openssh-vl.spec 25 KB


  1. %define ver 5.6p1
  2. %define rel 1%{_dist_release}
  3. # SELinux
  4. %define WITH_SELINUX 0
  5. # OpenSSH privilege separation requires a user & group ID
  6. %define sshd_uid 74
  7. %define sshd_gid 74
  8. # Version of ssh-askpass
  9. %define aversion 1.2.4.1
  10. # Do we want to disable building of gnome-askpass? (1=yes 0=no)
  11. %define no_gnome_askpass 0
  12. # Use GTK2 for gnome-ssh-askpass
  13. %define gtk2 1
  14. # Build position-independent executables (requires toolchain support)?
  15. %define pie 1
  16. # Do we want to link against a static libcrypto? (1=yes 0=no)
  17. %define static_libcrypto 0
  18. # Do we want smartcard support (1=yes 0=no)
  19. %define scard 0
  20. # Disable IPv6 (avoids DNS hangs on some glibc versions)
  21. %define noip6 0
  22. # Do we want kerberos5 support (1=yes 0=no)
  23. %define kerberos5 0
  24. # Reserve options to override askpass settings with:
  25. # rpm -ba|--rebuild --define 'skip_xxx 1'
  26. %{?skip_gnome_askpass:%define no_gnome_askpass 1}
  27. # Options for static OpenSSL link:
  28. # rpm -ba|--rebuild --define "static_openssl 1"
  29. %{?static_openssl:%define static_libcrypto 1}
  30. # Options for Smartcard support: (needs libsectok and openssl-engine)
  31. # rpm -ba|--rebuild --define "smartcard 1"
  32. %{?smartcard:%define scard 1}
  33. # Option to disable ipv6
  34. # rpm -ba|--rebuild --define "noipv6 1"
