From wyllys@borg.sfbay.sun.com Fri Jun 12 06:18:35 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CDIZa7011517
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 06:18:35 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5CDIGSI002560;
	Fri, 12 Jun 2009 06:18:34 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL400F17NMYC200@brm-avmta-1.central.sun.com>; Fri,
 12 Jun 2009 07:18:34 -0600 (MDT)
Received: from borg.sfbay ([10.5.240.20]) by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL4008CKNMXSI60@brm-avmta-1.central.sun.com>; Fri,
 12 Jun 2009 07:18:33 -0600 (MDT)
Received: from borg.sfbay (localhost [127.0.0.1])
	by borg.sfbay (8.14.3+Sun/8.14.3) with ESMTP id n5CDIQQn000964; Fri,
 12 Jun 2009 06:18:26 -0700 (PDT)
Received: (from wyllys@localhost)	by borg.sfbay (8.14.3+Sun/8.14.3/Submit)
 id n5CDIN01000960; Fri, 12 Jun 2009 06:18:23 -0700 (PDT)
Date: Fri, 12 Jun 2009 06:18:23 -0700 (PDT)
From: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>
Subject: ssh config update [PSARC/2009/353 FastTrack timeout 06/19/2009]
To: PSARC-ext@sun.com
Cc: huie-ying.lee@sun.com
Message-id: <200906121318.n5CDIN01000960@borg.sfbay>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 1933


Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 ssh config update
    1.2. Name of Document Author/Supplier:
	 Author:  HuieYing Lee
    1.3  Date of This Document:
	12 June, 2009
4. Technical Description
1. Introduction

   1.1. Project/Component Working Name:

        SunSSH /etc/ssh/sshd_config update
        
   1.2. Name of Document Author/Supplier:

        Author: HuieYing Lee
        
   1.3. Date of This Document:

        June 11 2009
 
4. Technical Description:

   Remove "AllowTcpForwarding=no" from the /etc/ssh/sshd_config configuration
   file.

   The /etc/ssh/sshd_config file, which is the configuration file for SunSSH
   daemon, explicitly includes "AllowTcpForwarding=no", which disables
   port forwarding by default.  However, the sshd_config(4) man page states
   that "The default is yes."   

   To fix the inconsistency, we would like to propose removing the 
   AllowTcpForwarding line completely from the /etc/ssh/sshd_config file,
   because 
 
   - Removing the "AllowTcpForwarding=no" line is equivalent to having a "yes"
     as default.

   - "Disabling TCP forwarding does not improve security unless users
     are also denied shell access, as they can alway install their own
     forwarders.", as stated in the sshd_config(4) man page.

   - OpenSSH uses "yes" as the default setting.


   For more information, see the attached diffs to the default sshd_config
   file.

   Doc Impact:

   The relevant portion in the "Using Solaris Secure Shell" chapter of 
   the "System Administration Guide: Security Services" needs to be updated.
   Will work with the technical writer for this.



6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From wyllys.ingersoll@sun.com Fri Jun 12 06:23:48 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CDNmX3011567
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 06:23:48 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5CDNl1n016245
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 12 Jun 2009 06:23:48 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL40010XNVNQC00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 12 Jun 2009 06:23:47 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL400GJ9NVM9280@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 12 Jun 2009 06:23:46 -0700 (PDT)
Received: from [10.7.251.182] (punchin-wyllys.SFBay.Sun.COM [10.7.251.182])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5CDNjYk152216
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO)
	for <PSARC-ext@sun.com>; Fri, 12 Jun 2009 06:23:46 -0700 (PDT)
Date: Fri, 12 Jun 2009 09:23:45 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
Subject: PSARC 2009/353 ssh config update
To: PSARC-ext@sun.com
Message-id: <4A3256E1.1090308@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
User-Agent: Thunderbird 2.0.0.21 (X11/20090323)
Status: RO
Content-Length: 1371


I filed the "ssh config update" fast track for Huie-Ying Lee. 
The timer expires on 6/19/2009

The release binding is micro (patch).

Below is the patch for the default sshd_config file (a copy is also in the
case directory).

