- 30f704e Deny (non-fatal) ipc in preauth privsep child. by Jeremy Drake · 5 years ago
- b110cef seccomp: Allow clock_gettime64() in sandbox. by Khem Raj · 4 years, 10 months ago
- 3cc60c8 upstream: missing else in check_enroll_options() by djm@openbsd.org · 4 years, 10 months ago
- ff5784e upstream: fix error message by djm@openbsd.org · 4 years, 10 months ago
- dd2acc8 upstream: adapt sk-dummy to SK API changes by djm@openbsd.org · 4 years, 10 months ago
- c312ca0 upstream: Extends the SK API to accept a set of key/value options by djm@openbsd.org · 4 years, 10 months ago
- 2ab3357 upstream: fix CanonicalizeHostname, broken by rev 1.507 by beck@openbsd.org · 4 years, 10 months ago
- 69e44ba Fix typo: 'you' -> 'your'. by Darren Tucker · 4 years, 10 months ago
- 7652a57 Remove auth-skey.c. by Darren Tucker · 4 years, 10 months ago
- c593cc5 upstream: the download resident keys option is -K (upper) not -k by jmc@openbsd.org · 4 years, 10 months ago
- ff31f15 upstream: what bozo decided to use 2020 as a future date in a regress by djm@openbsd.org · 4 years, 10 months ago
- 680eb77 upstream: implement recent SK API change to support resident keys by djm@openbsd.org · 4 years, 10 months ago
- 86834fe upstream: Update keygen moduli screen test to match recent command by dtucker@openbsd.org · 4 years, 10 months ago
- 9039971 upstream: ability to download FIDO2 resident keys from a token via by djm@openbsd.org · 4 years, 10 months ago
- 878ba43 upstream: add sshkey_save_public(), to save a public key; ok by djm@openbsd.org · 4 years, 10 months ago
- 3b1382f upstream: simplify the list for moduli options - no need for by jmc@openbsd.org · 4 years, 10 months ago
- 0248ec7 ssh-sk-null.cc needs extern "C" {} by Damien Miller · 4 years, 10 months ago
- 5ca4b41 add dummy ssh-sk API for linking with fuzzers by Damien Miller · 4 years, 10 months ago
- c4b2664 refresh depend by Damien Miller · 4 years, 10 months ago
- 3093d12 upstream: Remove the -x option currently used for by djm@openbsd.org · 4 years, 10 months ago
- ef65e7d upstream: document SK API changes in PROTOCOL.u2f by djm@openbsd.org · 4 years, 10 months ago
- 43ce964 upstream: translate and return error codes; retry on bad PIN by djm@openbsd.org · 4 years, 10 months ago
- d433596 upstream: improve some error messages; ok markus@ by djm@openbsd.org · 4 years, 10 months ago
- c54cd18 upstream: SK API and sk-helper error/PIN passing by djm@openbsd.org · 4 years, 10 months ago
- 79fe22d upstream: implement loading resident keys in ssh-add by djm@openbsd.org · 4 years, 10 months ago
- 27753a8 upstream: implement loading of resident keys in ssh-sk-helper by djm@openbsd.org · 4 years, 10 months ago
- 14cea36 upstream: resident keys support in SK API by djm@openbsd.org · 4 years, 10 months ago
- 2fe05fc upstream: Factor out parsing of struct sk_enroll_response by djm@openbsd.org · 4 years, 10 months ago
- 4532bd0 upstream: basic support for generating FIDO2 resident keys by djm@openbsd.org · 4 years, 10 months ago
- 3e60d18 upstream: remove single-letter flags for moduli options by djm@openbsd.org · 4 years, 10 months ago
- 1e645fe upstream: prepare for use of ssh-keygen -O flag beyond certs by djm@openbsd.org · 4 years, 10 months ago
- 20ccd85 upstream: sort -Y internally in the options list, as is already by jmc@openbsd.org · 4 years, 10 months ago
