LWN.net Logo

Cryptographic weakness on Debian systems

Cryptographic weakness on Debian systems

Posted May 13, 2008 14:44 UTC (Tue) by maks (subscriber, #32426)
In reply to: Cryptographic weakness on Debian systems by elanthis
Parent article: Cryptographic weakness on Debian systems

read the announcement gpg is not affected.

openssl is bad enough!


(Log in to post comments)

Cryptographic weakness on Debian systems

Posted May 13, 2008 17:43 UTC (Tue) by neiljerram (subscriber, #12005) [Link]

Thanks everyone for your answers.  I see now that GPG keys are in a separate space from the
ssh keys, and unaffected.

Cryptographic weakness on Debian systems

Posted May 13, 2008 21:03 UTC (Tue) by lab (subscriber, #51153) [Link]

Hmmm.. Can I just ask a stupid question - how come the OpenSSH package in Ubuntu is affected,
but not in Debian?

http://www.ubuntu.com/usn/usn-612-2

"A weakness has been discovered in the random number generator used by OpenSSL on Debian and
Ubuntu systems. As a result of this weakness, certain encryption keys are much more common
than they should be, such that an attacker could guess the key through a brute-force attack
given minimal knowledge of the system. This particularly affects the use of encryption keys in
OpenSSH."

Cryptographic weakness on Debian systems

Posted May 14, 2008 0:16 UTC (Wed) by cjwatson (subscriber, #7322) [Link]

It's affected in exactly the same sense (i.e. only as collateral damage) in Debian too;
unfortunately problems due to the advisory itself have made it difficult to publish an OpenSSH
update in Debian, but it should be on its way soon.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds