<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: HP-UX Secure Shell in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762182#M72697</link>
    <description>This is the latest update received from HP:&lt;BR /&gt;&lt;BR /&gt;""OpenSSH Vulnerabilities in Challenge Response Handling If the SKEY and BSD_AUTH authentication compile-time options are explicitly enabled, it may cause a remote denial of service attack on the OpenSSH daemon. Does this security problem exist with HP-UX Secure Shell? See CERT on OpenSSH ulnerabilities in Challenge Response Handling HP-UX Secure Shell does NOT enable either of these options. There is no denial of service risk with HP-UX Secure Shell. &lt;BR /&gt;&lt;BR /&gt;I wanted to provide you with an update to this case. I have information&lt;BR /&gt;regarding CERT CA-2002-18, HP is not vulnerable to the first issue described&lt;BR /&gt;in the CERT noted below, we are vulnerable to the second issue and will have&lt;BR /&gt;a sw update available via a patch soon ( I believe by next week but I cant&lt;BR /&gt;supply any dates ). &lt;BR /&gt;&lt;BR /&gt;The HP Security Doc is HPSBUX0206-195 and will be updated when the fix is&lt;BR /&gt;available, I'll also send you a email when it comes out.""&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
    <pubDate>Mon, 15 Jul 2002 14:19:44 GMT</pubDate>
    <dc:creator>Daimian Woznick</dc:creator>
    <dc:date>2002-07-15T14:19:44Z</dc:date>
    <item>
      <title>HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762177#M72692</link>
      <description>The HP-UX Secure Shell is based on and older version of Openssh.  This older version has several security vulnerabilities.  When will HP have a newer version out that is based on Openssh 3.4p1 ?</description>
      <pubDate>Thu, 11 Jul 2002 17:25:20 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762177#M72692</guid>
      <dc:creator>Craig Cooper</dc:creator>
      <dc:date>2002-07-11T17:25:20Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762178#M72693</link>
      <description>Craig,&lt;BR /&gt;&lt;BR /&gt;You can try downloading the source and compiling it yourself, or you can try emailing hpux@hpux.cs.utah.edu. Usually, it's just a hurry up and wait for it to show up.&lt;BR /&gt;&lt;BR /&gt;live free or die&lt;BR /&gt;harry</description>
      <pubDate>Thu, 11 Jul 2002 18:09:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762178#M72693</guid>
      <dc:creator>harry d brown jr</dc:creator>
      <dc:date>2002-07-11T18:09:57Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762179#M72694</link>
      <description>I currently have a call in to support to answer this question and will post the answer when I receive it.  The following is from the CERT advisory:&lt;BR /&gt;&lt;BR /&gt;HP has issued a security bulletin (HPSBUX0206-195) for HP 9000 Servers running HP-UX release 11.00 and 11.11 only with the T1471AA SSH product installed.&lt;BR /&gt;&lt;BR /&gt;It says in part: &lt;BR /&gt;&lt;BR /&gt;As a short-term solution, disable PAMAuthenticationViaKbdInt in the sshd_config file; i.e.,&lt;BR /&gt;&lt;BR /&gt;PAMAuthenticationViaKbdInt no&lt;BR /&gt;&lt;BR /&gt;NOTE: ChallengeResponseAuthentication is not used in the HP product.&lt;BR /&gt;HP is working to produce a patch for its version which is based on OpenSSH release 3.1p1.&lt;BR /&gt;&lt;BR /&gt;HPSBUX0206-195 will be updated when the patch is available.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Thu, 11 Jul 2002 18:42:27 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762179#M72694</guid>
      <dc:creator>Daimian Woznick</dc:creator>
      <dc:date>2002-07-11T18:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762180#M72695</link>
      <description>Openssh 3.4 is available in depot format from this link.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://hpux.connect.org.uk/hppd/hpux/Networking/Admin/openssh-3.4p1/" target="_blank"&gt;http://hpux.connect.org.uk/hppd/hpux/Networking/Admin/openssh-3.4p1/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;I have not heard when HP will release their supported bundle.&lt;BR /&gt;&lt;BR /&gt;Openssh requires zlib, and openssl also available from that site.  I have not installed this version yet so I am unable to provide feedback on their compile options or any particulars.&lt;BR /&gt;&lt;BR /&gt;Best Regards!&lt;BR /&gt;Bryan Payne&lt;BR /&gt;Senior Unix Admin</description>
      <pubDate>Fri, 12 Jul 2002 01:31:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762180#M72695</guid>
      <dc:creator>Bryan Payne</dc:creator>
      <dc:date>2002-07-12T01:31:08Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762181#M72696</link>