-Wyllys Ingersoll


*** sshd_config.orig    Wed Jun 10 16:16:21 2009
--- sshd_config Thu Jun 11 14:56:59 2009
***************
*** 1,8 ****
  #
! # Copyright 2008 Sun Microsystems, Inc.  All rights reserved.
  # Use is subject to license terms.
  #
! # Configuration file for sshd(1m)
  
  # Protocol versions supported
  #
--- 1,8 ----
  #
! # Copyright 2009 Sun Microsystems, Inc.  All rights reserved.
  # Use is subject to license terms.
  #
! # Configuration file for sshd(1m) (see also sshd_config(4))
  
  # Protocol versions supported
  #
***************
*** 39,48 ****
  # IPv4 & IPv6
  ListenAddress ::
  
! # Port forwarding
! AllowTcpForwarding no
! 
! # If port forwarding is enabled, specify if the server can bind to INADDR_ANY.
 
  # This allows the local port forwarding to work when connections are received
  # from any remote host.
  GatewayPorts no
--- 39,46 ----
  # IPv4 & IPv6
  ListenAddress ::
  
! # If port forwarding is enabled (default), specify if the server can bind to
! # INADDR_ANY. 
  # This allows the local port forwarding to work when connections are received
  # from any remote host.
  GatewayPorts no


From carlsonj@phorcys.east.sun.com Fri Jun 12 06:37:12 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CDbCTe011802
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 06:37:12 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5CDbB0u010490
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Fri, 12 Jun 2009 06:37:11 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL40030VOHYDZ00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Fri, 12 Jun 2009 06:37:10 -0700 (PDT)
Received: from dm-east-02.east.sun.com ([129.148.13.5])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL400GD8OHW90A0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Fri,
 12 Jun 2009 06:37:08 -0700 (PDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-02.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n5CDb7JT005777; Fri, 12 Jun 2009 09:37:07 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5CDZqK8026485; Fri,
 12 Jun 2009 09:35:52 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n5CDZpDr026482; Fri,
 12 Jun 2009 09:35:51 -0400 (EDT)
Date: Fri, 12 Jun 2009 09:35:51 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <4A3256E1.1090308@sun.com>
To: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>
Cc: PSARC-ext@sun.com
Message-id: <18994.22967.951514.139755@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
Status: RO
Content-Length: 887

Wyllys Ingersoll writes:
> I filed the "ssh config update" fast track for Huie-Ying Lee. 
> The timer expires on 6/19/2009

Previously, the configuration file had a list of all(?) the
configuration options along with comments that described each one.
Why is this one being deleted?  Is it no longer accepted as an option?
(That is, is it now impossible to disable TCP port forwarding?)

Why not just change the way it installs, so that it installs as
"AllowTcpForwarding yes" by default, and leaves it unchanged on
upgrade or patch?

> The release binding is micro (patch).

Changing defaults in a patch seems a bit surprising.  Are you sure you
want to do that?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From gdamore@sun.com Fri Jun 12 07:15:04 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CEF3pq013853
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 07:15:04 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5CEEiXs011931
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 12 Jun 2009 07:15:03 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL40075BQ93R800@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 12 Jun 2009 07:15:03 -0700 (PDT)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL4007LGQ937C00@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 12 Jun 2009 07:15:03 -0700 (PDT)
Received: from fe-sfbay-09.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5CEF31U008158	for
 <PSARC-ext@sun.com>; Fri, 12 Jun 2009 07:15:03 -0700 (PDT)
Received: from conversion-daemon.fe-sfbay-09.sun.com by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL400000Q10GS00@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 12 Jun 2009 07:15:03 -0700 (PDT)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KL400L8BQ8XMK20@fe-sfbay-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 12 Jun 2009 07:14:57 -0700 (PDT)
Date: Fri, 12 Jun 2009 07:14:56 -0700
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <18994.22967.951514.139755@gargle.gargle.HOWL>
Sender: Garrett.Damore@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <4A3262E0.7050109@sun.com>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 947

James Carlson wrote:
> Wyllys Ingersoll writes:
>   
>> I filed the "ssh config update" fast track for Huie-Ying Lee. 
>> The timer expires on 6/19/2009
>>     
>
> Previously, the configuration file had a list of all(?) the
> configuration options along with comments that described each one.
> Why is this one being deleted?  Is it no longer accepted as an option?
> (That is, is it now impossible to disable TCP port forwarding?)
>
> Why not just change the way it installs, so that it installs as
> "AllowTcpForwarding yes" by default, and leaves it unchanged on
> upgrade or patch?
>
>   
>> The release binding is micro (patch).
>>     
>
> Changing defaults in a patch seems a bit surprising.  Are you sure you
> want to do that?
>
>   
I agree with Jim's comments here.  I was just getting ready to say much 
the same thing.

