openssh-vl.spec 30 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899
  1. %bcond_with systemd
  2. # SELinux
  3. %define WITH_SELINUX 0
  4. # OpenSSH privilege separation requires a user & group ID
  5. %define sshd_uid 74
  6. %define sshd_gid 74
  7. # Do we want to disable building of gnome-askpass? (1=yes 0=no)
  8. %define no_gnome_askpass 0
  9. # Use GTK3 for gnome-ssh-askpass
  10. %define gtk3 1
  11. # Build position-independent executables (requires toolchain support)?
  12. %define pie 1
  13. # Do we want to link against a static libcrypto? (1=yes 0=no)
  14. %define static_libcrypto 0
  15. # Do we want smartcard support (1=yes 0=no)
  16. %define scard 0
  17. # Disable IPv6 (avoids DNS hangs on some glibc versions)
  18. %define noip6 0
  19. # Do we want kerberos5 support (1=yes 0=no)
  20. %define kerberos5 0
  21. # Reserve options to override askpass settings with:
  22. # rpm -ba|--rebuild --define 'skip_xxx 1'
  23. %{?skip_gnome_askpass:%define no_gnome_askpass 1}
  24. # Options for static OpenSSL link:
  25. # rpm -ba|--rebuild --define "static_openssl 1"
  26. %{?static_openssl:%define static_libcrypto 1}
  27. # Options for Smartcard support: (needs libsectok and openssl-engine)
  28. # rpm -ba|--rebuild --define "smartcard 1"
  29. %{?smartcard:%define scard 1}
  30. # Option to disable ipv6
  31. # rpm -ba|--rebuild --define "noipv6 1"
  32. %{?noipv6:%define noip6 1}
  33. # Is this a build for the rescue CD (without PAM)? (1=yes 0=no)
  34. %define rescue 0
  35. %{?build_rescue:%define rescue 1}
  36. # Turn off some stuff for resuce builds
  37. %if %{rescue}
  38. %define kerberos5 0
  39. %endif
  40. Summary: The OpenSSH implementation of SSH.
  41. Summary(ja): OpenSSH - フリーの Secure Shell (SSH) の実装
  42. Name: openssh
  43. Version: 8.3p1
  44. Release: 1%{_dist_release}%{?with_systemd:.systemd}
  45. Group: Applications/Internet
  46. Vendor: Project Vine
  47. Distribution: Vine Linux
  48. Packager: daisuke
  49. License: BSD
  50. URL: https://www.openssh.com/portable.html
  51. Source0: https://cdn.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-%{version}.tar.gz
  52. # files for systemd
  53. Source9: sshd@.service
  54. Source10: sshd.socket
  55. Source11: sshd.service
  56. Source12: sshd-keygen@.service
  57. Source13: sshd-keygen
  58. Source14: sshd.tmpfiles
  59. Source15: sshd-keygen.target
  60. Patch0: openssh-7.6p1-vine.patch
  61. #Patch4: openssh-8.0p1-vendor.patch
  62. # Patch12: openssh-selinux.patch
  63. # Patch20: openssh-3.9p1-gssapimitm.patch
  64. Patch21: openssh-7.6p1-safe-stop.patch
  65. Patch24: openssh-7.6p1-fromto-remote.patch
  66. Patch26: openssh-5.2p1-pam-no-stack.patch
  67. # Patch27: openssh-5.1p1-log-in-chroot.patch
  68. # Patch30: openssh-5.6p1-exit-deadlock.patch
  69. # Patch31: openssh-3.9p1-skip-used.patch
  70. Patch35: openssh-8.2p1-askpass-progress-gtk3.patch
  71. # Help systemd to track the running service
  72. Patch948: openssh-7.4p1-systemd.patch
  73. # Vine Source
  74. Source100: sshd.init.vine
  75. Source110: sshd.sysconfig.vine
  76. BuildRoot: %{_tmppath}/%{name}-%{version}-buildroot
  77. Obsoletes: ssh
  78. BuildRequires: perl, openssl-devel
  79. BuildRequires: util-linux
  80. %if "%{_dist_release}" >= "vl7"