  35. %{?noipv6:%define noip6 1}
  36. # Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
  37. %define rescue 0
  38. %{?build_rescue:%define rescue 1}
  39. # Turn off some stuff for resuce builds
  40. %if %{rescue}
  41. %define kerberos5 0
  42. %endif
  43. Summary: The OpenSSH implementation of SSH.
  44. Summary(ja): OpenSSH - フリーの Secure Shell (SSH) の実装
  45. Name: openssh
  46. Version: %{ver}
  47. Release: %{rel}
  48. URL: http://www.openssh.com/portable.html
  49. Source0: ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-%{version}.tar.gz
  50. Patch0: openssh-5.5p1-vine.patch
  51. Patch4: openssh-5.2p1-vendor.patch
  52. Patch5: openssh-3.9p1-noinitlog.patch
  53. Patch12: openssh-selinux.patch
  54. Patch20: openssh-3.9p1-gssapimitm.patch
  55. Patch21: openssh-3.9p1-safe-stop.patch
  56. Patch24: openssh-4.3p1-fromto-remote.patch
  57. Patch26: openssh-5.2p1-pam-no-stack.patch
  58. Patch27: openssh-5.1p1-log-in-chroot.patch
  59. Patch30: openssh-4.0p1-exit-deadlock.patch
  60. # Patch31: openssh-3.9p1-skip-used.patch
  61. Patch35: openssh-4.2p1-askpass-progress.patch
  62. # Vine Patch
  63. Patch100: openssh-norootlogin.patch
  64. Patch120: openssh-4.7p1-sshd.init.patch
  65. License: BSD
  66. Group: Applications/Internet
  67. BuildRoot: %{_tmppath}/%{name}-%{version}-buildroot
  68. Obsoletes: ssh
  69. BuildRequires: perl, openssl-devel, sharutils, tcp_wrappers
  70. BuildRequires: util-linux
  71. BuildRequires: db4-devel
  72. BuildRequires: pam-devel
  73. BuildRequires: zlib-devel
  74. %if ! %{no_gnome_askpass}
  75. BuildRequires: libX11-devel
  76. BuildRequires: gtk2-devel
  77. %endif
  78. BuildRequires: xorg-x11-xauth
  79. BuildRequires: groff
  80. BuildRequires: libedit-devel
  81. Vendor: Project Vine
  82. Distribution: Vine Linux
  83. Packager: daisuke
  84. %package clients
  85. Summary: OpenSSH clients.
  86. Summary(ja): OpenSSH Secure Shell プロトコルクライアント
  87. Requires: openssh = %{version}-%{release}
  88. Group: Applications/Internet
  89. Obsoletes: ssh-clients
  90. Obsoletes: openssh-contrib
  91. %package server
  92. Summary: The OpenSSH server daemon.
  93. Summary(ja): OpenSSH Secure Shell プロトコルサーバ (sshd)
  94. Group: System Environment/Daemons
  95. Obsoletes: ssh-server
  96. Requires(post): openssh = %{version}-%{release}
  97. Requires(post): chkconfig
  98. Requires(pre): shadow-utils
  99. Requires(post): initscripts >= 5.20
  100. Requires: pam
  101. %package askpass-gnome
  102. Summary: A passphrase dialog for OpenSSH, X, and GNOME.
  103. Summary(ja): OpenSSH GNOME パスフレーズ入力ダイアログ
  104. Group: Applications/Internet
  105. Requires: openssh = %{version}-%{release}
  106. Obsoletes: ssh-extras
  107. Obsoletes: openssh-askpass < 5.5p1-3vl6
  108. Provides: openssh-askpass = %{version}-%{release}
  109. %description
  110. SSH (Secure SHell) is a program for logging into and executing
  111. commands on a remote machine. SSH is intended to replace rlogin and
  112. rsh, and to provide secure encrypted communications between two
  113. untrusted hosts over an insecure network. X11 connections and
  114. arbitrary TCP/IP ports can also be forwarded over the secure channel.
  115. OpenSSH is OpenBSD's version of the last free version of SSH, bringing
  116. it up to date in terms of security and features, as well as removing
  117. all patented algorithms to separate libraries.
  118. This package includes the core files necessary for both the OpenSSH
  119. client and server. To make this package useful, you should also
  120. install openssh-clients, openssh-server, or both.
  121. #'
  122. %description -l ja
  123. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  124. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  125. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  126. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  127. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  128. な通信路の中を通すことができます。
  129. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  130. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  131. アルゴリズムは分割したライブラリにわかれています。
  132. このパッケージは OpenSSH のクライアントとサーバの両方で必要とされる
  133. コアのファイルを含んでいます。実際に使用するにはこのパッケージの他に
  134. openssh-clients および/または openssh-server が必要です。
  135. %description clients
  136. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  137. into and executing commands on a remote machine. This package includes
  138. the clients necessary to make encrypted connections to SSH servers.
  139. You'll also need to install the openssh package on OpenSSH clients.
  140. #'
  141. %description -l ja clients
  142. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  143. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  144. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  145. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  146. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  147. な通信路の中を通すことができます。
  148. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  149. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  150. アルゴリズムは分割したライブラリにわかれています。
  151. このパッケージは OpenSSH をクライアントとして使用する場合に
  152. 必要なものを含んでいます。
  153. %description server
  154. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  155. into and executing commands on a remote machine. This package contains
  156. the secure shell daemon (sshd). The sshd daemon allows SSH clients to
  157. securely connect to your SSH server. You also need to have the openssh
  158. package installed.
  159. %description -l ja server
  160. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  161. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  162. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  163. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  164. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  165. な通信路の中を通すことができます。
  166. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  167. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  168. アルゴリズムは分割したライブラリにわかれています。
  169. このパッケージは OpenSSH をサーバとして使用する場合に必要な
  170. デーモンなどを含んでいます。
  171. %description askpass-gnome
  172. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  173. into and executing commands on a remote machine. This package contains
  174. an X11 passphrase dialog for OpenSSH and the GNOME GUI desktop
  175. environment.
