Portable OpenSSH
Go to file
djm@openbsd.org f208e3b9ff upstream: ssh-keygen: fix touch prompt, pin retries;
part of GHPR329 from Pedro Martelletto

OpenBSD-Commit-ID: 75d1005bd2ef8f29fa834c90d2684e73556fffe8
2022-07-20 13:38:48 +10:00
.github Move vmshutdown to first step. 2022-07-15 21:31:48 +10:00
contrib update version numbers for release 2022-04-06 10:47:48 +10:00
m4 Improve detection of -fzero-call-used-regs=all support 2022-02-25 11:24:04 +11:00
openbsd-compat Return ERANGE from getcwd() if buffer size is 1. 2022-07-14 11:22:08 +10:00
regress Remove unintended changes. 2022-07-14 19:22:47 +10:00
.depend depend 2022-03-31 14:11:36 +11:00
.gitignore
.skipped-commit-ids upstream: Import regenerated moduli 2022-04-20 15:08:54 +10:00
addr.c upstream: be stricter in which characters will be accepted in 2022-05-02 09:20:50 +10:00
addr.h
addrmatch.c
atomicio.c remove sys/param.h in -portable, after upstream 2021-12-22 09:02:50 +11:00
atomicio.h
audit-bsm.c
audit-linux.c
audit.c
audit.h
auth2-chall.c
auth2-gss.c upstream: prepare for multiple names for authmethods 2021-12-20 09:28:07 +11:00
auth2-hostbased.c upstream: include rejected signature algorithm in error message 2022-01-07 09:21:38 +11:00
auth2-kbdint.c upstream: prepare for multiple names for authmethods 2021-12-20 09:28:07 +11:00
auth2-none.c upstream: prepare for multiple names for authmethods 2021-12-20 09:28:07 +11:00
auth2-passwd.c upstream: f sshpkt functions fail, then password is not cleared 2022-05-27 14:59:17 +10:00
auth2-pubkey.c upstream: make sure that UseDNS hostname lookup happens in the monitor 2022-06-16 02:12:11 +10:00
auth2-pubkeyfile.c upstream: bump up loglevel from debug to info when unable to open 2022-07-01 13:54:53 +10:00
auth2.c upstream: avoid integer overflow of auth attempts (harmless, caught 2022-02-23 22:22:20 +11:00
auth-bsdauth.c
auth-krb5.c
auth-options.c upstream: Switch hpdelim interface to accept only ":" as delimiter. 2022-02-10 15:14:17 +11:00
auth-options.h upstream: make authorized_keys environment="..." directives 2021-07-23 14:07:19 +10:00
auth-pam.c Fix memory leak in error path. 2021-09-03 13:42:08 +10:00
auth-pam.h
auth-passwd.c
auth-rhosts.c upstream: free(3) wants stdlib.h 2022-02-24 08:24:17 +11:00
auth-shadow.c
auth-sia.c
auth-sia.h
auth.c upstream: move auth_openprincipals() and auth_openkeyfile() over to 2022-06-03 14:49:18 +10:00
auth.h upstream: make sure that UseDNS hostname lookup happens in the monitor 2022-06-16 02:12:11 +10:00
authfd.c upstream: Add authfd path to debug output. ok markus@ 2022-04-27 21:33:11 +10:00
authfd.h upstream: ssh-add side of destination constraints 2021-12-20 09:25:17 +11:00
authfile.c upstream: Make sure not to fclose() the same fd twice in case of an 2022-06-24 14:28:29 +10:00
authfile.h
bitmap.c
bitmap.h
buildpkg.sh.in
canohost.c
canohost.h
chacha.c
chacha.h
channels.c upstream: channel_new no longer frees remote_name. So update the 2022-05-05 11:34:52 +10:00
channels.h upstream: channel_new no longer frees remote_name. So update the 2022-05-05 11:34:52 +10:00
cipher-aes.c
cipher-aesctr.c
cipher-aesctr.h
cipher-chachapoly-libcrypto.c
cipher-chachapoly.c
cipher-chachapoly.h
cipher-ctr.c
cipher.c
cipher.h
cleanup.c
clientloop.c upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
clientloop.h
compat.c upstream: Always return allocated strings from the kex filtering so 2022-07-01 13:41:16 +10:00
compat.h
config.guess Revert "update build-aux files to match autoconf-2.71" 2022-04-11 16:07:09 +10:00
config.sub Revert "update build-aux files to match autoconf-2.71" 2022-04-11 16:07:09 +10:00
configure.ac Add AUDIT_ARCH_PPC to supported seccomp arches. 2022-07-15 13:37:29 +10:00
CREDITS
crypto_api.h
defines.h Correct value for IPTOS_DSCP_LE. 2021-12-15 10:50:33 +11:00
dh.c
dh.h
digest-libc.c Use SHA.*_HMAC_BLOCK_SIZE if needed. 2021-12-23 11:36:08 +11:00