  81. BuildRequires: libdb-devel
  82. %else
  83. BuildRequires: db4-devel
  84. %endif
  85. BuildRequires: pam-devel
  86. BuildRequires: zlib-devel
  87. %if ! %{no_gnome_askpass}
  88. BuildRequires: libX11-devel
  89. BuildRequires: gtk3-devel
  90. %endif
  91. BuildRequires: xorg-x11-xauth
  92. BuildRequires: groff
  93. BuildRequires: libedit-devel
  94. %if %{with systemd}
  95. BuildRequires: systemd-devel
  96. %endif
  97. %package clients
  98. Summary: OpenSSH clients.
  99. Summary(ja): OpenSSH Secure Shell プロトコルクライアント
  100. Requires: openssh = %{version}-%{release}
  101. Group: Applications/Internet
  102. Obsoletes: ssh-clients
  103. Obsoletes: openssh-contrib
  104. %package server
  105. Summary: The OpenSSH server daemon.
  106. Summary(ja): OpenSSH Secure Shell プロトコルサーバ (sshd)
  107. Group: System Environment/Daemons
  108. Obsoletes: ssh-server
  109. Requires(post): openssh = %{version}-%{release}
  110. Requires(post): chkconfig
  111. Requires(pre): shadow-utils
  112. Requires(post): initscripts >= 5.20
  113. Requires: pam
  114. %package askpass-gnome
  115. Summary: A passphrase dialog for OpenSSH, X, and GNOME.
  116. Summary(ja): OpenSSH GNOME パスフレーズ入力ダイアログ
  117. Group: Applications/Internet
  118. Requires: openssh = %{version}-%{release}
  119. Obsoletes: ssh-extras
  120. Obsoletes: openssh-askpass < 5.5p1-3vl6
  121. Provides: openssh-askpass = %{version}-%{release}
  122. %description
  123. SSH (Secure SHell) is a program for logging into and executing
  124. commands on a remote machine. SSH is intended to replace rlogin and
  125. rsh, and to provide secure encrypted communications between two
  126. untrusted hosts over an insecure network. X11 connections and
  127. arbitrary TCP/IP ports can also be forwarded over the secure channel.
  128. OpenSSH is OpenBSD's version of the last free version of SSH, bringing
  129. it up to date in terms of security and features, as well as removing
  130. all patented algorithms to separate libraries.
  131. This package includes the core files necessary for both the OpenSSH
  132. client and server. To make this package useful, you should also
  133. install openssh-clients, openssh-server, or both.
  134. #'
  135. %description -l ja
  136. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  137. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  138. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  139. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  140. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  141. な通信路の中を通すことができます。
  142. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  143. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  144. アルゴリズムは分割したライブラリにわかれています。
  145. このパッケージは OpenSSH のクライアントとサーバの両方で必要とされる
  146. コアのファイルを含んでいます。実際に使用するにはこのパッケージの他に
  147. openssh-clients および/または openssh-server が必要です。
  148. %description clients
  149. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  150. into and executing commands on a remote machine. This package includes
  151. the clients necessary to make encrypted connections to SSH servers.
  152. You'll also need to install the openssh package on OpenSSH clients.
  153. #'
  154. %description -l ja clients
  155. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  156. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  157. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  158. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  159. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  160. な通信路の中を通すことができます。
  161. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  162. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  163. アルゴリズムは分割したライブラリにわかれています。
  164. このパッケージは OpenSSH をクライアントとして使用する場合に
  165. 必要なものを含んでいます。
  166. %description server
  167. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  168. into and executing commands on a remote machine. This package contains
  169. the secure shell daemon (sshd). The sshd daemon allows SSH clients to
  170. securely connect to your SSH server. You also need to have the openssh
  171. package installed.
  172. %description -l ja server