I think for minor binding just commenting out (and fixing the value) the 
option would be better.

    - Garrett

From huie-ying.lee@sun.com Fri Jun 12 11:49:58 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CInvWh024608
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 11:49:58 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5CInlmY012279;
	Sat, 13 Jun 2009 02:49:53 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL5006092Z40H00@nwk-avmta-2.sfbay.sun.com>; Fri,
 12 Jun 2009 11:49:52 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL5001TW2Z3N340@nwk-avmta-2.sfbay.sun.com>; Fri,
 12 Jun 2009 11:49:51 -0700 (PDT)
Received: from [10.7.250.50]
 (punchin-client-10-7-250-50.SFBay.Sun.COM [10.7.250.50])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5CInpng213066; Fri, 12 Jun 2009 11:49:51 -0700 (PDT)
Date: Fri, 12 Jun 2009 11:49:51 -0700
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <18994.22967.951514.139755@gargle.gargle.HOWL>
To: James Carlson <james.d.carlson@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <4A32A34F.20400@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.17 (X11/20081023)
Status: RO
Content-Length: 1334

James Carlson wrote:
> Wyllys Ingersoll writes:
>   
>> I filed the "ssh config update" fast track for Huie-Ying Lee. 
>> The timer expires on 6/19/2009
>>     
>
> Previously, the configuration file had a list of all(?) the
> configuration options along with comments that described each one.
> Why is this one being deleted?  Is it no longer accepted as an option?
> (That is, is it now impossible to disable TCP port forwarding?)
>
>   
The current SunSSH sshd_config file does not list all the configuration 
options.  This is the reason that I added a "(see also sshd_config(4)" 
note in the new sshd_config file (see line 5).

The "AllowTcpForwarding" option is still accepted as an option.  An  
administrator can disable it by adding "AllowTcpForwarding=no" to the 
configuration file.

I can change the relevant lines as below, if that looks better.

#Port forwarding
#AllowTcpForwarding yes

> Why not just change the way it installs, so that it installs as
> "AllowTcpForwarding yes" by default, and leaves it unchanged on
> upgrade or patch?
>
>   
Right,  that's our goal also.   What would be the right release binding ?
>> The release binding is micro (patch).
>>     
>
> Changing defaults in a patch seems a bit surprising.  Are you sure you
> want to do that?
>
>   
No, we don't want to do that.

Thanks,
Huie-Ying

From wyllys.ingersoll@sun.com Fri Jun 12 11:53:06 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CIr5nh024725
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 11:53:06 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5CIqvWY024705;
	Fri, 12 Jun 2009 19:53:03 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL50060D34D7E00@nwk-avmta-2.sfbay.sun.com>; Fri,
 12 Jun 2009 11:53:01 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.63])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL5001G434DMV50@nwk-avmta-2.sfbay.sun.com>; Fri,
 12 Jun 2009 11:53:01 -0700 (PDT)
Received: from Wyllys-MacBook-Pro.local
 (punchin-wyllys.SFBay.Sun.COM [10.7.251.182])	by jurassic-x4600.sfbay.sun.com
 (8.14.3+Sun/8.14.3) with ESMTP id n5CIquvT213662
	(version=TLSv1/SSLv3 cipher=DHE-RSA-AES256-SHA bits=256 verify=NO); Fri,
 12 Jun 2009 11:53:00 -0700 (PDT)
Date: Fri, 12 Jun 2009 14:52:53 -0400
From: Wyllys Ingersoll <wyllys.ingersoll@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <4A32A34F.20400@sun.com>
To: Huie-Ying Lee <huie-ying.lee@sun.com>
Cc: James Carlson <james.d.carlson@sun.com>, PSARC-ext@sun.com
Message-id: <4A32A405.2040400@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A32A34F.20400@sun.com>
User-Agent: Thunderbird 2.0.0.21 (Macintosh/20090302)
Status: RO
Content-Length: 1471