      <description>Bryan,&lt;BR /&gt;&lt;BR /&gt;Thank you.  I did try it and everything worked fine, except one of the files 3.4p1-run was corrupt and would not install.  I removed all of the pieces and went back to the T1471AA depot from HP</description>
      <pubDate>Fri, 12 Jul 2002 20:16:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762181#M72696</guid>
      <dc:creator>Craig Cooper</dc:creator>
      <dc:date>2002-07-12T20:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762182#M72697</link>
      <description>This is the latest update received from HP:&lt;BR /&gt;&lt;BR /&gt;""OpenSSH Vulnerabilities in Challenge Response Handling If the SKEY and BSD_AUTH authentication compile-time options are explicitly enabled, it may cause a remote denial of service attack on the OpenSSH daemon. Does this security problem exist with HP-UX Secure Shell? See CERT on OpenSSH ulnerabilities in Challenge Response Handling HP-UX Secure Shell does NOT enable either of these options. There is no denial of service risk with HP-UX Secure Shell. &lt;BR /&gt;&lt;BR /&gt;I wanted to provide you with an update to this case. I have information&lt;BR /&gt;regarding CERT CA-2002-18, HP is not vulnerable to the first issue described&lt;BR /&gt;in the CERT noted below, we are vulnerable to the second issue and will have&lt;BR /&gt;a sw update available via a patch soon ( I believe by next week but I cant&lt;BR /&gt;supply any dates ). &lt;BR /&gt;&lt;BR /&gt;The HP Security Doc is HPSBUX0206-195 and will be updated when the fix is&lt;BR /&gt;available, I'll also send you a email when it comes out.""&lt;BR /&gt;&lt;BR /&gt;Hope this helps</description>
      <pubDate>Mon, 15 Jul 2002 14:19:44 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762182#M72697</guid>
      <dc:creator>Daimian Woznick</dc:creator>
      <dc:date>2002-07-15T14:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762183#M72698</link>
      <description>Here is the newest update I received from HP:&lt;BR /&gt;&lt;BR /&gt;Regarding version 3.4 it appears there were&lt;BR /&gt;some issues during testing of this release, its possible HP will not releas&lt;BR /&gt;a version based on 3.4 at all and will skip to the next available version.&lt;BR /&gt;As a general rule there will be updates to the product once a quarter via&lt;BR /&gt;software.hp.com.&lt;BR /&gt;</description>
      <pubDate>Tue, 16 Jul 2002 12:35:14 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762183#M72698</guid>
      <dc:creator>Daimian Woznick</dc:creator>
      <dc:date>2002-07-16T12:35:14Z</dc:date>
    </item>
    <item>
      <title>Re: HP-UX Secure Shell</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762184#M72699</link>
      <description>I previously opened an issue with HP on a problem I encountered with Secure Shell and mentioned the CERT Advisory issue.  HP has the depot files available to address the issue at:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.software.hp.com/ISS_products_list.html" target="_blank"&gt;http://www.software.hp.com/ISS_products_list.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;The following I received from HP in regards to advisory:&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;The ssh release 3.10.02 is available on &lt;A href="http://software.hp.com" target="_blank"&gt;http://software.hp.com&lt;/A&gt; this fixes the second part of CA-2002-18, HP was not ulnerable to the first part of the CERT:&lt;BR /&gt;&lt;BR /&gt;PART I: &lt;BR /&gt;&lt;BR /&gt;If the SKEY and BSD_AUTH authentication compile-time options are explicitly enabled, it may cause a remote denial of service attack on the OpenSSH daemon. Does this security problem exist with HP-UX Secure Shell? See CERT on OpenSSH Vulnerabilities in Challenge Response Handling&lt;BR /&gt;&amp;lt;&amp;gt; HP-UX Secure Shell does NOT enable either of these options. There is no denial of service risk with HP-UX Secure Shell. &lt;BR /&gt;&lt;BR /&gt;Part II, we were vulnerable to,  3.10.002 fixed it and is now out on the software.hp.com portal.&lt;BR /&gt;&lt;BR /&gt;Will there be a patch or a release to incorporate the fix for the Cert problem mentioned above? &lt;BR /&gt;HP-UX Secure Shell will be updated with a license file for OpenSSL to the product and the fix for the security cert on PAMAuthenticationViaKbdInt. The next version A.03.10.002 will be available for the software depot on 7/29&lt;BR /&gt;and the September HP-UX quarterly application release. &lt;BR /&gt;&lt;BR /&gt;Hope this helps anyone looking at Secure Shell.</description>
      <pubDate>Wed, 31 Jul 2002 12:03:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/hp-ux-secure-shell/m-p/2762184#M72699</guid>
      <dc:creator>Daimian Woznick</dc:creator>
      <dc:date>2002-07-31T12:03:05Z</dc:date>
    </item>
  </channel>
</rss>