  173. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  174. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  175. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  176. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  177. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  178. な通信路の中を通すことができます。
  179. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  180. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  181. アルゴリズムは分割したライブラリにわかれています。
  182. このパッケージは OpenSSH をサーバとして使用する場合に必要な
  183. デーモンなどを含んでいます。
  184. %description askpass-gnome
  185. OpenSSH is a free version of SSH (Secure SHell), a program for logging
  186. into and executing commands on a remote machine. This package contains
  187. an X11 passphrase dialog for OpenSSH and the GNOME GUI desktop
  188. environment.
  189. %description -l ja askpass-gnome
  190. OpenSSH は、ネットワーク接続ツールである SSH プロトコル実装の フリー版 です。
  191. Ssh はリモートマシンへログインしたり、リモートマシンでコマンドを実行したり
  192. するためのプログラムです。rlogin や rsh を置き換えるもので、二つの信頼でき
  193. ないホスト間の信頼できない通信路でセキュアで暗号化された通信を行うことが
  194. 可能にします。X11 のコネクションやあらゆる TCP/IP のポートもまた、セキュア
  195. な通信路の中を通すことができます。
  196. OpenSSH は OpenBSD による最後のフリーのバージョンの再実装で、
  197. 最新のセキュリティと機能を提供しています。またすべての特許がからむ
  198. アルゴリズムは分割したライブラリにわかれています。
  199. このパッケージは GNOME 用のパスフレーズ入力ダイアログを含んでいます。
  200. %prep
  201. %setup -q
  202. %patch0 -p1 -b .vine
  203. #patch4 -p1 -b .vendor
  204. %if %{WITH_SELINUX}
  205. #SELinux
  206. #%patch12 -p1 -b .selinux
  207. %endif
  208. %patch21 -p1 -b .safe-stop
  209. %patch24 -p1 -b .fromto-remote
  210. %patch26 -p1 -b .stack
  211. # %patch27 -p1 -b .log-chroot
  212. # %patch30 -p1 -b .exit-deadlock
  213. %patch35 -p1 -b .progress
  214. %if %{with systemd}
  215. %patch948 -p1
  216. %endif
  217. autoreconf
  218. %build
  219. CFLAGS="$RPM_OPT_FLAGS"; export CFLAGS
  220. %if %{rescue}
  221. CFLAGS="$RPM_OPT_FLAGS -Os"; export CFLAGS
  222. %endif
  223. %if %{pie}
  224. %ifarch s390 s390x sparc sparc64
  225. CFLAGS="$CFLAGS -fPIE"
  226. %else
  227. CFLAGS="$CFLAGS -fpie"
  228. %endif
  229. export CFLAGS
  230. LDFLAGS="$LDFLAGS -pie"; export LDFLAGS
  231. %endif
  232. %configure \
  233. --sysconfdir=%{_sysconfdir}/ssh \
  234. --libexecdir=%{_libexecdir}/openssh \
  235. --datadir=%{_datadir}/openssh \
  236. --with-tcp-wrappers \
  237. --with-default-path=/usr/local/bin:/bin:/usr/bin \
  238. --with-superuser-path=/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin \
  239. --with-privsep-path=%{_var}/empty/sshd \
  240. --enable-vendor-patchlevel="VL-%{version}-%{release}" \
  241. --with-libedit \
  242. --with-xauth=/usr/bin/xauth \
  243. %if %{scard}
  244. --with-smartcard \
  245. %endif
  246. %if %{noip6}
  247. --with-ipv4-default \
  248. %endif
  249. %if %{rescue}
  250. --without-pam --with-md5-passwords \
  251. %else
  252. --with-pam \
  253. %endif
  254. %if %{with systemd}
  255. --with-systemd \
  256. %endif
  257. %{nil}
  258. %if %{static_libcrypto}
  259. perl -pi -e "s|-lcrypto|%{_libdir}/libcrypto.a|g" Makefile
  260. %endif
  261. make
  262. %if %{gtk3}
  263. gtk3=yes
  264. %else
  265. gtk3=no
  266. %endif
  267. %if ! %{no_gnome_askpass}
  268. pushd contrib
  269. if [ $gtk3 = yes ]; then
  270. make gnome-ssh-askpass3
  271. mv gnome-ssh-askpass3 gnome-ssh-askpass
  272. else
  273. make gnome-ssh-askpass2
  274. mv gnome-ssh-askpass2 gnome-ssh-askpass
  275. fi
  276. popd
  277. %endif
  278. %install
  279. rm -rf $RPM_BUILD_ROOT
  280. mkdir -p -m755 $RPM_BUILD_ROOT%{_sysconfdir}/ssh
  281. mkdir -p -m755 $RPM_BUILD_ROOT%{_libexecdir}/openssh
  282. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd
  283. mkdir -p -m755 $RPM_BUILD_ROOT%{_var}/empty/sshd/etc
  284. make install DESTDIR=$RPM_BUILD_ROOT
  285. touch $RPM_BUILD_ROOT%{_var}/empty/sshd/etc/localtime
  286. install -d $RPM_BUILD_ROOT/etc/pam.d/
  287. install -d $RPM_BUILD_ROOT/etc/rc.d/init.d
  288. install -d $RPM_BUILD_ROOT/etc/sysconfig/
  289. install -d $RPM_BUILD_ROOT%{_libexecdir}/openssh
  290. install -m644 contrib/redhat/sshd.pam $RPM_BUILD_ROOT/etc/pam.d/sshd
  291. install -m644 %{SOURCE110} $RPM_BUILD_ROOT/etc/sysconfig/sshd
  292. %if %{with systemd}
  293. install -d -m755 $RPM_BUILD_ROOT/%{_unitdir}