digest-openssl.c
digest.h
dispatch.c
dispatch.h
dns.c upstream: mark const string array contents const too, i.e. static 2022-02-02 10:38:59 +11:00
dns.h upstream: Ensure that all returned SSHFP records for the specified host 2021-07-19 13:46:13 +10:00
ed25519.c
entropy.c
entropy.h
fatal.c
fe25519.c
fe25519.h
fixalgorithms
fixpaths
ge25519_base.data
ge25519.c
ge25519.h
groupaccess.c
groupaccess.h
gss-genr.c need stdlib.h for free(3) 2021-10-01 16:36:24 +10:00
gss-serv-krb5.c
gss-serv.c
hash.c
hmac.c
hmac.h
hostfile.c upstream: piece of UpdateHostkeys client strictification: when 2022-01-07 09:21:38 +11:00
hostfile.h
includes.h remove sys/param.h in -portable, after upstream 2021-12-22 09:02:50 +11:00
INSTALL Note that, for now, we need variadic macros. 2022-05-06 14:46:09 +10:00
install-sh Revert "update build-aux files to match autoconf-2.71" 2022-04-11 16:07:09 +10:00
kex.c upstream: mark const string array contents const too, i.e. static 2022-02-02 10:38:59 +11:00
kex.h upstream: Fix signature algorithm selection logic for 2022-01-07 09:21:38 +11:00
kexc25519.c
kexdh.c
kexecdh.c
kexgen.c upstream: Record session ID, host key and sig at intital KEX 2021-12-20 09:24:42 +11:00
kexgex.c
kexgexc.c upstream: Record session ID, host key and sig at intital KEX 2021-12-20 09:24:42 +11:00
kexgexs.c upstream: Record session ID, host key and sig at intital KEX 2021-12-20 09:24:42 +11:00
kexsntrup761x25519.c upstream: fix unintended sizeof pointer in debug path ok markus@ 2021-12-07 12:30:50 +11:00
krl.c upstream: avoid printing hash algorithm twice; from lucas AT sexy.is 2022-04-28 13:55:12 +10:00
krl.h
LICENCE Fix typo in Neils' name. 2021-11-29 14:03:19 +11:00
log.c upstream: allow log_stderr==2 to prefix log messages with argv[0] 2021-09-19 17:21:59 +10:00
log.h
loginrec.c remove sys/param.h in -portable, after upstream 2021-12-22 09:02:50 +11:00
loginrec.h
logintest.c
mac.c
mac.h
Makefile.in upstream: split the low-level file handling functions out from 2022-05-27 16:38:03 +10:00
match.c
match.h
mdoc2man.awk
misc.c upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
misc.h upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
mkinstalldirs
moduli upstream: Import regenerated moduli 2022-04-20 15:30:13 +10:00
moduli.5 Resync moduli.5 with upstream. 2022-04-16 14:33:20 +10:00
moduli.c upstream: fix some integer overflows in sieve_large() that show up when 2022-05-02 09:22:44 +10:00
monitor_fdpass.c
monitor_fdpass.h
monitor_wrap.c upstream: make sure that UseDNS hostname lookup happens in the monitor 2022-06-16 02:12:11 +10:00
monitor_wrap.h upstream: make sure that UseDNS hostname lookup happens in the monitor 2022-06-16 02:12:11 +10:00
monitor.c upstream: make sure that UseDNS hostname lookup happens in the monitor 2022-06-16 02:12:11 +10:00
monitor.h
msg.c
msg.h
mux.c upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
myproposal.h upstream: select post-quantum KEX 2022-03-31 08:16:38 +11:00
nchan2.ms
nchan.c upstream: mark const string array contents const too, i.e. static 2022-02-02 10:38:59 +11:00
nchan.ms
openssh.xml.in
opensshd.init.in Replace shell function with ssh-keygen -A. 2021-08-20 18:14:13 +10:00
OVERVIEW
packet.c upstream: add a ssh_packet_process_read() function that reads from 2022-01-25 12:18:35 +11:00
packet.h upstream: add a ssh_packet_process_read() function that reads from 2022-01-25 12:18:35 +11:00
pathnames.h
pkcs11.h
platform-misc.c
platform-pledge.c
platform-tracing.c Include string.h and stdio.h for strerror. 2021-10-15 12:59:06 +11:00
platform.c Factor out platform-specific locked account check. 2022-03-26 12:49:50 +11:00
platform.h Missing semicolon. 2022-03-26 13:15:44 +11:00
poly1305.c
poly1305.h
progressmeter.c
progressmeter.h
PROTOCOL upstream: Note that curve25519-sha256 was later published in 2022-04-12 09:35:31 +10:00
