Bug 187384 - Add umask configuration support to sftp-server
Summary: Add umask configuration support to sftp-server
Keywords:
Status: CLOSED UPSTREAM
Alias: None
Product: Red Hat Enterprise Linux 4
Classification: Red Hat
Component: openssh
Version: 4.0
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
: ---
Assignee: Tomas Mraz
QA Contact: Brian Brock
URL: http://sftplogging.sourceforge.net/
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2006-03-30 17:23 UTC by Jonathan Abbey
Modified: 2007-11-30 22:07 UTC (History)
0 users

Fixed In Version:
Doc Type: Enhancement
Doc Text:
Clone Of:
Environment:
Last Closed: 2006-04-04 15:15:47 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Jonathan Abbey 2006-03-30 17:23:00 UTC
Description of problem:

Red Hat's OpenSSH RPMs do not include the popular sftplogging patch from
http://sftplogging.sourceforge.net/, which makes it possible to use sftp-server
for site management in a reasonable fashion.

Version-Release number of selected component (if applicable):

All versions

I've made my own RPM set based on the RHEL4U3 OpenSSH RPM 3.9p1-8.RHEL4.12 src
rpm, incorporating this patch, but this functionality is desireable enough that
it would be nice for Red Hat to support it.

A number of vendors, including Gentoo and HP-UX, already incorporate this patch.

I can provide my modified .src.rpm, if desired.

Comment 1 Jonathan Abbey 2006-03-30 18:29:58 UTC
I've just done some research on this patch in the OpenSSH archives, and the
OpenSSH team has resisted this patch due to implementation issues (the use of
environment variables to pass data between sshd and sftp-server, etc.).

I'm looking at crafting a new patch that has better security characteristics in
the interfacing between sshd and sftp-server.  I'll look at submitting it
upstream to the OpenSSH folks.  If it goes well, I'll spin an RPM for RHEL4 and
see about providing the src here.

Comment 2 Tomas Mraz 2006-04-04 15:15:47 UTC
We try to keep as close to upstream as possible so we don't add conflicting
command-line options or other incompatibilities with future upstream releases.
Please reopen this bug after the patch was accepted upstream.



Note You need to log in before you can comment on or make changes to this bug.