]> CyberLeo.Net >> Repos - FreeBSD/FreeBSD.git/commit
ssh: default VerifyHostKeyDNS to no, following upstream
authorEd Maste <emaste@FreeBSD.org>
Fri, 17 Feb 2023 01:26:41 +0000 (20:26 -0500)
committerEd Maste <emaste@FreeBSD.org>
Thu, 2 Mar 2023 03:09:45 +0000 (22:09 -0500)
commit43fd77233cd49061839cfdd936cfeba53e9855c3
tree47283183cedb8eb1ecbd5ec9c85c8102277ff20a
parent95f418fe2a0fb96080afbd2afc160929a32d12fb
ssh: default VerifyHostKeyDNS to no, following upstream

Revert to upstream's default.  Using VerifyHostKeyDNS may depend on a
trusted nameserver and network path.

This reverts commit 83c6a5242c80160fff76fb85454938761645b0c4.

Reported by: David Leadbeater, G-Research
Reviewed by: gordon
Relnotes: Yes
Sponsored by: The FreeBSD Foundation
Differential Revision: https://reviews.freebsd.org/D38648

(cherry picked from commit 41ff5ea22cb95deb9e7415510eb2f5f00b91537a)
crypto/openssh/FREEBSD-upgrade
crypto/openssh/readconf.c
crypto/openssh/ssh_config
crypto/openssh/ssh_config.5