vishalmishra434 / rpms / openssh

Forked from rpms/openssh a month ago
Clone
Jakub Jelen d9d957
diff -up openssh-7.1p1/ssh_config.5.gss-docs openssh-7.1p1/ssh_config.5
Jakub Jelen d9d957
--- openssh-7.1p1/ssh_config.5.gss-docs	2015-12-10 15:28:47.451966457 +0100
Jakub Jelen d9d957
+++ openssh-7.1p1/ssh_config.5	2015-12-10 15:30:28.070738047 +0100
Jakub Jelen d9d957
@@ -773,15 +773,26 @@ Note that this option applies to protoco
Jakub Jelen d9d957
 If set to 
Jakub Jelen d9d957
 .Dq yes
Jakub Jelen d9d957
 then renewal of the client's GSSAPI credentials will force the rekeying of the
Jakub Jelen d9d957
-ssh connection. With a compatible server, this can delegate the renewed 
Jakub Jelen d9d957
+ssh connection. With a compatible server, this will delegate the renewed 
Jakub Jelen d9d957
 credentials to a session on the server.
Jakub Jelen d9d957
+.Pp
Jakub Jelen d9d957
+Checks are made to ensure that credentials are only propagated when the new
Jakub Jelen d9d957
+credentials match the old ones on the originating client and where the
Jakub Jelen d9d957
+receiving server still has the old set in its cache.
Jakub Jelen d9d957
+.Pp
Jakub Jelen d9d957
 The default is
Jakub Jelen d9d957
 .Dq no .
Jakub Jelen d9d957
+.Pp
Jakub Jelen d9d957
+For this to work
Jakub Jelen d9d957
+.Cm GSSAPIKeyExchange
Jakub Jelen d9d957
+needs to be enabled in the server and also used by the client.
Jakub Jelen d9d957
 .It Cm GSSAPITrustDns
Jakub Jelen d9d957
 Set to 
Jakub Jelen d9d957
-.Dq yes to indicate that the DNS is trusted to securely canonicalize
Jakub Jelen d9d957
+.Dq yes
Jakub Jelen d9d957
+to indicate that the DNS is trusted to securely canonicalize
Jakub Jelen d9d957
 the name of the host being connected to. If 
Jakub Jelen d9d957
-.Dq no, the hostname entered on the
Jakub Jelen d9d957
+.Dq no ,
Jakub Jelen d9d957
+the hostname entered on the
Jakub Jelen d9d957
 command line will be passed untouched to the GSSAPI library.
Jakub Jelen d9d957
 The default is
Jakub Jelen d9d957
 .Dq no .
Jakub Jelen d9d957
diff -up openssh-7.1p1/sshd_config.5.gss-docs openssh-7.1p1/sshd_config.5
Jakub Jelen d9d957
--- openssh-7.1p1/sshd_config.5.gss-docs	2015-12-10 15:28:47.453966452 +0100
Jakub Jelen d9d957
+++ openssh-7.1p1/sshd_config.5	2015-12-10 15:28:47.461966434 +0100
Jakub Jelen d9d957
@@ -653,6 +653,10 @@ Controls whether the user's GSSAPI crede
Jakub Jelen d9d957
 successful connection rekeying. This option can be used to accepted renewed 
Jakub Jelen d9d957
 or updated credentials from a compatible client. The default is
Jakub Jelen d9d957
 .Dq no .
Jakub Jelen d9d957
+.Pp
Jakub Jelen d9d957
+For this to work
Jakub Jelen d9d957
+.Cm GSSAPIKeyExchange
Jakub Jelen d9d957
+needs to be enabled in the server and also used by the client.
Jakub Jelen d9d957
 .It Cm HostbasedAcceptedKeyTypes
Jakub Jelen d9d957
 Specifies the key types that will be accepted for hostbased authentication
Jakub Jelen d9d957
 as a comma-separated pattern list.