login
Header Space

 
 

Re: Debian libssl security (OpenSSH safe?)

Score:
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Date: Thursday, May 15, 2008 - 5:02 am

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Thursday, 15.05.2008 at 07:11 +0200, Otto Moerbeek wrote:


For info

Debian (and thus also Ubuntu) have released updated openssh packages
which include a new tool called ssh-vulnkey which can be used to check
the running system[1] for vulnerable keys: ssh-vulnkey works similarly
to the Perl script in the Debian announcement.  The package has also had
an additional option added to sshd_config which blacklists (i.e. stops
use of) these vulnerable keys.  Once updated, Debian and Ubuntu systems
will reject connections based on these vulnerable keys.

One of my machines at home is an Ubuntu laptop and my OpenBSD box had a
copy of its public key in ~/.ssh/authorized_keys so that logging into it
is simpler from the laptop - if this box were exposed to the world, then
it would only take 32,000 attempts to get into it, if my username is
known.  I've removed the vulnerable public key from the OpenBSD box now.

I believe the original assessment was correct: *all* systems running SSH
ought to check for these vulnerable keys, not just those systems running
Debian or derivatives.  Yes, it's Debian's "fault", but we all have to
manage the consequences.  If only Debian and Ubuntu's openssh is
updated, then they will be *more* secure than non-updated OpenBSD,
Solaris, Red Hat Linux etc.

Cheers,

Dave.

[1] It checks host keys and also the contents of authorized_keys

- -- 
Dave Ewart
iD8DBQFIK/wbbpQs/WlN43ARAnKvAJ4pYbbhW4pCYvp7hqApTCqr43BWmwCg864Q
xBTY5bfIl4KLiSsYsDMplS8=
=5mhX
-----END PGP SIGNATURE-----
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
Debian libssl security (OpenSSH safe?), Juan Miscaro, (Tue May 13, 11:37 am)
Re: Debian libssl security (OpenSSH safe?), Sean Malloy, (Tue May 13, 12:14 pm)
Re: Debian libssl security (OpenSSH safe?), Gabriel Linder, (Wed May 14, 3:41 am)
Re: Debian libssl security (OpenSSH safe?), Otto Moerbeek, (Wed May 14, 7:22 am)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 7:24 am)
Re: Debian libssl security (OpenSSH safe?), raven, (Wed May 14, 7:45 pm)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Wed May 14, 8:22 pm)
Re: Debian libssl security (OpenSSH safe?), Ben Calvert, (Wed May 14, 8:30 pm)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 10:22 pm)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Wed May 14, 10:43 pm)
Re: Debian libssl security (OpenSSH safe?), Otto Moerbeek, (Thu May 15, 1:11 am)
Re: Debian libssl security (OpenSSH safe?), Dave Ewart, (Thu May 15, 5:02 am)
Re: Debian libssl security (OpenSSH safe?), Tim Post, (Thu May 15, 5:44 am)
Re: Debian libssl security (OpenSSH safe?), Darrin Chandler, (Thu May 15, 9:31 am)
Re: Debian libssl security (OpenSSH safe?), Tim Post, (Fri May 16, 2:51 am)
Re: Debian libssl security (OpenSSH safe?), Ted Unangst, (Wed May 14, 11:10 pm)
Re: Debian libssl security (OpenSSH safe?), Jussi Peltola, (Wed May 14, 8:53 pm)
Re: Debian libssl security (OpenSSH safe?), Douglas A. Tutty, (Thu May 15, 9:52 am)
Re: Debian libssl security (OpenSSH safe?), Marc Espie, (Tue May 13, 1:00 pm)
speck-geostationary