Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 533462 - net-misc/openssh-6.6.1_p1-r4 stabilization request
Summary: net-misc/openssh-6.6.1_p1-r4 stabilization request
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: [OLD] Keywording and Stabilization (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Gentoo's Team for Core System packages
URL:
Whiteboard:
Keywords: STABLEREQ
Depends on:
Blocks:
 
Reported: 2014-12-24 16:19 UTC by Martin Mokrejš
Modified: 2014-12-31 07:30 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Mokrejš 2014-12-24 16:19:29 UTC
Thanks to bug #531156 we have lost tcpd support. Surprisingly to me, on amd (stable) I had to unmask manually net-misc/openssh-6.6.1_p1-r4, the only ebuild below 6.7.
Comment 1 Jeroen Roovers (RETIRED) gentoo-dev 2014-12-24 17:03:46 UTC
Um, nothing happened to the 6.6 branch while a security issue was resolved in the 6.7 branch. You want to use a vulnerable openssh just because another bug with the newer branch is unresolved, and you want it stable for everyone when it isn't even selectable without masking the newer branch? How would that work?
Comment 2 Martin Mokrejš 2014-12-24 19:22:11 UTC
OK, I don't know it is flawed, I was just looking for any ssh prior 6.7_p1 when the tcpd-removal happened. I would be happy with any, even with 6.7_p1 with reverted patch. ;-)

Removal of the tcpd is a bad surprise to me, have realized that after somebody tested continually my root password for several days and syslog grew over 50GB and filled up the drive. Dropping functionality on working/configured systems with *configured* hosts.allow/deny is like installing a Trojan horse. Nobody expects their config files are ignored since some upgrade. And as I mentioned in the #531156 bug, I don't even see same functionality provided by sshd itself.

Thank you for any efforts bringing into stable some secure sshd with tcpd support. I gladly leave it upto you, devs, which version is be recommended.
Comment 3 SpanKY gentoo-dev 2014-12-31 07:30:48 UTC
(In reply to Martin Mokrejš from comment #2)

sorry, but we don't have the resources (or desire?) to hand maintain tcpd support in openssh.  it's unfortunate that you relied on it and upstream just dropped it, but that's what they've done :/.