From david@pontiac3.nfrance.com  Wed May  5 17:32:35 2010
Return-Path: <david@pontiac3.nfrance.com>
Received: from mx1.freebsd.org (mx1.freebsd.org [69.147.83.52])
	by hub.freebsd.org (Postfix) with ESMTP id 101C11065672
	for <FreeBSD-gnats-submit@freebsd.org>; Wed,  5 May 2010 17:32:35 +0000 (UTC)
	(envelope-from david@pontiac3.nfrance.com)
Received: from pontiac3.nfrance.com (pontiac3.nfrance.com [80.247.233.60])
	by mx1.freebsd.org (Postfix) with ESMTP id 9A6ED8FC0C
	for <FreeBSD-gnats-submit@freebsd.org>; Wed,  5 May 2010 17:32:34 +0000 (UTC)
Received: from pontiac3.nfrance.com (localhost [127.0.0.1])
	by pontiac3.nfrance.com (8.14.3/8.14.3) with ESMTP id o45H2u6B041695;
	Wed, 5 May 2010 19:03:01 +0200 (CEST)
	(envelope-from david@pontiac3.nfrance.com)
Received: (from david@localhost)
	by pontiac3.nfrance.com (8.14.3/8.14.3/Submit) id o45H2uEB041694;
	Wed, 5 May 2010 19:02:56 +0200 (CEST)
	(envelope-from david)
Message-Id: <201005051702.o45H2uEB041694@pontiac3.nfrance.com>
Date: Wed, 5 May 2010 19:02:56 +0200 (CEST)
From: David BERARD <david@nfrance.com>
Reply-To: David BERARD <david@nfrance.com>
To: FreeBSD-gnats-submit@freebsd.org
Cc: <contact@davidberard.fr>
Subject: OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
X-Send-Pr-Version: 3.113
X-GNATS-Notify:

>Number:         146334
>Category:       conf
>Synopsis:       OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
>Confidential:   no
>Severity:       non-critical
>Priority:       low
>Responsible:    des
>State:          feedback
>Quarter:        
>Keywords:       
>Date-Required:  
>Class:          doc-bug
>Submitter-Id:   current-users
>Arrival-Date:   Wed May 05 17:40:04 UTC 2010
>Closed-Date:    
>Last-Modified:  Wed Jun  2 10:30:01 UTC 2010
>Originator:     David BERARD
>Release:        FreeBSD 8.0-STABLE i386
>Organization:
NFrance Conseil
>Environment:
System: FreeBSD beaver.polymorf.fr 8.0-STABLE FreeBSD 8.0-STABLE #2: Wed May 5 07:46:09 UTC 2010 root@beaver.nfrance.com:/usr/obj/usr/src/sys/BEAVER i386


>Description:
	Since FreeBSD 8.0-STABLE use OpenSSH 5.4p1 new AuthorizedKeysFile syntax should be used in sshd_config.
	OpenSSH 5.5 revert to old old syntax style (see openssh changelog)
>How-To-Repeat:
>Fix:

	See attached diff

--- sshd_config.patch begins here ---
--- ./crypto/openssh/sshd_config	2010-05-05 16:46:38.000000000 +0000
+++ ./crypto/openssh/sshd_config	2010-05-05 16:47:02.000000000 +0000
@@ -49,7 +49,7 @@
 
 #RSAAuthentication yes
 #PubkeyAuthentication yes
-#AuthorizedKeysFile	.ssh/authorized_keys
+#AuthorizedKeysFile	%h/.ssh/authorized_keys
 
 # For this to work you will also need host keys in /etc/ssh/ssh_known_hosts
 #RhostsRSAAuthentication no
--- sshd_config.patch ends here ---


>Release-Note:
>Audit-Trail:
Responsible-Changed-From-To: freebsd-bugs->des 
Responsible-Changed-By: linimon 
Responsible-Changed-When: Wed May 5 23:38:46 UTC 2010 
Responsible-Changed-Why:  
Looks like something for des to consider. 

http://www.freebsd.org/cgi/query-pr.cgi?pr=146334 

From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no>
To: freebsd-gnats-submit@freebsd.org 
Cc:  
Subject: Re: conf/146334: OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
Date: Thu, 06 May 2010 09:32:13 +0200

 I'm not sure I understand what you mean.  Our sshd_config is identical
 to that distributed with the OpenSSH source code apart from a few very
 specific changes.  If there is something wrong with AuthorizedKeysFile
 in either head's or stable/8's sshd_config, you should submit a bug
 report upstream.
 
 BTW, the documentation says:
 
      After expansion, AuthorizedKeysFile is taken to be an absolute
      path or one relative to the user's home directory.  The default
      is ``.ssh/authorized_keys''.
 
 so "%h/.ssh/foo" and ".ssh/foo" are equivalent.
 
 DES
 --=20
 Dag-Erling Sm=C3=B8rgrav - des@des.no
State-Changed-From-To: open->feedback 
State-Changed-By: des 
State-Changed-When: Thu May 6 13:36:37 UTC 2010 
State-Changed-Why:  
awaiting originator feedback 

http://www.freebsd.org/cgi/query-pr.cgi?pr=146334 

From: =?ISO-8859-1?Q?David_B=C9RARD?= <david@nfrance.com>
To: bug-followup@FreeBSD.org, david@nfrance.com
Cc:  
Subject: Re: conf/146334: OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
Date: Thu, 06 May 2010 15:41:15 +0200

 -----BEGIN PGP SIGNED MESSAGE-----
 Hash: SHA1
 
 > so "%h/.ssh/foo" and ".ssh/foo" are equivalent.
 
