Jump to content United States-English
HP.com Home Products and Services Support and Drivers Solutions How to Buy
» Contact HP
More options
HP.com home
HP-UX 11i Version 3 Release Notes: HP 9000 and HP Integrity Servers > Chapter 8 Security

HP-UX Secure Shell A.04.40.005

» 

Technical documentation

Complete book in PDF
» Feedback
Content starts here

 » Table of Contents

HP-UX Secure Shell A.04.40.005 (A.04.40) is based on the public domain OpenSSH 4.4p1. The client/server architecture supports the SSH-1 and SSH-2 protocols and provides secured remote login, file transfer, and remote command execution.

Summary of Change

What’s New for Customers Migrating from HP-UX 11i v1 September 2005?

The following features are new in HP-UX Secure Shell A.04.40.005 as compared to A.04.00.002 on HP-UX 11i v1:

  • Introduced in version A.04.10:

    • Audit logging of login and logout events, and system calls for HP-UX 11.0 and 11iv1

    • Enforcement of the max-bad-login-attempt limit for key-based authentication methods

    • Modified utmp(s) log record with a telnet-compatible ut_id format

    • New zlib version 1.2.3

  • Introduced in version A.04.20:

    • High Performance Enabled SSH/SCP patch

    • New configuration directives in the server:

      • The CountKeyAuthBadLogins directive

      • The EnforceSecureTTY directive

    • Inclusion of the Auth Selection patch

    • Increase in the default size of RSA and DSA keys

    • Delayed compression

    • Support for improved Arcfour cipher modes

    • Modified ControlPath client configuration directive

    • Support for X11 and agent forwarding over multiplexed connections

  • Introduced in version A.04.30:

    • Provides an sftponly solution in a chroot environment

    • HP-UX Secure Shell’s usage of TCP Wrappers support IPv6

  • Introduced in version A.04.40:

    • Implemented conditional configuration in the sshd_config file using the 'Match' directive. This allows you to selectively override some configuration options if specific criteria (based on user, group, hostname or address) are met.

    • Added a ForceCommand configuration directive to sshd_config(5). Similar to the command='...' option accepted in ~/.ssh/authorized_keys, this forces the execution of the specified command regardless of what the user requested. This is very useful in conjunction with the new “Match” directive.

    • Added a “PermitOpen” directive to sshd_config(5). This mirrors the permitopen='...' authorized_keys option, allowing fine-grained control over the port-forwardings that a user is allowed to establish.

    • Enabled optional logging of transactions to sftp-server.

    • Added an ExitOnForwardFailure option to cause ssh(1) to exit (with a non-zero exit code) when requested port forwardings are not established.

    • Extended sshd_configSubSystem” declarations to allow the specification of command-line arguments.

    • Replaced all integer overflow susceptible invocations of malloc(3) and realloc(3) with overflow-checking equivalents.

    • Modified ssh behavior so that ssh(1) now records port numbers for hosts stored in ~/.ssh/known_hosts when a non-standard port has been requested.

  • HP-UX Secure Shell A.04.40.005 also contains some defect fixes. For more information on these new features and defect fixes, see the HP-UX Secure Shell Release Notes at http://docs.hp.com.

What’s New for Customers Migrating from HP-UX 11i v2 June 2006?

The following features are new in HP-UX Secure Shell A.04.40.005 as compared to A.04.20.009 on HP-UX 11i v2:

  • Introduced in version A.04.30:

    • Provides an sftponly solution in a chroot environment

    • HP-UX Secure Shell’s usage of TCP Wrappers support IPv6

  • Introduced in version A.04.40:

    • Implemented conditional configuration in the sshd_config file using the “Match” directive. This allows you to selectively override some configuration options if specific criteria (based on user, group, hostname or address) are met.

    • Added a ForceCommand configuration directive to sshd_config(5). Similar to the command='...' option accepted in ~/.ssh/authorized_keys, this forces the execution of the specified command regardless of what the user requested. This is very useful in conjunction with the new “Match” directive.

    • Added a “PermitOpen” directive to sshd_config(5). This mirrors the permitopen='...' authorized_keys option, allowing fine-grained control over the port-forwardings that a user is allowed to establish.

    • Enabled optional logging of transactions to sftp-server.

    • Added an ExitOnForwardFailure option to cause ssh(1) to exit (with a non-zero exit code) when requested port forwardings are not established.

    • Extended sshd_configSubSystem” declarations to allow the specification of command-line arguments.

    • Replaced all integer overflow susceptible invocations of malloc(3) and realloc(3) with overflow-checking equivalents.

    • Modified ssh behavior so that ssh(1) now records port numbers for hosts stored in ~/.ssh/known_hosts when a non-standard port has been requested.

  • HP-UX Secure Shell A.04.40.005 also contains some defect fixes. For more information on these new features and defect fixes, see the HP-UX Secure Shell Release Notes at http://docs.hp.com.

Impact

There is no impact other than that previously listed.

Compatibility

There are no known compatibility issues.

Performance

There are no known performance issues.

Documentation

Following documents are available on http://docs.hp.com in the “Internet and Security Solutions” section:

  • HP-UX Secure Shell Getting Started Guide

  • HP-UX Secure Shell A.04.40.005 Release Notes

Manpages:

  • sshd_config(5)

  • ssh_config(5)

  • ssh(1)

Obsolescence

Not applicable.

Printable version
Privacy statement Using this site means you accept its terms Feedback to webmaster
© 2006-2007 Hewlett-Packard Development Company, L.P.