summary refs log tree commit diff
path: root/pkgs/tools/networking/openssh/default.nix
AgeCommit message (Collapse)AuthorFilesLines
2023-03-21openssh_*: Add knownVulnerabilitiesJanne Heß1-1/+5
2023-03-21openssh: 9.2p1 -> 9.3p1Janne Heß1-2/+2
2023-02-18openssh_hpn: 9.1p1 -> 9.2p1Ashish SHUKLA1-9/+11
The latest patch has diffs with mixed strip prefixes counts (i.e. patch -pX) so it needs to be split into two diffs, one that can be applied with -p1 and one that needs to be fixed up
2023-02-14openssh: 9.1p1 -> 9.2p1Janne Heß1-2/+9
2022-10-27openssh_hpn: 9.0p1 -> 9.1p1Ashish SHUKLA1-2/+2
2022-10-04openssh: 9.0p1 -> 9.1p1Janne Heß1-2/+2
2022-07-06openssh_gssapi: 8.4p1 -> 9.0p1Jairo Llopis1-13/+5
Fixes https://github.com/NixOS/nixpkgs/issues/142999, CVE-2021-28041, CVE-2021-41617, CVE-2016-20012 @moduon MT-904
2022-04-16Merge pull request #168326 from wahjava/update-openssh-hpnGuillaume Girol1-2/+2
openssh_hpn: 8.9p1 -> 9.0p1
2022-04-12openssh_hpn: 8.9p1 -> 9.0p1Ashish SHUKLA1-2/+2
2022-04-10Merge #167852: openssh: 8.9p1 -> 9.0p1Janne Heß1-2/+2
(cherry picked from commit 830b4daeb1f3f4791e1e4965acaeb910aeaee3d4) > This release is focused on bug fixing.
2022-03-04Merge remote-tracking branch 'nixpkgs/staging-next' into stagingAlyssa Ross1-4/+4
Conflicts: pkgs/development/python-modules/hypothesmith/default.nix
2022-03-04openssh_hpn: 8.8p1 -> 8.9p1Ashish SHUKLA1-4/+4
2022-02-23openssh: 8.8p1 -> 8.9p1Janne Heß1-2/+2
2022-01-05openssh_hpn: 8.4p1 -> 8.8p1Ashish SHUKLA1-13/+14
- Switch to using patch from the FreeBSD port security/openssh-portable which is regularly maintained - Add myself as maintainer for openssh_hpn
2021-10-03Merge staging-next into staginggithub-actions[bot]1-0/+2
2021-10-03openssh_hpn/openssh_gssapi: Add CVE-2021-41617Janne Heß1-0/+2
2021-09-30openssh: Add myself as maintainerJanne Heß1-1/+2
2021-09-30openssh: 8.7p1 -> 8.8p1Janne Heß1-2/+2
2021-09-23Merge master into staging-nextgithub-actions[bot]1-6/+9
2021-09-22openssh-portable: switch to fetchFromGitHubFelix Buehler1-6/+9
2021-08-20openssh: 8.6p1 -> 8.7p1Janne Heß1-2/+2
2021-04-19openssh: 8.5p1 -> 8.6p1Janne Heß1-2/+2
2021-03-11openssh_hpn/openssh_gssapi: Add CVE-2021-28041Janne Heß1-0/+8
2021-03-03openssh: 8.4p1 -> 8.5p1 and refactorJanne Heß1-122/+44
Also split out the variants of the package because I'm sick of waiting for random patches to be updated before I can update my unpatched openssh. Also make pname correspond to the attribute name.
2021-01-16pkgs/tools: pkgconfig -> pkg-configBen Siraphob1-3/+3
2021-01-15pkgs/tools: stdenv.lib -> libBen Siraphob1-3/+3
2020-12-25openssh: fix cross-compilation after #100906Ben Wolsieffer1-1/+2
krb5-config from the host platform needs to be added to PATH so it can be run during build. This works because krb5-config is a platform independent shell-script. Before #100906, krb5-config was not used, so we didn't run into this problem.