  176. %description -l ja askpass-gnome
  177. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  178. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  179. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  180. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  181. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  182. な通信路の中を通すことができます。
  183. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  184. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  185. アルゴリズムは分割したライブラリにわかれています。
  186. このパッケージは GNOME 用のパスフレーズ入力ダイアログを含んでいます。
  187. %prep
  188. %setup -q
  189. %patch0 -p1 -b .vine
  190. %patch4 -p1 -b .vendor
  191. %patch5 -p1 -b .noinitlog
  192. %if %{WITH_SELINUX}
  193. #SELinux
  194. %patch12 -p1 -b .selinux
  195. %endif
  196. %patch21 -p1 -b .safe-stop
  197. %patch24 -p1 -b .fromto-remote
  198. %patch26 -p1 -b .stack
  199. %patch27 -p1 -b .log-chroot
  200. %patch30 -p1 -b .exit-deadlock
  201. %patch35 -p1 -b .progress
  202. %patch100 -p1 -b .norootlogin
  203. %patch120 -p1 -b .localtime
  204. autoreconf
  205. %build
  206. CFLAGS="$RPM_OPT_FLAGS"; export CFLAGS
  207. %if %{rescue}
  208. CFLAGS="$RPM_OPT_FLAGS -Os"; export CFLAGS
  209. %endif
  210. %if %{pie}
  211. %ifarch s390 s390x sparc sparc64
  212. CFLAGS="$CFLAGS -fPIE"
  213. %else
  214. CFLAGS="$CFLAGS -fpie"
  215. %endif
  216. export CFLAGS
  217. LDFLAGS="$LDFLAGS -pie"; export LDFLAGS
  218. %endif
  219. %configure \
  220. --sysconfdir=%{_sysconfdir}/ssh \
  221. --libexecdir=%{_libexecdir}/openssh \
  222. --datadir=%{_datadir}/openssh \
  223. --with-tcp-wrappers \
  224. --with-default-path=/usr/local/bin:/bin:/usr/bin \
  225. --with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
  226. --with-privsep-path=%{_var}/empty/sshd \
  227. --enable-vendor-patchlevel="VL-%{version}-%{release}" \
  228. --with-libedit \
  229. %if %{scard}
  230. --with-smartcard \
  231. %endif
  232. %if %{noip6}
  233. --with-ipv4-default \
  234. %endif
  235. %if %{rescue}
  236. --without-pam --with-md5-passwords
  237. %else
  238. --with-pam
  239. %endif
  240. %if %{static_libcrypto}
  241. perl -pi -e "s|-lcrypto|%{_libdir}/libcrypto.a|g" Makefile
  242. %endif
  243. make
  244. %if %{gtk2}
  245. gtk2=yes
  246. %else
  247. gtk2=no
  248. %endif
  249. %if ! %{no_gnome_askpass}
  250. pushd contrib
  251. if [ $gtk2 = yes ]; then
  252. make gnome-ssh-askpass2
  253. mv gnome-ssh-askpass2 gnome-ssh-askpass
  254. else
  255. make gnome-ssh-askpass1
  256. mv gnome-ssh-askpass1 gnome-ssh-askpass
  257. fi
  258. popd
  259. %endif
  260. %install
  261. rm -rf $RPM_BUILD_ROOT
  262. mkdir -p -m755 $RPM_BUILD_ROOT%{_sysconfdir}/ssh
  263. mkdir -p -m755 $RPM_BUILD_ROOT%{_libexecdir}/openssh
  264. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd
  265. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd/etc
  266. make install DESTDIR=$RPM_BUILD_ROOT
  267. touch $RPM_BUILD_ROOT%{_var}/empty/sshd/etc/localtime
  268. install -d $RPM_BUILD_ROOT/etc/pam.d/
  269. install -d $RPM_BUILD_ROOT/etc/rc.d/init.d
  270. install -d $RPM_BUILD_ROOT%{_libexecdir}/openssh
  271. install -m644 contrib/redhat/sshd.pam $RPM_BUILD_ROOT/etc/pam.d/sshd
  272. install -m755 contrib/redhat/sshd.init $RPM_BUILD_ROOT/etc/rc.d/init.d/sshd
  273. %if ! %{scard}
  274. rm -f $RPM_BUILD_ROOT%{_datadir}/openssh/Ssh.bin
  275. %endif
  276. %if ! %{no_gnome_askpass}
  277. install -s contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
  278. install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  279. install -m 755 contrib/redhat/gnome-ssh-askpass.{sh,csh} $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  280. %endif
  281. %if %{no_gnome_askpass}
  282. rm -f $RPM_BUILD_ROOT/etc/profile.d/gnome-ssh-askpass.*
  283. %endif
  284. # for contrib package
  285. install -m 0755 contrib/ssh-copy-id $RPM_BUILD_ROOT%{_bindir}
  286. install -m 0644 contrib/ssh-copy-id.1 $RPM_BUILD_ROOT%{_mandir}/man1
  287. mv contrib/README contrib/README.contrib
  288. perl -pi -e "s|$RPM_BUILD_ROOT||g" $RPM_BUILD_ROOT%{_mandir}/man*/*
  289. %clean
  290. rm -rf $RPM_BUILD_ROOT
  291. %triggerun server -- ssh-server
  292. if [ "$1" != 0 -a -r /var/run/sshd.pid ] ; then
  293. touch /var/run/sshd.restart
  294. fi
  295. %triggerun server -- openssh-server < 2.5.0p1
  296. # Count the number of HostKey and HostDsaKey statements we have.
