From: djm@openbsd.org Date: Fri, 28 Feb 2020 01:07:28 +0000 (+0000) Subject: upstream: no-touch-required certificate option should be an X-Git-Tag: V_8_3_P1~131 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=9b47bd7b09d191991ad9e0506bb66b74bbc93d34;p=thirdparty%2Fopenssh-portable.git upstream: no-touch-required certificate option should be an extension, not a critical option. OpenBSD-Commit-ID: 626b22c5feb7be8a645e4b9a9bef89893b88600d --- diff --git a/ssh-keygen.c b/ssh-keygen.c index d9c207b42..b652bbbfc 100644 --- a/ssh-keygen.c +++ b/ssh-keygen.c @@ -1,4 +1,4 @@ -/* $OpenBSD: ssh-keygen.c,v 1.399 2020/02/26 13:40:09 jsg Exp $ */ +/* $OpenBSD: ssh-keygen.c,v 1.400 2020/02/28 01:07:28 djm Exp $ */ /* * Author: Tatu Ylonen * Copyright (c) 1994 Tatu Ylonen , Espoo, Finland @@ -1670,7 +1670,7 @@ prepare_options_buf(struct sshbuf *c, int which) if ((which & OPTIONS_EXTENSIONS) != 0 && (certflags_flags & CERTOPT_USER_RC) != 0) add_flag_option(c, "permit-user-rc"); - if ((which & OPTIONS_CRITICAL) != 0 && + if ((which & OPTIONS_EXTENSIONS) != 0 && (certflags_flags & CERTOPT_NO_REQUIRE_USER_PRESENCE) != 0) add_flag_option(c, "no-touch-required"); if ((which & OPTIONS_CRITICAL) != 0 &&