Re: [VOTE] Release Apache MINA SSHD 2.13.2

2024-07-28 Thread Thomas Wolf
On 25.07.24 20:08 , Gary Gregory wrote: Is there something special I have to do on macOS? I'm getting a lot of: IllegalState Previous attempts to find a Docker environment failed. Will not retry. Please see logs and check configuration I have Docker Desktop 4.33.0 (160616). I tested the src

Re: [VOTE] Release Apache MINA SSHD 2.13.2

2024-07-25 Thread Thomas Wolf
On 25.07.24 20:08 , Gary Gregory wrote: Is there something special I have to do on macOS? Not really. I'm getting a lot of: IllegalState Previous attempts to find a Docker environment failed. Will not retry. Please see logs and check configuration I have Docker Desktop 4.33.0 (160616).

Re: [VOTE] Release Apache MINA SSHD 2.13.2

2024-07-24 Thread Thomas Wolf
* JGit tests pass * Class version 52 (i.e., Java 8) Thanks, Guillaume! Cheers, Thomas Le mar. 23 juil. 2024 à 19:15, Thomas Wolf a écrit : On 23.07.24 18:24 , Guillaume Nodet wrote: Hey, I've staged a candidate release for an SSHD 2.13.2 release. This release contains a single bug fix

Re: [VOTE] Release Apache MINA SSHD 2.13.2

2024-07-23 Thread Thomas Wolf
On 23.07.24 18:24 , Guillaume Nodet wrote: Hey, I've staged a candidate release for an SSHD 2.13.2 release. This release contains a single bug fix: * Fix sntrup761x25519-sha512 (https://github.com/apache/mina-sshd/issues/525) Official staging repo:

Re: Bugfix Release 2.13.2 for Apache MINA sshd?

2024-07-20 Thread Thomas Wolf
On 20.07.24 14:52 , Gary Gregory wrote: Could this be achieved via a mock, if only to validate that a regression won't happen? Assuming we'd want to test that on an XDH instantiated with raw=true calculateK() returns the full 32 bytes of the secret resulting from a curve25519 key agreement

Re: Bugfix Release 2.13.2 for Apache MINA sshd?

2024-07-20 Thread Thomas Wolf
On 20.07.24 01:46 , Gary Gregory wrote: > I don't see a matching unit test in [2] so we are asking for a future > regression IMO... This _is_ tested. Our tests connect to old OpenSSH, not using this key exchange method, and to new OpenSSH method, where it is used. The problem is that to test

Bugfix Release 2.13.2 for Apache MINA sshd?

2024-07-19 Thread Thomas Wolf
Could we do a bugfix release 2.13.2 for Apache MINA sshd, please? I know it's only one change, but I think it's worth it. In 2.13.0 we had introduced an implementation for the sntrup761x25519-s...@openssh.com key exchange method, which is supposed to be quantum-safe. Unfortunately the

[jira] [Closed] (SSHD-1229) Infinite clientMethods iteration in ClientUserAuthService

2024-07-19 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1229?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf closed SSHD-1229. - Resolution: Duplicate Duplicate of [GH-533|https://github.com/apache/mina-sshd/issues/533]. > Infin

[jira] [Commented] (SSHD-1229) Infinite clientMethods iteration in ClientUserAuthService

2024-07-19 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1229?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17867371#comment-17867371 ] Thomas Wolf commented on SSHD-1229: --- Actually, there is a bug in the handling of "these methods tha

[jira] [Updated] (SSHD-1229) Infinite clientMethods iteration in ClientUserAuthService

2024-07-19 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1229?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1229: -- External issue URL: https://github.com/apache/mina-sshd/issues/533 > Infinite clientMethods iterat

Re: FW: HostKey Algorithm rsa-sha2-512 not supported by RSABufferPublicKeyParser Error

2024-07-06 Thread Thomas Wolf
On 05.07.24 09:55 , Surya Vasundhara Devi Motamarry wrote: While using apachemina for ssh connectivity to server, getting below error : SshException after 2101034762 nanos at read cycle=4: Key type=rsa-sha2-512) not supported by parser=[RSABufferPublicKeyParser - supported=[ssh-rsa],