  294. install -m644 %{SOURCE9} $RPM_BUILD_ROOT/%{_unitdir}/sshd@.service
  295. install -m644 %{SOURCE10} $RPM_BUILD_ROOT/%{_unitdir}/sshd.socket
  296. install -m644 %{SOURCE11} $RPM_BUILD_ROOT/%{_unitdir}/sshd.service
  297. install -m644 %{SOURCE12} $RPM_BUILD_ROOT/%{_unitdir}/sshd-keygen@.service
  298. install -m644 %{SOURCE15} $RPM_BUILD_ROOT/%{_unitdir}/sshd-keygen.target
  299. install -m744 %{SOURCE13} $RPM_BUILD_ROOT/%{_libexecdir}/openssh/sshd-keygen
  300. install -m755 contrib/ssh-copy-id $RPM_BUILD_ROOT%{_bindir}/
  301. install contrib/ssh-copy-id.1 $RPM_BUILD_ROOT%{_mandir}/man1/
  302. install -m644 -D %{SOURCE14} $RPM_BUILD_ROOT%{_tmpfilesdir}/%{name}.conf
  303. %else
  304. install -m755 %{SOURCE100} $RPM_BUILD_ROOT/etc/rc.d/init.d/sshd
  305. %endif
  306. %if ! %{scard}
  307. rm -f $RPM_BUILD_ROOT%{_datadir}/openssh/Ssh.bin
  308. %endif
  309. %if ! %{no_gnome_askpass}
  310. install -s contrib/gnome-ssh-askpass $RPM_BUILD_ROOT%{_libexecdir}/openssh/gnome-ssh-askpass
  311. install -m 755 -d $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  312. install -m 755 contrib/redhat/gnome-ssh-askpass.{sh,csh} $RPM_BUILD_ROOT%{_sysconfdir}/profile.d/
  313. %endif
  314. %if %{no_gnome_askpass}
  315. rm -f $RPM_BUILD_ROOT/etc/profile.d/gnome-ssh-askpass.*
  316. %endif
  317. # for contrib package
  318. install -m 0755 contrib/ssh-copy-id $RPM_BUILD_ROOT%{_bindir}
  319. install -m 0644 contrib/ssh-copy-id.1 $RPM_BUILD_ROOT%{_mandir}/man1
  320. mv contrib/README contrib/README.contrib
  321. perl -pi -e "s|$RPM_BUILD_ROOT||g" $RPM_BUILD_ROOT%{_mandir}/man*/*
  322. %clean
  323. rm -rf $RPM_BUILD_ROOT
  324. %triggerun server -- ssh-server
  325. if [ "$1" != 0 -a -r /var/run/sshd.pid ] ; then
  326. touch /var/run/sshd.restart
  327. fi
  328. %triggerun server -- openssh-server < 2.5.0p1
  329. # Count the number of HostKey and HostDsaKey statements we have.
  330. gawk 'BEGIN {IGNORECASE=1}
  331. /^hostkey/ || /^hostdsakey/ {sawhostkey = sawhostkey + 1}
  332. END {exit sawhostkey}' /etc/ssh/sshd_config
  333. # And if we only found one, we know the client was relying on the old default
  334. # behavior, which loaded the the SSH2 DSA host key when HostDsaKey wasn't
  335. # specified. Now that HostKey is used for both SSH1 and SSH2 keys, specifying
  336. # one nullifies the default, which would have loaded both.
  337. if [ $? -eq 1 ] ; then
  338. echo HostKey /etc/ssh/ssh_host_rsa_key >> /etc/ssh/sshd_config
  339. echo HostKey /etc/ssh/ssh_host_dsa_key >> /etc/ssh/sshd_config
  340. fi
  341. %triggerpostun server -- ssh-server
  342. if [ "$1" != 0 ] ; then
  343. /sbin/chkconfig --add sshd
  344. if test -f /var/run/sshd.restart ; then
  345. rm -f /var/run/sshd.restart
  346. # /sbin/service sshd start > /dev/null 2>&1 || :
  347. /sbin/service sshd start
  348. fi
  349. fi
  350. %if %{with systemd}
  351. %pre
  352. getent group ssh_keys >/dev/null || groupadd -r ssh_keys || :
  353. %endif
  354. %pre server
  355. %{_sbindir}/groupadd -r -g %{sshd_gid} sshd 2>/dev/null || :
  356. %{_sbindir}/useradd -d /var/empty/sshd -s /bin/false -u %{sshd_uid} \
  357. -g sshd -M -r sshd 2>/dev/null || :
  358. %post server
  359. %if %{with systemd}
  360. %systemd_post sshd.service sshd.socket
  361. %else
  362. /sbin/chkconfig --add sshd
  363. %endif
  364. %postun server
  365. %if %{with systemd}
  366. %systemd_postun_with_restart sshd.service
  367. %else
  368. # /sbin/service sshd condrestart > /dev/null 2>&1 || :
  369. /sbin/service sshd condrestart
  370. exit 0
  371. %endif
  372. %preun server
  373. %if %{with systemd}
  374. %systemd_preun sshd.service sshd.socket
  375. %else
  376. if [ "$1" = 0 -o -x /bin/systemctl ]; then
  377. /sbin/service sshd stop > /dev/null 2>&1 || :
  378. /sbin/chkconfig --del sshd
  379. %endif
  380. fi
  381. %files
  382. %defattr(-,root,root)
  383. %license LICENCE
  384. %doc CREDITS ChangeLog INSTALL OVERVIEW PROTOCOL* README* TODO
  385. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  386. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/moduli
  387. %attr(644,root,root) %{_mandir}/man5/moduli.5*
  388. %if ! %{rescue}
