使用するにはこのパッケージの他に
  139. openssh-clients および/または openssh-server が必要です。
  140. %description clients
  141. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  142. into and executing commands on a remote machine. This package includes
  143. the clients necessary to make encrypted connections to SSH servers.
  144. You'll also need to install the openssh package on OpenSSH clients.
  145. #'
  146. %description -l ja clients
  147. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  148. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  149. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  150. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  151. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  152. な通信路の中を通すことができます。
  153. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  154. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  155. アルゴリズムは分割したライブラリにわかれています。
  156. このパッケージは OpenSSH をクライアントとして使用する場合に
  157. 必要なものを含んでいます。
  158. %description server
  159. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  160. into and executing commands on a remote machine. This package contains
  161. the secure shell daemon (sshd). The sshd daemon allows SSH clients to
  162. securely connect to your SSH server. You also need to have the openssh
  163. package installed.
  164. %description -l ja server
  165. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  166. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  167. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  168. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  169. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  170. な通信路の中を通すことができます。
  171. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  172. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  173. アルゴリズムは分割したライブラリにわかれています。
  174. このパッケージは OpenSSH をサーバとして使用する場合に必要な
  175. デーモンなどを含んでいます。
  176. %description askpass-gnome
  177. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  178. into and executing commands on a remote machine. This package contains
  179. an X11 passphrase dialog for OpenSSH and the GNOME GUI desktop
  180. environment.
  181. %description -l ja askpass-gnome
  182. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  183. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  184. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  185. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  186. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  187. な通信路の中を通すことができます。
  188. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  189. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  190. アルゴリズムは分割したライブラリにわかれています。
  191. このパッケージは GNOME 用のパスフレーズ入力ダイアログを含んでいます。
  192. %description contrib
  193. addons for OpenSSH
  194. %description -l ja contrib
  195. OpenSSH のためのアドオン
  196. %prep
  197. %setup -q
  198. %patch0 -p1 -b .vine
  199. %patch2 -p1 -b .skip-initial
  200. %patch4 -p1 -b .vendor
  201. %patch5 -p1 -b .noinitlog
  202. %if %{WITH_SELINUX}
  203. #SELinux
  204. %patch12 -p1 -b .selinux
  205. %endif
  206. %patch21 -p1 -b .safe-stop
  207. %patch24 -p1 -b .fromto-remote
  208. %patch26 -p1 -b .stack
  209. %patch27 -p1 -b .log-chroot
  210. %patch30 -p1 -b .exit-deadlock
  211. %patch35 -p1 -b .progress
  212. %patch100 -p1 -b .norootlogin
  213. %patch120 -p1 -b .localtime
  214. autoreconf
  215. %build
  216. CFLAGS="$RPM_OPT_FLAGS"; export CFLAGS
  217. %if %{rescue}
  218. CFLAGS="$RPM_OPT_FLAGS -Os"; export CFLAGS
  219. %endif
  220. %if %{pie}
  221. %ifarch s390 s390x sparc sparc64
  222. CFLAGS="$CFLAGS -fPIE"
  223. %else
  224. CFLAGS="$CFLAGS -fpie"
  225. %endif
  226. export CFLAGS
  227. LDFLAGS="$LDFLAGS -pie"; export LDFLAGS
  228. %endif
  229. %configure \
  230. --sysconfdir=%{_sysconfdir}/ssh \
  231. --libexecdir=%{_libexecdir}/openssh \
  232. --datadir=%{_datadir}/openssh \
  233. --with-tcp-wrappers \
  234. --with-default-path=/usr/local/bin:/bin:/usr/bin \
  235. --with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
  236. --with-privsep-path=%{_var}/empty/sshd \
  237. --enable-vendor-patchlevel="VL-%{version}-%{release}" \
  238. --with-libedit \
  239. %if %{scard}
  240. --with-smartcard \
  241. %endif
  242. %if %{noip6}
  243. --with-ipv4-default \
  244. %endif
