From e6a64a84ea85d2b0b5b4d3c9cb8808d12bd8b2f5 Mon Sep 17 00:00:00 2001 From: "Bjoern A. Zeeb" Date: Thu, 17 Jan 2013 01:51:04 +0000 Subject: Add a src.conf(5) option to allow users to compile in the "NONE cipher", which, only after authentication, disables crypto, and only for sessions without a terminal. Submitted by: Jeremy Chadwick (freebsd jdc.parodius.com) PR: bin/163095 MFC after: 10 days --- secure/lib/libssh/Makefile | 4 ++++ secure/usr.bin/ssh/Makefile | 4 ++++ secure/usr.sbin/sshd/Makefile | 4 ++++ share/mk/bsd.own.mk | 1 + tools/build/options/WITH_OPENSSH_NONE_CIPHER | 9 +++++++++ 5 files changed, 22 insertions(+) create mode 100644 tools/build/options/WITH_OPENSSH_NONE_CIPHER diff --git a/secure/lib/libssh/Makefile b/secure/lib/libssh/Makefile index 7224823d06efd..937fa247e90bb 100644 --- a/secure/lib/libssh/Makefile +++ b/secure/lib/libssh/Makefile @@ -38,6 +38,10 @@ DPADD+= ${LIBGSSAPI} ${LIBKRB5} ${LIBHX509} ${LIBASN1} ${LIBCOM_ERR} ${LIBMD} ${ LDADD+= -lgssapi -lkrb5 -lhx509 -lasn1 -lcom_err -lmd -lroken .endif +.if ${MK_OPENSSH_NONE_CIPHER} != "no" +CFLAGS+= -DNONE_CIPHER_ENABLED +.endif + NO_LINT= DPADD+= ${LIBCRYPTO} ${LIBCRYPT} diff --git a/secure/usr.bin/ssh/Makefile b/secure/usr.bin/ssh/Makefile index 9304fd55f256e..0bee10cbc012d 100644 --- a/secure/usr.bin/ssh/Makefile +++ b/secure/usr.bin/ssh/Makefile @@ -25,6 +25,10 @@ DPADD+= ${LIBGSSAPI} LDADD+= -lgssapi .endif +.if ${MK_OPENSSH_NONE_CIPHER} != "no" +CFLAGS+= -DNONE_CIPHER_ENABLED +.endif + DPADD+= ${LIBCRYPT} ${LIBCRYPTO} LDADD+= -lcrypt -lcrypto diff --git a/secure/usr.sbin/sshd/Makefile b/secure/usr.sbin/sshd/Makefile index cc914c4d0e93a..3fb07087ca790 100644 --- a/secure/usr.sbin/sshd/Makefile +++ b/secure/usr.sbin/sshd/Makefile @@ -40,6 +40,10 @@ DPADD+= ${LIBGSSAPI_KRB5} ${LIBGSSAPI} ${LIBKRB5} ${LIBASN1} LDADD+= -lgssapi_krb5 -lgssapi -lkrb5 -lasn1 .endif +.if ${MK_OPENSSH_NONE_CIPHER} != "no" +CFLAGS+= -DNONE_CIPHER_ENABLED +.endif + DPADD+= ${LIBCRYPTO} ${LIBCRYPT} LDADD+= -lcrypto -lcrypt diff --git a/share/mk/bsd.own.mk b/share/mk/bsd.own.mk index 24a0f9222fbd7..174e0a77cf815 100644 --- a/share/mk/bsd.own.mk +++ b/share/mk/bsd.own.mk @@ -360,6 +360,7 @@ __DEFAULT_NO_OPTIONS = \ NMTREE \ NAND \ OFED \ + OPENSSH_NONE_CIPHER \ SHARED_TOOLCHAIN # diff --git a/tools/build/options/WITH_OPENSSH_NONE_CIPHER b/tools/build/options/WITH_OPENSSH_NONE_CIPHER new file mode 100644 index 0000000000000..8d44cc00c7c47 --- /dev/null +++ b/tools/build/options/WITH_OPENSSH_NONE_CIPHER @@ -0,0 +1,9 @@ +.\" $FreeBSD$ +Set to include the "None" cipher support in OpenSSH and its libraries. +Additional adjustments may need to be done to system configuration +files, such as +.Xr sshd_config 5 , +to enable this cipher. +Please see +.Pa /usr/src/crypto/openssh/README.hpn +for full details. -- cgit v1.3