Bug 1211673 - [RFE] Backport Match LocalAddress from OpenSSH 6.1 (and later)
Summary: [RFE] Backport Match LocalAddress from OpenSSH 6.1 (and later)
Keywords:
Status: CLOSED ERRATA
Alias: None
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: openssh
Version: 6.6
Hardware: All
OS: Linux
high
unspecified
Target Milestone: rc
: ---
Assignee: Jakub Jelen
QA Contact: Eva Mrakova
Tomas Capek
URL:
Whiteboard:
Depends On:
Blocks: 1172231
TreeView+ depends on / blocked
 
Reported: 2015-04-14 14:53 UTC by Pat Riehecky
Modified: 2019-10-10 09:45 UTC (History)
9 users (show)

Fixed In Version: openssh-5.3p1-113.el6
Doc Type: Enhancement
Doc Text:
The *LocalAddress* and *LocalPort* keywords are now supported for *Match* conditions in *sshd_config* Systems connected to several physical networks might require different access policies. With this update, you can enforce different policies for different local addresses or ports directly in *sshd_config*, without the need to run several services with different configuration files.
Clone Of:
Environment:
Last Closed: 2016-05-10 19:28:24 UTC
Target Upstream Version:


Attachments (Terms of Use)
Rebased upstream patch (18.49 KB, patch)
2015-11-11 13:22 UTC, Jakub Jelen
no flags Details | Diff


Links
System ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2016:0741 normal SHIPPED_LIVE Moderate: openssh security, bug fix, and enhancement update 2016-05-10 22:29:45 UTC

Description Pat Riehecky 2015-04-14 14:53:36 UTC
Description of problem:
OpenSSH 6.1 adds an additional Match condition set for LocalAddress and LocalPort

Can these conditions be backported to RHEL6?

Version-Release number of selected component (if applicable):openssh-5.3p1-104.el6_6.1


How reproducible:100%


Steps to Reproduce:
1.Look to use Match LocalAddress
2.
3.

Actual results:
feature not present

Expected results:
this is a backport request, so this feature - while useful - was not originally present within the 5.3 release.

Additional info:
http://www.openssh.com/txt/release-6.1

Comment 2 Jakub Jelen 2015-04-15 08:52:56 UTC
Thank you for taking time to fill this feature request. We appreciate the feedback and look to use reports such as this to guide our efforts at improving our products.
But this bug tracking system is not a mechanism for requesting support. Please, raise a ticket through your regular Red Hat Support to achieve correct attention and prioritization. Pushing new features requires appropriate business justification.

Comment 3 Jakub Jelen 2015-08-25 12:01:10 UTC
Please, connect with your regular support if it is still actual for you. Now moving to the next release.

Comment 4 Pat Riehecky 2015-08-25 13:25:25 UTC
I will reach out to those folks.

Comment 6 Jakub Jelen 2015-11-11 13:22:09 UTC
Created attachment 1092713 [details]
Rebased upstream patch

Rebased patch for our version from these upstream commits (with upstream test case):

    https://anongit.mindrot.org/openssh.git/commit/?id=fbcf827559b38f7992e1bd0bcdc4b4ccdf63bc74
    https://anongit.mindrot.org/openssh.git/commit/?id=301390316cf73fc50d769691ed7f95c21ea6646a

Upstream testsuite passes on my testing build. I think we can cover also this one in the next release. The patch is not large, makes the Match handling more transparent and doesn't look like breaking anything.

Comment 11 errata-xmlrpc 2016-05-10 19:28:24 UTC
Since the problem described in this bug report should be
resolved in a recent advisory, it has been closed with a
resolution of ERRATA.

For information on the advisory, and where to find the updated
files, follow the link below.

If the solution does not work for you, open a new bug report.

https://rhn.redhat.com/errata/RHSA-2016-0741.html


Note You need to log in before you can comment on or make changes to this bug.