Commit message (Collapse) | Author | Age | Files | Lines | ||
---|---|---|---|---|---|---|
... | ||||||
* | server: Add a ssh_send_keepalive() function. | Nicolas Viennot | 2013-11-24 | 2 | -0/+43 | |
| | | | | Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | channel: fix infinite loop in channel_write_common | Jon Simons | 2013-11-22 | 1 | -1/+3 | |
| | | | | | | BUG: https://red.libssh.org/issues/130 Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | flush channel after EOF and CLOSE | Rod Vagg | 2013-11-18 | 1 | -0/+8 | |
| | ||||||
* | logging: fix server-side logging | Aris Adamantiadis | 2013-11-18 | 1 | -2/+3 | |
| | ||||||
* | gssapi: fix logging | Aris Adamantiadis | 2013-11-18 | 1 | -14/+14 | |
| | ||||||
* | sockets: null pointer check | Aris Adamantiadis | 2013-11-18 | 1 | -5/+7 | |
| | ||||||
* | gssapi: Fix support of delegated credentials | Simo Sorce | 2013-11-15 | 1 | -23/+37 | |
| | | | | | | | | | | | | In a previous refactoring patch, the code underpinning the ssh_gssapi_set_creds() API was inadvertently removed. This patch fixes the problem. Also clarify what variable holds which credentials and insure that credentials created within the library are propelry freed. Signed-off-by: Simo Sorce <simo@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | gssapi: Add support for GSSAPIDelegateCredentials config option. | Simo Sorce | 2013-11-15 | 2 | -1/+12 | |
| | | | | | Signed-off-by: Simo Sorce <simo@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | options: Add SSH_OPTIONS_GSSAPI_DELEGATE_CREDENTIALS option. | Simo Sorce | 2013-11-15 | 3 | -1/+18 | |
| | | | | | Signed-off-by: Simo Sorce <simo@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | gssapi: Add error checks and cleanup the code in ssh_gssapi_auth_mic(). | Andreas Schneider | 2013-11-15 | 1 | -2/+13 | |
| | ||||||
* | gssapi: Use GSSAPIClientIdentity to acquire creds | Simo Sorce | 2013-11-15 | 1 | -3/+23 | |
| | | | | | Signed-off-by: Simo Sorce <simo@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | gssapi: Add support for GSSAPIClientIdentity config option. | Andreas Schneider | 2013-11-15 | 1 | -1/+9 | |
| | ||||||
* | options: Add SSH_OPTIONS_GSSAPI_CLIENT_IDENTITY option. | Andreas Schneider | 2013-11-15 | 4 | -1/+22 | |
| | ||||||
* | gssapi: Add support for GSSAPIServerIdentity config option. | Andreas Schneider | 2013-11-15 | 1 | -1/+9 | |
| | ||||||
* | gssapi: Add suppport to set GSSAPI server identity. | Andreas Schneider | 2013-11-15 | 5 | -2/+28 | |
| | ||||||
* | Fix gssapi credential handling. | Simo Sorce | 2013-11-15 | 1 | -105/+65 | |
| | | | | | | | | | | | - Properly acquire and inquitre credentials to get the list of available credentials. - Avoid enforcing a specific username it breaks some use cases (k5login). - Remove confusing references to delegated credentials as there is no code that actually uses delegated credentials in the initialization case. Signed-off-by: Siom Sorce <simo@redhat.com> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | socket: Fix connect if we pass in a fd. | Andreas Schneider | 2013-11-15 | 1 | -9/+13 | |
| | | | | | | BUG: https://red.libssh.org/issues/106 Thanks to Saju Panikulam. | |||||
* | packet: Remove dead code. | Andreas Schneider | 2013-11-14 | 1 | -6/+0 | |
| | ||||||
* | packet: Set the packet to the processed data position. | Andreas Schneider | 2013-11-14 | 1 | -1/+1 | |
| | | | | Else we could end up with packet - current_macsize if to_be_read is 0. | |||||
* | dh: Fix wrong assignment. | Andreas Schneider | 2013-11-14 | 1 | -1/+1 | |
| | | | | Ups, sorry. | |||||
* | poll: Fix realloc in ssh_poll_ctx_resize(). | Andreas Schneider | 2013-11-09 | 1 | -2/+6 | |
| | ||||||
* | dh: Avoid possible memory leaks with realloc. | Andreas Schneider | 2013-11-09 | 1 | -4/+13 | |
| | ||||||
* | packet: Refactor ssh_packet_socket_callback(). | Andreas Schneider | 2013-11-09 | 1 | -156/+201 | |
| | | | | Make error checking more readable and add additional NULL checks. | |||||
* | server: Fix malloc call. | Andreas Schneider | 2013-11-09 | 1 | -1/+1 | |
| | ||||||
* | session: Always request POLLIN | Colin Walters | 2013-11-09 | 1 | -3/+1 | |
| | | | | | | | The assumption is that if libssh functions are being invoked, we want to read data. Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | Add ssh_get_poll_flags() | Colin Walters | 2013-11-09 | 4 | -0/+32 | |