  297. gawk 'BEGIN {IGNORECASE=1}
  298. /^hostkey/ || /^hostdsakey/ {sawhostkey = sawhostkey + 1}
  299. END {exit sawhostkey}' /etc/ssh/sshd_config
  300. # And if we only found one, we know the client was relying on the old default
  301. # behavior, which loaded the the SSH2 DSA host key when HostDsaKey wasn't
  302. # specified. Now that HostKey is used for both SSH1 and SSH2 keys, specifying
  303. # one nullifies the default, which would have loaded both.
  304. if [ $? -eq 1 ] ; then
  305. echo HostKey /etc/ssh/ssh_host_rsa_key >> /etc/ssh/sshd_config
  306. echo HostKey /etc/ssh/ssh_host_dsa_key >> /etc/ssh/sshd_config
  307. fi
  308. %triggerpostun server -- ssh-server
  309. if [ "$1" != 0 ] ; then
  310. /sbin/chkconfig --add sshd
  311. if test -f /var/run/sshd.restart ; then
  312. rm -f /var/run/sshd.restart
  313. # /sbin/service sshd start > /dev/null 2>&1 || :
  314. /sbin/service sshd start
  315. fi
  316. fi
  317. %pre server
  318. %{_sbindir}/groupadd -r -g %{sshd_gid} sshd 2>/dev/null || :
  319. %{_sbindir}/useradd -d /var/empty/sshd -s /bin/false -u %{sshd_uid} \
  320. -g sshd -M -r sshd 2>/dev/null || :
  321. %post server
  322. /sbin/chkconfig --add sshd
  323. %postun server
  324. # /sbin/service sshd condrestart > /dev/null 2>&1 || :
  325. /sbin/service sshd condrestart
  326. exit 0
  327. %preun server
  328. if [ "$1" = 0 ]
  329. then
  330. /sbin/service sshd stop > /dev/null 2>&1 || :
  331. /sbin/chkconfig --del sshd
  332. fi
  333. %files
  334. %defattr(-,root,root)
  335. %doc CREDITS ChangeLog INSTALL LICENCE OVERVIEW README* RFC* TODO WARNING*
  336. %attr(0755,root,root) %{_bindir}/scp
  337. %attr(0644,root,root) %{_mandir}/man1/scp.1*
  338. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  339. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/moduli
  340. %attr(644,root,root) %{_mandir}/man5/moduli.5*
  341. %if ! %{rescue}
  342. %attr(0755,root,root) %{_bindir}/ssh-keygen
  343. %attr(0644,root,root) %{_mandir}/man1/ssh-keygen.1*
  344. %attr(0755,root,root) %dir %{_libexecdir}/openssh
  345. %attr(4711,root,root) %{_libexecdir}/openssh/ssh-keysign
  346. %attr(0644,root,root) %{_mandir}/man8/ssh-keysign.8*
  347. %endif
  348. %if %{scard}
  349. %attr(0755,root,root) %dir %{_datadir}/openssh
  350. %attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
  351. %endif
  352. %files clients
  353. %defattr(-,root,root)
  354. %attr(0755,root,root) %{_bindir}/ssh
  355. %attr(0644,root,root) %{_mandir}/man1/ssh.1*
  356. %attr(0644,root,root) %{_mandir}/man5/ssh_config.5*
  357. %attr(0644,root,root) %{_mandir}/man1/slogin.1*
  358. %attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ssh/ssh_config
  359. %attr(-,root,root) %{_bindir}/slogin
  360. %if ! %{rescue}
  361. %attr(0755,root,root) %{_bindir}/ssh-agent
  362. %attr(0755,root,root) %{_bindir}/ssh-add
  363. %attr(0755,root,root) %{_bindir}/ssh-keyscan
  364. %attr(0755,root,root) %{_bindir}/sftp
  365. %attr(0755,root,root) %{_bindir}/ssh-copy-id
  366. %attr(0755,root,root) %{_libexecdir}/openssh/ssh-pkcs11-helper
  367. %attr(0644,root,root) %{_mandir}/man1/ssh-agent.1*
  368. %attr(0644,root,root) %{_mandir}/man1/ssh-add.1*
  369. %attr(0644,root,root) %{_mandir}/man1/ssh-keyscan.1*