  389. %attr(0755,root,root) %{_bindir}/ssh-keygen
  390. %attr(0644,root,root) %{_mandir}/man1/ssh-keygen.1*
  391. %attr(0755,root,root) %dir %{_libexecdir}/openssh
  392. %attr(4711,root,root) %{_libexecdir}/openssh/ssh-keysign
  393. %attr(0644,root,root) %{_mandir}/man8/ssh-keysign.8*
  394. %endif
  395. %if %{scard}
  396. %attr(0755,root,root) %dir %{_datadir}/openssh
  397. %attr(0644,root,root) %{_datadir}/openssh/Ssh.bin
  398. %endif
  399. %files clients
  400. %defattr(-,root,root)
  401. %attr(0755,root,root) %{_bindir}/scp
  402. %attr(0755,root,root) %{_bindir}/ssh
  403. %attr(0644,root,root) %{_mandir}/man1/scp.1*
  404. %attr(0644,root,root) %{_mandir}/man1/ssh.1*
  405. %attr(0644,root,root) %{_mandir}/man5/ssh_config.5*
  406. # %attr(0644,root,root) %{_mandir}/man1/slogin.1*
  407. %attr(0644,root,root) %config(noreplace) %{_sysconfdir}/ssh/ssh_config
  408. # %attr(-,root,root) %{_bindir}/slogin
  409. %if ! %{rescue}
  410. %attr(0755,root,root) %{_bindir}/ssh-agent
  411. %attr(0755,root,root) %{_bindir}/ssh-add
  412. %attr(0755,root,root) %{_bindir}/ssh-keyscan
  413. %attr(0755,root,root) %{_bindir}/sftp
  414. %attr(0755,root,root) %{_bindir}/ssh-copy-id
  415. %attr(0755,root,root) %{_libexecdir}/openssh/ssh-pkcs11-helper
  416. %attr(0755,root,root) %{_libexecdir}/openssh/ssh-sk-helper
  417. %attr(0644,root,root) %{_mandir}/man1/ssh-agent.1*
  418. %attr(0644,root,root) %{_mandir}/man1/ssh-add.1*
  419. %attr(0644,root,root) %{_mandir}/man1/ssh-keyscan.1*
  420. %attr(0644,root,root) %{_mandir}/man1/sftp.1*
  421. %attr(0644,root,root) %{_mandir}/man1/ssh-copy-id.1*
  422. %attr(0644,root,root) %{_mandir}/man8/ssh-pkcs11-helper.8*
  423. %attr(0644,root,root) %{_mandir}/man8/ssh-sk-helper.8*
  424. %endif
  425. %if ! %{rescue}
  426. %files server
  427. %defattr(-,root,root)
  428. %dir %attr(0711,root,root) %{_var}/empty/sshd
  429. %dir %attr(0755,root,root) %{_var}/empty/sshd/etc
  430. %ghost %verify(not md5 size mtime) %{_var}/empty/sshd/etc/localtime
  431. %attr(0755,root,root) %{_sbindir}/sshd
  432. %attr(0755,root,root) %{_libexecdir}/openssh/sftp-server
  433. %attr(0644,root,root) %{_mandir}/man5/sshd_config.5*
  434. %attr(0644,root,root) %{_mandir}/man8/sshd.8*
  435. %attr(0644,root,root) %{_mandir}/man8/sftp-server.8*
  436. %attr(0755,root,root) %dir %{_sysconfdir}/ssh
  437. %attr(0600,root,root) %config(noreplace) %{_sysconfdir}/ssh/sshd_config
  438. %attr(0600,root,root) %config(noreplace) /etc/pam.d/sshd
  439. %attr(0755,root,root) %config /etc/sysconfig/sshd
  440. %if %{with systemd}
  441. %attr(0755,root,root) %{_libexecdir}/openssh/sshd-keygen
  442. %attr(0644,root,root) %{_unitdir}/sshd.service
  443. %attr(0644,root,root) %{_unitdir}/sshd@.service
  444. %attr(0644,root,root) %{_unitdir}/sshd.socket
  445. %attr(0644,root,root) %{_unitdir}/sshd-keygen@.service
  446. %attr(0644,root,root) %{_unitdir}/sshd-keygen.target
  447. %attr(0644,root,root) %{_tmpfilesdir}/openssh.conf
  448. %else
  449. %attr(0755,root,root) %config /etc/rc.d/init.d/sshd
  450. %endif
  451. %endif
  452. %if ! %{no_gnome_askpass}
  453. %files askpass-gnome
  454. %defattr(-,root,root)
  455. %attr(0755,root,root) %config %{_sysconfdir}/profile.d/gnome-ssh-askpass.*
  456. %attr(0755,root,root) %{_libexecdir}/openssh/gnome-ssh-askpass
  457. %endif
  458. %changelog
  459. * Wed May 27 2020 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 8.3p1-1
  460. - new upstream release.
  461. * Thu Apr 02 2020 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 8.2p1-2
  462. - added systemd support (disabled as default).
  463. * Thu Mar 19 2020 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 8.2p1-1
  464. - new upstream release.
  465. - updated Patch35.
  466. * Thu Oct 17 2019 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 8.1p1-1
  467. - new upstream release.
  468. * Sat Jun 22 2019 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 8.0p1-1
  469. - new upstream release.
  470. - moved scp to openssh-clients.
  471. - changed "PasswordAuthentication" to "no" as default.
  472. - dropped Patch4.
  473. - updated Patch35 to use GTK+3 for gnome-ssh-askpass.