- 5b6c954 upstream: in the options list, sort -Y and -y; by jmc@openbsd.org · 4 years, 10 months ago
- 141df48 upstream: Replace the term "security key" with "(FIDO) by naddy@openbsd.org · 4 years, 11 months ago
- fbd9729 upstream: unit tests for ForwardAgent=/path; from Eric Chiang by djm@openbsd.org · 4 years, 11 months ago
- e5b7cf8 upstream: test security key host keys in addition to user keys by djm@openbsd.org · 4 years, 11 months ago
- 40be78f upstream: Allow forwarding a different agent socket to the path by djm@openbsd.org · 4 years, 11 months ago
- 416f153 upstream: SSH U2F keys can now be used as host keys. Fix a garden by naddy@openbsd.org · 4 years, 11 months ago
- 68010ac upstream: Move always unsupported keywords to be grouped with the other by dtucker@openbsd.org · 4 years, 11 months ago
- 8784b02 upstream: Remove obsolete opcodes from the configuation enum. by dtucker@openbsd.org · 4 years, 11 months ago
- 345be60 upstream: Remove now-obsolete config options from example in by dtucker@openbsd.org · 4 years, 11 months ago
- ae024b2 upstream: Document that security key-hosted keys can act as host by naddy@openbsd.org · 4 years, 11 months ago
- bc2dc09 upstream: "Forward security" -> "Forward secrecy" since that's the by dtucker@openbsd.org · 4 years, 11 months ago
- e905f72 upstream: cut obsolete lists of crypto algorithms from outline of by naddy@openbsd.org · 4 years, 11 months ago
- f65cf11 upstream: strdup may return NULL if memory allocation fails. Use by tobhe@openbsd.org · 4 years, 11 months ago
- 57634bf upstream: sort sk-* methods behind their plain key methods cousins by djm@openbsd.org · 4 years, 11 months ago
- b8df8fe Mac OS X has PAM too. by Darren Tucker · 4 years, 11 months ago
- bf8de8b Show portable tarball pattern in example. by Darren Tucker · 4 years, 11 months ago
- a19ef61 OpenSSL is now optional. by Darren Tucker · 4 years, 11 months ago
- 1a7217a upstream: adapt to ssh-sk-client change by djm@openbsd.org · 4 years, 11 months ago
- a7fc1df upstream: it's no longer possible to disable privilege separation by djm@openbsd.org · 5 years ago
- 3145d38 upstream: don't treat HostKeyAgent=none as a path either; avoids by djm@openbsd.org · 4 years, 11 months ago
- 747e251 upstream: do not attempt to find an absolute path for sshd_config by djm@openbsd.org · 4 years, 11 months ago
- 9b6e30b upstream: allow ssh-keyscan to find security key hostkeys by djm@openbsd.org · 4 years, 11 months ago
- 56584cc upstream: allow security keys to act as host keys as well as user by djm@openbsd.org · 4 years, 11 months ago
- 5af6fd5 Allow clock_nanosleep_time64 in seccomp sandbox. by Darren Tucker · 4 years, 11 months ago
- fff8ff6 Put SK ECDSA bits inside ifdef OPENSSL_HAS_ECC. by Darren Tucker · 4 years, 11 months ago
- 9244990 remove a bunch of ENABLE_SK #ifdefs by Damien Miller · 4 years, 11 months ago
- a33ab16 ssh-sk-client.c needs includes.h by Damien Miller · 4 years, 11 months ago
- 633778d only link ssh-sk-helper against libfido2 by Damien Miller · 4 years, 11 months ago
- 7b47b40 adapt Makefile to ssh-sk-client everywhere by Damien Miller · 4 years, 11 months ago
- f45f3a8 fixup by Damien Miller · 4 years, 11 months ago
- d214347 upstream: actually commit the ssh-sk-helper client code; ok markus by djm@openbsd.org · 4 years, 11 months ago
- 611073f upstream: perform security key enrollment via ssh-sk-helper too. by djm@openbsd.org · 4 years, 11 months ago