 ".ssh/foo" doesn't work on 8-STABLE
 
 - -- 
 David BERARD
 - ---------------------------------------
 NFrance Conseil, Toulouse, France
 david(at)nfrance.com
 GPG|PGP KeyId 0x7FC68EB8
 GPG|PGP Key http://tinyurl.com/gpgdavid
 - ---------------------------------------
 *     No electrons were harmed in     *
 *    the transmission of this email   *
 -----BEGIN PGP SIGNATURE-----
 
 iEYEARECAAYFAkvixvsACgkQYIAREn/GjrgJ7QCgi9eYJUAzLHZTMyAYV1IavNWE
 p3wAoLyRyTYdLw3umWI7uwsBWEK5OQkJ
 =NX8N
 -----END PGP SIGNATURE-----

From: =?utf-8?Q?Dag-Erling_Sm=C3=B8rgrav?= <des@des.no>
To: freebsd-gnats-submit@freebsd.org 
Cc:  
Subject: Re: conf/146334: OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
Date: Fri, 07 May 2010 09:50:13 +0200

 David B=C3=89RARD <david@nfrance.com> writes:
 >  ".ssh/foo" doesn't work on 8-STABLE
 
 Yes, it does.  If you're absolutely sure it doesn't, ktrace sshd while
 attempting to log in and send me the output from 'kdump -tcn'.
 
 DES
 --=20
 Dag-Erling Sm=C3=B8rgrav - des@des.no

From: "Andrei V. Lavreniyuk" <andy.lavr@reactor-xg.kiev.ua>
To: bug-followup@FreeBSD.org, david@nfrance.com
Cc:  
Subject: Re: conf/146334: OpenSSH 5.4 AuthorizedKeysFile bad syntax in sshd_config
Date: Tue, 11 May 2010 08:40:27 +0300

 Hi!
 
 
 
 http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/145940
 
 
 
 
 
 --- crypto/openssh/servconf.c    4 Mar 2010 10:36:03 -0000       1.204
 +++ crypto/openssh/servconf.c    12 Mar 2010 11:37:40 -0000      1.206
 @@ -1180,7 +1180,17 @@ process_server_config_line(ServerOptions 
 *options, cha
                   charptr = (opcode == sAuthorizedKeysFile) ?
                       &options->authorized_keys_file :
                       &options->authorized_keys_file2;
 -                goto parse_filename;
 +                arg = strdelim(&cp);
 +                if (!arg || *arg == '\0')
 +                        fatal("%s line %d: missing file name.",
 +                            filename, linenum);
 +                if (*activep && *charptr == NULL) {
 +                        *charptr = tilde_expand_filename(arg, getuid());
 +                        /* increase optional counter */
 +                        if (intptr != NULL)
 +                                *intptr = *intptr + 1;
 +                }
 +                break;
           case sClientAliveInterval:
                   intptr = &options->client_alive_interval;
 
 
 
 
 -- 
   Best regards, Andrei V. Lavreniyuk.
 

From: dfilter@FreeBSD.ORG (dfilter service)
To: bug-followup@FreeBSD.org
Cc:  
Subject: Re: conf/146334: commit references a PR
Date: Wed,  2 Jun 2010 10:26:51 +0000 (UTC)

 Author: des
 Date: Wed Jun  2 10:26:31 2010
 New Revision: 208735
 URL: http://svn.freebsd.org/changeset/base/208735
 
 Log:
   Fix expansion of AuthorizedKeysFile (upstream patch)
   
   PR:		146334, 145940
   Approved by:	re (kib@)
 
 Modified:
   stable/8/crypto/openssh/servconf.c
 
 Modified: stable/8/crypto/openssh/servconf.c
 ==============================================================================
 --- stable/8/crypto/openssh/servconf.c	Wed Jun  2 10:20:38 2010	(r208734)
 +++ stable/8/crypto/openssh/servconf.c	Wed Jun  2 10:26:31 2010	(r208735)
 @@ -1227,7 +1227,17 @@ process_server_config_line(ServerOptions
  		charptr = (opcode == sAuthorizedKeysFile) ?
  		    &options->authorized_keys_file :
  		    &options->authorized_keys_file2;
 -		goto parse_filename;
 +		arg = strdelim(&cp);
 +		if (!arg || *arg == '\0')
 +			fatal("%s line %d: missing file name.",
 +			    filename, linenum);
 +		if (*activep && *charptr == NULL) {
 +			*charptr = tilde_expand_filename(arg, getuid());
 +			/* increase optional counter */
 +			if (intptr != NULL)
 +				*intptr = *intptr + 1;
 +		}
 +		break;
  
  	case sClientAliveInterval:
  		intptr = &options->client_alive_interval;
 _______________________________________________
 svn-src-all@freebsd.org mailing list
 http://lists.freebsd.org/mailman/listinfo/svn-src-all
 To unsubscribe, send any mail to "svn-src-all-unsubscribe@freebsd.org"
 
>Unformatted:
