- Package:
- src:openssh
- Source:
- openssh
- Submitter:
- Christoph Anton Mitterer
- Date:
- 2026-08-23 11:43:05 UTC
- Severity:
- wishlist
- Tags:
Hi Colin. I would find the attached patch to be a useful addition to the description of the two options regarding cascading credentials in the manpages. Could you please have a look at it and if you like it merge it with your gssapi.patch? Thanks, Chris.
Oh, and I've just seen that there is also an issue with the quotation
marks:
GSSAPITrustDns
Set to “yes to indicate that the DNS is trusted to securely canonicalize” the
name of the host being connected to. If “no, the hostname entered on the”
command line will be passed untouched to the GSSAPI library. The default is
“no”. This option only applies to protocol version 2 connections using GSS‐
API.
which is corrected by a 2nd patch attached to this mail.
Colin, you possibly further please clarify, which of the options added
by gssapi.patch, actually require GSSAPI key exchange?
Thanks,
Chris.
Christoph Anton Mitterer <calestyo@scientia.net> writes: Hi Christoph, The GSSAPI patch is actually maintained by Simon Wilkinson at: http://www.sxw.org.uk/computing/patches/openssh.html Many different distributions incorporate it. For issues that are generic to any packaging of ssh with that patch, you may want to report them directly to Simon, or at least copy him on these reports, and he's probably the best person to ask questions about how the patch works.
tags 765655 + upstream stop Hi Simon. Russ Allerby just reminded me that these things should go upstream respectively that you can likely answer them. Could you please have a look at: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=765655 Thanks, Chris.