  245. %if %{rescue}
  246. --without-pam --with-md5-passwords
  247. %else
  248. --with-pam
  249. %endif
  250. %if %{static_libcrypto}
  251. perl -pi -e "s|-lcrypto|%{_libdir}/libcrypto.a|g" Makefile
  252. %endif
  253. make
  254. %if %{gtk2}
  255. gtk2=yes
  256. %else
  257. gtk2=no
  258. %endif
  259. %if ! %{no_gnome_askpass}
  260. pushd contrib
  261. if [ $gtk2 = yes ]; then
  262. make gnome-ssh-askpass2
  263. mv gnome-ssh-askpass2 gnome-ssh-askpass
  264. else
  265. make gnome-ssh-askpass1
  266. mv gnome-ssh-askpass1 gnome-ssh-askpass
  267. fi
  268. popd
  269. %endif
  270. %install
  271. rm -rf $RPM_BUILD_ROOT
  272. mkdir -p -m755 $RPM_BUILD_ROOT%{_sysconfdir}/ssh
  273. mkdir -p -m755 $RPM_BUILD_ROOT%{_libexecdir}/openssh
  274. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd
  275. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd/etc
  276. make install DESTDIR=$RPM_BUILD_ROOT
  277. touch $RPM_BUILD_ROOT%{_var}/empty/sshd/etc/localtime
  278. install -d $RPM_BUILD_ROOT/etc/pam.d/
  279. install -d $RPM_BUILD_ROOT/etc/rc.d/init.d
  280. install -d $RPM_BUILD_ROOT%{_libexecdir}/openssh
  281. install -m644 contrib/redhat/sshd.pam $RPM_BUILD_ROOT/etc/pam.d/sshd
  282. install -m755 contrib/redhat/sshd.init $RPM_BUILD_ROOT/etc/rc.d/init.d/sshd
  283. %if ! %{scard}
  284. rm -f $RPM_BUILD_ROOT%{_datadir}/openssh/Ssh.bin
  285. %endif
  286. %if ! %{no_gnome_askpass}
  287. install -s contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
  288. install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  289. install -m 755 contrib/redhat/gnome-ssh-askpass.{sh,csh} $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  290. %endif
  291. %if %{no_gnome_askpass}
  292. rm -f $RPM_BUILD_ROOT/etc/profile.d/gnome-ssh-askpass.*
  293. %endif
  294. # for contrib package
  295. install -m 0755 contrib/ssh-copy-id $RPM_BUILD_ROOT%{_bindir}
  296. install -m 0644 contrib/ssh-copy-id.1 $RPM_BUILD_ROOT%{_mandir}/man1
  297. mv contrib/README contrib/README.contrib
  298. perl -pi -e "s|$RPM_BUILD_ROOT||g" $RPM_BUILD_ROOT%{_mandir}/man*/*
  299. %clean
  300. rm -rf $RPM_BUILD_ROOT
  301. %triggerun server -- ssh-server
  302. if [ "$1" != 0 -a -r /var/run/sshd.pid ] ; then
  303. touch /var/run/sshd.restart
  304. fi
  305. %triggerun server -- openssh-server < 2.5.0p1
  306. # Count the number of HostKey and HostDsaKey statements we have.
  307. gawk 'BEGIN {IGNORECASE=1}
  308. /^hostkey/ || /^hostdsakey/ {sawhostkey = sawhostkey + 1}
  309. END {exit sawhostkey}' /etc/ssh/sshd_config
  310. # And if we only found one, we know the client was relying on the old default
  311. # behavior, which loaded the the SSH2 DSA host key when HostDsaKey wasn't
  312. # specified. Now that HostKey is used for both SSH1 and SSH2 keys, specifying
  313. # one nullifies the default, which would have loaded both.
  314. if [ $? -eq 1 ] ; then
  315. echo HostKey /etc/ssh/ssh_host_rsa_key >> /etc/ssh/sshd_config
  316. echo HostKey /etc/ssh/ssh_host_dsa_key >> /etc/ssh/sshd_config
  317. fi
  318. %triggerpostun server -- ssh-server
  319. if [ "$1" != 0 ] ; then
  320. /sbin/chkconfig --add sshd
  321. if test -f /var/run/sshd.restart ; then
  322. rm -f /var/run/sshd.restart
  323. # /sbin/service sshd start > /dev/null 2>&1 || :
  324. /sbin/service sshd start
  325. fi
  326. fi
  327. %pre server
  328. %{_sbindir}/groupadd -r -g %{sshd_gid} sshd 2>/dev/null || :
  329. %{_sbindir}/useradd -d /var/empty/sshd -s /bin/false -u %{sshd_uid} \
  330. -g sshd -M -r sshd 2>/dev/null || :
  331. %post server
  332. /sbin/chkconfig --add sshd
  333. %postun server
  334. # /sbin/service sshd condrestart > /dev/null 2>&1 || :
  335. /sbin/service sshd condrestart
  336. exit 0
  337. %preun server
  338. if [ "$1" = 0 ]
  339. then
  340. /sbin/service sshd stop > /dev/null 2>&1 || :
  341. /sbin/chkconfig --del sshd
  342. fi
  343. %files
  344. %defattr(-,root,root)
  345. %doc CREDITS ChangeLog INSTALL LICENCE OVERVIEW README* RFC* TODO WARNING*
  346. %attr(0755,root,root) %{_bindir}/scp
  347. %attr(0644,root,root) %{_mandir}/man1/scp.1*
  348. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  349. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/moduli
  350. %attr(644,root,root) %{_mandir}/man5/moduli.5*
