Re: openssh version info bug or feature ?
On Thu, Feb 07, 2002 at 12:21:06AM +1100, Paul Hampson wrote:
> On Wed, Feb 06, 2002 at 08:11:44AM -0500, Anthony DeRobertis wrote:
> > I'd just worry that existing network audits will be thrown off
> > by changing the version. I _do_ think we should change the
> > version when we release a security fix, though. Or when we make
> > major changes (not sure if we do for ssh).
>
> That's pretty much it in a nutshell.
Um. Just to clarify, this is *NOT* a change in the version number. It's
a change in the RFC-compliant *comment field*. Any scanner that's
confused by that has real issues, *especially* since the next version of
openssh will probably make that string a config file item.
--
Mike Stone
Reply to: