(In reply to Werner Fink from comment #6) > I hang on patch openssh-6.6p1-audit5-session_key_destruction.patch as > upstream has changed a lot in e.g. ssh_packet_close() of packet.c ... that > is the changes becomes not trivial and without deep knowledge on audit > memory management the risk of crashing and/or causing a memory leak > increases a lot. > > I'll copy my current tree to ~werner/Export/ > > The question rises if there is an upstream source for FIPS as well as audit > patches for `openssh-6.8p1' Not really. As far as I know, the only upstream for both the FIPS us and RH (because I didn't really like the way they did it, I deviated from them). The audit patches are easier, since those I took verbatim from Fedora (several versions back).