Huie-Ying Lee wrote:
> James Carlson wrote:
>> Wyllys Ingersoll writes:
>>  
>>> I filed the "ssh config update" fast track for Huie-Ying Lee. The 
>>> timer expires on 6/19/2009
>>>     
>>
>> Previously, the configuration file had a list of all(?) the
>> configuration options along with comments that described each one.
>> Why is this one being deleted?  Is it no longer accepted as an option?
>> (That is, is it now impossible to disable TCP port forwarding?)
>>
>>   
> The current SunSSH sshd_config file does not list all the 
> configuration options.  This is the reason that I added a "(see also 
> sshd_config(4)" note in the new sshd_config file (see line 5).
>
> The "AllowTcpForwarding" option is still accepted as an option.  An  
> administrator can disable it by adding "AllowTcpForwarding=no" to the 
> configuration file.
>
> I can change the relevant lines as below, if that looks better.
>
> #Port forwarding
> #AllowTcpForwarding yes
>
>> Why not just change the way it installs, so that it installs as
>> "AllowTcpForwarding yes" by default, and leaves it unchanged on
>> upgrade or patch?
>>
>>   
> Right,  that's our goal also.   What would be the right release binding ?
>>> The release binding is micro (patch).
>>>     
>>
>> Changing defaults in a patch seems a bit surprising.  Are you sure you
>> want to do that?
>>
>>   
> No, we don't want to do that.

The bit release binding statement was my fault, I added it out of habit.

-Wyllys


From huie-ying.lee@sun.com Fri Jun 12 11:53:29 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CIrSr1024761
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 11:53:29 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5CIrN59024983;
	Fri, 12 Jun 2009 19:53:24 +0100 (BST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL500K0534ZFV00@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 12 Jun 2009 11:53:23 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL5007W134YSGA0@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 12 Jun 2009 11:53:22 -0700 (PDT)
Received: from [10.7.250.50]
 (punchin-client-10-7-250-50.SFBay.Sun.COM [10.7.250.50])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5CIrMg5213691; Fri, 12 Jun 2009 11:53:22 -0700 (PDT)
Date: Fri, 12 Jun 2009 11:53:22 -0700
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <4A3262E0.7050109@sun.com>
To: "Garrett D'Amore" <gdamore@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>,
        Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <4A32A422.7010809@sun.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A3262E0.7050109@sun.com>
User-Agent: Thunderbird 2.0.0.17 (X11/20081023)
Status: RO
Content-Length: 1068

Garrett D'Amore wrote:
> James Carlson wrote:
>> Wyllys Ingersoll writes:
>>  
>>> I filed the "ssh config update" fast track for Huie-Ying Lee. The 
>>> timer expires on 6/19/2009
>>>     
>>
>> Previously, the configuration file had a list of all(?) the
>> configuration options along with comments that described each one.
>> Why is this one being deleted?  Is it no longer accepted as an option?
>> (That is, is it now impossible to disable TCP port forwarding?)
>>
>> Why not just change the way it installs, so that it installs as
>> "AllowTcpForwarding yes" by default, and leaves it unchanged on
>> upgrade or patch?
>>
>>  
>>> The release binding is micro (patch).
>>>     
>>
>> Changing defaults in a patch seems a bit surprising.  Are you sure you
>> want to do that?
>>
>>   
> I agree with Jim's comments here.  I was just getting ready to say 
> much the same thing.
>
> I think for minor binding just commenting out (and fixing the value) 
> the option would be better.
>
>    - Garrett
Right.   Your suggestions are well received.

Thanks,
Huie-Ying

From carlsonj@phorcys.east.sun.com Fri Jun 12 12:43:37 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5CJhaW7025340
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 12 Jun 2009 12:43:36 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5CJhXLN025305
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Fri, 12 Jun 2009 20:43:35 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL5008015GMP500@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Fri, 12 Jun 2009 13:43:34 -0600 (MDT)
Received: from dm-east-02.east.sun.com ([129.148.13.5])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL5002F65GL2A50@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Fri,
 12 Jun 2009 13:43:33 -0600 (MDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-02.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n5CJhWpU003580; Fri, 12 Jun 2009 15:43:32 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5CJgI0R027954; Fri,
 12 Jun 2009 15:42:18 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n5CJgHvo027951; Fri,
 12 Jun 2009 15:42:17 -0400 (EDT)
Date: Fri, 12 Jun 2009 15:42:17 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <4A32A34F.20400@sun.com>
To: Huie-Ying Lee <Huie-Ying.Lee@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <18994.44953.972880.587240@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A32A34F.20400@sun.com>
Status: RO
Content-Length: 1755

Huie-Ying Lee writes:
> I can change the relevant lines as below, if that looks better.
> 
> #Port forwarding
> #AllowTcpForwarding yes

I think it's a little less surprising that way, so I prefer it, but
now that I understand the project a good bit better, it's not a
significant issue.

