1
0
mirror of https://git.tartarus.org/simon/putty.git synced 2025-01-25 01:02:24 +00:00
Go to file
Simon Tatham 70ab076d83 New option to manually configure the expected host key(s).
This option is available from the command line as '-hostkey', and is
also configurable through the GUI. When enabled, it completely
replaces all of the automated host key management: the server's host
key will be checked against the manually configured list, and the
connection will be allowed or disconnected on that basis, and the host
key store in the registry will not be either consulted or updated.

The main aim is to provide a means of automatically running Plink,
PSCP or PSFTP deep inside Windows services where HKEY_CURRENT_USER
isn't available to have stored the right host key in. But it also
permits you to specify a list of multiple host keys, which means a
second use case for the same mechanism will probably be round-robin
DNS names that select one of several servers with different host keys.

Host keys can be specified as the standard MD5 fingerprint or as an
SSH-2 base64 blob, and are canonicalised on input. (The base64 blob is
more unwieldy, especially with Windows command-line length limits, but
provides a means of specifying the _whole_ public key in case you
don't trust MD5. I haven't bothered to provide an analogous mechanism
for SSH-1, on the basis that anyone worrying about MD5 should have
stopped using SSH-1 already!)

[originally from svn r10220]
2014-09-09 11:46:24 +00:00
charset It's probably well past time for this: change PuTTY's default 2013-05-25 14:03:19 +00:00
contrib Fix SSH2_MSG_CHANNEL_EXTENDED_DATA in logparse. 2013-09-07 16:15:11 +00:00
doc New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
icons Stop using physical tabs in Python. (I was goaded into doing this by 2009-02-28 23:04:58 +00:00
macosx Correct an inequality sign causing the bounds check in Windows 2013-07-22 07:12:26 +00:00
testdata Fix an array-size bug in modmul, and add some tests for it. 2013-08-02 06:27:54 +00:00
unix Add an option to suppress horizontal scroll bars in list boxes. 2014-09-09 11:46:14 +00:00
windows New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
be_all_s.c Rationalise access to, and content of, backends[] array. 2007-06-30 21:56:44 +00:00
be_all.c Rationalise access to, and content of, backends[] array. 2007-06-30 21:56:44 +00:00
be_none.c Fix bug in which the SSH-only tools (pscp, psftp) did not honour a 2011-07-27 18:43:16 +00:00
be_nos_s.c Rationalise access to, and content of, backends[] array. 2007-06-30 21:56:44 +00:00
be_nossh.c Rationalise access to, and content of, backends[] array. 2007-06-30 21:56:44 +00:00
be_ssh.c Fix bug in which the SSH-only tools (pscp, psftp) did not honour a 2011-07-27 18:43:16 +00:00
Buildscr Introduce a new version type, 'prerelease'. Quotes the version number 2011-11-26 17:35:21 +00:00
Buildscr.cv Add a bob script to do Coverity scanning. 2013-07-22 19:56:00 +00:00
callback.c Oops! Remove a tight-looping diagnostic. 2013-09-15 14:40:46 +00:00
CHECKLST.txt Checklist update following the 0.62 release. I managed to send out the 2011-12-10 14:03:02 +00:00
cmdgen.c Fix assertion failure in Unix PuTTYgen exports. 2014-01-16 19:16:19 +00:00
cmdline.c New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
conf.c Tighten up a lot of casts from unsigned to int which are read by one 2013-07-14 10:45:54 +00:00
config.c New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
configure.ac Move the Unix configure script up to the top level. 2014-02-22 18:01:32 +00:00
cproxy.c Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
dialog.c Add an option to suppress horizontal scroll bars in list boxes. 2014-09-09 11:46:14 +00:00
dialog.h Add an option to suppress horizontal scroll bars in list boxes. 2014-09-09 11:46:14 +00:00
errsock.c Remove sk_{get,set}_private_ptr completely! 2013-11-17 14:04:48 +00:00
import.c Fix a null-dereference introduced by another mis-fix in r9919. 2013-07-20 13:15:20 +00:00
int64.c Further correction: on reflection, after examining all the call 2008-09-16 22:56:08 +00:00
int64.h Some extra int64 functions. 2006-08-05 13:48:53 +00:00
LATEST.VER Bump version number prior to tagging 0.63. 2013-08-06 17:09:07 +00:00
ldisc.c Make calling term_nopaste() a cross-platform feature. 2013-08-17 16:06:40 +00:00
ldisc.h Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
ldiscucs.c Patch from Yoshida Masato to fill in the missing pieces of Windows 2012-02-17 19:28:55 +00:00
LICENCE It's a new year. 2014-01-15 23:57:54 +00:00
logging.c Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
minibidi.c Fix a type mismatch in minibidi.c - r9409 changed the 'wc' fields in 2012-03-05 18:34:40 +00:00
misc.c New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
misc.h New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
mkauto.sh Move the Unix configure script up to the top level. 2014-02-22 18:01:32 +00:00
mkfiles.pl Add the 'subdir-objects' option in the automake makefile. 2014-02-22 18:02:06 +00:00
mksrcarc.sh Stop using 'zip -k' to construct the Windows source archive. 2014-03-04 22:56:08 +00:00
mkunxarc.sh Move the Unix configure script up to the top level. 2014-02-22 18:01:32 +00:00
network.h Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
nocproxy.c
nogss.c Rewrite gprefs() in settings.c so that its input mapping includes 2011-06-25 17:37:31 +00:00
noprint.c A few small changes to make the PuTTY source base more usable as a 2005-12-09 20:04:19 +00:00
noshare.c Fix the prototype of the stub function in noshare.c. 2014-04-22 17:53:50 +00:00
noterm.c Make calling term_nopaste() a cross-platform feature. 2013-08-17 16:06:40 +00:00