  370. %attr(0644,root,root) %{_mandir}/man1/sftp.1*
  371. %attr(0644,root,root) %{_mandir}/man1/ssh-copy-id.1*
  372. %attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
  373. %endif
  374. %if ! %{rescue}
  375. %files server
  376. %defattr(-,root,root)
  377. %dir %attr(0711,root,root) %{_var}/empty/sshd
  378. %dir %attr(0755,root,root) %{_var}/empty/sshd/etc
  379. %ghost %verify(not md5 size mtime) %{_var}/empty/sshd/etc/localtime
  380. %attr(0755,root,root) %{_sbindir}/sshd
  381. %attr(0755,root,root) %{_libexecdir}/openssh/sftp-server
  382. %attr(0644,root,root) %{_mandir}/man5/sshd_config.5*
  383. %attr(0644,root,root) %{_mandir}/man8/sshd.8*
  384. %attr(0644,root,root) %{_mandir}/man8/sftp-server.8*
  385. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  386. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/sshd_config
  387. %attr(0600,root,root) %config(noreplace) /etc/pam.d/sshd
  388. %attr(0755,root,root) %config /etc/rc.d/init.d/sshd
  389. %endif
  390. %if ! %{no_gnome_askpass}
  391. %files askpass-gnome
  392. %defattr(-,root,root)
  393. %attr(0755,root,root) %config %{_sysconfdir}/profile.d/gnome-ssh-askpass.*
  394. %attr(0755,root,root) %{_libexecdir}/openssh/gnome-ssh-askpass
  395. %endif
  396. %changelog
  397. * Mon Jan 10 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 5.6p1-1
  398. - new upstream release
  399. - obsolete contrib subpackage, move ssh-copy-id to client subpackage
  400. * Sun Jan 9 2011 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.5p1-4
  401. - rebuilt with openssl 1.0.0c
  402. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-3
  403. - drop x11-askpass, add Obsoletes: openssh-askpass
  404. - add BR: groff
  405. - enable --with-libedit option, add BR: libedit-devel
  406. - remove unrecognized option '--with-rsh'
  407. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-2
  408. - add BR: xorg-x11-xauth for X11 forwarding support
  409. * Thu Apr 22 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-1
  410. - new upstream release
  411. - update patch0,2
  412. - drop patch3,22
  413. * Tue Feb 24 2009 Daisuke SUZUKI <daisuke@linux.or.jp> 5.2p1-1
  414. - new upstream release
  415. * Tue Jul 22 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.1p1-1
  416. - new upstream release
  417. * Thu May 29 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.0p1-2
  418. - rebuild with xorg-x11-7.3
  419. * Fri Apr 04 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.0p1-1
  420. - new upstream release with security fix (CVE-2008-1483)
  421. - drop patch31 which is included in new release (This was for CVE-2008-1483)
  422. * Tue Apr 01 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.9p1-1
  423. - new upstream release with security fix ("ForceCommand" Directive)
  424. - turn on daemon restart message
  425. - new versioning policy
  426. * Mon Nov 26 2007 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.7p1-0vl2
  427. - add /var/empty/sshd/etc/localtime to fix secure log bad timestamps
  428. * Tue Nov 13 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.7p1-0vl1
  429. - new upstream release
  430. * Thu May 17 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl2
  431. - build with -fpie/-pie by default.
