Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 26 Feb 2004 14:32:55 +0300
From:      "Sergey A. Osokin" <osa@freebsd.org.ru>
To:        Dag-Erling Sm?rgrav <des@des.no>
Cc:        security@freebsd.org
Subject:   Re: HEADS UP: OpenSSH 3.8p1
Message-ID:  <20040226113255.GF49750@freebsd.org.ru>
In-Reply-To: <xzpk72a13k4.fsf@dwp.des.no>
References:  <xzpk72a13k4.fsf@dwp.des.no>

next in thread | previous in thread | raw e-mail | index | archive | help
On Thu, Feb 26, 2004 at 12:30:03PM +0100, Dag-Erling Sm?rgrav wrote:
> Take the usual precautions when upgrading.
> 
> Also note that I have changed some configuration defaults: the server
> no longer accepts protocol version 1 nor password authentication by
> default.  If your ssh client does not support ssh protocol version 2
> or keyboard-interactive authentication, the recommended measures are:
> 
>  1) get a better client
>  2) get a better client (I mean it)
>  3) get a better client (for real this time!)
> 
> and as a last resort
> 
>  4) enable procol version 1 and password authentication in sshd_config

What do you think about add the note into UPDATING?
Thanks.
-- 

Regards,                 /"\  ascii ribbon campaign
Sergey "ozz" Osokin,     \ /    against html mail
http://ozz.pp.ru/         X         and news
                         / \



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20040226113255.GF49750>