notiming.c Two related changes to timing code: 2012-09-18 21:42:48 +00:00
pgssapi.c Patch from Alejandro Sedeno, somewhat modified by me, which 2010-05-19 18:22:17 +00:00
pgssapi.h Patch from Alejandro Sedeno, somewhat modified by me, which 2010-05-19 18:22:17 +00:00
pinger.c Two related changes to timing code: 2012-09-18 21:42:48 +00:00
portfwd.c Refactor ssh.c's APIs to x11fwd.c and portfwd.c. 2013-11-17 14:04:41 +00:00
pproxy.c Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
proxy.c Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
proxy.h Replace the hacky 'OSSocket' type with a closure. 2013-11-17 14:03:55 +00:00
pscp.c Use the new host_str* functions to improve IPv6 literal support. 2014-01-25 15:58:54 +00:00
psftp.c Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
psftp.h Propagate file permissions in both directions in Unix pscp and psftp. 2011-08-11 17:59:30 +00:00
putty.h New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
puttymem.h Rework the new type-check in sresize so that it doesn't cause a 2012-07-19 04:29:50 +00:00
puttyps.h Oops: r9004 should have removed various pieces from the Makefile and 2010-09-25 08:37:30 +00:00
raw.c Use the new host_str* functions to improve IPv6 literal support. 2014-01-25 15:58:54 +00:00
README Better document the various environments with which Makefile.cyg works. 2012-09-18 23:07:42 +00:00
Recipe Fix automatic version numbering in the Unix tarball. 2014-07-07 19:47:23 +00:00
resource.h
rlogin.c Use the new host_str* functions to improve IPv6 literal support. 2014-01-25 15:58:54 +00:00
sercfg.c Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
settings.c New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
sftp.c Tighten up a lot of casts from unsigned to int which are read by one 2013-07-14 10:45:54 +00:00
sftp.h Propagate file permissions in both directions in Unix pscp and psftp. 2011-08-11 17:59:30 +00:00
sign.sh Generate some checksum files with more up-to-date hash functions than 2011-07-10 11:45:52 +00:00
ssh.c New option to manually configure the expected host key(s). 2014-09-09 11:46:24 +00:00
ssh.h Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
sshaes.c Introduce a new utility function smemclr(), which memsets things to 2012-07-22 19:51:50 +00:00
ssharcf.c Introduce a new utility function smemclr(), which memsets things to 2012-07-22 19:51:50 +00:00
sshblowf.c Enable blowfish-ctr by default. It's been tested and found working. 2005-04-28 08:56:03 +00:00
sshbn.c One more defensive assert, just to be sure. 2013-08-06 16:45:49 +00:00
sshcrc.c
sshcrcda.c Unify GET_32BIT()/PUT_32BIT() et al from numerous source files into misc.h. 2005-04-12 20:04:56 +00:00
sshdes.c Implement connection sharing between instances of PuTTY. 2013-11-17 14:05:41 +00:00
sshdh.c Add support for RFC 4432 RSA key exchange, the patch for which has been 2007-04-30 22:09:26 +00:00
sshdss.c Make modinv able to return NULL if its inputs are not coprime, and 2013-08-04 19:34:07 +00:00
sshdssg.c Generate keys more carefully, so that when the user asks for an n-bit 2012-03-04 00:24:49 +00:00
sshgss.h Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
sshgssc.c Patch from Alejandro Sedeno, somewhat modified by me, which 2010-05-19 18:22:17 +00:00
sshgssc.h Patch from Alejandro Sedeno, somewhat modified by me, which 2010-05-19 18:22:17 +00:00
sshmd5.c Take advantage of PUT_32BIT_MSB_FIRST when constructing sequence numbers 2013-02-20 22:37:34 +00:00
sshnogss.c Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
sshprime.c Generate keys more carefully, so that when the user asks for an n-bit 2012-03-04 00:24:49 +00:00
sshpubk.c Move base64_decode_atom into misc.c. 2014-09-09 11:46:10 +00:00
sshrand.c random_ref() should always increment the reference count. 2013-10-09 18:38:35 +00:00
sshrsa.c Add a missing bn_restore_invariant in RSA blinding code. 2014-02-24 23:35:55 +00:00
sshrsag.c Make modinv able to return NULL if its inputs are not coprime, and 2013-08-04 19:34:07 +00:00
sshsh256.c Add support for HMAC-SHA-256 as an SSH-2 MAC algorithm ("hmac-sha2-256") 2013-02-20 23:30:55 +00:00
sshsh512.c Patch from Tim Kosse to fix 64-bit-cleanness in SHA-512. 2009-11-10 19:14:15 +00:00
sshsha.c Add an assortment of missing consts I've just noticed. 2013-07-27 18:35:48 +00:00
sshshare.c Close the listening socket when a sharing upstream dies. 2014-09-07 13:06:52 +00:00
sshzlib.c Add some assertions in sshzlib.c. 2014-02-22 18:02:14 +00:00
storage.h Turn 'Filename' into a dynamically allocated type with no arbitrary 2011-10-02 11:01:57 +00:00
telnet.c Use the new host_str* functions to improve IPv6 literal support. 2014-01-25 15:58:54 +00:00
terminal.c Truncate all terminal lines when we clear scrollback. 2014-07-24 18:13:16 +00:00
terminal.h Remove the timed part of the terminal paste mechanism. 2013-09-15 14:05:38 +00:00
testback.c Post-release destabilisation! Completely remove the struct type 2011-07-14 18:52:21 +00:00
time.c Comment explaining location in top-level directory. 2005-02-07 15:23:45 +00:00
timing.c Fix a stupid sign bug in run_timers() that broke Windows Plink (and 2012-09-19 22:12:00 +00:00
tree234.c Fixes for the tree234 unit test: break its dependencies on half of the 2013-07-11 17:24:32 +00:00
tree234.h
version.c Introduce a new version type, 'prerelease'. Quotes the version number 2011-11-26 17:35:21 +00:00
wcwidth.c Fix another type mismatch introduced by r9409. 2012-03-05 18:40:36 +00:00
wildcard.c Add a missing null pointer check in wc_unescape, to bring it in line 2013-07-14 10:46:17 +00:00
x11fwd.c Use the new host_str* functions to improve IPv6 literal support. 2014-01-25 15:58:54 +00:00

