Debian vulnerability fallout
Travis Vachon <[email protected]>
| Newsgroups | gmane.org.osaf.cosmo,gmane.org.osaf.devel |
|---|---|
| Message-ID | <[email protected]> |
Hi folks A serious bug with ssl key generation on debian systems was recently disclosed: http://lists.debian.org/debian-security-announce/2008/msg00152.html This effected nearly all of our servers, as we are primarily debian based. I've gone and updated the appropriate packages and regenerated host keys on the appropriate servers to limit our vulnerability, but several loose ends remain. The most obvious consequence of this change will be a connection failure from ssh clients as a result of the new host keys. This problem can be fixed by clearing the appropriate entries in ~/.ssh/ known_hosts or the corresponding file on a windows machine. Please let me know if you have any questions. Also, please respond to this message on [email protected] instead of cross-posting replies. Thanks, Travis _______________________________________________ cosmo-dev mailing list [email protected] http://lists.osafoundation.org/mailman/listinfo/cosmo-dev