> > Why not just change the way it installs, so that it installs as
> > "AllowTcpForwarding yes" by default, and leaves it unchanged on
> > upgrade or patch?
> >
> >   
> Right,  that's our goal also.   What would be the right release binding ?

Patch/micro is the right release binding.  What's missing is the
description of how the delivery will work.  Something like this:

	Since we're changing a default value, and we want to avoid
	suprise on upgrade, and since we can't tell whether a user has
	intentionally configured the "no" value or whether it was just
	left at the default, we will do the following for the patch
	delivery:

	- If the system is initially installed from freshbitted
          packages containing this change, then the system will have
          AllowTcpForwarding set to "yes" by default.  The release
          notes for the release containing this change will note the
          difference.

	- When upgrading or patching an existing system (installed
          before this fix was introduced), the AllowTcpForwarding
          value will not be changed.  A release note (for the update
          release) and README for the patch will be included to tell
          users what to do if they want the new value.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Jan.Pechanec@Sun.COM Mon Jun 15 01:37:27 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5F8bQsw017259
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 15 Jun 2009 01:37:27 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5F8bPwE018365
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 15 Jun 2009 09:37:25 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL900801UMDUB00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 15 Jun 2009 02:37:25 -0600 (MDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL9005OYUM5IG20@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 15 Jun 2009 02:37:17 -0600 (MDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5F8bGtN019771	for
 <PSARC-ext@sun.com>; Mon, 15 Jun 2009 08:37:17 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL900900S5V1B00@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 15 Jun 2009 09:37:16 +0100 (BST)
Received: from rejewski ([unknown] [10.18.138.121])
 by fe-emea-09.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KL900D79ULEXX00@fe-emea-09.sun.com>;
 Mon, 15 Jun 2009 09:36:50 +0100 (BST)
Date: Mon, 15 Jun 2009 10:36:00 +0200 (CEST)
From: Jan Pechanec <Jan.Pechanec@Sun.COM>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <18994.44953.972880.587240@gargle.gargle.HOWL>
Sender: Jan.Pechanec@Sun.COM
X-X-Sender: jp161948@rejewski
To: James Carlson <James.D.Carlson@Sun.COM>
Cc: Huie-Ying Lee <Huie-Ying.Lee@Sun.COM>,
        Wyllys Ingersoll <Wyllys.Ingersoll@Sun.COM>, PSARC-ext@Sun.COM
Message-id: <Pine.SOC.4.64.0906151030240.13873@rejewski>
MIME-version: 1.0
Content-type: TEXT/PLAIN; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A32A34F.20400@sun.com>
 <18994.44953.972880.587240@gargle.gargle.HOWL>
Status: RO
Content-Length: 1226

On Fri, 12 Jun 2009, James Carlson wrote:

>Huie-Ying Lee writes:
>> I can change the relevant lines as below, if that looks better.
>> 
>> #Port forwarding
>> #AllowTcpForwarding yes
>
>I think it's a little less surprising that way, so I prefer it, but
>now that I understand the project a good bit better, it's not a
>significant issue.
>
>> > Why not just change the way it installs, so that it installs as
>> > "AllowTcpForwarding yes" by default, and leaves it unchanged on
>> > upgrade or patch?
>> >
>> >   
>> Right,  that's our goal also.   What would be the right release binding ?
>
>Patch/micro is the right release binding.  What's missing is the
>description of how the delivery will work.  Something like this:

	when we discussed this removal in the ssh iteam we thought that 
we should not do that in patch. It might be suprising to our customers 
and also patching the sshd_config is always a little bit tricky and RPE 
prefer not to do that.

	I can't find a working search for the mail aliases but I put 
this note to the CR (6830483).

# this was discussed and agreed on on the ssh-iteam@ alias, in Octorber 
# 23, 2008, with the subject "AllowTcpForwarding off by default - why?"

	J.