Re: [VOTE] Release Mina SSHD 2.13.0

2024-06-13 Thread Thomas Wolf
On 12.06.24 17:53 , Guillaume Nodet wrote: I've staged a candidate release for an SSHD 2.13.0 release at: [...] Thanks, Guillaume! +1 Since other people have tested other things already, I only checked: * Class files have class version 52 (Java 8), as expected * JGit tests run fine when

Re: [VOTE] Release Mina SSHD 2.13.0

2024-06-13 Thread Thomas Wolf
On 13.06.24 16:54 , Emmanuel Lécharny wrote: My +1: - checked the signature - checked the N files - built from source One side note: on my new M3 mac, the org.apache.sshd.common.cipher.ArcFourOpenSshTest test never finishes. I will relaunch the tests to be sure, but it works just fine on my

Re: [VOTE] Release Mina SSHD 2.13.0

2024-06-13 Thread Thomas Wolf
On 13.06.24 19:55 , Gary D. Gregory wrote: +1 Tested src zip file, ASC OK (gpg --verify'), SHA512 eyeballed OK (but couldn't use 'shasum --check') OK: mvn clean verify Would you please remind at the next go around us to turn off VPNs? Also point to the KEYS file :-) The build took 33

Re: Release Apache MINA SSHD 2.13.0?

2024-06-10 Thread Thomas Wolf
Guillaume, could you please prepare and stage a release? Cheers, Thomas On 08.06.24 21:35 , Gary Gregory wrote: Sounds  good to me. Gary On Sat, Jun 8, 2024, 2:56 PM Thomas Wolf <mailto:tw...@apache.org>> wrote: On 2024-06-08 20:48 , Thomas Wolf wrote: > I sugg

Re: Release Apache MINA SSHD 2.13.0?

2024-06-08 Thread Thomas Wolf
On 2024-06-08 20:48 , Thomas Wolf wrote: I suggest we start with a release for Apache MINA 2.13.0. Apache MINA SSHD, of course. Cheers, Thomas - To unsubscribe, e-mail: dev-unsubscr...@mina.apache.org For additional

Release Apache MINA SSHD 2.13.0?

2024-06-08 Thread Thomas Wolf
I suggest we start with a release for Apache MINA 2.13.0. The 2.12.0 release was in January. Since then, we've had a number of minor bug fixes, some SFTP client improvements to deal with broken servers doing strange things, and a lot of clean-ups (thanks, Gary!). The most important changes are

Re: SSHD-CORE vulnerabilities

2024-05-14 Thread Thomas Wolf
On 14.05.24 10:31 , Teki Harsha sesha sai wrote: We are working on the project using sshd-core dependence version ( 2.12.1 ), in this version we came across vulnerabilities. So when can we expect the lastest version without vulnerabilities. We need your support advance thanks This is an

[jira] [Resolved] (SSHD-1237) SftpClient logs warnings on keepalive messages

2024-05-01 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1237?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1237. --- Fix Version/s: 2.13.0 Resolution: Fixed PR 492 merged. > SftpClient logs warni

Re: [VOTE] Release Mina SSHD 2.12.0

2024-01-12 Thread Thomas Wolf
On 12.01.24 14:14 , Guillaume Nodet wrote: I've staged a candidate release for 2.12.0 at: Official staging repo: https://dist.apache.org/repos/dist/dev/mina/sshd/2.12.0/ Maven staging repo: https://repository.apache.org/content/repositories/orgapachemina-1090 Git tag:

New release of Apache MINA SSHD needed

2024-01-09 Thread Thomas Wolf
Could we have a new Apache MINA SSHD 2.12.0 release, please? There've been a few minor improvements, but the main reason for a new release is that we've implemented the "strict key exchange" mitigation against the Terrapin attack (CVE-2023-48795, which is a CVE against the SSH protocol itself.)