PROTOCOL.agent upstream: Remove errant apostrophe. From haruyama at queen-ml org. 2022-05-13 13:22:50 +10:00
PROTOCOL.certkeys
PROTOCOL.chacha20poly1305
PROTOCOL.key upstream: use consistent field names (s/char/byte) 2022-07-01 16:00:01 +10:00
PROTOCOL.krl
PROTOCOL.mux upstream: spelling ok dtucker@ 2022-01-01 15:19:48 +11:00
PROTOCOL.sshsig
PROTOCOL.u2f
readconf.c upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
readconf.h upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
README update version numbers for release 2022-04-06 10:47:48 +10:00
README.dns
README.md Split README.platform into its own line. 2022-07-14 10:02:35 +10:00
README.platform
README.privsep
README.tun
readpass.c upstream: Avoid kill with -1 argument. The out_ctx label can be 2022-05-27 14:59:17 +10:00
rijndael.c
rijndael.h upstream: Make prototype for rijndaelEncrypt match function 2021-09-29 11:09:27 +10:00
sandbox-capsicum.c Cache timezone data in capsicum sandbox. 2022-04-23 21:14:01 +10:00
sandbox-darwin.c
sandbox-null.c
sandbox-pledge.c
sandbox-rlimit.c
sandbox-seccomp-filter.c Allow ppoll_time64 in seccomp sandbox. 2022-02-26 14:06:14 +11:00
sandbox-solaris.c
sandbox-systrace.c
sc25519.c
sc25519.h
scp.1 upstream: list the correct version number 2022-04-16 14:37:15 +10:00
scp.c upstream: arrange for scp, when in sftp mode, to not ftruncate(3) files 2022-05-13 17:00:56 +10:00
SECURITY.md basic SECURITY.md (refers people to the website) 2021-11-03 12:08:21 +11:00
servconf.c upstream: Make SetEnv directives first-match-wins in both 2022-06-03 14:33:18 +10:00
servconf.h upstream: don't try to resolve ListenAddress directives in the sshd 2022-03-20 19:54:35 +11:00
serverloop.c upstream: Try to continue running local I/O for channels in state 2022-04-20 15:08:54 +10:00
serverloop.h
session.c upstream: Switch hpdelim interface to accept only ":" as delimiter. 2022-02-10 15:14:17 +11:00
session.h
sftp-client.c upstream: fix in-place copies; r1.163 incorrectly skipped truncation in 2022-05-16 22:56:58 +10:00
sftp-client.h upstream: arrange for scp, when in sftp mode, to not ftruncate(3) files 2022-05-13 17:00:56 +10:00
sftp-common.c
sftp-common.h
sftp-glob.c upstream: Remove the char * casts from arguments to do_lstat, 2022-03-01 13:00:26 +11:00
sftp-realpath.c upstream: sys/param.h is not needed for any visible reason 2021-09-03 14:20:22 +10:00
sftp-server-main.c Remove unintended changes. 2022-07-14 19:22:47 +10:00
sftp-server.8 upstream: standardise the grammar in the options list; issue 2021-08-03 09:39:57 +10:00
sftp-server.c upstream: add support for the "corp-data" protocol extension to 2022-03-31 14:09:42 +11:00
sftp.1 upstream: allow arguments to sftp -D option, e.g. sftp -D 2022-06-28 07:43:15 +10:00
sftp.c upstream: reflect the update to -D arg name in usage(); 2022-07-01 10:37:46 +10:00
sftp.h
sk-api.h upstream: when enrolling a resident key on a security token, check 2022-07-20 13:38:47 +10:00
sk-usbhid.c upstream: sk-usbhid: preserve error code returned by key_lookup() 2022-07-20 13:38:47 +10:00
smult_curve25519_ref.c
sntrup761.c
sntrup761.sh
srclimit.c
srclimit.h
ssh2.h
ssh_api.c
ssh_api.h
ssh_config
ssh_config.5 upstream: make it clear that RekeyLimit applies to both transmitted 2022-06-24 14:28:29 +10:00
ssh-add.1 upstream: Since they are deprecated, move DSA to the end of the 2022-02-07 12:27:48 +11:00
ssh-add.c upstream: Don't attempt to fprintf a null identity comment. From 2022-06-24 14:28:29 +10:00
ssh-agent.1 upstream: man pages: add missing commas between subordinate and 2022-04-06 09:16:05 +10:00
ssh-agent.c upstream: fix memleak on session-bind path; from Pedro Martelletto, ok 2022-04-29 13:18:31 +10:00
ssh-dss.c
ssh-ecdsa-sk.c
ssh-ecdsa.c
ssh-ed25519-sk.c
ssh-ed25519.c
ssh-gss.h
ssh-keygen.1 upstream: ssh-keygen -A: do not generate DSA keys by default. 2022-06-03 13:38:19 +10:00
ssh-keygen.c upstream: ssh-keygen: fix touch prompt, pin retries; 2022-07-20 13:38:48 +10:00
