| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search | 
| Name: openssh | Distribution: AlmaLinux | 
| Version: 9.9p1 | Vendor: AlmaLinux | 
| Release: 7.el10_0 | Build date: Fri Mar 28 15:35:40 2025 | 
| Group: Unspecified | Build host: s390x-builder03 | 
| Size: 1456211 | Source RPM: openssh-9.9p1-7.el10_0.src.rpm | 
| Packager: AlmaLinux Packaging Team <packager@almalinux.org> | |
| Url: http://www.openssh.com/portable.html | |
| Summary: An open source implementation of SSH protocol version 2 | |
SSH (Secure SHell) is a program for logging into and executing commands on a remote machine. SSH is intended to replace rlogin and rsh, and to provide secure encrypted communications between two untrusted hosts over an insecure network. X11 connections and arbitrary TCP/IP ports can also be forwarded over the secure channel. OpenSSH is OpenBSD's version of the last free version of SSH, bringing it up to date in terms of security and features. This package includes the core files necessary for both the OpenSSH client and server. To make this package useful, you should also install openssh-clients, openssh-server, or both.
BSD-3-Clause AND BSD-2-Clause AND ISC AND SSH-OpenSSH AND ssh-keyscan AND sprintf AND LicenseRef-Fedora-Public-Domain AND X11-distribute-modifications-variant
* Tue Feb 18 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-7
  - rebuilt
    Related: RHEL-78699
* Thu Feb 13 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-6
  - Fix regression of Match directive processing
    Related: RHEL-76317
  - Fix missing error codes set and invalid error code checks in OpenSSH. It
    prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS
    is on (CVE-2025-26465, CVE-2025-26466).
    Resolves: RHEL-78699
    Resolves: RHEL-78943
* Mon Jan 27 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-5
  - Fix regression of Match directive processing
    Resolves: RHEL-76317
  - Avoid linking issues for openssl logging
    Related: RHEL-63190
* Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 9.9p1-4.1
  - Bump release for October 2024 mass rebuild:
    Resolves: RHEL-64018
* Mon Oct 28 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-4
  - Fix MLKEM for BE platforms
    Related: RHEL-60564
* Fri Oct 18 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-3
  - Extra help information should not be printed if stderr is not a TTY
    Resolves: RHEL-63061
  - Provide details on crypto error instead of "error in libcrypto"
    Resolves: RHEL-63190
* Tue Oct 15 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-2
  - Resolve memory management issues after rebase
    Related: RHEL-60564
  - Add extra help information on ssh early failure
    Resolves: RHEL-62718
* Thu Oct 10 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-1
  - Update to OpenSSH 9.9p1
    Resolves: RHEL-60564
  - Separate ssh-keysign to a dedicated package
    Resolves: RHEL-62112
  - Use FIPS KEX defaults in FIPS mode
    Resolves: RHEL-58986
* Mon Sep 16 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-6
  - rebuilt
    Related: RHEL-59024
* Mon Aug 26 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-5
  - Restore GSS connectivity when no hostkeys are present
    Related: RHEL-42635
  - Add missing gsskeyex authentication method
    Related: RHEL-42635
  - "publickey-hostbound@openssh.com" extension makes no sense with GSS
    Related: RHEL-42635
* Fri Aug 16 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-4
  - Address SAST scan issues
    Resolves: RHEL-36766
  - Remove obsoleted patches
    Related: RHEL-42635
* Mon Aug 05 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-3
  - sshd doesn't propose to enter password again when a non-existing user is specified
    Resolves: RHEL-11981
  - Reenabling self-test on rpm build
    Related: RHEL-42635
* Fri Jul 26 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-2.0
  - Temporary disabling self-test
    Related: RHEL-42635
  - Change ssh-keygen defaults in FIPS mode
    Resolves: RHEL-37324
  - Use FIPS-compatible API for key derivation RHEL-10
    Resolves: RHEL-43592
* Thu Jul 25 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-1.0
  - Rebase OpenSSH to 9.8p1
    Resolves: RHEL-42635
* Fri Jul 12 2024 Zoltan Fridrich <zfridric@redhat.com> - 9.6p1-1.5
  - Build OpenSSH without ENGINE API
    Resolves: RHEL-45507
  - Remove pam_ssh_agent_auth subpackage
    Resolves: RHEL-45002
* Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 9.6p1-1.4
  - Bump release for June 2024 mass rebuild
* Thu May 09 2024 Zoltan Fridrich <zfridric@redhat.com> - 9.6p1-1.3
  - Correctly audit hostname and IP address (RHEL-22316)
  - Make default key sizes configurable in sshd-keygen (RHEL-26454)
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 9.6p1-1.2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 9.6p1-1.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Tue Dec 26 2023 Daniel Milnes <daniel@daniel-milnes.uk> - 9.6p1-1