Re: [VOTE] Release Apache Mina SSHD 2.9.3

2023-10-16 Thread Thomas Wolf
On 16.10.23 01:04 , Emmanuel Lécharny wrote: My main concern is that we now need to install Docker to get the test passing, due to the usage of TestContainer. I don't really like it, the build should be self-supported. The use of TestContainers isn't new. Add to that it took 25mins to ran

Re: [VOTE] Release Apache Mina SSHD 2.9.3

2023-10-12 Thread Thomas Wolf
On 12.10.23 16:33 , Guillaume Nodet wrote: I've staged a candidate release for 2.9.3 at: +1 * Src tar unpacks and builds fine; all tests pass locally (OS X) * Signatures verify * Class version 52 (Java 8) Cheers, Thomas

Re: [VOTE] Release Apache Mina SSHD 2.11.0

2023-10-12 Thread Thomas Wolf
On 12.10.23 16:33 , Guillaume Nodet wrote: I've staged a candidate release for 2.11.0 at: +1 * Src tar unpacks and builds fine; all tests pass locally (OS X) * Signatures verify * Maven JARs work with Java 8 * Github CI builds are green * JGit SSH tests all pass Thanks Guillaume! Cheers,

Time for a new Apache MINA SSHD release?

2023-10-09 Thread Thomas Wolf
I think it would be about time for a new Apache MINA SSHD 2.11.0 release. The last 2.10.0 release was in May 2023; since then we have a couple of bug fixes and improvements ([1], [2]). Two regressions from 2.10.0 were fixed (GH-407 and SSHD-1332), from the rest the fixes for GH-410 and GH-414

[jira] [Updated] (SSHD-1259) DefaultKnownHostsServerKeyVerifier not checking all Key algorithms present in known_hosts

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1259: -- Fix Version/s: 2.11.0 > DefaultKnownHostsServerKeyVerifier not checking all Key algorithms pres

[jira] [Updated] (SSHD-1310) SftpFileSystem.close() method, closes the session as well.

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1310?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1310: -- Fix Version/s: 2.11.0 > SftpFileSystem.close() method, closes the session as w

[jira] [Updated] (SSHD-1332) Identities using tilde specified in config are not loaded

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1332: -- Fix Version/s: 2.10.1 > Identities using tilde specified in config are not loa

[jira] [Updated] (SSHD-1327) WriteState causes memory overflow

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1327?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1327: -- Fix Version/s: 2.11.0 > WriteState causes memory overf

[jira] [Updated] (SSHD-1330) keep-alive handler on client

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1330?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1330: -- Fix Version/s: 2.10.1 > keep-alive handler on cli

[jira] [Updated] (SSHD-1330) keep-alive handler on client

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1330?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1330: -- Fix Version/s: 2.11.0 (was: 2.10.1) > keep-alive handler on cli

[jira] [Updated] (SSHD-1332) Identities using tilde specified in config are not loaded

2023-10-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1332: -- Fix Version/s: 2.11.0 (was: 2.10.1) > Identities using tilde specified in con

[jira] [Commented] (SSHD-1335) Add landing directory feature

2023-09-21 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1335?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17767695#comment-17767695 ] Thomas Wolf commented on SSHD-1335: --- It depends. If the user should only be able to access {{/A/B}} via

[jira] [Commented] (SSHD-1335) Add landing directory feature

2023-09-19 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1335?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17766877#comment-17766877 ] Thomas Wolf commented on SSHD-1335: --- AFAIK there is no server-side concept of a "current wo

[jira] [Resolved] (SSHD-1332) Identities using tilde specified in config are not loaded

2023-07-02 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1332. --- Fix Version/s: 2.10.1 Resolution: Fixed > Identities using tilde specified in con

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-07-01 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17739291#comment-17739291 ] Thomas Wolf commented on SSHD-1329: --- I just spent some two hours to set up a VirtualBox VM with Ubuntu

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-07-01 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17739277#comment-17739277 ] Thomas Wolf commented on SSHD-1329: --- Maybe this a red herring, but... perhaps check the crypto policies

[jira] [Commented] (SSHD-1332) Identities using tilde specified in config are not loaded

2023-06-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1332?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17739194#comment-17739194 ] Thomas Wolf commented on SSHD-1332: --- Yes indeed. [PR 394|https://github.com/apache/mina-sshd/pull/394

