mirror of
https://git.yoctoproject.org/poky
synced 2026-09-29 07:36:20 +02:00
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote servers to trigger the skipping of SSHFP DNS RR checking by presenting an unacceptable HostCertificate. (From OE-Core rev: 7b2fff61b3d1c0566429793ee348fa8978ef0cba) (From OE-Core rev: 6a8a9903de24cc7e1f27b1f7202bd4157719327c) Signed-off-by: Chen Qi <Qi.Chen@windriver.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> Conflicts: meta/recipes-connectivity/openssh/openssh_6.5p1.bb
145 lines
5.8 KiB
BlitzBasic
145 lines
5.8 KiB
BlitzBasic
SUMMARY = "Secure rlogin/rsh/rcp/telnet replacement"
|
|
DESCRIPTION = "Secure rlogin/rsh/rcp/telnet replacement (OpenSSH) \
|
|
Ssh (Secure Shell) is a program for logging into a remote machine \
|
|
and for executing commands on a remote machine."
|
|
HOMEPAGE = "http://openssh.org"
|
|
SECTION = "console/network"
|
|
LICENSE = "BSD"
|
|
LIC_FILES_CHKSUM = "file://LICENCE;md5=e326045657e842541d3f35aada442507"
|
|
|
|
DEPENDS = "zlib openssl"
|
|
DEPENDS += "${@base_contains('DISTRO_FEATURES', 'pam', 'libpam', '', d)}"
|
|
|
|
RPROVIDES_${PN}-ssh = "ssh"
|
|
RPROVIDES_${PN}-sshd = "sshd"
|
|
|
|
RCONFLICTS_${PN} = "dropbear"
|
|
RCONFLICTS_${PN}-sshd = "dropbear"
|
|
RCONFLICTS_${PN}-keygen = "ssh-keygen"
|
|
|
|
SRC_URI = "ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-${PV}.tar.gz \
|
|
file://nostrip.patch \
|
|
file://sshd_config \
|
|
file://ssh_config \
|
|
file://init \
|
|
file://openssh-CVE-2011-4327.patch \
|
|
${@base_contains('DISTRO_FEATURES', 'pam', '${PAM_SRC_URI}', '', d)} \
|
|
file://sshd.socket \
|
|
file://sshd@.service \
|
|
file://sshdgenkeys.service \
|
|
file://volatiles.99_sshd \
|
|
file://openssh-CVE-2014-2532.patch \
|
|
file://openssh-CVE-2014-2653.patch"
|
|
|
|
PAM_SRC_URI = "file://sshd"
|
|
|
|
SRC_URI[md5sum] = "a084e7272b8cbd25afe0f5dce4802fef"
|
|
SRC_URI[sha256sum] = "a1195ed55db945252d5a1730d4a2a2a5c1c9a6aa01ef2e5af750a962623d9027"
|
|
|
|
inherit useradd update-rc.d update-alternatives systemd
|
|
|
|
USERADD_PACKAGES = "${PN}-sshd"
|
|
USERADD_PARAM_${PN}-sshd = "--system --no-create-home --home-dir /var/run/sshd --shell /bin/false --user-group sshd"
|
|
INITSCRIPT_PACKAGES = "${PN}-sshd"
|
|
INITSCRIPT_NAME_${PN}-sshd = "sshd"
|
|
INITSCRIPT_PARAMS_${PN}-sshd = "defaults 9"
|
|
|
|
SYSTEMD_PACKAGES = "${PN}-sshd"
|
|
SYSTEMD_SERVICE_${PN}-sshd = "sshd.socket"
|
|
|
|
PACKAGECONFIG ??= "tcp-wrappers"
|
|
PACKAGECONFIG[tcp-wrappers] = "--with-tcp-wrappers,,tcp-wrappers"
|
|
|
|
inherit autotools-brokensep
|
|
|
|
# LFS support:
|
|
CFLAGS += "-D__FILE_OFFSET_BITS=64"
|
|
export LD = "${CC}"
|
|
|
|
# login path is hardcoded in sshd
|
|
EXTRA_OECONF = "'LOGIN_PROGRAM=${base_bindir}/login' \
|
|
${@base_contains('DISTRO_FEATURES', 'pam', '--with-pam', '--without-pam', d)} \
|
|
--without-zlib-version-check \
|
|
--with-privsep-path=/var/run/sshd \
|
|
--sysconfdir=${sysconfdir}/ssh \
|
|
--with-xauth=/usr/bin/xauth"
|
|
|
|
# Since we do not depend on libbsd, we do not want configure to use it
|
|
# just because it finds libutil.h. But, specifying --disable-libutil
|
|
# causes compile errors, so...
|
|
CACHED_CONFIGUREVARS += "ac_cv_header_bsd_libutil_h=no ac_cv_header_libutil_h=no"
|
|
|
|
# passwd path is hardcoded in sshd
|
|
CACHED_CONFIGUREVARS += "ac_cv_path_PATH_PASSWD_PROG=${bindir}/passwd"