ssh-keyscan.1 upstream: Add missing *-sk types to ssh-keyscan manpage. From 2022-06-03 14:33:18 +10:00
ssh-keyscan.c upstream: When poll(2) returns -1, for some error conditions 2022-01-25 10:33:03 +11:00
ssh-keysign.8 upstream: man pages: add missing commas between subordinate and 2022-04-06 09:16:05 +10:00
ssh-keysign.c upstream: make ssh-keysign use the requested signature algorithm 2022-01-07 09:21:38 +11:00
ssh-pkcs11-client.c make OPENSSL_HAS_ECC checks more thorough 2021-10-01 16:36:24 +10:00
ssh-pkcs11-helper.8 upstream: mention that the helpers are used by ssh(1), ssh-agent(1) 2022-04-29 13:26:24 +10:00
ssh-pkcs11-helper.c upstream: check for POLLHUP wherever we check for POLLIN 2021-11-18 14:32:54 +11:00
ssh-pkcs11.c upstream: avoid xmalloc(0) for PKCS#11 keyid for ECDSA keys (we 2021-11-19 08:12:57 +11:00
ssh-pkcs11.h
ssh-rsa.c
ssh-sandbox.h
ssh-sk-client.c upstream: sshsk_load_resident: don't preallocate resp 2022-01-14 14:40:40 +11:00
ssh-sk-helper.8 upstream: mention that the helpers are used by ssh(1), ssh-agent(1) 2022-04-29 13:26:24 +10:00
ssh-sk-helper.c upstream: Don't leak SK device. Patch from Pedro Martelletto via 2022-04-29 13:26:24 +10:00
ssh-sk.c upstream: when enrolling a resident key on a security token, check 2022-07-20 13:38:47 +10:00
ssh-sk.h upstream: When downloading resident keys from a FIDO token, pass 2021-10-28 13:56:59 +11:00
ssh-xmss.c upstream: Add missing includes of stdlib.h and stdint.h. We need 2022-04-27 21:29:17 +10:00
ssh.1 upstream: keywords ref ssh_config.5; 2022-06-03 13:38:12 +10:00
ssh.c upstream: ignore SIGPIPE earlier in main(), specifically before 2022-07-01 10:37:46 +10:00
ssh.h
sshbuf-getput-basic.c upstream: revert previous; it was broken (spotted by Theo) 2022-05-25 16:06:03 +10:00
sshbuf-getput-crypto.c upstream: revert previous; it was broken (spotted by Theo) 2022-05-25 16:06:03 +10:00
sshbuf-io.c
sshbuf-misc.c upstream: Add a sshbuf_read() that attempts to read(2) directly in 2022-01-25 10:45:47 +11:00
sshbuf.c upstream: revert previous; it was broken (spotted by Theo) 2022-05-25 16:06:03 +10:00
sshbuf.h upstream: revert previous; it was broken (spotted by Theo) 2022-05-25 16:06:03 +10:00
sshconnect2.c upstream: Don't leak the strings allocated by order_hostkeyalgs() 2022-07-01 13:41:16 +10:00
sshconnect.c upstream: Add period at end of "not known by any other names" 2022-06-03 13:38:21 +10:00
sshconnect.h
sshd_config
sshd_config.5 upstream: make it clear that RekeyLimit applies to both transmitted 2022-06-24 14:28:29 +10:00
sshd.8 upstream: remove an obsolete rsa1 format example from an example; 2022-05-05 11:34:52 +10:00
sshd.c upstream: Remove leftover line. 2022-07-01 16:00:17 +10:00
ssherr.c
ssherr.h
sshkey-xmss.c
sshkey-xmss.h
sshkey.c upstream: sshkey_unshield_private() contains a exact duplicate of 2022-05-05 11:34:52 +10:00
sshkey.h upstream: add a helper function to match a key type to a list of 2022-01-07 09:21:38 +11:00
sshlogin.c Include stdlib.h for free() prototype. 2022-04-23 21:14:01 +10:00
sshlogin.h
sshpty.c
sshpty.h
sshsig.c upstream: avoid NULL deref via ssh-keygen -Y find-principals. 2022-03-30 15:34:33 +11:00
sshsig.h upstream: Add ssh-keygen -Y match-principals operation to perform 2021-11-27 18:22:41 +11:00
sshtty.c
survey.sh.in
TODO
ttymodes.c
ttymodes.h
uidswap.c
uidswap.h
umac128.c
umac.c upstream: spelling 2022-01-04 18:22:46 +11:00
umac.h upstream: spelling ok dtucker@ 2022-01-01 15:19:48 +11:00
utf8.c
utf8.h
verify.c
version.h upstream: openssh-9.0 2022-04-06 09:16:11 +10:00
xmalloc.c upstream: ssh: xstrdup(): use memcpy(3) 2022-03-18 13:33:36 +11:00
xmalloc.h
xmss_commons.c
xmss_commons.h
xmss_fast.c
xmss_fast.h
xmss_hash_address.c
xmss_hash_address.h
xmss_hash.c upstream: Remove unnecessary includes: openssl/hmac.h and 2022-04-27 21:30:01 +10:00
xmss_hash.h
xmss_wots.c
xmss_wots.h