  - Update to OpenSSH 9.6
    Original patches from https://src.fedoraproject.org/rpms/openssh/pull-request/63
    Tuned by Dmitry Belyavskiy for GSS and PKCS#11 URI processing
* Fri Dec 22 2023 Florian Weimer <fweimer@redhat.com> - 9.3p1-13.1
  - Fix type errors in downstream gssapi-keyex patch
* Mon Oct 16 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-13
  - Fix issue with read-only ssh buffer during gssapi key exchange (rhbz#1938224)
  - https://github.com/openssh-gsskex/openssh-gsskex/pull/19
* Sun Oct 15 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-12
  - Fix FTBFS due to implicit declarations (rhbz#2241211)
* Tue Sep 19 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-11
  - migrated to SPDX license
* Fri Sep 15 2023 Timothée Ravier <tim@siosm.fr> - 9.3p1-10
  - Revert "Remove sshd.socket unit (rhbz#2025716)"
* Thu Aug 03 2023 Norbert Pocs <npocs@redhat.com> - 9.3p1-9
  - pkcs11: Add support for 'serial' in PKCS#11 URI
  - Apply the upstream MR related to the previous pkcs11 issue
  - https://github.com/openssh/openssh-portable/pull/406
* Thu Aug 03 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-8
  - Split including crypto-policies to a separate config (rhbz#1970566)
  - Disable forking of ssh-agent on startup (rhbz#2148555)
  - Remove sshd.socket unit (rhbz#2025716)
  - Minor optimization of ssh_krb5_kuserok (rhbz#2112501)
* Tue Aug 01 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-7
  - Relax checks of OpenSSL version
* Wed Jul 26 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-6
  - Update gssapi-keyex patch for OpenSSH 9.0+
* Fri Jul 21 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-5
  - Fix remote code execution in ssh-agent PKCS#11 support
    Resolves: CVE-2023-38408
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 9.3p1-3.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jun 08 2023 Norbert Pocs <npocs@redhat.com> - 9.3p1-4
  - Fix deprecated %patchN syntax
  - Reduce the number of patches by merging related patches
* Wed Jun 07 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-3
  - Fix DSS verification problem
    Resolves: rhbz#2212937
* Fri Jun 02 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-2
  - Remove unused patch
* Thu Jun 01 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-1 + 0.10.4-9
  - Rebase OpenSSH to 9.3p1
* Wed May 24 2023 Norbert Pocs <npocs@redhat.com> - 9.0p1-18
  - Fix pkcs11 issue with the recent changes
  - Clarify HostKeyAlgorithms relation with crypto-policies
* Fri Apr 14 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.0p1-17
  - In case when sha1 signatures are not supported, fallback to sha2 in hostproof
  - Audit logging patch was not applied (rhbz#2177471)
* Thu Apr 13 2023 Norbert Pocs <npocs@redhat.com> - 9.0p1-16
  - Make the sign, dh, ecdh processes FIPS compliant by adopting to
    openssl 3.0
* Thu Apr 13 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.0p1-15
  - Fix self-DoS
    Resolves: CVE-2023-25136
  - Remove too aggressive coverity fix causing native tests failure
* Wed Apr 12 2023 Florian Weimer <fweimer@redhat.com> - 9.0p1-14.2
  - C99 compatiblity fixes
* Tue Mar 14 2023 Timothée Ravier <tim@siosm.fr> - 9.0p1-14
  - Make sshd & sshd@ units want ssh-host-keys-migration.service
* Mon Mar 13 2023 Zoltan Fridrich <zfridric@redhat.com> - 9.0p1-13
  - Add sk-dummy subpackage for test purposes (rhbz#2176795)
* Mon Mar 06 2023 Dusty Mabe <dusty@dustymabe.com> - 9.0p1-12
  - Mark /var/lib/.ssh-host-keys-migration as %ghost file
  - Make ssh-host key migration less conditional
* Wed Mar 01 2023 Dusty Mabe <dusty@dustymabe.com> - 9.0p1-11
  - Provide a systemd unit for restoring default host key permissions (rhbz#2172956)
  - Co-Authored by Timothée Ravier <tim@siosm.fr>
/etc/ssh /etc/ssh/moduli /usr/bin/ssh-keygen /usr/lib/.build-id /usr/lib/.build-id/e5 /usr/lib/.build-id/e5/bf3444f3013e24a405df00e4793e836371a5e9 /usr/libexec/openssh /usr/share/doc/openssh /usr/share/doc/openssh/CREDITS /usr/share/doc/openssh/ChangeLog /usr/share/doc/openssh/OVERVIEW /usr/share/doc/openssh/PROTOCOL /usr/share/doc/openssh/PROTOCOL.agent /usr/share/doc/openssh/PROTOCOL.certkeys /usr/share/doc/openssh/PROTOCOL.chacha20poly1305 /usr/share/doc/openssh/PROTOCOL.key /usr/share/doc/openssh/PROTOCOL.krl /usr/share/doc/openssh/PROTOCOL.mux /usr/share/doc/openssh/PROTOCOL.sshsig /usr/share/doc/openssh/PROTOCOL.u2f /usr/share/doc/openssh/README /usr/share/doc/openssh/README.dns /usr/share/doc/openssh/README.platform /usr/share/doc/openssh/README.privsep /usr/share/doc/openssh/README.tun /usr/share/doc/openssh/TODO /usr/share/licenses/openssh /usr/share/licenses/openssh/LICENCE /usr/share/man/man1/ssh-keygen.1.gz
Generated by rpm2html 1.8.1
Fabrice Bellet, Thu Oct 23 06:14:43 2025