| | | | | | | | | | | For integration with an external mainloop, we need to know how to replicate libssh's internal poll() calls. We originally through ssh_get_status() was that API, but it's not really - those flags only get updated from the *result* of a poll(), where what we really need is to know how libssh would *start* a poll(). Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | client: If we have a pre-connected FD, set state to SOCKET_CONNECTED | Colin Walters | 2013-11-09 | 1 | -0/+1 | |
| | | | | | | | Otherwise applications providing their own fd end up tripping an assertion, since the session is just in _CONNECTING. Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | example: Use ssh_get_publickey_hash(). | Andreas Schneider | 2013-11-06 | 1 | -4/+16 | |
| | ||||||
* | dh: Move ssh_get_hexa() and ssh_print_hexa() down. | Andreas Schneider | 2013-11-06 | 1 | -57/+57 | |
| | | | | | This way they are in the documentation block for the session and we get documentation for them. | |||||
* | dh: Add new ssh_get_publickey_hash() function. | Andreas Schneider | 2013-11-06 | 2 | -20/+115 | |
| | ||||||
* | doc: Add curve25519 to features list. | Andreas Schneider | 2013-11-05 | 1 | -1/+1 | |
| | ||||||
* | doc: Fix doxygen warnings. | Andreas Schneider | 2013-11-04 | 2 | -6/+7 | |
| | ||||||
* | Fix cast warnings on 64bits | Aris Adamantiadis | 2013-11-04 | 2 | -3/+3 | |
| | ||||||
* | remove warnings on OSX (workaround) | Aris Adamantiadis | 2013-11-04 | 2 | -2/+12 | |
| | ||||||
* | logging: fix wording | Aris Adamantiadis | 2013-11-04 | 1 | -2/+2 | |
| | ||||||
* | curve25519: include reference implementation | Aris Adamantiadis | 2013-11-03 | 4 | -9/+293 | |
| | ||||||
* | examples: fix forktty() warning on OSX | Aris Adamantiadis | 2013-11-03 | 3 | -1/+7 | |
| | ||||||
* | Fix examples compilation on OSX (libargp) | Aris Adamantiadis | 2013-11-03 | 3 | -3/+9 | |
| | ||||||
* | Compile libssh with nacl if possible | Aris Adamantiadis | 2013-11-03 | 4 | -2/+77 | |
| | | | | | Conflicts: DefineOptions.cmake | |||||
* | socket: Fix check for pending data. | Aris Adamantiadis | 2013-11-03 | 2 | -4/+8 | |
| | | | | | | BUG: https://red.libssh.org/issues/119 Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | server: Fix ssh_execute_server_callbacks() client execution | Nicolas Viennot | 2013-11-03 | 1 | -4/+2 | |
| | | | | | | | | | | When the public key auth handler is executed and returns SSH_OK, ssh_execute_server_callbacks() still runs some client callbacks, which may set rc to SSH_AGAIN, which triggers a default reply on auth, denying auth. Signed-off-by: Nicolas Viennot <nicolas@viennot.biz> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | server kex: enable delayed compression | Nicolas Viennot | 2013-11-03 | 1 | -4/+14 | |
| | | | | | | | The code is careful to reenable compression when rekeying. Signed-off-by: Nicolas Viennot <nicolas@viennot.biz> Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | session: Make sure we correctly burn the buffer. | Andreas Schneider | 2013-11-03 | 1 | -1/+1 | |
| | ||||||
* | wrapper: Make sure we really burn the buffer. | Andreas Schneider | 2013-11-03 | 1 | -1/+1 | |
| | ||||||
* | priv: Fix brackets of burn macros. | Andreas Schneider | 2013-11-03 | 1 | -2/+2 | |
| | ||||||
* | doc: Add missing RFCs. | Andreas Schneider | 2013-11-03 | 1 | -0/+8 | |
| | ||||||
* | server: fix pubkey reply for key probes | Jon Simons | 2013-11-02 | 1 | -1/+9 | |
| | | | | | | | | | | | | | | | Per RFC 4252, it is required to send back only one of either SSH_MSG_USERAUTH_PK_OK or SSH_MSG_USERAUTH_FAILURE for public key probes. Update the handling of 'auth_pubkey_function' to send back PK_OK instead of SSH_MSG_USERAUTH_SUCCESS for the case that the state of the message at hand is SSH_PUBLICKEY_STATE_NONE. With this change, it is now possible to process an initial key probe and then subsequent signature validation using the server callbacks. Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | ssh_options_get can now return ProxyCommand | William Orr | 2013-11-02 | 1 | -0/+9 | |
| | | | | Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | connect: fix memory leak in ssh_select | Jon Simons | 2013-10-31 | 1 | -2/+9 | |
| | | | | | | | | Balance 'ssh_event_add_fd' with 'ssh_event_remove_fd' in 'ssh_select'. BUG: https://red.libssh.org/issues/128 Reviewed-by: Andreas Schneider <asn@cryptomilk.org> | |||||
* | tests: Add a test for ssh_channel(). | Andreas Schneider | 2013-10-31 | 2 | -0/+50 | |
| |