-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 02 Apr 2022 15:51:17 +0200 Source: dropbear Architecture: source Version: 2022.82-1 Distribution: unstable Urgency: medium Maintainer: Guilhem Moulin <guilhem@debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 903403 955384 1003951 Changes: dropbear (2022.82-1) unstable; urgency=medium . [ Matt Johnston ] * New upstream release 2022.82. Highlights include: - dropbearconvert(1): Support converting from OpenSSH (>=7.8) private key format (closes: #955384), and convert to that format rather than PEM - Reworked -v verbose printing, specifying multiple times will increase verbosity. - Added server support for U2F/FIDO keys (ecdsa-sk and ed25519-sk) in authorized_keys(5). - Use a separate $PATH when logging in as root (closes: #903403). - Disable dh-group1 key exchange by default. It has been disabled server side by default since 2018.76-1. - Removed Twofish cipher. . [ Lee Garrett ] * Add quotes to indicate they're required. (Closes: #1003951) . [ Guilhem Moulin ] * Add missing build dependency on dh addon. * initramfs script configuration: Clarify that assignment follow shell semantics. * d/gbp.conf: Add upstream VCS tag as additional parent to upstream/$VERSION. * Run wrap-and-sort(1). * Fix autopkgtest for non-sid suites. * Create localoptions.h in d/rules not from d/patches. * d/localoptions.h: Hardcode PATH environment variable when a regular user resp. the superuser logs in to the login.defs(5) default values, namely "/usr/local/bin:/usr/bin:/bin:/usr/local/games:/usr/games" resp. "/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin". * d/tests: Run the upstream test suite as a DEP-8 test. We skip it at build time since it needs access to ~/.ssh which is forbidden in the build environment. * Update d/copyright. * d/rules: Remove useless override_dh_installinit target and rename d/dropbear.dropbear.init to d/dropbear.init. * d/dropbear.init: Put PID file in /run not /var/run. * d/dropbear.init: Minor refactoring. * d/dropbear.postinst: Replace deprecated which(1) calls with `command -v`. * d/dropbear.postinst: Also convert OpenSSH keys in new format since dropbearconvert(1) can now convert those. * Remove d/README.Debian.diet from 'dropbear-bin' documentation. * Install README.Debian in 'dropbear' package not 'dropbear-bin'. * Minor d/dropbear.README.Debian improvement. * d/control: Improve package description. * Add systemd.service(5) file. * /etc/default/dropbear: Breaking changes to accommodate the systemd.service(5) logic: + Drop support for NO_START=1 (one needs to manually disable the service or remove the package instead); and + Drop support for DROPBEAR_*KEY and DROPBEAR_BANNER (one needs to use DROPBEAR_EXTRA_ARGS with the adequate dropbear(8) instead instead). * Handle /etc/default/dropbear as a conffile instead of letting postinst create it. Checksums-Sha1: f8a44000c4d67110b6bc09a8d02878efc0e65a44 2582 dropbear_2022.82-1.dsc 9719ea91b5ce8d93ee9a50b5c3a5bcd628736181 2309514 dropbear_2022.82.orig.tar.bz2 f1602a00a189923d458146482d7776eb8007266e 833 dropbear_2022.82.orig.tar.bz2.asc c2b7abb93b938e981d73624baf9ea60efd8f910f 32900 dropbear_2022.82-1.debian.tar.xz 0bda9463835ff4e6ea7fc1df2fd65a4b6895f783 7053 dropbear_2022.82-1_amd64.buildinfo Checksums-Sha256: b7fc60d2d7cf67cc1d9861f97c5e2112a26320e546ce31e708955374ebcd70d8 2582 dropbear_2022.82-1.dsc 3a038d2bbc02bf28bbdd20c012091f741a3ec5cbe460691811d714876aad75d1 2309514 dropbear_2022.82.orig.tar.bz2 01347278eccfd744d9ea9c427820b150179a9f5cdd44de5fb72787e40b410eff 833 dropbear_2022.82.orig.tar.bz2.asc f499622cfc164ed7a67df55cfb79ded846e10fbae4c49fae5e4f79c35bf44869 32900 dropbear_2022.82-1.debian.tar.xz 93c58b4bebd19dc9df119aa7016f2e0941613fa3e1a580c456d78d7c0fc90f69 7053 dropbear_2022.82-1_amd64.buildinfo Files: a8f822b98ebe26d7effdd8e6650afff9 2582 net optional dropbear_2022.82-1.dsc 7a4a5f2c6d23ff2e6627c97d7c1aeceb 2309514 net optional dropbear_2022.82.orig.tar.bz2 fe3bf559e79bf5c67160c0e4afe70082 833 net optional dropbear_2022.82.orig.tar.bz2.asc aa0879a8e46152a1b2cbfb30bd4da33a 32900 net optional dropbear_2022.82-1.debian.tar.xz 53ac987c79a026756c1b0f02a0aef7bd 7053 net optional dropbear_2022.82-1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmJIVSQACgkQ05pJnDwh pVLVRw/+JtHVOIqqjB1CPRwy9oCHJSZKxWtEg9vCyy/zAcTHo7hm9BopwzKyLeIf 5/Vj4k9OcbqlHO9LEPmEY8rHnaPBTdeDwly5kL8NKZkORVJvf9aDugIFKhG6LKuJ IuHzHzM2qyuBawYrljtn/Lti9aycmSRhlbs4aIMwW8H60iiD4r++E6wAQzyV191k QdhivZhZd8wML/OFym30u3paAFmasoMWIB9smCzUe/j135YkwEoyhRKpvlBMrZzM +qHxrVlwSKVFBKW7bv6bnwDMmBTi0WaFrFZt+y3KcWRmCTiwlNmMY7t6Z3Y60I5Z zXNBFAq2/Hwgvka+1rL3YhhepI2BgLUjYNUl4GwBrh7b2n+GPVhCHtJvzmogRsS3 6Fd6LJIWlX9aACF8BjcqcO41TmExnQx6Qr9OXeKQtguciL5856zhKqQ5Rl5i5nNn 7XivgdnEKA2b0dvTA1ssoRGE/0cwRDsUmKUBfV9BR4WmFxnNdTg621ghWA8RUUlk iRXpixVlvuEnk6RGjQtEvR7yseb/3APiJm1cFWiKsCnBhN3lS5e1wlF+YqTfmi30 Ez7ClMcRQSkvQbzNBtNdSLheKrLeeIaB0+TcsQlfK/f/h/zhqvhP3X6jLgIaEtpj cfohgSIvbT2rwind9E3EHPK/qPt6o9lhbD2GKj6WIEwvYCVgt/s= =ifaR -----END PGP SIGNATURE-----