  432. - enable ipv6 by default.
  433. * Fri May 04 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl1
  434. - new upstream release
  435. * Wed Nov 08 2006 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.5p1-0vl1
  436. - new upstream release
  437. * Fri Sep 29 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.4p1-0vl1
  438. - new upstream release
  439. * Thu Jul 27 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p2-0vl1
  440. - new upstream release
  441. * Mon Apr 10 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p1-0vl1
  442. - new upstream release
  443. - remove build6x stuff
  444. - remove libgnome-devel from BuildRequires
  445. - cleanup BuildRequires
  446. - drop Patch200, it is merged in upstream.
  447. - import patches(25-35) from FC-devel
  448. * Mon Apr 10 2006 IWAI, Masaharu <iwai@alib.jp> 4.2p1-0vl3
  449. - SECURITY FIX: CVE-2006-0225
  450. - add scp no system patch ( Patch200 ): from Fedora Core 4 4.2p1-fc4.10
  451. - update BuildPreReq: s/XFree86-devel/XOrg-devel/
  452. - fix BuildPreReq for GNOME: gnome-libs-devel ( GNOME1 ) was always used
  453. - When GNOME2 is used, using libgnome-devel
  454. - add BuildPreReq: gtk2-devel for GNOME2
  455. * Sat Sep 24 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl2
  456. - rebuild with gtk+-2.8 final
  457. * Sun Sep 4 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl1
  458. - new upstream release
  459. - build with gtk+-2.7
  460. * Sun May 29 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.1p1-0vl1
  461. - new upstream release
  462. * Fri Apr 01 2005 KOBAYASHI Taizo <tkoba@vinelinux.org> 4.0p1-0vl2
  463. - cleanup obsolete patches and added patches from fedora
  464. * Wed Mar 16 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.0p1-0vl1
  465. - new upstream release
  466. * Thu Aug 19 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.9pl1-0vl1
  467. - new upstream release
  468. * Wed Apr 21 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8.1p1-0vl1
  469. - new upstream release
  470. * Fri Mar 26 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl2
  471. - rebuild with openssl-0.9.7d
  472. * Fri Feb 27 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl1
  473. - new upstream release
  474. * Thu Oct 2 2003 IWAI, Masaharu <iwai@alib.jp> 3.7.1p2-0vl2
  475. - create contrib package
  476. * Wed Sep 24 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p2-0vl1
  477. - new upstream release
  478. - fix security issue: http://www.openssh.com/txt/sshpam.adv
  479. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p1-0vl1
  480. - new upstream release
  481. - fix security issue: http://www.openssh.com/txt/buffer.adv
  482. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7p1-0vl1
  483. - new upstream release
  484. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1.1
  485. - rebuild with gtk2
  486. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1
  487. - new upstream release
  488. * Sat Apr 13 2003 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.5p1-0vl2
  489. - rebuild with new tool chain
  490. * Tue Oct 29 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.5p1-0vl1
  491. - new upstream release
  492. - merge with upstream spec (drop anonymous mmap patch, suid of ssh)
  493. * Tue Aug 20 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl3
  494. - change some defines in spec files
  495. * Wed Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl2
  496. - add patch110 ( 3.4p1 does not include mmap-fallback patch )
  497. * Wed Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl1
  498. - new upstream release
  499. - security fix
  500. - drop patch10
  501. * Wed Jun 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl2
  502. - add patch from Solar Designer to make privsep work with a 2.2 kernel.
  503. * Sun Jun 23 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl1
  504. - new upstream release
  505. - add {sshd,ssh}_config.5 manpages
  506. - add ssh-keysign
  507. * Sun May 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.3p1-0vl1
  508. - new upstream release
  509. * Sat May 18 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.2p1-0vl1
  510. - new upstream release
  511. - drop patch1
  512. * Fri Mar 08 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.1p1-2vl1
  513. - new upstream release
  514. - merged with rawhide release.