- 612b1dd upstream: allow sshbuf_put_stringb(buf, NULL); ok markus@ by djm@openbsd.org · 4 years, 11 months ago
- b52ec0b upstream: use ssh-sk-helper for all security key signing operations by djm@openbsd.org · 4 years, 11 months ago
- c33d468 upstream: add a note about the 'extensions' field in the signed by djm@openbsd.org · 5 years ago
- a62f4e1 upstream: some more corrections for documentation problems spotted by djm@openbsd.org · 5 years ago
- 22d4beb upstream: loading security keys into ssh-agent used the extension by djm@openbsd.org · 5 years ago
- 75f7f22 upstream: add security key types to list of keys allowed to act as by djm@openbsd.org · 5 years ago
- 516605f upstream: when acting as a CA and using a security key as the CA by djm@openbsd.org · 5 years ago
- c4036fe upstream: chop some unnecessary and confusing verbiage from the by djm@openbsd.org · 5 years ago
- 59175a3 upstream: fix setting of $SSH_ASKPASS_PROMPT - it shouldn't be set by djm@openbsd.org · 5 years ago
- 36eaa35 upstream: bring the __func__ by djm@openbsd.org · 5 years ago
- 483cc72 upstream: tweak the Nd lines for a bit of consistency; ok markus by jmc@openbsd.org · 5 years ago
- afffd31 Check if memmem is declared in system headers. by Darren Tucker · 5 years ago
- ad8cd42 Sort depends. by Darren Tucker · 5 years ago
- 5e3abff Sort .depend when rebuilding. by Darren Tucker · 5 years ago
- 5df9d1f Update depend to include sk files. by Darren Tucker · 5 years ago
- 9a967c5 Describe how to build libcrypto as PIC. by Darren Tucker · 5 years ago
- b66fa5d Recommend running LibreSSL or OpenSSL self-tests. by Darren Tucker · 5 years ago
- fa79240 Wrap ECC specific bits in ifdef. by Darren Tucker · 5 years ago
- 2ff822e Wrap sha2.h include in ifdef. by Darren Tucker · 5 years ago
- 4438481 compile sk-dummy.so with no-PIE version of LDFLAGS by Damien Miller · 5 years ago
- 37f5b53 includes.h for sk-dummy.c, dummy by Damien Miller · 5 years ago
- b218055 (yet) another x-platform fix for sk-dummy.so by Damien Miller · 5 years ago
- 0dedb70 needs includes.h for WITH_OPENSSL by Damien Miller · 5 years ago
- ef3853b another attempt at sk-dummy.so working x-platform by Damien Miller · 5 years ago
- d46ac56 upstream: lots of dependencies go away here with ed25519 no longer by djm@openbsd.org · 5 years ago
- 7404b81 upstream: perform hashing directly in crypto_hash_sha512() using by djm@openbsd.org · 5 years ago
- d39a865 upstream: improve the text for -A a little; input from naddy and by jmc@openbsd.org · 5 years ago
- 9a0e01b upstream: reshuffle the text to read better; input from naddy, by jmc@openbsd.org · 5 years ago
- 5ca52c0 $< doesn't work as` I thought; explicily list objs by Damien Miller · 5 years ago
- 18e84bf upstream: tweak wording by djm@openbsd.org · 5 years ago
- 8ef5bf9 missing .SUFFIXES line makes make sad by Damien Miller · 5 years ago
- 323da82 (hopefully) fix out of tree builds of sk-dummy.so by Damien Miller · 5 years ago
- d8b2838 upstream: remove stray semicolon after closing brace of function; by djm@openbsd.org · 5 years ago
- 6e1d1bb upstream: Revert previous commit. The channels code still uses int by dtucker@openbsd.org · 5 years ago
- 4898924 wire sk-dummy.so into test suite by Damien Miller · 5 years ago
- f79364b upstream: use error()+_exit() instead of fatal() to avoid running by djm@openbsd.org · 5 years ago