Re: Regeneration of gpg keys after HeartBleed

Luis Ressel <[email protected]> Wed, 9 Apr 2014 19:01:16 +0200
Newsgroups gmane.linux.gentoo.security
Message-ID <[email protected]>
--Sig_/Z4_VfGO7dkrWzlcIEhmJpq.
Content-Type: text/plain; charset=US-ASCII
Content-Transfer-Encoding: quoted-printable

On Wed, 09 Apr 2014 18:39:41 +0200
Jo <[email protected]> wrote:

> I'm a bit concerned about the signing keys of the portage tree
> releases, I know that gpg is not the same as openssl but keeping in
> mind that SSH, VPN, HTTPS keys might be compromised for two years,
> don't you think it's a healthy measure to generate a new pair of keys?

It seems highly unlikely that GPG keys got compromised. This could only
have happened if either private GPG keys were transmitted via an
OpenSSL encrypted connection, or if the information leak created a
secondary attack vector.

SSL certifcates and credentials transmitted via SSL on affected servers
should be renewed, but other than that, there's not that much to worry
about as some people think.


Regards,
Luis Ressel

--Sig_/Z4_VfGO7dkrWzlcIEhmJpq.
Content-Type: application/pgp-signature; name=signature.asc
Content-Disposition: attachment; filename=signature.asc

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.22 (GNU/Linux)

iQJ8BAEBCgBmBQJTRXzcXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRBMjU3MDBFQTc5QkYzMkY4NEQzMTFGNDlD
NzE4OTFBNkEwRUZCN0U5AAoJEMcYkaag77fp7xUP/1KGnSz/nx9Bq2J1GYaTwNJy
bMo2QSPLMCH9FaixIDOuHEG50Cmrh6Rv1HNRM2DxnMRAklv+7G+qjvMZhXnF9XJd
eKdt3i5frKH2ZkUYxV9jldrgNCu/mJUXaNm7Zu0QpUC+Xn6Z6q7Sg5MPKO/HwCUh
bTZX6dc+t48Ynz4hE3MDEWcrVuH8njOZvZXwUqQ+T8Elrc9q9vlU5GP0lmN1pQ13
YVKXFwmzhKG5VWmUOY2aL/zx03xgmsCuH4Bta4XiqVTAVEkyA2pIkCH6hVU2zUcC
z+md0erf/AZnel2z43/thSVE9d1fV1m8gQSr2BHwV2Jwub328dXDYz7Z0N49g/EZ
+u7CjnbLGU1u2ptSdLaWWDDQrzii2fbUD9zEr1ymJxx6gPItUBirD54ZPfpEya/a
JFYnqooV1m+lDXtFhSx14uEoYPPd2zy3st3R69iLWC8Cy1GvI4qXzY7UDdJ2p14q
jxt/77V+xlBAQirghnx+S/C9VWltpHacyb0mnMwFJxCEvHg9NPLbToC3x5QTmA6g
/vAB433h4/c2e7orYEj1L8vz+K62c0xaMIBO1cv+630ehzFXCU+XSwImitfowf1T
NSnkBPBEySgiccP4mXOpwL6qVLQtIjGNcjC+4DZNXIcyr9BKor0s9n9OteHndniZ
DDb+dTE+7HW72Z29FwJ/
=FD2Q
-----END PGP SIGNATURE-----

--Sig_/Z4_VfGO7dkrWzlcIEhmJpq.--