  351. %if ! %{rescue}
  352. %attr(0755,root,root) %{_bindir}/ssh-keygen
  353. %attr(0644,root,root) %{_mandir}/man1/ssh-keygen.1*
  354. %attr(0755,root,root) %dir %{_libexecdir}/openssh
  355. %attr(4711,root,root) %{_libexecdir}/openssh/ssh-keysign
  356. %attr(0644,root,root) %{_mandir}/man8/ssh-keysign.8*
  357. %endif
  358. %if %{scard}
  359. %attr(0755,root,root) %dir %{_datadir}/openssh
  360. %attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
  361. %endif
  362. %files clients
  363. %defattr(-,root,root)
  364. %attr(0755,root,root) %{_bindir}/ssh
  365. %attr(0644,root,root) %{_mandir}/man1/ssh.1*
  366. %attr(0644,root,root) %{_mandir}/man5/ssh_config.5*
  367. %attr(0644,root,root) %{_mandir}/man1/slogin.1*
  368. %attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ssh/ssh_config
  369. %attr(-,root,root) %{_bindir}/slogin
  370. %if ! %{rescue}
  371. %attr(0755,root,root) %{_bindir}/ssh-agent
  372. %attr(0755,root,root) %{_bindir}/ssh-add
  373. %attr(0755,root,root) %{_bindir}/ssh-keyscan
  374. %attr(0755,root,root) %{_bindir}/sftp
  375. %attr(0644,root,root) %{_mandir}/man1/ssh-agent.1*
  376. %attr(0644,root,root) %{_mandir}/man1/ssh-add.1*
  377. %attr(0644,root,root) %{_mandir}/man1/ssh-keyscan.1*
  378. %attr(0644,root,root) %{_mandir}/man1/sftp.1*
  379. %endif
  380. %if ! %{rescue}
  381. %files server
  382. %defattr(-,root,root)
  383. %dir %attr(0711,root,root) %{_var}/empty/sshd
  384. %dir %attr(0755,root,root) %{_var}/empty/sshd/etc
  385. %ghost %verify(not md5 size mtime) %{_var}/empty/sshd/etc/localtime
  386. %attr(0755,root,root) %{_sbindir}/sshd
  387. %attr(0755,root,root) %{_libexecdir}/openssh/sftp-server
  388. %attr(0644,root,root) %{_mandir}/man5/sshd_config.5*
  389. %attr(0644,root,root) %{_mandir}/man8/sshd.8*
  390. %attr(0644,root,root) %{_mandir}/man8/sftp-server.8*
  391. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  392. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/sshd_config
  393. %attr(0600,root,root) %config(noreplace) /etc/pam.d/sshd
  394. %attr(0755,root,root) %config /etc/rc.d/init.d/sshd
  395. %endif
  396. %if ! %{no_gnome_askpass}
  397. %files askpass-gnome
  398. %defattr(-,root,root)
  399. %attr(0755,root,root) %config %{_sysconfdir}/profile.d/gnome-ssh-askpass.*
  400. %attr(0755,root,root) %{_libexecdir}/openssh/gnome-ssh-askpass
  401. %endif
  402. %files contrib
  403. %defattr(-,root,root)
  404. %doc contrib/README.contrib
  405. %{_bindir}/ssh-copy-id
  406. %{_mandir}/man1/ssh-copy-id.1*
  407. %changelog
  408. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-3
  409. - drop x11-askpass, add Obsoletes: openssh-askpass
  410. - add BR: groff
  411. - enable --with-libedit option, add BR: libedit-devel
  412. - remove unrecognized option '--with-rsh'
  413. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-2
  414. - add BR: xorg-x11-xauth for X11 forwarding support
  415. * Thu Apr 22 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-1
  416. - new upstream release
  417. - update patch0,2
  418. - drop patch3,22
  419. * Tue Feb 24 2009 Daisuke SUZUKI <daisuke@linux.or.jp> 5.2p1-1
  420. - new upstream release
  421. * Tue Jul 22 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.1p1-1
  422. - new upstream release
  423. * Thu May 29 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.0p1-2
  424. - rebuild with xorg-x11-7.3
  425. * Fri Apr 04 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.0p1-1
  426. - new upstream release with security fix (CVE-2008-1483)
  427. - drop patch31 which is included in new release (This was for CVE-2008-1483)
  428. * Tue Apr 01 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.9p1-1
  429. - new upstream release with security fix ("ForceCommand" Directive)
  430. - turn on daemon restart message
  431. - new versioning policy
  432. * Mon Nov 26 2007 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.7p1-0vl2
  433. - add /var/empty/sshd/etc/localtime to fix secure log bad timestamps
  434. * Tue Nov 13 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.7p1-0vl1
  435. - new upstream release
  436. * Thu May 17 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl2
  437. - build with -fpie/-pie by default.
