Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

openssh-keycat-9.9p1-7.el10_0 RPM for s390x

From AlmaLinux 10.0 BaseOS for s390x

Name: openssh-keycat Distribution: AlmaLinux
Version: 9.9p1 Vendor: AlmaLinux
Release: 7.el10_0 Build date: Fri Mar 28 15:35:40 2025
Group: Unspecified Build host: s390x-builder03
Size: 20663 Source RPM: openssh-9.9p1-7.el10_0.src.rpm
Packager: AlmaLinux Packaging Team <packager@almalinux.org>
Url: http://www.openssh.com/portable.html
Summary: A mls keycat backend for openssh
OpenSSH mls keycat is backend for using the authorized keys in the
openssh in the mls mode.

Provides

Requires

License

BSD-3-Clause AND BSD-2-Clause AND ISC AND SSH-OpenSSH AND ssh-keyscan AND sprintf AND LicenseRef-Fedora-Public-Domain AND X11-distribute-modifications-variant

Changelog

* Tue Feb 18 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-7
  - rebuilt
    Related: RHEL-78699
* Thu Feb 13 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-6
  - Fix regression of Match directive processing
    Related: RHEL-76317
  - Fix missing error codes set and invalid error code checks in OpenSSH. It
    prevents memory exhaustion attack and a MITM attack when VerifyHostKeyDNS
    is on (CVE-2025-26465, CVE-2025-26466).
    Resolves: RHEL-78699
    Resolves: RHEL-78943
* Mon Jan 27 2025 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-5
  - Fix regression of Match directive processing
    Resolves: RHEL-76317
  - Avoid linking issues for openssl logging
    Related: RHEL-63190
* Tue Oct 29 2024 Troy Dawson <tdawson@redhat.com> - 9.9p1-4.1
  - Bump release for October 2024 mass rebuild:
    Resolves: RHEL-64018
* Mon Oct 28 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-4
  - Fix MLKEM for BE platforms
    Related: RHEL-60564
* Fri Oct 18 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-3
  - Extra help information should not be printed if stderr is not a TTY
    Resolves: RHEL-63061
  - Provide details on crypto error instead of "error in libcrypto"
    Resolves: RHEL-63190
* Tue Oct 15 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-2
  - Resolve memory management issues after rebase
    Related: RHEL-60564
  - Add extra help information on ssh early failure
    Resolves: RHEL-62718
* Thu Oct 10 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.9p1-1
  - Update to OpenSSH 9.9p1
    Resolves: RHEL-60564
  - Separate ssh-keysign to a dedicated package
    Resolves: RHEL-62112
  - Use FIPS KEX defaults in FIPS mode
    Resolves: RHEL-58986
* Mon Sep 16 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-6
  - rebuilt
    Related: RHEL-59024
* Mon Aug 26 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-5
  - Restore GSS connectivity when no hostkeys are present
    Related: RHEL-42635
  - Add missing gsskeyex authentication method
    Related: RHEL-42635
  - "publickey-hostbound@openssh.com" extension makes no sense with GSS
    Related: RHEL-42635
* Fri Aug 16 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-4
  - Address SAST scan issues
    Resolves: RHEL-36766
  - Remove obsoleted patches
    Related: RHEL-42635
* Mon Aug 05 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-3
  - sshd doesn't propose to enter password again when a non-existing user is specified
    Resolves: RHEL-11981
  - Reenabling self-test on rpm build
    Related: RHEL-42635
* Fri Jul 26 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-2.0
  - Temporary disabling self-test
    Related: RHEL-42635
  - Change ssh-keygen defaults in FIPS mode
    Resolves: RHEL-37324
  - Use FIPS-compatible API for key derivation RHEL-10
    Resolves: RHEL-43592
* Thu Jul 25 2024 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.8p1-1.0
  - Rebase OpenSSH to 9.8p1
    Resolves: RHEL-42635
* Fri Jul 12 2024 Zoltan Fridrich <zfridric@redhat.com> - 9.6p1-1.5
  - Build OpenSSH without ENGINE API
    Resolves: RHEL-45507
  - Remove pam_ssh_agent_auth subpackage
    Resolves: RHEL-45002
* Mon Jun 24 2024 Troy Dawson <tdawson@redhat.com> - 9.6p1-1.4
  - Bump release for June 2024 mass rebuild
* Thu May 09 2024 Zoltan Fridrich <zfridric@redhat.com> - 9.6p1-1.3
  - Correctly audit hostname and IP address (RHEL-22316)
  - Make default key sizes configurable in sshd-keygen (RHEL-26454)
* Thu Jan 25 2024 Fedora Release Engineering <releng@fedoraproject.org> - 9.6p1-1.2
