Re: Cygwin OpenSSH version detection by Tenable

2025-03-06 Thread Corinna Vinschen via Cygwin
On Mar 5 20:49, Dimitry Andric via Cygwin wrote: > In my opinion, it is wrong that scanners rely on this information. :-) Exactly. > I guess something similar could be done in the Cygwin package. This is > up to the Cygwin maintainers of course. And that doesn't change if some distros tweak the

RE: Cygwin OpenSSH version detection by Tenable

2025-03-05 Thread SUMMERS, TED via Cygwin
try to make the case that Tenable needs to change it's method or get an exception. Best Regards, Ted Summers From: Dimitry Andric Sent: Wednesday, March 5, 2025 11:50 AM To: SUMMERS, TED Cc: cygwin@cygwin.com Subject: Re: Cygwin OpenSSH version detection by Tenable CAUTION: External Email

Re: Cygwin OpenSSH version detection by Tenable

2025-03-05 Thread Dimitry Andric via Cygwin
In my opinion, it is wrong that scanners rely on this information. :-) But putting that discussion aside, the openssh-portable distribution does not announce its "patch level" in its version banner by default. See e.g. https://github.com/openssh/openssh-portable/blob/master/version.h, where SSH