  438. - enable ipv6 by default.
  439. * Fri May 04 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl1
  440. - new upstream release
  441. * Wed Nov 08 2006 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.5p1-0vl1
  442. - new upstream release
  443. * Fri Sep 29 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.4p1-0vl1
  444. - new upstream release
  445. * Thu Jul 27 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p2-0vl1
  446. - new upstream release
  447. * Mon Apr 10 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p1-0vl1
  448. - new upstream release
  449. - remove build6x stuff
  450. - remove libgnome-devel from BuildRequires
  451. - cleanup BuildRequires
  452. - drop Patch200, it is merged in upstream.
  453. - import patches(25-35) from FC-devel
  454. * Mon Apr 10 2006 IWAI, Masaharu <iwai@alib.jp> 4.2p1-0vl3
  455. - SECURITY FIX: CVE-2006-0225
  456. - add scp no system patch ( Patch200 ): from Fedora Core 4 4.2p1-fc4.10
  457. - update BuildPreReq: s/XFree86-devel/XOrg-devel/
  458. - fix BuildPreReq for GNOME: gnome-libs-devel ( GNOME1 ) was always used
  459. - When GNOME2 is used, using libgnome-devel
  460. - add BuildPreReq: gtk2-devel for GNOME2
  461. * Sat Sep 24 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl2
  462. - rebuild with gtk+-2.8 final
  463. * Sun Sep 4 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl1
  464. - new upstream release
  465. - build with gtk+-2.7
  466. * Sun May 29 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.1p1-0vl1
  467. - new upstream release
  468. * Fri Apr 01 2005 KOBAYASHI Taizo <tkoba@vinelinux.org> 4.0p1-0vl2
  469. - cleanup obsolete patches and added patches from fedora
  470. * Wed Mar 16 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.0p1-0vl1
  471. - new upstream release
  472. * Thu Aug 19 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.9pl1-0vl1
  473. - new upstream release
  474. * Wed Apr 21 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8.1p1-0vl1
  475. - new upstream release
  476. * Fri Mar 26 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl2
  477. - rebuild with openssl-0.9.7d
  478. * Fri Feb 27 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl1
  479. - new upstream release
  480. * Thu Oct 2 2003 IWAI, Masaharu <iwai@alib.jp> 3.7.1p2-0vl2
  481. - create contrib package
  482. * Wed Sep 24 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p2-0vl1
  483. - new upstream release
  484. - fix security issue: http://www.openssh.com/txt/sshpam.adv
  485. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p1-0vl1
  486. - new upstream release
  487. - fix security issue: http://www.openssh.com/txt/buffer.adv
  488. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7p1-0vl1
  489. - new upstream release
  490. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1.1
  491. - rebuild with gtk2
  492. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1
  493. - new upstream release
  494. * Sat Apr 13 2003 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.5p1-0vl2
  495. - rebuild with new tool chain
  496. * Tue Oct 29 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.5p1-0vl1
  497. - new upstream release
  498. - merge with upstream spec (drop anonymous mmap patch, suid of ssh)
  499. * Tue Aug 20 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl3
  500. - change some defines in spec files
  501. * Wed Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl2
  502. - add patch110 ( 3.4p1 does not include mmap-fallback patch )
  503. * Wed Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl1
  504. - new upstream release
  505. - security fix
  506. - drop patch10
  507. * Wed Jun 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl2
  508. - add patch from Solar Designer to make privsep work with a 2.2 kernel.
  509. * Sun Jun 23 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl1
  510. - new upstream release
  511. - add {sshd,ssh}_config.5 manpages
  512. - add ssh-keysign
  513. * Sun May 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.3p1-0vl1
  514. - new upstream release
  515. * Sat May 18 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.2p1-0vl1
  516. - new upstream release
  517. - drop patch1
  518. * Fri Mar 08 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.1p1-2vl1
  519. - new upstream release
  520. - merged with rawhide release.