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Sun Jan 21 2024 Fedora Release Engineering <releng@fedoraproject.org> - 9.6p1-1.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild
* Tue Dec 26 2023 Daniel Milnes <daniel@daniel-milnes.uk> - 9.6p1-1
  - Update to OpenSSH 9.6
    Original patches from https://src.fedoraproject.org/rpms/openssh/pull-request/63
    Tuned by Dmitry Belyavskiy for GSS and PKCS#11 URI processing
* Fri Dec 22 2023 Florian Weimer <fweimer@redhat.com> - 9.3p1-13.1
  - Fix type errors in downstream gssapi-keyex patch
* Mon Oct 16 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-13
  - Fix issue with read-only ssh buffer during gssapi key exchange (rhbz#1938224)
  - https://github.com/openssh-gsskex/openssh-gsskex/pull/19
* Sun Oct 15 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-12
  - Fix FTBFS due to implicit declarations (rhbz#2241211)
* Tue Sep 19 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-11
  - migrated to SPDX license
* Fri Sep 15 2023 Timothée Ravier <tim@siosm.fr> - 9.3p1-10
  - Revert "Remove sshd.socket unit (rhbz#2025716)"
* Thu Aug 03 2023 Norbert Pocs <npocs@redhat.com> - 9.3p1-9
  - pkcs11: Add support for 'serial' in PKCS#11 URI
  - Apply the upstream MR related to the previous pkcs11 issue
  - https://github.com/openssh/openssh-portable/pull/406
* Thu Aug 03 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-8
  - Split including crypto-policies to a separate config (rhbz#1970566)
  - Disable forking of ssh-agent on startup (rhbz#2148555)
  - Remove sshd.socket unit (rhbz#2025716)
  - Minor optimization of ssh_krb5_kuserok (rhbz#2112501)
* Tue Aug 01 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-7
  - Relax checks of OpenSSL version
* Wed Jul 26 2023 Mattias Ellert <mattias.ellert@physics.uu.se> - 9.3p1-6
  - Update gssapi-keyex patch for OpenSSH 9.0+
* Fri Jul 21 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-5
  - Fix remote code execution in ssh-agent PKCS#11 support
    Resolves: CVE-2023-38408
* Thu Jul 20 2023 Fedora Release Engineering <releng@fedoraproject.org> - 9.3p1-3.1
  - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild
* Thu Jun 08 2023 Norbert Pocs <npocs@redhat.com> - 9.3p1-4
  - Fix deprecated %patchN syntax
  - Reduce the number of patches by merging related patches
* Wed Jun 07 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-3
  - Fix DSS verification problem
    Resolves: rhbz#2212937
* Fri Jun 02 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-2
  - Remove unused patch
* Thu Jun 01 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.3p1-1 + 0.10.4-9
  - Rebase OpenSSH to 9.3p1
* Wed May 24 2023 Norbert Pocs <npocs@redhat.com> - 9.0p1-18
  - Fix pkcs11 issue with the recent changes
  - Clarify HostKeyAlgorithms relation with crypto-policies
* Fri Apr 14 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.0p1-17
  - In case when sha1 signatures are not supported, fallback to sha2 in hostproof
  - Audit logging patch was not applied (rhbz#2177471)
* Thu Apr 13 2023 Norbert Pocs <npocs@redhat.com> - 9.0p1-16
  - Make the sign, dh, ecdh processes FIPS compliant by adopting to
    openssl 3.0
* Thu Apr 13 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 9.0p1-15
  - Fix self-DoS
    Resolves: CVE-2023-25136
  - Remove too aggressive coverity fix causing native tests failure
* Wed Apr 12 2023 Florian Weimer <fweimer@redhat.com> - 9.0p1-14.2
  - C99 compatiblity fixes
* Tue Mar 14 2023 Timothée Ravier <tim@siosm.fr> - 9.0p1-14
  - Make sshd & sshd@ units want ssh-host-keys-migration.service
* Mon Mar 13 2023 Zoltan Fridrich <zfridric@redhat.com> - 9.0p1-13
  - Add sk-dummy subpackage for test purposes (rhbz#2176795)
* Mon Mar 06 2023 Dusty Mabe <dusty@dustymabe.com> - 9.0p1-12
  - Mark /var/lib/.ssh-host-keys-migration as %ghost file
  - Make ssh-host key migration less conditional
* Wed Mar 01 2023 Dusty Mabe <dusty@dustymabe.com> - 9.0p1-11
  - Provide a systemd unit for restoring default host key permissions (rhbz#2172956)
  - Co-Authored by Timothée Ravier <tim@siosm.fr>

Files

/etc/pam.d/ssh-keycat
/usr/lib/.build-id
/usr/lib/.build-id/b2
/usr/lib/.build-id/b2/1ba14a0de4bb91a1ba45f94f11a8cdebac5841
/usr/libexec/openssh/ssh-keycat
/usr/share/doc/openssh-keycat
/usr/share/doc/openssh-keycat/HOWTO.ssh-keycat


Generated by rpm2html 1.8.1

Fabrice Bellet, Thu Oct 23 06:14:43 2025