Re: Regeneration of gpg keys after HeartBleed

Matthias Niethammer <[email protected]> Fri, 11 Apr 2014 01:45:32 +0200
Newsgroups gmane.linux.gentoo.security
Message-ID <CAFfC8aZZi_zR+E_BnJSVANYC+AFqxfnJzbwmp-dU9_fiOX6HhA@mail.gmail.com>
--001a11336dee7fd71704f6b8d2b7
Content-Type: text/plain; charset=UTF-8

Hi Chris & List,

f.y.i.: the post you linked got retracted by the author because as he
states missread the code interpreted it in a wrong way.

Best regards,
Matthias Niethammer



2014-04-09 21:21 GMT+02:00 Chris Frederick <[email protected]>:

> On 04/09/14 12:01, Luis Ressel wrote:
>
>> On Wed, 09 Apr 2014 18:39:41 +0200
>> Jo <[email protected]> wrote:
>>
>>  I'm a bit concerned about the signing keys of the portage tree
>>> releases, I know that gpg is not the same as openssl but keeping in
>>> mind that SSH, VPN, HTTPS keys might be compromised for two years,
>>> don't you think it's a healthy measure to generate a new pair of keys?
>>>
>>
>> SSL certifcates and credentials transmitted via SSL on affected servers
>> should be renewed, but other than that, there's not that much to worry
>> about as some people think.
>>
>
> It's worth a trip to http://blog.erratasec.com/
> 2014/04/why-heartbleed-doesnt-leak-private-key.html
>
> It's not impossible that ssl keys could be compromised, but in most cases
> it shouldn't happen.
>
> Chris
>
>

--001a11336dee7fd71704f6b8d2b7
Content-Type: text/html; charset=UTF-8

<div dir="ltr">Hi Chris &amp; List,<div><br></div><div>f.y.i.: the post you linked got retracted by the author because as he states missread the code interpreted it in a wrong way.</div><div><br></div><div>Best regards,</div>

<div>Matthias Niethammer</div><div><br></div><div class="gmail_extra"><br><br><div class="gmail_quote">2014-04-09 21:21 GMT+02:00 Chris Frederick <span dir="ltr">&lt;<a href="mailto:[email protected]" target="_blank">[email protected]</a>&gt;</span>:<br>


<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>On 04/09/14 12:01, Luis Ressel wrote:<br>
</div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div>
On Wed, 09 Apr 2014 18:39:41 +0200<br>
Jo &lt;<a href="mailto:[email protected]" target="_blank">[email protected]</a>&gt; wrote:<br>
<br>
<blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
I&#39;m a bit concerned about the signing keys of the portage tree<br>
releases, I know that gpg is not the same as openssl but keeping in<br>
mind that SSH, VPN, HTTPS keys might be compromised for two years,<br>
don&#39;t you think it&#39;s a healthy measure to generate a new pair of keys?<br>
</blockquote>
<br></div><div>
SSL certifcates and credentials transmitted via SSL on affected servers<br>
should be renewed, but other than that, there&#39;s not that much to worry<br>
about as some people think.<br>
</div></blockquote>
<br>
It&#39;s worth a trip to <a href="http://blog.erratasec.com/2014/04/why-heartbleed-doesnt-leak-private-key.html" target="_blank">http://blog.erratasec.com/<u></u>2014/04/why-heartbleed-doesnt-<u></u>leak-private-key.html</a><br>



<br>
It&#39;s not impossible that ssl keys could be compromised, but in most cases it shouldn&#39;t happen.<span><font color="#888888"><br>
<br>
Chris<br>
<br>
</font></span></blockquote></div><br></div></div>

--001a11336dee7fd71704f6b8d2b7--