sid 10.5p1-1 pool only provides orig.tar.xz and no .asc; previous hard-coded gz/.asc caused wget 404 and set -e abort in pullsrc.sh (failing Create release 33487065147 19s quick fail across all codenames). Parse .dsc for actual orig filename dynamically with fallback to xz, and make compile.sh SOURCES expect xz with compat fallback to gz for old caches (e.g. 10.4).
Backport OpenSSH for Debian / Ubuntu distros.
A script to build openssh deb backport to older distros, using Debian sid sources
Similar Project: Backport OpenSSH RPM for CentOS
Current Version:
Package version are defined in version.env file.
Current version (CI Build version): (script follows debian/sid automatically)
- OpenSSH 10.5p1-1
- OpenSSL 3.5.8
Supported (tested) Distro:
- Ubuntu 24.04/22.04/20.04/18.04
- Debian 13/trixie 12/bookworm 11/bullseye 10/buster
- UnionTech OS Desktop 20 Home (Debian GLIBC 2.28.21-1+deepin-1)
- Kylin V10 SP1 (Ubuntu GLIBC 2.31-0kylin9.2k0.1)
Lazy Install
Github Action builds common distro DEBs.
If your server OS is in the supported list, you can download and install them in the server.
Release supported OSs
- Debian
buster(10)/bullseye(11)/bookworm(12)/trixie(13)-amd64/arm64 - Ubuntu
bionic(18.04)/focal(20.04)/jammy(22.04)/noble(24.04)-amd64/arm64
sudo bash -c "$(curl -L https://github.com/boypt/openssh-deb/raw/master/lazy_install.sh)"
Or when the host needs a github proxy to access:
sudo bash -c "$(curl -L https://gh-proxy.com/github.com/boypt/openssh-deb/raw/master/lazy_install.sh)" @ gh-proxy.com
Direct Build
# pull source (also fetches sid debhelper .debs into builddep/ for old distros)
./pullsrc.sh
# Install Dependencies
./install_deps.sh
# direct build
./compile.sh
Docker Build
Build without installing a bunch of dev packages, and build for different versions of distros.
# pull source from debian sid
./pullsrc.sh
# run with a docker image that fits your target system.
docker run --rm -v "$(pwd):/work" -w /work ubuntu:20.04 bash -c "./install_deps.sh && ./compile.sh"
# clean up docker image
docker builder prune
Using a APT mirror or proxy inside docker
using -e to set environment variables inside docker. APT_MIRROR is automatically applied together with EOL archive handling (switch to archive.debian.org when needed) inside install_deps.sh.
docker run --rm -v "$(pwd):/work" -w /work \
-e APT_MIRROR=mirrors.ustc.edu.cn \
-e http_proxy=http://x.x.x.x \
-e https_proxy=http://x.x.x.x \
ubuntu:20.04 bash -c "./install_deps.sh && ./compile.sh"
Install DEBs
Generated DEBs are right under the output directory. (both direct build and docker build).
ls -l output/*.deb
sudo apt install -y output/*.deb
NOTES
Restore distro default version
sudo apt update
V=$(apt-cache madison ssh | awk 'NR==1 {print $3}')
sudo apt install --allow-downgrades -y \
ssh=$V openssh-client=$V openssh-server=$V openssh-sftp-server=$V
Known issues
sshd-session issue
If installing backported openssh 9.8+ on older distros, some other programs may face problems while interacting with the openssh service. Since openssh-9.8, the subprocess name have changed from sshd to sshd-session.
Known programs with issue:
- fail2ban
- sshguard
Make sure to upgrade or reconfigure them to meet the latest changes.
fail2ban
change in filter.d/sshd.conf:
_daemon = sshd
into
_daemon = sshd(?:-session)?
Distro Issues
Extra steps are needed to install on some distros.
UnionTech OS Desktop 20 Home (Debian GLIBC 2.28.21-1+deepin-1)
- Exclude
libfido2-devfrom the build Dependencies intall command, it's not available. - Install following packages from
debian/bullseye.
Kylin V10 SP1 (Ubuntu GLIBC 2.31-0kylin9.2k0.1)
Run ./compile.sh from the desktop Terminal(mate-terminal).
During install the builddep/*.deb, a kysec_auth dialog would pop up asking for installing permissions. Manual click on the permit button is needed.
If running in a ssh session, the compile script would fail without permissions.
Technical Details
The build process takes the Debian sid source package and applies the following patches before compiling:
- Skip test packages:
openssh-testspackage is excluded from the build (viaBUILD_PACKAGES += -Nopenssh-testsand a patch tochmod +x debian/openssh-tests). - Skip udebs and GNOME askpass: Build profiles
noudebandpkg.openssh.nognomeare set. - Disable build-time tests:
DEB_BUILD_OPTIONS=noddebs nocheckskips compile-time test suites. - Distro codename suffix: The target distro codename is appended to the package version (e.g.
10.4p1-3~noble), so the backport can be distinguished from the official package. - OpenSSL linking timing (checked against the system
libssl-devversion at build time):- Dynamic (system
libssl-dev >= 3.0.0andFORCESSLunset): OpenSSH links against the system OpenSSL library (libssl-dev). The build does not compile OpenSSL from source and keepslibssl-devin the build deps. - Static (system
libssl-dev < 3.0.0orFORCESSL=1): OpenSSL is compiled from source and linked statically.libssl-devis removed from build deps, and--with-ssl-diris injected into the configure flags. SetFORCESSL=1to force static linking even on distros withlibssl >= 3.0.
- Dynamic (system
- FIDO2/Security Key (when libfido2-dev < 1.5.0): Removed from build deps, and
with-security-key-builtinis changed todisable-security-key. - wtmpdb (when
libwtmpdb-devis not available): Removed from build deps and--with-wtmpdbis stripped from configure flags. - init-system-helpers (when installed version < 1.66): Version requirement in
debian/controlis relaxed to 1.50.