freebsd kernel with SKQ
Go to file
Colin Percival 4ba35bc4db Resurrect r321659: Turn off ChallengeResponseAuthentication for EC2 AMIs.
EC2 instances are normally launched with an SSH public key specified,
which is then used for logging in (by default, as 'ec2-user').  Having
ChallengeResponseAuthentication enabled (as FreeBSD's default sshd_config
does) has no functional effect in a new EC2 instance, since you can't log
in using a password until a password has been set -- but having this
enabled results in alerts from automated scanning tools which can detect
that sshd advertises support for keyboard-interactive logins (since they
can't detect that accounts have no password set).

EC2 users who want to use passwords to log in to their instances will need
to set 'ChallengeResponseAuthentication yes' in FreeBSD 12.0 and later.

Discussed with:	gjb, gtetlow, emaste, des
Requested by:	Amazon
X-MFC:		No
Relnotes:	ChallengeResponseAuthentication is turned off by default in
		Amazon EC2 AMIs.
2017-12-05 09:08:48 +00:00
bin Add "vmaddr" ps(1) keyword. 2017-12-01 11:32:05 +00:00
cddl Complete support for dtrace's -x setenv option. 2017-12-03 16:57:28 +00:00
contrib Correctly prefix the infiniband include directory for buildworld. This fixes 2017-12-05 08:25:17 +00:00
crypto Merge OpenSSL 1.0.2m. 2017-11-02 18:04:29 +00:00
etc sponge(1): fix my tests 2017-12-05 04:43:39 +00:00
gnu build-tools: De-special-case the gcc tools build. 2017-10-31 19:02:05 +00:00
include Vendor import of libc++ release_50 branch r319231: 2017-12-02 12:47:11 +00:00
kerberos5 various: general adoption of SPDX licensing ID tags. 2017-11-27 15:37:16 +00:00
lib Add an envp argument to proc_create(). 2017-12-03 16:50:16 +00:00
libexec Use strlcpy(). 2017-12-05 07:21:47 +00:00
release Resurrect r321659: Turn off ChallengeResponseAuthentication for EC2 AMIs. 2017-12-05 09:08:48 +00:00
rescue Avoid referencing private lib names directly. 2017-11-10 07:53:02 +00:00
sbin Document gmirror sysctls. 2017-11-30 20:37:12 +00:00
secure secure: chase removal of pkg_install 2017-11-11 07:21:49 +00:00
share Fix DPSRCS not getting .depend.* files. 2017-12-05 02:23:33 +00:00
stand loader.efi: add note about iPXE into the efipart.c 2017-12-04 08:50:00 +00:00
sys DEPENDSRCS not used here. 2017-12-05 02:23:27 +00:00
targets Merge ^/head r325842 through r325998. 2017-11-19 12:36:03 +00:00
tests tests: ipsec: Don't load/unload aesni.ko in the test header 2017-12-03 18:35:07 +00:00
tools Just use the last line of the output from getting .OBJDIR. The 2017-12-04 16:38:20 +00:00
usr.bin Use strlcpy(). 2017-12-05 07:11:56 +00:00
usr.sbin fdformat is a sysadmin command and thus its man page should be in 2017-12-05 05:02:46 +00:00
.arcconfig callsign isn't required anymore 2016-09-29 06:19:45 +00:00
.arclint sponge(1): initial commit 2017-12-05 03:55:10 +00:00
COPYRIGHT Bump copyright year. 2016-12-31 12:41:42 +00:00
LOCKS
MAINTAINERS Move sys/boot to stand. Fix all references to new location 2017-11-14 23:02:19 +00:00
Makefile Use TARGET_ARCH=riscv64 when TARGET=riscv 2017-11-21 19:23:12 +00:00
Makefile.inc1 native-xtools: Fix build without META_MODE for GCC archs. 2017-12-05 02:23:36 +00:00
Makefile.libcompat Fix nested MAKEOBJDIRPREFIX breaking various release/buildworld/toolchain targets. 2017-11-05 00:11:51 +00:00
Makefile.sys.inc Fix top-level targets with read-only OBJDIR. 2017-11-18 20:01:15 +00:00
ObsoleteFiles.inc fdformat is a sysadmin command and thus its man page should be in 2017-12-05 05:02:46 +00:00
README Document the sys/boot -> stand move in hier.7 and the top-level README. 2017-12-03 20:36:36 +00:00
README.md Document the sys/boot -> stand move in hier.7 and the top-level README. 2017-12-03 20:36:36 +00:00
UPDATING Fill in date. 2017-11-26 04:55:23 +00:00

FreeBSD Source:

This is the top level of the FreeBSD source directory. This file was last revised on: FreeBSD

For copyright information, please see the file COPYRIGHT in this directory (additional copyright information also exists for some sources in this tree - please see the specific source directories for more information).

The Makefile in this directory supports a number of targets for building components (or all) of the FreeBSD source tree. See build(7) and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/makeworld.html for more information, including setting make(1) variables.

The buildkernel and installkernel targets build and install the kernel and the modules (see below). Please see the top of the Makefile in this directory for more information on the standard build targets and compile-time flags.

Building a kernel is a somewhat more involved process. See build(7), config(8), and https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/kernelconfig.html for more information.

Note: If you want to build and install the kernel with the buildkernel and installkernel targets, you might need to build world before. More information is available in the handbook.

The kernel configuration files reside in the sys/<arch>/conf sub-directory. GENERIC is the default configuration used in release builds. NOTES contains entries and documentation for all possible devices, not just those commonly used.

Source Roadmap:

bin				System/user commands.

cddl			Various commands and libraries under the Common Development  
				and Distribution License.

contrib			Packages contributed by 3rd parties.

crypto			Cryptography stuff (see crypto/README).

etc				Template files for /etc.

gnu				Various commands and libraries under the GNU Public License.  
				Please see gnu/COPYING* for more information.

include			System include files.

kerberos5		Kerberos5 (Heimdal) package.

lib				System libraries.

libexec			System daemons.

release			Release building Makefile & associated tools.

rescue			Build system for statically linked /rescue utilities.

sbin			System commands.

secure			Cryptographic libraries and commands.

share			Shared resources.

stand			Boot loader sources.

sys				Kernel sources.

tests			Regression tests which can be run by Kyua.  See tests/README
				for additional information.

tools			Utilities for regression testing and miscellaneous tasks.

usr.bin			User commands.

usr.sbin		System administration commands.

For information on synchronizing your source tree with one or more of the FreeBSD Project's development branches, please see:

https://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/current-stable.html