Re: Regeneration of gpg keys after HeartBleed
Matthias Niethammer <[email protected]> Fri, 11 Apr 2014 01:45:32 +0200
| Newsgroups | gmane.linux.gentoo.security |
|---|---|
| Message-ID | <CAFfC8aZZi_zR+E_BnJSVANYC+AFqxfnJzbwmp-dU9_fiOX6HhA@mail.gmail.com> |
--001a11336dee7fd71704f6b8d2b7 Content-Type: text/plain; charset=UTF-8 Hi Chris & List, f.y.i.: the post you linked got retracted by the author because as he states missread the code interpreted it in a wrong way. Best regards, Matthias Niethammer 2014-04-09 21:21 GMT+02:00 Chris Frederick <[email protected]>: > On 04/09/14 12:01, Luis Ressel wrote: > >> On Wed, 09 Apr 2014 18:39:41 +0200 >> Jo <[email protected]> wrote: >> >> I'm a bit concerned about the signing keys of the portage tree >>> releases, I know that gpg is not the same as openssl but keeping in >>> mind that SSH, VPN, HTTPS keys might be compromised for two years, >>> don't you think it's a healthy measure to generate a new pair of keys? >>> >> >> SSL certifcates and credentials transmitted via SSL on affected servers >> should be renewed, but other than that, there's not that much to worry >> about as some people think. >> > > It's worth a trip to http://blog.erratasec.com/ > 2014/04/why-heartbleed-doesnt-leak-private-key.html > > It's not impossible that ssl keys could be compromised, but in most cases > it shouldn't happen. > > Chris > > --001a11336dee7fd71704f6b8d2b7 Content-Type: text/html; charset=UTF-8 <div dir="ltr">Hi Chris & List,<div><br></div><div>f.y.i.: the post you linked got retracted by the author because as he states missread the code interpreted it in a wrong way.</div><div><br></div><div>Best regards,</div> <div>Matthias Niethammer</div><div><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">2014-04-09 21:21 GMT+02:00 Chris Frederick <span dir="ltr"><<a href="mailto:[email protected]" target="_blank">[email protected]</a>></span>:<br> <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>On 04/09/14 12:01, Luis Ressel wrote:<br> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div> On Wed, 09 Apr 2014 18:39:41 +0200<br> Jo <<a href="mailto:[email protected]" target="_blank">[email protected]</a>> wrote:<br> <br> <blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"> I'm a bit concerned about the signing keys of the portage tree<br> releases, I know that gpg is not the same as openssl but keeping in<br> mind that SSH, VPN, HTTPS keys might be compromised for two years,<br> don't you think it's a healthy measure to generate a new pair of keys?<br> </blockquote> <br></div><div> SSL certifcates and credentials transmitted via SSL on affected servers<br> should be renewed, but other than that, there's not that much to worry<br> about as some people think.<br> </div></blockquote> <br> It's worth a trip to <a href="http://blog.erratasec.com/2014/04/why-heartbleed-doesnt-leak-private-key.html" target="_blank">http://blog.erratasec.com/<u></u>2014/04/why-heartbleed-doesnt-<u></u>leak-private-key.html</a><br> <br> It's not impossible that ssl keys could be compromised, but in most cases it shouldn't happen.<span><font color="#888888"><br> <br> Chris<br> <br> </font></span></blockquote></div><br></div></div> --001a11336dee7fd71704f6b8d2b7--