  474. * Tue Nov 06 2018 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 7.9p1-1
  475. - new upstream release.
  476. - updated Patch4.
  477. * Wed Nov 15 2017 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 7.6p1-1
  478. - new upstream release.
  479. - update patch0,4,21,24
  480. - update patch35 from fc26
  481. - drop patch12,20,30
  482. * Fri Aug 5 2016 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 7.2p2-2
  483. - disabled rsa1 hostkey generation.
  484. * Sat Jul 30 2016 Tomohiro "Tomo-p" KATO <tomop@teamgedoh.net> 7.2p2-1
  485. - new upstream release.
  486. * Wed Mar 9 2016 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 7.2p1-1
  487. - new upstream release
  488. - built with openssl 1.0.2g
  489. - drop slogin command and manual, this is upstream change.
  490. * Sun Jan 17 2016 Daisuke SUZUKI <daisuke@vinelinux.org> 7.1p2-1
  491. - update to 7.1p2
  492. * Mon Dec 28 2015 Daisuke SUZUKI <daisuke@vinelinux.org> 7.1p1-1
  493. - update to 7.1p1
  494. - remove patch100 to use default value "prohibit-password" for PermitRootLogin
  495. * Tue Oct 14 2014 Daisuke SUZUKI <daisuke@vinelinux.org> 6.7p1-1
  496. - update to 6.7p1
  497. - fix sshd.init
  498. * Thu Aug 07 2014 Daisuke SUZUKI <daisuke@vinelinux.org> 6.6p1-1
  499. - update to 6.6p1
  500. - remove BR: sharutils
  501. - add BR: libdb-devel instead of db4-devel
  502. * Tue Feb 04 2014 Daisuke SUZUKI <daisuke@linux.or.jp> 6.5p1-1
  503. - update to 6.5p1
  504. - update sshd_config
  505. - generate ED25519 host key.
  506. * Tue Nov 12 2013 Daisuke SUZUKI <daisuke@linux.or.jp> 6.4p1-1
  507. - update to 6.4p1
  508. * Mon May 20 2013 Daisuke SUZUKI <daisuke@linux.or.jp> 6.2p2-1
  509. - update to 6.2p2
  510. * Fri Mar 22 2013 Daisuke SUZUKI <daisuke@linux.or.jp> 6.2p1-1
  511. - update to 6.2p1
  512. * Fri Nov 2 2012 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 6.1p1-1
  513. - new upstream release
  514. - add -with-xauth option in configure
  515. - patch4, 30, 35 are updated from fc18
  516. * Mon May 07 2012 Daisuke SUZUKI <daisuke@linux.or.jp> 6.0p1-1
  517. - new upstream release
  518. * Tue Mar 06 2012 Daisuke SUZUKI <daisuke@linux.or.jp> 5.9p1-1
  519. - new upstream release
  520. * Sun May 8 2011 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.8p2-1
  521. - new upstream release
  522. * Tue Apr 19 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 5.8p1-2
  523. - add our own sshd.init based on fedora's sshd.init
  524. - generate ECDSA host key.
  525. * Sat Feb 05 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 5.8p1-1
  526. - new upstream release
  527. * Tue Jan 25 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 5.7p1-1
  528. - new upstream release
  529. * Mon Jan 10 2011 Daisuke SUZUKI <daisuke@linux.or.jp> 5.6p1-1
  530. - new upstream release
  531. - obsolete contrib subpackage, move ssh-copy-id to client subpackage
  532. * Sun Jan 9 2011 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.5p1-4
  533. - rebuilt with openssl 1.0.0c
  534. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-3
  535. - drop x11-askpass, add Obsoletes: openssh-askpass
  536. - add BR: groff
  537. - enable --with-libedit option, add BR: libedit-devel
  538. - remove unrecognized option '--with-rsh'
  539. * Sun May 23 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-2
  540. - add BR: xorg-x11-xauth for X11 forwarding support
  541. * Thu Apr 22 2010 Daisuke SUZUKI <daisuke@linux.or.jp> 5.5p1-1
  542. - new upstream release
  543. - update patch0,2
  544. - drop patch3,22
  545. * Tue Feb 24 2009 Daisuke SUZUKI <daisuke@linux.or.jp> 5.2p1-1
  546. - new upstream release
  547. * Tue Jul 22 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.1p1-1
  548. - new upstream release
  549. * Thu May 29 2008 Daisuke SUZUKI <daisuke@linux.or.jp> 5.0p1-2
  550. - rebuild with xorg-x11-7.3
  551. * Fri Apr 04 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 5.0p1-1
  552. - new upstream release with security fix (CVE-2008-1483)
  553. - drop patch31 which is included in new release (This was for CVE-2008-1483)
  554. * Tue Apr 01 2008 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.9p1-1
  555. - new upstream release with security fix ("ForceCommand" Directive)
  556. - turn on daemon restart message
  557. - new versioning policy
  558. * Mon Nov 26 2007 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.7p1-0vl2
  559. - add /var/empty/sshd/etc/localtime to fix secure log bad timestamps
  560. * Tue Nov 13 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.7p1-0vl1
  561. - new upstream release
  562. * Thu May 17 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl2
  563. - build with -fpie/-pie by default.