-- 
Jan Pechanec

From Jan.Pechanec@sun.com Mon Jun 15 01:49:02 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5F8n2km017428
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 15 Jun 2009 01:49:02 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5F8n19t000287
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 15 Jun 2009 01:49:02 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KL900K09V5QH100@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 15 Jun 2009 01:49:02 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com ([192.18.6.24])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KL9008RPV5OUE60@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 15 Jun 2009 01:49:01 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5F8n0WJ022337	for
 <PSARC-ext@sun.com>; Mon, 15 Jun 2009 08:49:00 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KL900N00UB03K00@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 15 Jun 2009 09:49:00 +0100 (BST)
Received: from rejewski ([unknown] [10.18.138.121])
 by fe-emea-09.sun.com (Sun Java(tm) System Messaging Server 7u2-7.02 64bit
 (built Apr 16 2009)) with ESMTPSA id <0KL900D8YV5LXX70@fe-emea-09.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 15 Jun 2009 09:48:58 +0100 (BST)
Date: Mon, 15 Jun 2009 10:48:08 +0200 (CEST)
From: Jan Pechanec <Jan.Pechanec@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <18994.22967.951514.139755@gargle.gargle.HOWL>
Sender: Jan.Pechanec@sun.com
X-X-Sender: jp161948@rejewski
To: James Carlson <James.D.Carlson@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <Pine.SOC.4.64.0906151036140.13873@rejewski>
MIME-version: 1.0
Content-type: TEXT/PLAIN; CHARSET=US-ASCII
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL>
Status: RO
Content-Length: 2250

On Fri, 12 Jun 2009, James Carlson wrote:

>Wyllys Ingersoll writes:
>> I filed the "ssh config update" fast track for Huie-Ying Lee. 
>> The timer expires on 6/19/2009
>
>Previously, the configuration file had a list of all(?) the
>configuration options along with comments that described each one.
>Why is this one being deleted?  Is it no longer accepted as an option?
>(That is, is it now impossible to disable TCP port forwarding?)

	I think that shipping uncommented defaults in a any 
configuration file is a big mistake. Explicitly set default is no longer 
a default but an explicit configuration. We hit that problems recently, 
as you probably remember, when we found out that S9 machines had 
explicitly set Ciphers option in sshd_config. Changing the default to 
offer new cipher modes then has no effect on such boxes and I don't 
think that changing the configuration file is a correct thing either - 
we don't know if setting the Ciphers option to that old, previously 
default value, is not what the customer wants now.

	another problem is that there is just a subset of existing 
options in the sshd_config. I filed this CR some time ago:

	6805294 sshd_config should not be shipped with explicit default 
		values

	and I really think we should get rid of all those options there 
as soon as possible. I do not think we should do that for S10 though.

	we might put the default values into comments, that's what 
OpenSSH does. However, this means again that any change must strictly 
modify the sshd_config as well. No problem for OpenSSH, but a bigger 
problem for us. I'd definitely prefer to point the admin to the 
sshd_config(4) manual page, I don't see a reason why we should document 
the default values at 2 different places. The part of that project would 
have to be to carefuly revisit the sshd_config manual page and make sure 
that it contains all the needed nformation about the default values.

	cheers, J.


>Why not just change the way it installs, so that it installs as
>"AllowTcpForwarding yes" by default, and leaves it unchanged on
>upgrade or patch?
>
>> The release binding is micro (patch).
>
>Changing defaults in a patch seems a bit surprising.  Are you sure you
>want to do that?
>
>

-- 
Jan Pechanec

From Darren.Moffat@sun.com Tue Jun 16 05:03:27 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GC3QF5017726
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 05:03:27 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n5GC3MIe012400
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 16 Jun 2009 20:03:25 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLB0070DYTN1600@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 16 Jun 2009 05:03:23 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLB003D4YTNHE10@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 16 Jun 2009 05:03:23 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n5GC3Mwj003928	for
 <PSARC-ext@sun.com>; Tue, 16 Jun 2009 12:03:22 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 id <0KLB00F00XWW2J00@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 16 Jun 2009 13:03:22 +0100 (BST)
Received: from [129.156.173.199] ([unknown] [129.156.173.199])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7u2-7.02 64bit (built Apr 16 2009))
 with ESMTPSA id <0KLB00CVSYTLYQ50@fe-emea-09.sun.com>; Tue,
 16 Jun 2009 13:03:21 +0100 (BST)
Date: Tue, 16 Jun 2009 13:03:21 +0100
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: ssh config update [PSARC/2009/353 FastTrack timeout 06/19/2009]
In-reply-to: <200906121318.n5CDIN01000960@borg.sfbay>
Sender: Darren.Moffat@sun.com
To: Wyllys Ingersoll <wyllys@borg.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Huie-Ying.Lee@sun.com
Message-id: <4A378A09.8000706@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; CHARSET=US-ASCII; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200906121318.n5CDIN01000960@borg.sfbay>
User-Agent: Thunderbird 2.0.0.18 (X11/20090127)
Status: RO
Content-Length: 164

+1 for the case as specified, particularly since I was the person who 
choose to have this set disabled when SunSSH first appears in Solaris 9.

--
Darren J Moffat

From huie-ying.lee@sun.com Tue Jun 16 11:36:49 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GIanOQ028840
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 11:36:49 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n5GIalU3015308;
	Tue, 16 Jun 2009 12:36:48 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC00901H1BE600@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 16 Jun 2009 11:36:47 -0700 (PDT)
Received: from jurassic-x4600.sfbay.sun.com ([129.146.17.59])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC002UAH1BZJ50@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 16 Jun 2009 11:36:47 -0700 (PDT)
Received: from [129.146.108.12] (comforter.SFBay.Sun.COM [129.146.108.12])
	by jurassic-x4600.sfbay.sun.com (8.14.3+Sun/8.14.3)
 with ESMTP id n5GIalbq823674; Tue, 16 Jun 2009 11:36:47 -0700 (PDT)
Date: Tue, 16 Jun 2009 11:34:49 -0700
From: Huie-Ying Lee <huie-ying.lee@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <18994.44953.972880.587240@gargle.gargle.HOWL>
To: James Carlson <james.d.carlson@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <4A37E5C9.2070209@sun.com>
MIME-version: 1.0
Content-type: multipart/alternative;
 boundary="Boundary_(ID_yrGLWZ6I/Tv28WVjkyGzKA)"
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A32A34F.20400@sun.com>
 <18994.44953.972880.587240@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.18 (X11/20081215)
Status: RO
Content-Length: 5243

This is a multi-part message in MIME format.

--Boundary_(ID_yrGLWZ6I/Tv28WVjkyGzKA)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

On 06/12/09 12:42, James Carlson wrote:
> Huie-Ying Lee writes:
>   
>> I can change the relevant lines as below, if that looks better.
>>
>> #Port forwarding
>> #AllowTcpForwarding yes
>>     
>
> I think it's a little less surprising that way, so I prefer it, but
> now that I understand the project a good bit better, it's not a
> significant issue.
>
>   
Glad to know this is no longer a big issue.
>>> Why not just change the way it installs, so that it installs as
>>> "AllowTcpForwarding yes" by default, and leaves it unchanged on
>>> upgrade or patch?
>>>
>>>   
>>>       
>> Right,  that's our goal also.   What would be the right release binding ?
>>     
>
> Patch/micro is the right release binding.  What's missing is the
> description of how the delivery will work.  Something like this:
>
> 	Since we're changing a default value, and we want to avoid
> 	suprise on upgrade, and since we can't tell whether a user has
> 	intentionally configured the "no" value or whether it was just
> 	left at the default, we will do the following for the patch
> 	delivery:
>
> 	- If the system is initially installed from freshbitted
>           packages containing this change, then the system will have
>           AllowTcpForwarding set to "yes" by default.  The release
>           notes for the release containing this change will note the
>           difference.
>
> 	- When upgrading or patching an existing system (installed
>           before this fix was introduced), the AllowTcpForwarding
>           value will not be changed.  A release note (for the update
>           release) and README for the patch will be included to tell
>           users what to do if they want the new value.
>
>   
Thank you for the suggestions. 

This change is intended for Nevada only, which I didn't mention clearly  
in the spec file.   (sorry!)
 The release binding should be "minor", if it is for Nevada only.    
Correct ?

Do we still need to have a description of how the delivery will work,  
if the release binding is "minor" ?
Do we  need to submit an updated spec file ?

Thanks,
Huie-Ying


--Boundary_(ID_yrGLWZ6I/Tv28WVjkyGzKA)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
On 06/12/09 12:42, James Carlson wrote:
<blockquote cite="mid:18994.44953.972880.587240@gargle.gargle.HOWL"
 type="cite">
  <pre wrap="">Huie-Ying Lee writes:
  </pre>
  <blockquote type="cite">
    <pre wrap="">I can change the relevant lines as below, if that looks better.