2020-12-09Merge pull request #100906 from KAction/opensshNiklas Hambüchen1-1/+19
openssh: fix static build
2020-11-27Merge master into staging-nextFrederik Rietdijk1-1/+1
2020-11-24[staging] openssh: Fix EOF: command not foundyoctocell1-0/+3
2020-11-14openssh: fix hpn sha256SCOTT-HAMILTON1-1/+1
2020-10-29openssh: 8.3p1 -> 8.4p1Janne Heß1-5/+5
Fixes CVE-2020-15778, CVE-2020-14145
2020-10-20openssh: fix static buildDmitry Bogatov1-1/+19
2020-09-20openssh_hpn: fix sourceRyan Burns1-1/+1
2020-07-31openssh: 8.2p1 -> 8.3p1Pavol Rusnak1-9/+20
compile openssh_hpn with recent openssl
2020-06-08openssh: don’t include fido2 on muslMatthew Bauer1-1/+1
libselinux pulls in openssh transitively, so can’t use fido here Fixes #89246
2020-04-10treewide: Per RFC45, remove all unquoted URLsMichael Reilly1-1/+1
2020-02-27openssh_hpn: 7.8p1 -> 8.1p1Pavol Rusnak1-13/+4
fix build failure
2020-02-27openssh: 8.1p1 -> 8.2p1Pavol Rusnak1-4/+8
https://www.openssh.com/txt/release-8.2 add libfido2 to enable hardware tokens support added in this release
2020-01-04openssh_gssapi: fix buildMaximilian Bosch1-8/+4
Hydra build is failing[1] because of a hash-mismatch of the gss-api patch from debian. I updated the patch, and activated the `autoreconfHook` when building gss support as well, otherwise the build would fail with the following error: ``` ERROR: configure is out of date; please run autoreconf (and configure) ``` [1] https://hydra.nixos.org/build/109409845
2019-10-19openssh: don't let configure override SSH_KEYSIGNedef1-0/+2
While 9fe10288f01984963faf47e21bf1bae4d7d37962 ensured that the ssh-keysign path is searched for in PATH if not absolute, it doesn't prevent the configure script from defaulting to an absolute path in $out/libexec, making the whole effort rather pointless.
2019-10-19openssh: mark hpnSupport as brokenedef1-0/+1
We're hoping to deprecate HPN support, given that as far as we can tell, nobody is using it, and the patches seem rather unmaintained.
2019-10-19openssh: 7.9p1 -> 8.1p1Will Dietz1-7/+6
https://www.openwall.com/lists/oss-security/2019/04/18/1
2019-08-15treewide: name -> pname (easy cases) (#66585)volth1-2/+2
treewide replacement of stdenv.mkDerivation rec { name = "*-${version}"; version = "*"; to pname
2019-07-31openssh: use ssh-keysign from PATHedef1-0/+2
ssh-keysign is used for host-based authentication, and is designed to be used as SUID-root program. OpenSSH defaults to referencing it from libexec, which cannot be made SUID in Nix.
2019-01-13openssh: apply CVE-2018-20685 patchAndreas Rammhold1-0/+9
2018-11-24direnv: make cross-compile on windowsJörg Thalheim1-1/+1
2018-10-26openssh: 7.7p1 -> 7.9p1 (#48784)zimbatm1-14/+6
added openssh_gssapi to make it easier to test the patched version the HPN edition isn't available on top of 7.9p1 yet fix-host-key-algorithms-plus.patch didn't apply anymore, assuming it's fixed. release notes: https://www.openssh.com/txt/release-7.9
2018-10-08openssh: fix tunnel forwarding (upstream patch)Vladimír Čunát1-0/+7
Close #48031, fixes #48016. I didn't use the PR commit because I think it's better to fetch the patch.
2018-07-21pkgs/*: remove unreferenced function argumentsvolth1-1/+1