From: djm@openbsd.org Date: Fri, 28 Feb 2020 01:07:28 +0000 (+0000) Subject: upstream: no-touch-required certificate option should be an X-Git-Url: http://git.ipfire.org/gitweb/?a=commitdiff_plain;h=refs%2Fheads%2FV_8_2;p=thirdparty%2Fopenssh-portable.git upstream: no-touch-required certificate option should be an extension, not a critical option. OpenBSD-Commit-ID: 626b22c5feb7be8a645e4b9a9bef89893b88600d --- diff --git a/ssh-keygen.c b/ssh-keygen.c index 0d6ed1fff..bf325cd61 100644 --- a/ssh-keygen.c +++ b/ssh-keygen.c @@ -1678,7 +1678,7 @@ prepare_options_buf(struct sshbuf *c, int which) if ((which & OPTIONS_EXTENSIONS) != 0 && (certflags_flags & CERTOPT_USER_RC) != 0) add_flag_option(c, "permit-user-rc"); - if ((which & OPTIONS_CRITICAL) != 0 && + if ((which & OPTIONS_EXTENSIONS) != 0 && (certflags_flags & CERTOPT_NO_REQUIRE_USER_PRESENCE) != 0) add_flag_option(c, "no-touch-required"); if ((which & OPTIONS_CRITICAL) != 0 &&