  564. - enable ipv6 by default.
  565. * Fri May 04 2007 Daisuke SUZUKI <daisuke@linux.or.jp> 4.6p1-0vl1
  566. - new upstream release
  567. * Wed Nov 08 2006 Satoshi IWAMOTO <satoshi.iwamoto@nifty.ne.jp> 4.5p1-0vl1
  568. - new upstream release
  569. * Fri Sep 29 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.4p1-0vl1
  570. - new upstream release
  571. * Thu Jul 27 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p2-0vl1
  572. - new upstream release
  573. * Mon Apr 10 2006 Daisuke SUZUKI <daisuke@linux.or.jp> 4.3p1-0vl1
  574. - new upstream release
  575. - remove build6x stuff
  576. - remove libgnome-devel from BuildRequires
  577. - cleanup BuildRequires
  578. - drop Patch200, it is merged in upstream.
  579. - import patches(25-35) from FC-devel
  580. * Mon Apr 10 2006 IWAI, Masaharu <iwai@alib.jp> 4.2p1-0vl3
  581. - SECURITY FIX: CVE-2006-0225
  582. - add scp no system patch ( Patch200 ): from Fedora Core 4 4.2p1-fc4.10
  583. - update BuildPreReq: s/XFree86-devel/XOrg-devel/
  584. - fix BuildPreReq for GNOME: gnome-libs-devel ( GNOME1 ) was always used
  585. - When GNOME2 is used, using libgnome-devel
  586. - add BuildPreReq: gtk2-devel for GNOME2
  587. * Sat Sep 24 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl2
  588. - rebuild with gtk+-2.8 final
  589. * Sun Sep 4 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.2p1-0vl1
  590. - new upstream release
  591. - build with gtk+-2.7
  592. * Sun May 29 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.1p1-0vl1
  593. - new upstream release
  594. * Fri Apr 01 2005 KOBAYASHI Taizo <tkoba@vinelinux.org> 4.0p1-0vl2
  595. - cleanup obsolete patches and added patches from fedora
  596. * Wed Mar 16 2005 Daisuke SUZUKI <daisuke@linux.or.jp> 4.0p1-0vl1
  597. - new upstream release
  598. * Thu Aug 19 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.9pl1-0vl1
  599. - new upstream release
  600. * Wed Apr 21 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8.1p1-0vl1
  601. - new upstream release
  602. * Fri Mar 26 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl2
  603. - rebuild with openssl-0.9.7d
  604. * Fri Feb 27 2004 Daisuke SUZUKI <daisuke@linux.or.jp> 3.8p1-0vl1
  605. - new upstream release
  606. * Thu Oct 2 2003 IWAI, Masaharu <iwai@alib.jp> 3.7.1p2-0vl2
  607. - create contrib package
  608. * Wed Sep 24 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p2-0vl1
  609. - new upstream release
  610. - fix security issue: http://www.openssh.com/txt/sshpam.adv
  611. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7.1p1-0vl1
  612. - new upstream release
  613. - fix security issue: http://www.openssh.com/txt/buffer.adv
  614. * Wed Sep 17 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.7p1-0vl1
  615. - new upstream release
  616. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1.1
  617. - rebuild with gtk2
  618. * Thu May 1 2003 Daisuke SUZUKI <daisuke@linux.or.jp> 3.6.1p2-0vl1
  619. - new upstream release
  620. * Sun Apr 13 2003 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.5p1-0vl2
  621. - rebuild with new tool chain
  622. * Tue Oct 29 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.5p1-0vl1
  623. - new upstream release
  624. - merge with upstream spec (drop anonymous mmap patch, suid of ssh)
  625. * Tue Aug 20 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl3
  626. - change some defines in spec files
  627. * Thu Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl2
  628. - add patch110 ( 3.4p1 does not include mmap-fallback patch )
  629. * Thu Jun 27 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.4p1-0vl1
  630. - new upstream release
  631. - security fix
  632. - drop patch10
  633. * Wed Jun 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl2
  634. - add patch from Solar Designer to make privsep work with a 2.2 kernel.
  635. * Sun Jun 23 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.3p1-0vl1
  636. - new upstream release
  637. - add {sshd,ssh}_config.5 manpages
  638. - add ssh-keysign
  639. * Sun May 26 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.3p1-0vl1
  640. - new upstream release
  641. * Sat May 18 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.2.2p1-0vl1
  642. - new upstream release
  643. - drop patch1
  644. * Fri Mar 08 2002 Daisuke SUZUKI <daisuke@linux.or.jp> 3.1p1-2vl1
  645. - new upstream release
  646. - merged with rawhide release.
