HP-UX Secure Shell A.05.90.001, A.05.90.002, and A.05.90.003 Release Notes (5900-2247, March 2012)

Defects fixed in HP-UX Secure Shell A.05.90
Fixed a bug to delete the kerberos credential cache file, displayed on session exit when
ChallengeResponse is used with PAM_Kerberos. This fix also includes setting the correct owner
of the cache files when UsePrivilegeSeparation=no.
Fixed a bug to support handling of "--" with exception to prepend only if the filename list entry
starts with '-'.
Added a new sshd_config keyword to support 2000 X window pseudo-displays. The default
is 1000.
Added a new sshd_config keyword to disable ISTRIP. This enables you to enter multibytes
chars (requires 8 bits).
Known problems and workarounds
The following are the known problems and workarounds in HP-UX Secure Shell A.05.90:
WARNING! Do not specify user specific information during configuration of host-based
authentication. Host-based authentication supports only authentication of hosts. It does not
allow user-specific authentication. When the user configures the host-based authentication
with the following, # cat /etc/hosts.equivmyhost.mydomain.com specificuser,
it allows the specificuser@myhost.mydomain.com to login to any local account on the
remote machine.
The base code of OpenSSH 5.9p1 supports logging of sftp transactions. LogFacility
and LogLevel options are added to sftp-server as command-line options to log these
transactions. As a result, the following directives are not supported in this release of HP-UX
Secure Shell:
#LogSftp no
#SftpLogFacility AUTH
#SftpLogLevel INFO
The following SMSE behavior is seen in this version of HP-UX Secure Shell:
Audit log messages show repeated entries for a user. This occurs because bad login attempts
are logged in the audit file.
6 HP-UX Secure Shell A.05.90