From owner-freebsd-stable Thu Jan 3 11:59:25 2002 Delivered-To: freebsd-stable@freebsd.org Received: from creme-brulee.marcuscom.com (rdu57-28-046.nc.rr.com [66.57.28.46]) by hub.freebsd.org (Postfix) with ESMTP id 6995337B416 for ; Thu, 3 Jan 2002 11:59:18 -0800 (PST) Received: from shumai.marcuscom.com (marcus@shumai.marcuscom.com [192.168.1.4]) by creme-brulee.marcuscom.com (8.11.6/8.11.6) with ESMTP id g03Jwlv27158; Thu, 3 Jan 2002 14:58:47 -0500 (EST) (envelope-from marcus@marcuscom.com) Subject: Re: Please integrate OpenSSH 3.x From: Joe Clarke To: Brett Glass Cc: stable@FreeBSD.ORG In-Reply-To: <4.3.2.7.2.20020103124027.02a29860@localhost> References: <4.3.2.7.2.20020103124027.02a29860@localhost> Content-Type: text/plain Content-Transfer-Encoding: 7bit X-Mailer: Evolution/1.0 (Preview Release) Date: 03 Jan 2002 14:59:23 -0500 Message-Id: <1010087964.86152.14.camel@shumai.marcuscom.com> Mime-Version: 1.0 Sender: owner-freebsd-stable@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Thu, 2002-01-03 at 14:45, Brett Glass wrote: > As per the recent discussion in freebsd-security, please integrate the > latest release of OpenSSH prior to shipment of 4.5-RELEASE. Many subtle > improvements have been made that prevent malfunctions which I'm seeing > with older releases. > > So far, I've been doing upgrades by hand on every copy of 4.4-RELEASE and > 4.4-STABLE I install... and I do mean "by hand," since installing the > port or package posted online puts OpenSSH in different place than the > default install. Upgrading is unnecessarily painful and time-consuming. > Since OpenSSH 3.x is now time-tested, FreeBSD 4.5-RELEASE should include it. While I haven't been following the -security thread, I'm not sure if this is necessary. The OpenSSH in FreeBSD has received specific FreeBSD "localizations" to fix bugs that may have arisen. Also, the OpenSSH port in /usr/ports/security/openssh-portable now supports a OPENSSH_OVERWRITE_BASE make option to replace the base SSH installation. Just add NO_OPENSSH=true in /etc/make.conf, and you'll be set. Joe > > --Brett > > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-stable" in the body of the message > To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-stable" in the body of the message