A script to build openssh deb backport to older distros, using Debian sid sources
Similar Project: Backport OpenSSH RPM for CentOS
Package version are defined in version.env file.
Current version (CI Build version): (script follows debian/sid automatically)
- OpenSSH 10.4p1-3
- OpenSSL 3.5.7
- Ubuntu 24.04/22.04/20.04
- Debian 13/trixie 12/bookworm 11/bullseye
- UnionTech OS Desktop 20 Home (Debian GLIBC 2.28.21-1+deepin-1)
- Kylin V10 SP1 (Ubuntu GLIBC 2.31-0kylin9.2k0.1)
Github Action builds common distro DEBs.
If your server OS is in the supported list, you can download and install them in the server.
- Debian
bullseye(11)/bookworm(12)/trixie(13)-amd64/arm64 - Ubuntu
focal(20.04)/jammy(22.04)/noble(24.04)-amd64/arm64
sudo bash -c "$(curl -L https://github.com/boypt/openssh-deb/raw/master/lazy_install.sh)"Or when the host needs a github proxy to access:
sudo bash -c "$(curl -L https://gh-proxy.com/github.com/boypt/openssh-deb/raw/master/lazy_install.sh)" @ gh-proxy.com# Install Dependencies
./install_deps.sh
# pull source
./pullsrc.sh
# direct build
./compile.shBuild without installing a bunch of dev packages, and build for different versions of distros.
# pull source from debian sid
./pullsrc.sh
# run with a docker image that fits your target system.
docker run --rm -v "$(pwd):/work" -w /work ubuntu:20.04 bash -c "./install_deps.sh && ./compile.sh"
# clean up docker image
docker builder pruneUsing a APT mirror or proxy inside docker
using -e to set environment variables inside docker.
docker run --rm -v "$(pwd):/work" -w /work \
-e APT_MIRROR=mirrors.ustc.edu.cn \
-e http_proxy=http://x.x.x.x \
-e https_proxy=http://x.x.x.x \
ubuntu:20.04 bash -c "./install_deps.sh && ./compile.sh"Generated DEBs are right under the output directory. (both direct build and docker build).
ls -l output/*.deb
sudo apt install -y output/*.debsudo apt update
V=$(apt-cache madison ssh | awk 'NR==1 {print $3}')
sudo apt install --allow-downgrades -y \
ssh=$V openssh-client=$V openssh-server=$V openssh-sftp-server=$VIf installing backported openssh 9.8+ on older distros, some other programs may face problems while interacting with the openssh service. Since openssh-9.8, the subprocess name have changed from sshd to sshd-session.
Known programs with issue:
- fail2ban
- sshguard
Make sure to upgrade or reconfigure them to meet the latest changes.
change in filter.d/sshd.conf:
_daemon = sshd
into
_daemon = sshd(?:-session)?
Extra steps are needed to install on some distros.
- Exclude
libfido2-devfrom the build Dependencies intall command, it's not available. - Install following packages from
debian/bullseye.
Run ./compile.sh from the desktop Terminal(mate-terminal).
During install the builddep/*.deb, a kysec_auth dialog would pop up asking for installing permissions. Manual click on the permit button is needed.
If running in a ssh session, the compile script would fail without permissions.
The build process takes the Debian sid source package and applies the following patches before compiling:
- Skip test packages:
openssh-testspackage is excluded from the build (viaBUILD_PACKAGES += -Nopenssh-testsand a patch tochmod +x debian/openssh-tests). - Skip udebs and GNOME askpass: Build profiles
noudebandpkg.openssh.nognomeare set. - Disable build-time tests:
DEB_BUILD_OPTIONS=noddebs nocheckskips compile-time test suites. - Distro codename suffix: The target distro codename is appended to the package version (e.g.
10.4p1-3~noble), so the backport can be distinguished from the official package. - Static OpenSSL (when libssl < 3.0 or
FORCESSL=1): OpenSSL is compiled from source and linked statically.libssl-devis removed from build deps, and--with-ssl-diris injected into the configure flags. - FIDO2/Security Key (when libfido2-dev < 1.5.0): Removed from build deps, and
with-security-key-builtinis changed todisable-security-key. - wtmpdb (when
libwtmpdb-devis not available): Removed from build deps and--with-wtmpdbis stripped from configure flags. - init-system-helpers (when installed version < 1.66): Version requirement in
debian/controlis relaxed to 1.50.