Your message dated Thu, 23 Aug 2012 03:57:04 +0200
with message-id <[email protected]>
and subject line libpam-ssh embeds code from OpenSSH
has caused the Debian Bug report #598522,
regarding libpam-ssh embeds code from OpenSSH
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
598522: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=598522
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: libpam-ssh
Version: 1.92-14
Severity: normal

libpam-ssh contains embeds code from the OpenSSH project.

At the very least, authfile.c is shared between projects; as a result,
security fixes or functionality enhancements that make it into OpenSSH
do not propagate automatically into libpam-ssh.

libpam-ssh's TODO file states:
----------------------------
Instead of calling OpenSSH's load_private_key(), execute ssh-add in the
authentication phase and something like

       ssh-agent ssh-add

in the session phase and parse the output.  (SSH's ssh-add provides
decent return values, whereas OpenSSH's does not.)
----------------------------

Resolving this TODO item should remove the need for the embedded code
copy.

Thanks,

        --dkg

-- System Information:
Debian Release: squeeze/sid
  APT prefers testing
  APT policy: (500, 'testing'), (200, 'unstable'), (1, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.36-rc5-686 (SMP w/1 CPU core)
Locale: LANG=en_US.utf8, LC_CTYPE=en_US.utf8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash



--- End Message ---
--- Begin Message ---
Hello:

This is definitively an OpenSSH design issue, so I close it.

Jerome

--- End Message ---

Reply via email to