[jira] [Assigned] (SSHD-1332) Identities using tilde specified in config are not loaded

2023-06-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1332?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf reassigned SSHD-1332: - Assignee: Thomas Wolf > Identities using tilde specified in config are not loa

[jira] [Commented] (SSHD-1331) SSH Algorithm negotiation

2023-06-28 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1331?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17738281#comment-17738281 ] Thomas Wolf commented on SSHD-1331: --- I read this statement from the RFC a bit differently. The first

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-06-28 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17738272#comment-17738272 ] Thomas Wolf commented on SSHD-1329: --- Interesting indeed. I have no Ubuntu 22.04 readily available; I

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-06-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17735544#comment-17735544 ] Thomas Wolf commented on SSHD-1329: --- {quote}the issue seems to be with the SSH key loading{quote

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-06-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17735464#comment-17735464 ] Thomas Wolf commented on SSHD-1329: --- {quote}Client is running Ubuntu 22.04.2 LTS on x86.{quote} So

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-06-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17735361#comment-17735361 ] Thomas Wolf commented on SSHD-1329: --- {quote}... works fine regardless of putting 2.10.0 or 2.9.2

[jira] [Commented] (SSHD-1329) SSH Public key authentication works with 2.9.2 but fails with 2.10.0

2023-06-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1329?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17735164#comment-17735164 ] Thomas Wolf commented on SSHD-1329: --- Cannot reproduce so far. I'll keep looking, though. What OS

[jira] [Closed] (SSHD-1328) Hanging while executing rsync commands.

2023-06-03 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1328?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf closed SSHD-1328. - I cannot fix your code. I thought I had pointed out what I thought was wrong, and that implies a solution

[jira] [Resolved] (SSHD-1328) Hanging while executing rsync commands.

2023-06-03 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1328?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1328. --- Resolution: Not A Bug This code opens a channel and then waits until the channel is closed, and only

[jira] [Resolved] (SSHD-1259) DefaultKnownHostsServerKeyVerifier not checking all Key algorithms present in known_hosts

2023-05-29 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1259?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1259. --- Fix Version/s: 2.10.1 Resolution: Fixed [PR 368|https://github.com/apache/mina-sshd/pull/368

[jira] [Resolved] (SSHD-1310) SftpFileSystem.close() method, closes the session as well.

2023-05-24 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1310?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1310. --- Fix Version/s: 2.10.1 Resolution: Fixed [PR 377|https://github.com/apache/mina-sshd/pull/377

[jira] [Reopened] (SSHD-1310) SftpFileSystem.close() method, closes the session as well.

2023-05-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1310?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf reopened SSHD-1310: --- Assignee: Thomas Wolf Re-opening. Actually, yes, an {{SftpFileSystem}} is intended to be used

[jira] [Resolved] (SSHD-1327) WriteState causes memory overflow

2023-05-18 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1327?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1327. --- Fix Version/s: 2.10.1 Resolution: Fixed > WriteState causes memory overf

[jira] [Updated] (SSHD-1327) WriteState causes memory overflow

2023-05-17 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1327?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1327: -- Affects Version/s: 2.10.0 > WriteState causes memory overf

[jira] [Assigned] (SSHD-1327) WriteState causes memory overflow

2023-05-17 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1327?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf reassigned SSHD-1327: - Assignee: Thomas Wolf > WriteState causes memory overf

[jira] [Commented] (SSHD-1327) WriteState causes memory overflow

2023-05-17 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1327?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17723734#comment-17723734 ] Thomas Wolf commented on SSHD-1327: --- [PR 374|https://github.com/apache/mina-sshd/pull/374] set

[jira] [Resolved] (SSHD-1326) Failed to establish an SSH connection because the server identifier exceeds the int range

2023-05-15 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1326?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1326. --- Fix Version/s: 2.10.0 Resolution: Fixed This is a duplicate of [GitHub issue 300|https

Re: [VOTE] Release Apache Mina SSHD 2.10.0

2023-05-10 Thread Thomas Wolf
On 10.05.23 09:35 , Guillaume Nodet wrote: I've staged a candidate release for 2.10.0 at: [...] Please review and vote ! +1 * JGit SSH tests pass * CI builds in Github are all green * Class versions are 52 (Java 8) * Src tar unpacks and builds fine; all tests pass locally (OS X) Thanks,

[jira] [Commented] (SSHD-1325) Not useful sorting of signature algrithms?

