From nobody Sun Sep 05 04:04:07 2021 X-Original-To: freebsd-hackers@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4531517A45D6 for ; Sun, 5 Sep 2021 04:04:20 +0000 (UTC) (envelope-from kaduk@mit.edu) Received: from outgoing.mit.edu (outgoing-auth-1.mit.edu [18.9.28.11]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 4H2HwM5Wyfz4pyS; Sun, 5 Sep 2021 04:04:19 +0000 (UTC) (envelope-from kaduk@mit.edu) Received: from kduck.mit.edu ([24.16.140.251]) (authenticated bits=56) (User authenticated as kaduk@ATHENA.MIT.EDU) by outgoing.mit.edu (8.14.7/8.12.4) with ESMTP id 185448LF020354 (version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-GCM-SHA384 bits=256 verify=NOT); Sun, 5 Sep 2021 00:04:12 -0400 Date: Sat, 4 Sep 2021 21:04:07 -0700 From: Benjamin Kaduk To: Ed Maste Cc: FreeBSD Hackers Subject: Re: OpenSSH 8.7p1 update for the base system Message-ID: <20210905040341.GG96301@kduck.mit.edu> References: List-Id: Technical discussions relating to FreeBSD List-Archive: https://lists.freebsd.org/archives/freebsd-hackers List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-hackers@freebsd.org MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: X-Rspamd-Queue-Id: 4H2HwM5Wyfz4pyS X-Spamd-Bar: ---- Authentication-Results: mx1.freebsd.org; none X-Spamd-Result: default: False [-4.00 / 15.00]; REPLY(-4.00)[] X-Spam: Yes X-ThisMailContainsUnwantedMimeParts: N Hi Ed, I'm not sure whether this would be something for the release notes or not, but I believe that making privilege separation mandatory causes GSSAPI credential delegation to essentially not work. (There are several pieces that interact to make this happen, and I don't expect you to do any work to try to fix it; this would just be a question of whether any documentation of the change should occur.) -Ben On Sat, Sep 04, 2021 at 11:59:06AM -0400, Ed Maste wrote: > I'm preparing to update OpenSSH in the FreeBSD base system to 8.7p1, > and am sharing an initial patch for testing. > > The update is available from a branch in my github repo: > https://github.com/emaste/freebsd/tree/openssh-8.7p1-wip > (commit 0afe07936bbd37a1b91ead95f580c47ccc16df79) > > Also as a diff against main: > https://people.freebsd.org/~emaste/openssh/FreeBSD-base-openssh-8.7p1-20210904-114623.diff > > In addition I have a review open in Phabricator, although it is quite > awkward to usefully review a vendor update presented like this. > https://reviews.freebsd.org/D29985 > > If you give it a try please let me know what you've tested out. >