RedHat forks OpenSSH?

Ben Lindstrom mouring at etoh.eviladmin.org
Tue Nov 9 13:32:59 EST 2004



On Mon, 8 Nov 2004, Stephen Frost wrote:

> * Sten Drescher (stend at sten.org) wrote:
[..]
> > Or, it can be forked, which it appears Red Hat is doing, albeit in a
> > very impolite fashion.
>
> Impolite is the implication that RedHat is forking OpenSSH because
> they're prudently removing specific files which are definitely of a
> questionable legal status.
>

Impolite in the fact they take a clean tar ball physically remove code
from it instead of using the native RPM patch methology.  Thus you have an
unsignable and unverifiable *.tar.gz file within the srpm.

Frankly, if they feel they need to do this.  Then they should at least be
polite enough to call it "RedhatSSH" or "OurModifiedOpenSSH" so people
expecting such chain of verification will fail if someone tries to verify
it against upstream code.

To me(I can't and won't speak for anyone else), the issue isn't WHAT
they removed more as *HOW* they removed it.

- Ben




More information about the openssh-unix-dev mailing list