2023-05-10 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1325?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17721491#comment-17721491 ] Thomas Wolf commented on SSHD-1325: --- I quite agree that documentation could be improved. A simple flag

[jira] [Commented] (SSHD-1325) Not useful sorting of signature algrithms?

2023-05-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1325?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17721061#comment-17721061 ] Thomas Wolf commented on SSHD-1325: --- I don't understand. If the {{ClientBuilder}} is used, the default

[jira] [Commented] (SSHD-1322) How to identify received LSTAT command is part of PUT command at Server

2023-04-17 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1322?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17713257#comment-17713257 ] Thomas Wolf commented on SSHD-1322: --- I don't think you can. The LSTAT comes from OpenSSH querying

[jira] [Updated] (SSHD-1319) SftpRemotePathChannel.transferFrom(...) ignores position argument

2023-04-02 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1319?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1319: -- Fix Version/s: 2.10.0 (was: 2.9.3) > SftpRemotePathChannel.transferF

[jira] [Updated] (SSHD-1316) Possible OOM in ChannelPipedInputStream

2023-04-02 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1316?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1316: -- Fix Version/s: 2.10.0 (was: 2.9.3) > Possible OOM in ChannelPipedInputStr

[jira] [Updated] (SSHD-1315) Password in clear in SSHD server's logs

2023-04-02 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1315?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1315: -- Fix Version/s: 2.10.0 (was: 2.9.3) > Password in clear in SSHD server's l

[jira] [Updated] (SSHD-1295) Connection attempt not canceled when a connection timeout occurs

2023-04-02 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1295?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1295: -- Fix Version/s: 2.10.0 (was: 2.9.3) > Connection attempt not canceled w

[jira] [Resolved] (SSHD-1295) Connection attempt not canceled when a connection timeout occurs

2023-03-19 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1295?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1295. --- Fix Version/s: 2.9.3 Assignee: Thomas Wolf Resolution: Fixed [Github PR 315|https

[jira] [Resolved] (SSHD-1321) Cannot read ed25519 privatekey created using bouncy castle and eddsa-0.3.0.jar

2023-03-18 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1321?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1321. --- Resolution: Duplicate {quote}This needs to be immediately addressed. We are blocked because

[jira] [Resolved] (SSHD-1319) SftpRemotePathChannel.transferFrom(...) ignores position argument

2023-01-28 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1319?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1319. --- Fix Version/s: 2.9.3 Resolution: Fixed Thanks, Andreas! > SftpRemotePathChannel.transferF

[jira] [Assigned] (SSHD-1319) SftpRemotePathChannel.transferFrom(...) ignores position argument

2023-01-28 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1319?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf reassigned SSHD-1319: - Assignee: Thomas Wolf > SftpRemotePathChannel.transferFrom(...) ignores position argum

[jira] [Commented] (SSHD-1319) SftpRemotePathChannel.transferFrom(...) ignores position argument

2023-01-27 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1319?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17681453#comment-17681453 ] Thomas Wolf commented on SSHD-1319: --- Actually that <= 0 condition is fine for {{transferF

[jira] [Commented] (SSHD-1319) SftpRemotePathChannel.transferFrom(...) ignores position argument

2023-01-24 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1319?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17680339#comment-17680339 ] Thomas Wolf commented on SSHD-1319: --- Looks like this was an oversight in commit e85b67e0

[jira] [Closed] (SSHD-1318) Question about SSHD-1204

2022-12-31 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1318?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf closed SSHD-1318. - Assignee: Thomas Wolf Resolution: Information Provided > Question about SSHD-1

[jira] [Resolved] (SSHD-1316) Possible OOM in ChannelPipedInputStream

2022-12-31 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1316?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1316. --- Fix Version/s: 2.9.3 Assignee: Thomas Wolf Resolution: Fixed > Possible