This is the README for the source archive of PuTTY, a free Win32
and Unix Telnet and SSH client.

If you want to rebuild PuTTY from source, we provide a variety of
Makefiles and equivalents. (If you have fetched the source from
Subversion, you'll have to generate the Makefiles yourself -- see
below.)

There are various compile-time directives that you can use to
disable or modify certain features; it may be necessary to do this
in some environments. They are documented in `Recipe', and in
comments in many of the generated Makefiles.

For building on Windows:

 - windows/Makefile.vc is for command-line builds on MS Visual C++
   systems. Change into the `windows' subdirectory and type `nmake
   -f Makefile.vc' to build all the PuTTY binaries.

   Last time we checked, PuTTY built with vanilla VC7, or VC6 with
   an up-to-date Platform SDK. (It might still be possible to build
   with vanilla VC6, but you'll certainly have to remove some
   functionality with directives such as NO_IPV6.)

   (We've also had reports of success building with the
   OpenWatcom compiler -- www.openwatcom.org -- using Makefile.vc
   with `wmake -ms -f makefile.vc' and NO_MULTIMON, although we
   haven't tried this ourselves. Version 1.3 is reported to work.)

 - Inside the windows/MSVC subdirectory are MS Visual Studio project
   files for doing GUI-based builds of the various PuTTY utilities.
   These have been tested on Visual Studio 6.

   You should be able to build each PuTTY utility by loading the
   corresponding .dsp file in Visual Studio. For example,
   MSVC/putty/putty.dsp builds PuTTY itself, MSVC/plink/plink.dsp
   builds Plink, and so on.

 - windows/Makefile.bor is for the Borland C compiler. Type `make -f
   Makefile.bor' while in the `windows' subdirectory to build all
   the PuTTY binaries.