Portable OpenSSH

C/C++ CI Fuzzing Status

OpenSSH is a complete implementation of the SSH protocol (version 2) for secure remote login, command execution and file transfer. It includes a client ssh and server sshd, file transfer utilities scp and sftp as well as tools for key generation (ssh-keygen), run-time key storage (ssh-agent) and a number of supporting programs.

This is a port of OpenBSD's OpenSSH to most Unix-like operating systems, including Linux, OS X and Cygwin. Portable OpenSSH polyfills OpenBSD APIs that are not available elsewhere, adds sshd sandboxing for more operating systems and includes support for OS-native authentication and auditing (e.g. using PAM).

Documentation

The official documentation for OpenSSH are the man pages for each tool:

Stable Releases

Stable release tarballs are available from a number of download mirrors. We recommend the use of a stable release for most users. Please read the release notes for details of recent changes and potential incompatibilities.

Building Portable OpenSSH

Dependencies

Portable OpenSSH is built using autoconf and make. It requires a working C compiler, standard library and headers.

libcrypto from either LibreSSL or OpenSSL may also be used. OpenSSH may be built without either of these, but the resulting binaries will have only a subset of the cryptographic algorithms normally available.

zlib is optional; without it transport compression is not supported.

FIDO security token support needs libfido2 and its dependencies.

In addition, certain platforms and build-time options may require additional dependencies; see README.platform for details about your platform.

Building a release

Releases include a pre-built copy of the configure script and may be built using:

tar zxvf openssh-X.YpZ.tar.gz
cd openssh
./configure # [options]
make && make tests

See the Build-time Customisation section below for configure options. If you plan on installing OpenSSH to your system, then you will usually want to specify destination paths.

Building from git

If building from git, you'll need autoconf installed to build the configure script. The following commands will check out and build portable OpenSSH from git:

git clone https://github.com/openssh/openssh-portable # or https://anongit.mindrot.org/openssh.git
cd openssh-portable
autoreconf
./configure
make && make tests

Build-time Customisation

There are many build-time customisation options available. All Autoconf destination path flags (e.g. --prefix) are supported (and are usually required if you want to install OpenSSH).

For a full list of available flags, run ./configure --help but a few of the more frequently-used ones are described below. Some of these flags will require additional libraries and/or headers be installed.

Flag Meaning
--with-pam Enable PAM support. OpenPAM, Linux PAM and Solaris PAM are supported.
--with-libedit Enable libedit support for sftp.
--with-kerberos5 Enable Kerberos/GSSAPI support. Both Heimdal and MIT Kerberos implementations are supported.
--with-selinux Enable SELinux support.
--with-security-key-builtin Include built-in support for U2F/FIDO2 security keys. This requires libfido2 be installed.

Development

Portable OpenSSH development is discussed on the openssh-unix-dev mailing list (archive mirror). Bugs and feature requests are tracked on our Bugzilla.

Reporting bugs

Non-security bugs may be reported to the developers via Bugzilla or via the mailing list above. Security bugs should be reported to openssh@openssh.com.