[jira] [Commented] (SSHD-1317) Finding default shell and its escape, quote characters

2022-12-22 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1317?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651414#comment-17651414 ] Thomas Wolf commented on SSHD-1317: --- {quote}is it possible to find the followings by SSHD ?\{quote

[jira] [Comment Edited] (SSHD-1317) Finding default shell and its escape, quote characters

2022-12-22 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1317?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651414#comment-17651414 ] Thomas Wolf edited comment on SSHD-1317 at 12/22/22 8:26 PM: - {quote

[jira] [Commented] (SSHD-1318) Question about SSHD-1204

2022-12-22 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1318?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17651365#comment-17651365 ] Thomas Wolf commented on SSHD-1318: --- Did you verify with a packet trace that this is the same as SSHD

[jira] [Commented] (SSHD-1316) Possible OOM in ChannelPipedInputStream

2022-12-20 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1316?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17649802#comment-17649802 ] Thomas Wolf commented on SSHD-1316: --- Just yesterday I merged [PR-292|https://github.com/apache/mina-sshd

[jira] [Resolved] (SSHD-1315) Password in clear in SSHD server's logs

2022-12-17 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1315?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1315. --- Fix Version/s: 2.9.3 Resolution: Fixed PR merged. > Password in clear in SSHD server's l

[jira] [Assigned] (SSHD-1315) Password in clear in SSHD server's logs

2022-12-15 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1315?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf reassigned SSHD-1315: - Assignee: Thomas Wolf > Password in clear in SSHD server's l

[jira] [Commented] (SSHD-1315) Password in clear in SSHD server's logs

2022-12-15 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1315?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17648262#comment-17648262 ] Thomas Wolf commented on SSHD-1315: --- See [PR 289|https://github.com/apache/mina-sshd/pull/289

[jira] [Commented] (SSHD-1315) Password in clear in SSHD server's logs

2022-12-14 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1315?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17647705#comment-17647705 ] Thomas Wolf commented on SSHD-1315: --- In the future please report security issues privately. Also

[jira] [Comment Edited] (FTPSERVER-516) Bump Apache Mina Core from 2.1.6 to 2.2.1

2022-12-03 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/FTPSERVER-516?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642804#comment-17642804 ] Thomas Wolf edited comment on FTPSERVER-516 at 12/3/22 9:23 AM: {quote

[jira] [Commented] (FTPSERVER-516) Bump Apache Mina Core from 2.1.6 to 2.2.1

2022-12-03 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/FTPSERVER-516?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642804#comment-17642804 ] Thomas Wolf commented on FTPSERVER-516: --- {quote}how do I turn off this garbage Jira editor

[jira] [Comment Edited] (FTPSERVER-516) Bump Apache Mina Core from 2.1.6 to 2.2.1

2022-12-03 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/FTPSERVER-516?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17642193#comment-17642193 ] Thomas Wolf edited comment on FTPSERVER-516 at 12/3/22 9:20 AM: Hi

[jira] (SSHD-1314) OpenSSHKeyPairProvider is not able to load SimpleKey

2022-11-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1314 ] Thomas Wolf deleted comment on SSHD-1314: --- was (Author: wolft): BTW, something unrelated: that {{OpenSSHKeyPairProvider}} in Karaf de-serializes checking only the top-level class. AFAIK

[jira] [Commented] (SSHD-1314) OpenSSHKeyPairProvider is not able to load SimpleKey

2022-11-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641520#comment-17641520 ] Thomas Wolf commented on SSHD-1314: --- BTW, something unrelated: that {{OpenSSHKeyPairProvider}} in Karaf

[jira] [Commented] (SSHD-1314) OpenSSHKeyPairProvider is not able to load SimpleKey

2022-11-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641501#comment-17641501 ] Thomas Wolf commented on SSHD-1314: --- Using Java serialization to store a private key was a very bad idea

[jira] [Comment Edited] (SSHD-1314) OpenSSHKeyPairProvider is not able to load SimpleKey

2022-11-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641472#comment-17641472 ] Thomas Wolf edited comment on SSHD-1314 at 11/30/22 6:35 PM: - I must

