diff options
author | 2016-11-30 02:57:40 +0000 | |
---|---|---|
committer | 2016-11-30 02:57:40 +0000 | |
commit | 28f8f3b0d618a90aaf145c529afaaedeab7c0aaa (patch) | |
tree | 3c404c6d36e2ca02b60cde6fc91fd24dd453935c /usr.bin/ssh/serverloop.c | |
parent | On startup, check to see if sshd is already daemonized and if so, (diff) | |
download | wireguard-openbsd-28f8f3b0d618a90aaf145c529afaaedeab7c0aaa.tar.xz wireguard-openbsd-28f8f3b0d618a90aaf145c529afaaedeab7c0aaa.zip |
When a forced-command appears in both a certificate and an
authorized keys/principals command= restriction, refuse to accept
the certificate unless they are identical.
The previous (documented) behaviour of having the certificate forced-
command override the other could be a bit confused and more error-prone.
Pointed out by Jann Horn of Project Zero; ok dtucker@
Diffstat (limited to 'usr.bin/ssh/serverloop.c')
0 files changed, 0 insertions, 0 deletions