New upstream release 1.7.0
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
sshguard (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
Please consider updating to 1.7.0. You don't have to build for all versions. Doing for Yakkity is fine if you wish. 1.7.0 implements new filters that allow an individual to block more traffic. This becomes more relevant for those that restrict the ciphers in use on ssh servers and is getting a ton of key exchange failure messages as a result from automated scripts. This version filters for that and will block IPs that hit that error multiple times in a configurable section of time. For the most part, I'm not aware of needing new patches. The existing code works as is. I believe the man page patch is no longer needed.
Release date: 8/8/2016
Release Announcement:
Greetings,
SSHGuard 1.7.0 is available:
https:/
Added
Add sshg-logtail
Add sshg-parser
Control firewall using sshg-fw
Match "no matching key exchange method" for SSH
Deprecated
Hosts backend is deprecated
Logsuck (-l option) is deprecated, use sshg-logtail instead
Process validation (-f option) is deprecated
Removed
Remove external hooks (-e option)
Remove support for genfilt and ipfilter backends
Fixed
Accept socklog messages without a timestamp
Fix excessive logging causing endless looping in logsuck
Fix undefined assignment of initial inode number
Note on deprecation: Deprecated features will be removed in the next
non-bugfix release. If you would like to nominate a feature to be
un-deprecated, contact the project mailing list.
Best,
Kevin
--=20
Kevin Zheng
<email address hidden> | <email address hidden> | PGP: 0xC22E1090
tags: | added: upgrade-software-version |
This bug was fixed in the package sshguard - 1.7.1-1
---------------
sshguard (1.7.1-1) unstable; urgency=medium
* New upstream release. (LP: #1617549) patches/ 01-update- manpage- settings. diff: Remove, source/ lintian- overrides, Remove, it is not necessary
* debian/rules: Update upstream changelog name.
+ Remove autoreconf in dh sequence, not needed by
compat level 10.
* debian/copyright: Update copyright information.
* debian/control: Bump debhelper version to 10.
+ Apply wrap-and-sort command.
+ Add Depends on lsb-base (>= 3.0-6).
+ Remove dh-autoreconf from B-D.
* debian/compat: Switch compat level 9 to 10.
* debian/
merged with upstream.
* debian/
now.
-- Julián Moreno Patiño <email address hidden> Mon, 19 Dec 2016 15:09:29 -0500