[jira] [Commented] (SSHD-1314) OpenSSHKeyPairProvider is not able to load SimpleKey

2022-11-30 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1314?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17641472#comment-17641472 ] Thomas Wolf commented on SSHD-1314: --- I must be missing something fundamentally. What

[jira] [Commented] (SSHD-1307) Nio2Session.shutdownOutput() should wait for writes in progress

2022-11-23 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1307?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17637979#comment-17637979 ] Thomas Wolf commented on SSHD-1307: --- Sorry for having missed that. Yes, it is. 2.9.2 was released a few

CVE-2022-45047: Apache MINA SSHD: Java unsafe deserialization vulnerability

2022-11-15 Thread Thomas Wolf
Severity: important Description: Class org.apache.sshd.server.keyprovider.SimpleGeneratorHostKeyProvider in Apache MINA SSHD <= 2.9.1 uses Java deserialization to load a serialized java.security.PrivateKey. The class is one of several implementations that an implementor using Apache MINA SSHD

[ANNOUNCE] Apache MINA SSHD release 2.9.2

2022-11-15 Thread Thomas Wolf
/downloads.html and is also available via Maven Central. Thanks for all the contributions and the feedback that made this release possible! For the Apache MINA project, Thomas Wolf - To unsubscribe, e-mail: dev-unsubscr

[jira] [Commented] (SSHD-1312) using org.apache.sshd.sftp.client.SftpClient#read the Number of read bytes

2022-11-11 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1312?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17632509#comment-17632509 ] Thomas Wolf commented on SSHD-1312: --- I don't understand. It's a server-side property. It sets a limit

[jira] [Commented] (SSHD-1312) using org.apache.sshd.sftp.client.SftpClient#read the Number of read bytes

2022-11-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1312?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17631121#comment-17631121 ] Thomas Wolf commented on SSHD-1312: --- It's configured on the server side. If you want your client to work

[jira] [Commented] (SSHD-1312) using org.apache.sshd.sftp.client.SftpClient#read the Number of read bytes

2022-11-09 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1312?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17631093#comment-17631093 ] Thomas Wolf commented on SSHD-1312: --- A server is allowed to return less data than requested. Keep

[jira] [Resolved] (SSHD-1311) Do you have any timeline for the 2.9.2 release? 

2022-11-05 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1311?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1311. --- Resolution: Information Provided No. We're working on it. > Do you have any timeline for the 2.

[jira] [Resolved] (SSHD-1309) SSH Jumphost with User and password Auth

2022-11-05 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1309?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1309. --- Resolution: Information Provided > SSH Jumphost with User and password A

[jira] [Commented] (SSHD-1310) SftpFileSystem.close() method, closes the session as well.

2022-11-05 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1310?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17629378#comment-17629378 ] Thomas Wolf commented on SSHD-1310: --- The {{SftpFileSystem}} is intended to be used with a session

[jira] [Commented] (SSHD-1309) SSH Jumphost with User and password Auth

2022-11-01 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1309?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17627268#comment-17627268 ] Thomas Wolf commented on SSHD-1309: --- Install a {{UserInteraction}} with {{resolveAuthPasswordAttempt

[jira] [Resolved] (SSHD-1287) Use the maximum packet size of the communication partner

2022-10-31 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1287?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf resolved SSHD-1287. --- Fix Version/s: 2.9.2 Resolution: Fixed The bugs are fixed: * Use _remote_ window packet size

[jira] [Updated] (SSHD-1173) SFTP worker threads got stuck while processing PUT methods against one specific SFTP server

2022-10-31 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Thomas Wolf updated SSHD-1173: -- Issue Type: Bug (was: Question) > SFTP worker threads got stuck while processing PUT methods agai

[jira] [Commented] (SSHD-1307) Nio2Session.shutdownOutput() should wait for writes in progress

2022-10-27 Thread Thomas Wolf (Jira)
[ https://issues.apache.org/jira/browse/SSHD-1307?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17625229#comment-17625229 ] Thomas Wolf commented on SSHD-1307: --- Not really. I have one more fix to get in, but then I could ask our

  1   2   3   4   5   6   7   >