|
|
|
|
# This is a workaround for uclibc because including stdio.h
|
|
# pulls in pthreads.h and causes conflicts in function prototypes.
|
|
# This results in compilation failure, so unless this is fixed,
|
|
# disable pam for uclibc.
|
|
EXTRA_OECONF_append_libc-uclibc=" --without-pam"
|
|
|
|
do_configure_prepend () {
|
|
if [ ! -e acinclude.m4 -a -e aclocal.m4 ]; then
|
|
cp aclocal.m4 acinclude.m4
|
|
fi
|
|
}
|
|
|
|
do_compile_append () {
|
|
install -m 0644 ${WORKDIR}/sshd_config ${S}/
|
|
install -m 0644 ${WORKDIR}/ssh_config ${S}/
|
|
}
|
|
|
|
do_install_append () {
|
|
if [ "${@base_contains('DISTRO_FEATURES', 'pam', 'pam', '', d)}" = "pam" ]; then
|
|
install -D -m 0755 ${WORKDIR}/sshd ${D}${sysconfdir}/pam.d/sshd
|
|
sed -i -e 's:#UsePAM no:UsePAM yes:' ${WORKDIR}/sshd_config ${D}${sysconfdir}/ssh/sshd_config
|
|
fi
|
|
|
|
install -d ${D}${sysconfdir}/init.d
|
|
install -m 0755 ${WORKDIR}/init ${D}${sysconfdir}/init.d/sshd
|
|
rm -f ${D}${bindir}/slogin ${D}${datadir}/Ssh.bin
|
|
rmdir ${D}${localstatedir}/run/sshd ${D}${localstatedir}/run ${D}${localstatedir}
|
|
install -d ${D}/${sysconfdir}/default/volatiles
|
|
install -m 644 ${WORKDIR}/volatiles.99_sshd ${D}/${sysconfdir}/default/volatiles/99_sshd
|
|
|
|
# Create config files for read-only rootfs
|
|
install -d ${D}${sysconfdir}/ssh
|
|
install -m 644 ${D}${sysconfdir}/ssh/sshd_config ${D}${sysconfdir}/ssh/sshd_config_readonly
|
|
sed -i '/HostKey/d' ${D}${sysconfdir}/ssh/sshd_config_readonly
|
|
echo "HostKey /var/run/ssh/ssh_host_rsa_key" >> ${D}${sysconfdir}/ssh/sshd_config_readonly
|
|
echo "HostKey /var/run/ssh/ssh_host_dsa_key" >> ${D}${sysconfdir}/ssh/sshd_config_readonly
|
|
echo "HostKey /var/run/ssh/ssh_host_ecdsa_key" >> ${D}${sysconfdir}/ssh/sshd_config_readonly
|
|
|
|
install -d ${D}${systemd_unitdir}/system
|
|
install -c -m 0644 ${WORKDIR}/sshd.socket ${D}${systemd_unitdir}/system
|
|
install -c -m 0644 ${WORKDIR}/sshd@.service ${D}${systemd_unitdir}/system
|
|
install -c -m 0644 ${WORKDIR}/sshdgenkeys.service ${D}${systemd_unitdir}/system
|
|
sed -i -e 's,@BASE_BINDIR@,${base_bindir},g' \
|
|
-e 's,@SBINDIR@,${sbindir},g' \
|
|
-e 's,@BINDIR@,${bindir},g' \
|
|
${D}${systemd_unitdir}/system/sshd.socket ${D}${systemd_unitdir}/system/*.service
|
|
}
|
|
|
|
ALLOW_EMPTY_${PN} = "1"
|
|
|
|
PACKAGES =+ "${PN}-keygen ${PN}-scp ${PN}-ssh ${PN}-sshd ${PN}-sftp ${PN}-misc ${PN}-sftp-server"
|
|
FILES_${PN}-scp = "${bindir}/scp.${BPN}"
|
|
FILES_${PN}-ssh = "${bindir}/ssh.${BPN} ${sysconfdir}/ssh/ssh_config"
|
|
FILES_${PN}-sshd = "${sbindir}/sshd ${sysconfdir}/init.d/sshd ${systemd_unitdir}/system"
|
|
FILES_${PN}-sshd += "${sysconfdir}/ssh/moduli ${sysconfdir}/ssh/sshd_config ${sysconfdir}/ssh/sshd_config_readonly ${sysconfdir}/default/volatiles/99_sshd ${sysconfdir}/pam.d/sshd"
|
|
FILES_${PN}-sftp = "${bindir}/sftp"
|
|
FILES_${PN}-sftp-server = "${libexecdir}/sftp-server"
|
|
FILES_${PN}-misc = "${bindir}/ssh* ${libexecdir}/ssh*"
|
|
FILES_${PN}-keygen = "${bindir}/ssh-keygen"
|
|
|
|
RDEPENDS_${PN} += "${PN}-scp ${PN}-ssh ${PN}-sshd ${PN}-keygen"
|
|
RDEPENDS_${PN}-sshd += "${PN}-keygen ${@base_contains('DISTRO_FEATURES', 'pam', 'pam-plugin-keyinit pam-plugin-loginuid', '', d)}"
|
|
|
|
CONFFILES_${PN}-sshd = "${sysconfdir}/ssh/sshd_config"
|
|
CONFFILES_${PN}-ssh = "${sysconfdir}/ssh/ssh_config"
|
|
|
|
ALTERNATIVE_PRIORITY = "90"
|
|
ALTERNATIVE_${PN}-scp = "scp"
|
|
ALTERNATIVE_${PN}-ssh = "ssh"
|
|
|