You are not logged in.
Background:
the issue
immediate consequences for debian itself
What is of interest to us Archers:
potential collateral damage in other distros
So to sum up:
- if any of you generated some crypto key/certificate/whatever using openssl (or apps based on it) under debian (or a derivative), be sure to check your keys.
- the weak keys will certainly now be used regularly to brute force by Bad Guys(tm), so even if one has not generated keys under debian, one might want to check if current keys happen by sheer bad luck to be one of them (low probability but who knows)
- openssh package (server) should be instructed to reject such keys
Last edited by lloeki (2008-05-15 07:32:50)
To know recursion, you must first know recursion.
Offline
Thank you lloeki.
Except the fact that an Arch server may host some ssh keys generated on Debian/Ubuntu systems, does any one know if Arch's openssl package is also vunerable ?
Offline
Except the fact that an Arch server may host some ssh keys generated on Debian/Ubuntu systems, does any one know if Arch's openssl package is also vunerable ?
No, the patch was not applied in the Arch package.
Offline
No, the patch was not applied in the Arch package.
Thanks Allan for the info.
I guess this is another point in favor of having vanilla packages
Offline
This topic is worth bumping, it's not a small one.
I've had my SSH key since the days I used debian. I've replaced it now, so don't bother trying my accounts
Last edited by iphitus (2008-05-15 09:11:14)
Offline
I guess this is another point in favor of having vanilla packages
well, yes and no.
things are not as simple as it seems, for the curious ones:
http://blog.drinsama.de/erich/en/linux/ … aster.html
http://www.aigarius.com/blog/2008/05/14 … different/
http://changelog.complete.org/posts/714 … L-bug.html
To know recursion, you must first know recursion.
Offline
I've had my SSH key since the days I used debian
almost the same for me.
- I use debian lenny armel on my nslu2, with ssl certs on mail server and so on, so that one's a sure one. regenerated.
- I can't recall when I generated my personal key on my laptop. maybe using debian, maybe ubuntu, maybe gentoo. who knows... so I regenerated everything, just to be sure.
To know recursion, you must first know recursion.
Offline