  521. - drop Patch101 (merged in upstream)
  522. * Fri Mar 08 2002 Toru Sagami <sagami@vinelinux.org> 3.0.2p1-2vl2
  523. - seurity patch for off-by-one bug
  524. * Wed Jan 30 2002 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.0.2p-2vl1
  525. - merged with Rawhide 3.0.2p1-2
  526. * Sun Dec 02 2001 Toru Sagami <sagami@vinelinux.org>
  527. - updated to 3.0.2p1
  528. * Mon Nov 19 2001 Toru Sagami <sagami@vinelinux.org>
  529. - updated to 3.0.1p1
  530. * Thu Nov 08 2001 Toru Sagami <sagami@vinelinux.org> 3.0p1-0vl0
  531. - updated to 3.0p1
  532. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl2
  533. - add japanese summery and descriptions.
  534. - update x11-askpass 1.2.5
  535. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl1
  536. - update to openssh-2.9.9p2
  537. * Mon Jul 16 2001 MATSUBAYASHI 'Shaolin' Kohji <shaolin@vinelinux.org> 2.5.2p2-0vl3
  538. - rebuilt with openssl-0.9.6b
  539. * Tue Mar 27 2001 Jun Nishii <jun@vinelinux.org> 2.5.2p2-0vl2
  540. - do not Permit RootLogin
  541. * Tue Mar 27 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p2-0vl1
  542. - update to openssh-2.5.2p2
  543. * Wed Mar 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p1-0vl1
  544. - update to openssh-2.5.2p1
  545. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  546. - update to openssh-2.5.1p2
  547. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  548. - update to openssh-2.5.1p1
  549. * Wed Feb 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p1-0vl1
  550. - update to openssh-2.5.1p1
  551. * Thu Dec 28 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl4
  552. - remove suid bit from ssh
  553. * Tue Dec 19 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl3
  554. - moved man dir to /usr/share/man
  555. * Wed Dec 06 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl2
  556. - fixed askpass's link in ssh-add
  557. - partially used rpmmacros
  558. * Fri Nov 10 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl1
  559. - update to 2.3.0p1
  560. - update x11-askpass 1.0.3
  561. * Mon Oct 18 2000 Damien Miller <djm@mindrot.org>
  562. - Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
  563. Redhat 7.0 spec file
  564. * Sat Oct 14 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.2.0p2-2vl1
  565. - rebuild for Vine Linux
  566. * Tue Sep 05 2000 Damien Miller <djm@mindrot.org>
  567. - Use RPM configure macro
  568. * Tue Aug 08 2000 Damien Miller <djm@mindrot.org>
  569. - Some surgery to sshd.init (generate keys at runtime)
  570. - Cleanup of groups and removal of keygen calls
  571. * Wed Jul 12 2000 Damien Miller <djm@mindrot.org>
  572. - Make building of X11-askpass and gnome-askpass optional
  573. * Mon Jun 12 2000 Damien Miller <djm@mindrot.org>
  574. - Glob manpages to catch compressed files
  575. * Wed Mar 15 2000 Damien Miller <djm@ibs.com.au>
  576. - Updated for new location
  577. - Updated for new gnome-ssh-askpass build
  578. * Sun Dec 26 1999 Damien Miller <djm@mindrot.org>
  579. - Added Jim Knoble's <jmknoble@pobox.com> askpass
  580. * Mon Nov 15 1999 Damien Miller <djm@mindrot.org>
  581. - Split subpackages further based on patch from jim knoble <jmknoble@pobox.com>
  582. * Sat Nov 13 1999 Damien Miller <djm@mindrot.org>
  583. - Added 'Obsoletes' directives
  584. * Tue Nov 09 1999 Damien Miller <djm@ibs.com.au>
  585. - Use make install
  586. - Subpackages
  587. * Mon Nov 08 1999 Damien Miller <djm@ibs.com.au>
  588. - Added links for slogin
  589. - Fixed perms on manpages
  590. * Sat Oct 30 1999 Damien Miller <djm@ibs.com.au>
  591. - Renamed init script
  592. * Fri Oct 29 1999 Damien Miller <djm@ibs.com.au>
  593. - Back to old binary names
  594. * Thu Oct 28 1999 Damien Miller <djm@ibs.com.au>
  595. - Use autoconf
  596. - New binary names
  597. * Wed Oct 27 1999 Damien Miller <djm@ibs.com.au>
  598. - Initial RPMification, based on Jan "Yenya" Kasprzak's <kas@fi.muni.cz> spec.