summary refs log tree commit diff
path: root/pkgs/tools/networking/openssh
diff options
context:
space:
mode:
authorEelco Dolstra <eelco.dolstra@logicblox.com>2015-08-20 13:50:04 +0200
committerEelco Dolstra <eelco.dolstra@logicblox.com>2015-08-20 14:08:18 +0200
commit401782cb678d2e28c0f7f2d40c6421624f410148 (patch)
treebe49a9309ed5f0925986aac7c9bbed526a8054fe /pkgs/tools/networking/openssh
parente4c2f97a2764d5dcf763dce8c7f766737d0dffe0 (diff)
downloadnixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar.gz
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar.bz2
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar.lz
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar.xz
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.tar.zst
nixlib-401782cb678d2e28c0f7f2d40c6421624f410148.zip
Revert "openssh: 6.9p1 -> 7.0p1"
This reverts commit a8eb2a6a81524f3be0c8886f6d06090b50b0a513. OpenSSH
7.0 is causing too many interoperability problems so soon before the
15.08 release.

For instance, it causes NixOps EC2 initial deployments to fail with
"REMOTE HOST IDENTIFICATION HAS CHANGED". This is because the client
knows the server's ssh-dss host key, but this key is no longer
accepted by default. Setting "HostKeyAlgorithms" to "+ssh-dss" does
not work because it causes ssh-dss to be ordered after
"ecdsa-sha2-nistp521", which the server also offers. (Normally, ssh
prioritizes host key algorithms for which the client has a known host
key, but not if you set HostKeyAlgorithms.)
Diffstat (limited to 'pkgs/tools/networking/openssh')
-rw-r--r--pkgs/tools/networking/openssh/default.nix4
1 files changed, 2 insertions, 2 deletions
diff --git a/pkgs/tools/networking/openssh/default.nix b/pkgs/tools/networking/openssh/default.nix
index 57bbf1da22e2..357ee2b9f213 100644
--- a/pkgs/tools/networking/openssh/default.nix
+++ b/pkgs/tools/networking/openssh/default.nix
@@ -17,11 +17,11 @@ let
 in
 with stdenv.lib;
 stdenv.mkDerivation rec {
-  name = "openssh-7.0p1";
+  name = "openssh-6.9p1";
 
   src = fetchurl {
     url = "mirror://openbsd/OpenSSH/portable/${name}.tar.gz";
-    sha256 = "1rc52jyc5v5b8j9kvasrnz9vnj9b0i7fw4nqac8wix0r794k4ngx";
+    sha256 = "1zkci5nbpb4frmzj2vr3kv9j47x2h72kvybcpr0d8mzk73sls1vf";
   };
 
   prePatch = optionalString hpnSupport