  515. - drop Patch101 (merged in upstream)
  516. * Fri Mar 08 2002 Toru Sagami <sagami@vinelinux.org> 3.0.2p1-2vl2
  517. - seurity patch for off-by-one bug
  518. * Wed Jan 30 2002 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.0.2p-2vl1
  519. - merged with Rawhide 3.0.2p1-2
  520. * Sun Dec 02 2001 Toru Sagami <sagami@vinelinux.org>
  521. - updated to 3.0.2p1
  522. * Mon Nov 19 2001 Toru Sagami <sagami@vinelinux.org>
  523. - updated to 3.0.1p1
  524. * Thu Nov 08 2001 Toru Sagami <sagami@vinelinux.org> 3.0p1-0vl0
  525. - updated to 3.0p1
  526. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl2
  527. - add japanese summery and descriptions.
  528. - update x11-askpass 1.2.5
  529. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl1
  530. - update to openssh-2.9.9p2
  531. * Mon Jul 16 2001 MATSUBAYASHI 'Shaolin' Kohji <shaolin@vinelinux.org> 2.5.2p2-0vl3
  532. - rebuilt with openssl-0.9.6b
  533. * Tue Mar 27 2001 Jun Nishii <jun@vinelinux.org> 2.5.2p2-0vl2
  534. - do not Permit RootLogin
  535. * Tue Mar 27 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p2-0vl1
  536. - update to openssh-2.5.2p2
  537. * Wed Mar 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p1-0vl1
  538. - update to openssh-2.5.2p1
  539. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  540. - update to openssh-2.5.1p2
  541. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  542. - update to openssh-2.5.1p1
  543. * Wed Feb 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p1-0vl1
  544. - update to openssh-2.5.1p1
  545. * Thu Dec 28 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl4
  546. - remove suid bit from ssh
  547. * Tue Dec 19 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl3
  548. - moved man dir to /usr/share/man
  549. * Wed Dec 06 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl2
  550. - fixed askpass's link in ssh-add
  551. - partially used rpmmacros
  552. * Fri Nov 10 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl1
  553. - update to 2.3.0p1
  554. - update x11-askpass 1.0.3
  555. * Mon Oct 18 2000 Damien Miller <djm@mindrot.org>
  556. - Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
  557. Redhat 7.0 spec file
  558. * Sat Oct 14 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.2.0p2-2vl1
  559. - rebuild for Vine Linux
  560. * Tue Sep 05 2000 Damien Miller <djm@mindrot.org>
  561. - Use RPM configure macro
  562. * Tue Aug 08 2000 Damien Miller <djm@mindrot.org>
  563. - Some surgery to sshd.init (generate keys at runtime)
  564. - Cleanup of groups and removal of keygen calls
  565. * Wed Jul 12 2000 Damien Miller <djm@mindrot.org>
  566. - Make building of X11-askpass and gnome-askpass optional
  567. * Mon Jun 12 2000 Damien Miller <djm@mindrot.org>
  568. - Glob manpages to catch compressed files
  569. * Wed Mar 15 2000 Damien Miller <djm@ibs.com.au>
  570. - Updated for new location
  571. - Updated for new gnome-ssh-askpass build
  572. * Sun Dec 26 1999 Damien Miller <djm@mindrot.org>
  573. - Added Jim Knoble's <jmknoble@pobox.com> askpass
  574. * Mon Nov 15 1999 Damien Miller <djm@mindrot.org>
  575. - Split subpackages further based on patch from jim knoble <jmknoble@pobox.com>
  576. * Sat Nov 13 1999 Damien Miller <djm@mindrot.org>
  577. - Added 'Obsoletes' directives
  578. * Tue Nov 09 1999 Damien Miller <djm@ibs.com.au>
  579. - Use make install
  580. - Subpackages
  581. * Mon Nov 08 1999 Damien Miller <djm@ibs.com.au>
  582. - Added links for slogin
  583. - Fixed perms on manpages
  584. * Sat Oct 30 1999 Damien Miller <djm@ibs.com.au>
  585. - Renamed init script
  586. * Fri Oct 29 1999 Damien Miller <djm@ibs.com.au>
  587. - Back to old binary names
  588. * Thu Oct 28 1999 Damien Miller <djm@ibs.com.au>
  589. - Use autoconf
  590. - New binary names
  591. * Wed Oct 27 1999 Damien Miller <djm@ibs.com.au>
  592. - Initial RPMification, based on Jan "Yenya" Kasprzak's <kas@fi.muni.cz> spec.