LWN.net Logo

Cryptographic weakness on Debian systems

Cryptographic weakness on Debian systems

Posted May 13, 2008 15:50 UTC (Tue) by IkeTo (subscriber, #2122)
In reply to: Cryptographic weakness on Debian systems by bcl
Parent article: Cryptographic weakness on Debian systems

It doesn't seem to be as simple.  If a program can catch vulnerable keys, it is probably a
very serious issue.  From one of the comments in http://www.dslreports.com/forum/r204743,
apparently the intent of not using uninitialized data for random number pool is good, but the
code is wrong enough that trim down seriously the amount of possible random numbers being
used, making it rather easy to get through.  So if you do have something using Debian, go
regenerate all SSH and Apache-SSL keys that are originally generated by these systems, quick.


(Log in to post comments)

Cryptographic weakness on Debian systems

Posted May 13, 2008 16:27 UTC (Tue) by IkeTo (subscriber, #2122) [Link]

Somehow the URL in my message is chopped...  Here's the correct one.

http://www.dslreports.com/forum/r20474302-Heads-Up-Debian...

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds