# HG changeset patch # User Matt Johnston # Date 1361548487 -28800 # Node ID e698d1a9f42851999c0163a942da405c3391d683 # Parent 4b47ff154ff67c54495404485fa5bf4af8439dbb Some changes since 2012.55 diff -r 4b47ff154ff6 -r e698d1a9f428 CHANGES --- a/CHANGES Fri Feb 22 23:53:49 2013 +0800 +++ b/CHANGES Fri Feb 22 23:54:47 2013 +0800 @@ -1,3 +1,19 @@ +- Allow specifying cipher (-c) and MAC (-m) lists for dbclient + +- Allow using 'none' cipher or MAC + +- Allow a user in immediately if the account has a blank password and blank + passwords are enabled + +- Include a few extra sources of entropy from /proc on Linux, hash private keys + as well + +- Added sha2-256 and sha2-512 hashes + +- Don't sent "localhost" for -R forward connections, reported by Denis Bider + +- Add "-B" runtime option to allow blank passwords + 2012.55 - Wednesday 22 February 2012 - Security: Fix use-after-free bug that could be triggered if command="..."