  647. - drop Patch101 (merged in upstream)
  648. * Fri Mar 08 2002 Toru Sagami <sagami@vinelinux.org> 3.0.2p1-2vl2
  649. - seurity patch for off-by-one bug
  650. * Wed Jan 30 2002 KOBAYASHI R. Taizo <tkoba@vinelinux.org> 3.0.2p-2vl1
  651. - merged with Rawhide 3.0.2p1-2
  652. * Sun Dec 02 2001 Toru Sagami <sagami@vinelinux.org>
  653. - updated to 3.0.2p1
  654. * Mon Nov 19 2001 Toru Sagami <sagami@vinelinux.org>
  655. - updated to 3.0.1p1
  656. * Thu Nov 08 2001 Toru Sagami <sagami@vinelinux.org> 3.0p1-0vl0
  657. - updated to 3.0p1
  658. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl2
  659. - add japanese summery and descriptions.
  660. - update x11-askpass 1.2.5
  661. * Sun Sep 30 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.9.9p2-0vl1
  662. - update to openssh-2.9.9p2
  663. * Mon Jul 16 2001 MATSUBAYASHI 'Shaolin' Kohji <shaolin@vinelinux.org> 2.5.2p2-0vl3
  664. - rebuilt with openssl-0.9.6b
  665. * Tue Mar 27 2001 Jun Nishii <jun@vinelinux.org> 2.5.2p2-0vl2
  666. - do not Permit RootLogin
  667. * Tue Mar 27 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p2-0vl1
  668. - update to openssh-2.5.2p2
  669. * Wed Mar 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.2p1-0vl1
  670. - update to openssh-2.5.2p1
  671. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  672. - update to openssh-2.5.1p2
  673. * Thu Mar 15 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p2-0vl1
  674. - update to openssh-2.5.1p1
  675. * Wed Feb 21 2001 Daisuke SUZUKI <daisuke@linux.or.jp> 2.5.1p1-0vl1
  676. - update to openssh-2.5.1p1
  677. * Thu Dec 28 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl4
  678. - remove suid bit from ssh
  679. * Tue Dec 19 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl3
  680. - moved man dir to /usr/share/man
  681. * Wed Dec 06 2000 Satoshi MACHINO <machino@vinelinux.org> 2.3.0p1-0vl2
  682. - fixed askpass's link in ssh-add
  683. - partially used rpmmacros
  684. * Fri Nov 10 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.3.0p1-0vl1
  685. - update to 2.3.0p1
  686. - update x11-askpass 1.0.3
  687. * Wed Oct 18 2000 Damien Miller <djm@mindrot.org>
  688. - Merge some of Nalin Dahyabhai <nalin@redhat.com> changes from the
  689. Redhat 7.0 spec file
  690. * Sat Oct 14 2000 Daisuke SUZUKI <daisuke@linux.or.jp> 2.2.0p2-2vl1
  691. - rebuild for Vine Linux
  692. * Tue Sep 05 2000 Damien Miller <djm@mindrot.org>
  693. - Use RPM configure macro
  694. * Tue Aug 08 2000 Damien Miller <djm@mindrot.org>
  695. - Some surgery to sshd.init (generate keys at runtime)
  696. - Cleanup of groups and removal of keygen calls
  697. * Wed Jul 12 2000 Damien Miller <djm@mindrot.org>
  698. - Make building of X11-askpass and gnome-askpass optional
  699. * Mon Jun 12 2000 Damien Miller <djm@mindrot.org>
  700. - Glob manpages to catch compressed files
  701. * Wed Mar 15 2000 Damien Miller <djm@ibs.com.au>
  702. - Updated for new location
  703. - Updated for new gnome-ssh-askpass build
  704. * Sun Dec 26 1999 Damien Miller <djm@mindrot.org>
  705. - Added Jim Knoble's <jmknoble@pobox.com> askpass
  706. * Mon Nov 15 1999 Damien Miller <djm@mindrot.org>
  707. - Split subpackages further based on patch from jim knoble <jmknoble@pobox.com>
  708. * Sat Nov 13 1999 Damien Miller <djm@mindrot.org>
  709. - Added 'Obsoletes' directives
  710. * Tue Nov 09 1999 Damien Miller <djm@ibs.com.au>
  711. - Use make install
  712. - Subpackages
  713. * Mon Nov 08 1999 Damien Miller <djm@ibs.com.au>
  714. - Added links for slogin
  715. - Fixed perms on manpages
  716. * Sat Oct 30 1999 Damien Miller <djm@ibs.com.au>
  717. - Renamed init script
  718. * Fri Oct 29 1999 Damien Miller <djm@ibs.com.au>
  719. - Back to old binary names
  720. * Thu Oct 28 1999 Damien Miller <djm@ibs.com.au>
  721. - Use autoconf
  722. - New binary names
  723. * Wed Oct 27 1999 Damien Miller <djm@ibs.com.au>
  724. - Initial RPMification, based on Jan "Yenya" Kasprzak's <kas@fi.muni.cz> spec.