Subject: remove openssh/MESSAGE
To: None <tech-pkg@NetBSD.org>
From: Jeremy C. Reed <reed@reedmedia.net>
List: tech-pkg
Date: 05/25/2005 13:05:30
There is no maintainer for openssh in pkgsrc. The
pkgsrc/security/openssh/MESSAGE says:

===========================================================================
$NetBSD: MESSAGE,v 1.11 2002/09/24 12:30:34 wiz Exp $

                           *===* NOTICE *===*

If you have existing config files for OpenSSH located at /etc/ssh.conf
and /etc/sshd.conf, then you will have to copy them:

        /etc/ssh.conf  --> ${PKG_SYSCONFDIR}/ssh_config
        /etc/sshd.conf --> ${PKG_SYSCONFDIR}/sshd_config

The `${OPENSSH_USER}' user and `${OPENSSH_GROUP}' group used for
privilege separation have been created if they did not already exist.
For security reasons, UsePrivilegeSeparation has to be yes
(the default value).

===========================================================================

May I remove this?

1) /etc/ssh.conf and /etc/sshd.conf is old. And I assume some
configurations from there don't apply any more.

2) The user and group are not created automatically. Only created if
PKG_CREATE_USERGROUP is YES (which is the default though).

3) UsePrivilegeSeparation is the default. Also this seems to imply that
openssh is insecure without it. (I am not discussing that here.)

If I can't remove this MESSAGE, please suggest a reworded MESSAGE.




 Jeremy C. Reed

 	  	 	 technical support & remote administration
	  	 	 http://www.pugetsoundtechnology.com/