Accepted openssh 1:7.1p1-1 (source) into unstable

Format: 1.8
Date: Wed, 02 Dec 2015 20:18:35 +0000
Source: openssh
Binary: openssh-client openssh-server openssh-sftp-server ssh ssh-krb5 ssh-askpass-gnome openssh-client-udeb openssh-server-udeb
Architecture: source
Version: 1:7.1p1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenSSH Maintainers <debian-ssh@lists.debian.org>
Changed-By: Colin Watson <cjwatson@debian.org>
 openssh-client - secure shell (SSH) client, for secure access to remote machines
 openssh-client-udeb - secure shell client for the Debian installer (udeb)
 openssh-server - secure shell (SSH) server, for secure access from remote machines
 openssh-server-udeb - secure shell server for the Debian installer (udeb)
 openssh-sftp-server - secure shell (SSH) sftp server module, for SFTP access from remot
 ssh        - secure shell client and server (metapackage)
 ssh-askpass-gnome - interactive X program to prompt users for a passphrase for ssh-ad
 ssh-krb5   - secure shell client and server (transitional package)
Closes: 779068 785190
 openssh (1:7.1p1-1) unstable; urgency=medium
   * New upstream release (http://www.openssh.com/txt/release-7.0, closes:
     - Support for the legacy SSH version 1 protocol is disabled by default
       at compile time.
     - Support for the 1024-bit diffie-hellman-group1-sha1 key exchange is
       disabled by default at run-time.  It may be re-enabled using the
       instructions at http://www.openssh.com/legacy.html
     - Support for ssh-dss, ssh-dss-cert-* host and user keys is disabled by
       default at run-time.  These may be re-enabled using the instructions
       at http://www.openssh.com/legacy.html
     - Support for the legacy v00 cert format has been removed.
     - The default for the sshd_config(5) PermitRootLogin option has changed
       from "yes" to "prohibit-password".
     - PermitRootLogin=without-password/prohibit-password now bans all
       interactive authentication methods, allowing only public-key,
       hostbased and GSSAPI authentication (previously it permitted
       keyboard-interactive and password-less authentication if those were
     - ssh_config(5): Add PubkeyAcceptedKeyTypes option to control which
       public key types are available for user authentication.
     - sshd_config(5): Add HostKeyAlgorithms option to control which public
       key types are offered for host authentications.
     - ssh(1), sshd(8): Extend Ciphers, MACs, KexAlgorithms,
       HostKeyAlgorithms, PubkeyAcceptedKeyTypes and HostbasedKeyTypes
       options to allow appending to the default set of algorithms instead of
       replacing it.  Options may now be prefixed with a '+' to append to the
       default, e.g. "HostKeyAlgorithms=+ssh-dss".
     - sshd_config(5): PermitRootLogin now accepts an argument of
       'prohibit-password' as a less-ambiguous synonym of 'without-
     - ssh(1), sshd(8): Add compatability workarounds for Cisco and more
       PuTTY versions.
     - Fix some omissions and errors in the PROTOCOL and PROTOCOL.mux
       documentation relating to Unix domain socket forwarding.
     - ssh(1): Improve the ssh(1) manual page to include a better description
       of Unix domain socket forwarding (closes: #779068).
     - ssh(1), ssh-agent(1): Skip uninitialised PKCS#11 slots, fixing
       failures to load keys when they are present.
     - ssh(1), ssh-agent(1): Do not ignore PKCS#11 hosted keys that wth empty
     - sshd(8): Clarify documentation for UseDNS option.
     - Check realpath(3) behaviour matches what sftp-server requires and use
       a replacement if necessary.
   * New upstream release (http://www.openssh.com/txt/release-7.1):
     - sshd(8): OpenSSH 7.0 contained a logic error in PermitRootLogin=
       prohibit-password/without-password that could, depending on
       compile-time configuration, permit password authentication to root
       while preventing other forms of authentication.  This problem was
       reported by Mantas Mikulenas.
     - ssh(1), sshd(8): Add compatibility workarounds for FuTTY.
     - ssh(1), sshd(8): Refine compatibility workarounds for WinSCP.
     - Fix a number of memory faults (double-free, free of uninitialised
       memory, etc) in ssh(1) and ssh-keygen(1).  Reported by Mateusz
   * Change "PermitRootLogin without-password" to the new preferred spelling
     of "PermitRootLogin prohibit-password" in sshd_config, and update
     documentation to reflect the new upstream default.
   * Enable conch interoperability tests under autopkgtest.
