I believe FreeBSD should just have a slave port with OpenSSH 7.4, used only for SSHv1. People using such port should know the consequences of it. Debian does it too with https://packages.debian.org/stretch/openssh-client-ssh1 -------------- next part -------------- A non-text attachment was scrubbed... Name: signature.asc Type: application/pgp-signature Size: 833 bytes Desc: not available URL: <http://lists.freebsd.org/pipermail/freebsd-security/attachments/20170131/9ae7b88f/attachment.sig>
> I believe FreeBSD should just have a slave port with OpenSSH 7.4, used only > for SSHv1. People using such port should know the consequences of it.This could be a good candidate for a new ports category, /usr/ports/legacy If implemented there is a lot of code, in both ports and base, that should be relocated. (telnet, rsh/rlogin/rcp/..., nis/yp, rpc.*, cvs, games, ppp, sendmail, finger, ...) Roger