Debian vulnerability fallout

Travis Vachon <[email protected]>
Newsgroups gmane.org.osaf.cosmo,gmane.org.osaf.devel
Message-ID <[email protected]>
Hi folks

A serious bug with ssl key generation on debian systems was recently  
disclosed:

http://lists.debian.org/debian-security-announce/2008/msg00152.html

This effected nearly all of our servers, as we are primarily debian  
based. I've gone and updated the appropriate packages and regenerated  
host keys on the appropriate servers to limit our vulnerability, but  
several loose ends remain.

The most obvious consequence of this change will be a connection  
failure from ssh clients as a result of the new host keys. This  
problem can be fixed by clearing the appropriate entries in ~/.ssh/ 
known_hosts or the corresponding file on a windows machine.

Please let me know if you have any questions.

Also, please respond to this message on [email protected]  
instead of cross-posting replies.

Thanks,

Travis

_______________________________________________
cosmo-dev mailing list
[email protected]
http://lists.osafoundation.org/mailman/listinfo/cosmo-dev
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.