From owner-freebsd-ports Thu Aug 27 14:21:40 1998 Return-Path: Received: (from majordom@localhost) by hub.freebsd.org (8.8.8/8.8.8) id OAA02646 for freebsd-ports-outgoing; Thu, 27 Aug 1998 14:21:40 -0700 (PDT) (envelope-from owner-freebsd-ports@FreeBSD.ORG) Received: from shell6.ba.best.com (shell6.ba.best.com [206.184.139.137]) by hub.freebsd.org (8.8.8/8.8.8) with ESMTP id OAA02605; Thu, 27 Aug 1998 14:21:16 -0700 (PDT) (envelope-from jkb@best.com) Received: from localhost (jkb@localhost) by shell6.ba.best.com (8.9.0/8.9.0/best.sh) with SMTP id OAA17576; Thu, 27 Aug 1998 14:20:12 -0700 (PDT) X-Authentication-Warning: shell6.ba.best.com: jkb owned process doing -bs Date: Thu, 27 Aug 1998 14:20:11 -0700 (PDT) From: "Jan B. Koum " X-Sender: jkb@shell6.ba.best.com To: "Ron 'The Insane One' Rosson" cc: dima@best.net, axl@iafrica.com, freebsd-ports@FreeBSD.ORG, freebsd-security@FreeBSD.ORG Subject: Re: SSH port In-Reply-To: <19980827115247.B11893@oneinsane.net> Message-ID: MIME-Version: 1.0 Content-Type: TEXT/PLAIN; charset=US-ASCII Sender: owner-freebsd-ports@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org AFAIK both .25 and .26 have crc data injection bug fixed: % ssh -v -p 139 twentythree.jkb.org SSH Version 1.2.25 [i386-unknown-freebsd2.2.6], protocol version 1.5. Compiled with RSAREF. [snip] 0wn.jkb.org: Sent encrypted session key. 0wn.jkb.org: Installing crc compensation attack detector 0wn.jkb.org: Received encrypted confirmation. [snip] Is there another bug you guys are talking about? And yes, the license does blow. That means ISPs will have to pay if they want to use ssh2 -- Yan www.best.com/~jkb/ Unix users of the world unite: www.{free,open,net}bsd.org | www.linux.org | www.apache.org | www.perl.com "Turn up the lights, I don't want to go home in the dark." On Thu, 27 Aug 1998, Ron 'The Insane One' Rosson wrote: >On Thu, Aug 27, 1998 at 11:46:40AM -0700, Dima Ruban wrote: >> Grrr, I just went through the license. Sucks. >> Btw, I was under impression that 1.26 has a fix for the insertion attack... > >If you find the fix for the assertion let me know.. I would like to get this >one headache cleared up. I love my ssh. > >> >> Ron 'The Insane One' Rosson writes: >> > On Thu, Aug 27, 1998 at 07:32:42PM +0200, Sheldon Hearn wrote: >> > > >> > > >> > > On Thu, 27 Aug 1998 09:21:38 MST, "Ron 'The Insane One' Rosson" wrote: >> > > >> > > > Is there a reason why we dont have a port of the ver 2.x >> > > > ssh. >> > > >> > > It may have something to do with the software not being freely >> > > distributable. This is from the LICENSE document in the tarball: >> > > >> > > | THERE IS NO WARRANTY OF ANY KIND FOR THIS SOFTWARE. THIS SOFTWARE IS >> > > | FOR NON-COMMERCIAL USE ONLY. >> > > | >> > > | Please contact Data Fellows for >> > > | commercial licensing. To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-ports" in the body of the message