#Port forwarding
#AllowTcpForwarding yes
    </pre>
  </blockquote>
  <pre wrap=""><!---->
I think it's a little less surprising that way, so I prefer it, but
now that I understand the project a good bit better, it's not a
significant issue.

  </pre>
</blockquote>
Glad to know this is no longer a big issue.<br>
<blockquote cite="mid:18994.44953.972880.587240@gargle.gargle.HOWL"
 type="cite">
  <pre wrap=""></pre>
  <blockquote type="cite">
    <blockquote type="cite">
      <pre wrap="">Why not just change the way it installs, so that it installs as
"AllowTcpForwarding yes" by default, and leaves it unchanged on
upgrade or patch?

  
      </pre>
    </blockquote>
    <pre wrap="">Right,  that's our goal also.   What would be the right release binding ?
    </pre>
  </blockquote>
  <pre wrap=""><!---->
Patch/micro is the right release binding.  What's missing is the
description of how the delivery will work.  Something like this:

	Since we're changing a default value, and we want to avoid
	suprise on upgrade, and since we can't tell whether a user has
	intentionally configured the "no" value or whether it was just
	left at the default, we will do the following for the patch
	delivery:

	- If the system is initially installed from freshbitted
          packages containing this change, then the system will have
          AllowTcpForwarding set to "yes" by default.  The release
          notes for the release containing this change will note the
          difference.

	- When upgrading or patching an existing system (installed
          before this fix was introduced), the AllowTcpForwarding
          value will not be changed.  A release note (for the update
          release) and README for the patch will be included to tell
          users what to do if they want the new value.

  </pre>
</blockquote>
Thank you for the suggestions.&nbsp; <br>
<br>
This change is intended for Nevada only, which I didn't mention
clearly&nbsp; in the spec file.&nbsp;&nbsp; (sorry!)<br>
&nbsp;The release binding should be "minor", if it is for Nevada only. &nbsp;&nbsp;
Correct ?<br>
<br>
Do we still need to have a description of how the delivery will work,&nbsp;
if the release binding is "minor" ?<br>
Do we&nbsp; need to submit an updated spec file ?<br>
<br>
Thanks,<br>
Huie-Ying<br>
<br>
</body>
</html>

--Boundary_(ID_yrGLWZ6I/Tv28WVjkyGzKA)--

From carlsonj@phorcys.east.sun.com Tue Jun 16 12:28:32 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n5GJSWwR028822
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 16 Jun 2009 12:28:32 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n5GJSHCi008814
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@Sun.COM>; Tue, 16 Jun 2009 20:28:31 +0100 (BST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KLC0080XJFH7100@brm-avmta-1.central.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Tue, 16 Jun 2009 13:28:29 -0600 (MDT)
Received: from dm-east-01.east.sun.com ([129.148.9.192])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KLC00LTJJFEBV70@brm-avmta-1.central.sun.com> for
 PSARC-ext@Sun.COM (ORCPT PSARC-ext@Sun.COM); Tue,
 16 Jun 2009 13:28:27 -0600 (MDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-01.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n5GJSP8J021651; Tue, 16 Jun 2009 15:28:25 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n5GJR7Y6006237; Tue,
 16 Jun 2009 15:27:07 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n5GJR7V6006234; Tue,
 16 Jun 2009 15:27:07 -0400 (EDT)
Date: Tue, 16 Jun 2009 15:27:07 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: PSARC 2009/353 ssh config update
In-reply-to: <4A37E5C9.2070209@sun.com>
To: Huie-Ying Lee <Huie-Ying.Lee@sun.com>
Cc: Wyllys Ingersoll <Wyllys.Ingersoll@sun.com>, PSARC-ext@sun.com
Message-id: <18999.61963.124827.794612@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <4A3256E1.1090308@sun.com>
 <18994.22967.951514.139755@gargle.gargle.HOWL> <4A32A34F.20400@sun.com>
 <18994.44953.972880.587240@gargle.gargle.HOWL> <4A37E5C9.2070209@sun.com>
Status: RO
Content-Length: 697

Huie-Ying Lee writes:
> This change is intended for Nevada only, which I didn't mention clearly  
> in the spec file.   (sorry!)
>  The release binding should be "minor", if it is for Nevada only.    
> Correct ?

Yep.

> Do we still need to have a description of how the delivery will work,  
> if the release binding is "minor" ?
> Do we  need to submit an updated spec file ?

If it's not going to be released as a patch, then I think this one
becomes a no-brainer.  +1

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

