]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
upstream commit
authordjm@openbsd.org <djm@openbsd.org>
Wed, 22 Apr 2015 01:24:01 +0000 (01:24 +0000)
committerDamien Miller <djm@mindrot.org>
Wed, 29 Apr 2015 08:14:22 +0000 (18:14 +1000)
unknown certificate extensions are non-fatal, so don't
 fatal when they are encountered; bz#2387 reported by Bob Van Zant; ok
 dtucker@

auth-options.c

index 4f0da9c04d3327674122f9aa846acc9b37672cca..0595537beee96331fe10bfa5a1d859b718631646 100644 (file)
@@ -1,4 +1,4 @@
-/* $OpenBSD: auth-options.c,v 1.65 2015/01/14 10:30:34 markus Exp $ */
+/* $OpenBSD: auth-options.c,v 1.66 2015/04/22 01:24:01 djm Exp $ */
 /*
  * Author: Tatu Ylonen <ylo@cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -603,7 +603,7 @@ auth_cert_options(struct sshkey *k, struct passwd *pw)
                    &cert_source_address_done) == -1)
                        return -1;
                if (parse_option_list(k->cert->extensions, pw,
-                   OPTIONS_EXTENSIONS, 1,
+                   OPTIONS_EXTENSIONS, 0,
                    &cert_no_port_forwarding_flag,
                    &cert_no_agent_forwarding_flag,
                    &cert_no_x11_forwarding_flag,