Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 1 Jul 2002 12:57:51 -0700
From:      "Chris McCluskey" <chris@digitaldeck.com>
To:        <freebsd-questions@freebsd.org>
Subject:   Which SSH now (and when)?
Message-ID:  <ECEPLGOFLCLKKCNAGCBHMEHOCEAA.chris@digitaldeck.com>

next in thread | raw e-mail | index | archive | help
I was hoping that everyone out there can clarify a couple questions
(and/or possibly false statements) I have regarding SSH.

FreeBSD (4.5) SSH in the system source is (or was) built from
OpenSSH3.3?

FreeBSD (4.5) ships with the SSH ports (ssh and ssh2) from ssh.com?

To stay consistent with the FreeBSD project then, it would be a good
idea to build out of the openssh or openssh-portable ports instead of
the ssh/ssh2 ports -- using the portable port if and only if PAM
support is needed?

The security issues recently released from ISS and OpenSSH have been
fixed and the ports in openssh and openssh-portable (both OpenSSH 3.4)
have been initially tested, and found to be ok in the following
areas -- 1) ChallengeResponseAuth is now fixed, 2) key exchanges with
previously created DSA or RSA keys are now working currently, and 3)
PRIVSEP is now enabled by default in both openssh ports?

Are there any dangers in using the ssh.com ports (besides the possible
security issues with SSH1 on a protocol level)?

Thanks.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?ECEPLGOFLCLKKCNAGCBHMEHOCEAA.chris>