 - windows/Makefile.cyg is for Cygwin / MinGW installations. Type
   `make -f Makefile.cyg' while in the `windows' subdirectory to
   build all the PuTTY binaries.

   You'll probably need quite a recent version of the w32api package.
   Note that by default the multiple monitor and HTML Help support are
   excluded from the Cygwin build, since at the time of writing Cygwin
   doesn't include the necessary headers.

 - windows/Makefile.lcc is for lcc-win32. Type `make -f
   Makefile.lcc' while in the `windows' subdirectory. (You will
   probably need to specify COMPAT=-DNO_MULTIMON.)

 - Inside the windows/DEVCPP subdirectory are Dev-C++ project
   files for doing GUI-based builds of the various PuTTY utilities.

The PuTTY team actively use Makefile.vc (with VC7) and Makefile.cyg
(with mingw32), so we'll probably notice problems with those
toolchains fairly quickly. Please report any problems with the other
toolchains mentioned above.

For building on Unix:

 - unix/configure is for Unix and GTK. If you don't have GTK, you
   should still be able to build the command-line utilities (PSCP,
   PSFTP, Plink, PuTTYgen) using this script. To use it, change into
   the `unix' subdirectory, run `./configure' and then `make'. Or you
   can do the same in the top-level directory (we provide a little
   wrapper that invokes configure one level down), which is more like
   a normal Unix source archive but doesn't do so well at keeping the
   per-platform stuff in each platform's subdirectory; it's up to you.

   Note that Unix PuTTY has mostly only been tested on Linux so far;
   portability problems such as BSD-style ptys or different header file
   requirements are expected.

 - unix/Makefile.gtk and unix/Makefile.ux are for non-autoconfigured
   builds. These makefiles expect you to change into the `unix'
   subdirectory, then run `make -f Makefile.gtk' or `make -f
   Makefile.ux' respectively. Makefile.gtk builds all the programs but
   relies on Gtk, whereas Makefile.ux builds only the command-line
   utilities and has no Gtk dependence.

 - For the graphical utilities, Gtk+-1.2 and Gtk+-2.0 should both be
   supported. If you have both installed, you can manually specify
   which one you want by giving the option '--with-gtk=1' or
   '--with-gtk=2' to the configure script. (2 is the default, of
   course.) In the absence of either, the configure script will
   automatically construct a Makefile which builds only the
   command-line utilities; you can manually create this condition by
   giving configure the option '--without-gtk'.

 - pterm would like to be setuid or setgid, as appropriate, to permit
   it to write records of user logins to /var/run/utmp and
   /var/log/wtmp. (Of course it will not use this privilege for
   anything else, and in particular it will drop all privileges before
   starting up complex subsystems like GTK.) By default the makefile
   will not attempt to add privileges to the pterm executable at 'make
   install' time, but you can ask it to do so by running configure
   with the option '--enable-setuid=USER' or '--enable-setgid=GROUP'.

 - The Unix Makefiles have an `install' target. Note that by default
   it tries to install `man' pages; if you have fetched the source via
   Subversion then you will need to have built these using Halibut
   first - see below.

 - It's also possible to build the Windows version of PuTTY to run
   on Unix by using Winelib.  To do this, change to the `windows'
   directory and run `make -f Makefile.cyg CC=winegcc RC=wrc'.

All of the Makefiles are generated automatically from the file
`Recipe' by the Perl script `mkfiles.pl' (except for the Unix one,
which is generated by the `configure' script; mkfiles.pl only
generates the input to automake). Additions and corrections to Recipe,
mkfiles.pl and/or configure.ac are much more useful than additions and
corrections to the actual Makefiles, Makefile.am or Makefile.in.

The Unix `configure' script and its various requirements are generated
by the shell script `mkauto.sh', which requires GNU Autoconf, GNU
Automake, and Gtk; if you've got the source from Subversion rather
than using one of our source snapshots, you'll need to run this
yourself. The input file to Automake is generated by mkfiles.pl along
with all the rest of the makefiles, so you will need to run mkfiles.pl
and then mkauto.sh.

Documentation (in various formats including Windows Help and Unix
`man' pages) is built from the Halibut (`.but') files in the `doc'
subdirectory using `doc/Makefile'. If you aren't using one of our
source snapshots, you'll need to do this yourself. Halibut can be
found at <http://www.chiark.greenend.org.uk/~sgtatham/halibut/>.

The PuTTY home web site is

    http://www.chiark.greenend.org.uk/~sgtatham/putty/

If you want to send bug reports or feature requests, please read the
Feedback section of the web site before doing so. Sending one-line
reports saying `it doesn't work' will waste your time as much as
ours.

See the file LICENCE for the licence conditions.