LWN.net Logo

One week of infrastructure issues

One week of infrastructure issues

Posted Aug 22, 2008 15:06 UTC (Fri) by Klavs (subscriber, #10563)
Parent article: One week of infrastructure issues

They finally leaked some information about what happened: 
https://www.redhat.com/archives/fedora-announce-list/2008...


(Log in to post comments)

One week of infrastructure issues

Posted Aug 22, 2008 21:18 UTC (Fri) by Brenner (subscriber, #28232) [Link]

Thanks.

Following the link we have http://www.redhat.com/security/data/openssh-blacklist.html, with
this excerpt:

[ In connection with the incident, the intruder was able to sign a small
number of OpenSSH packages relating only to Red Hat Enterprise Linux 4
(i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64
architecture only). ]

Does anyone knows how RH can be sure that _only_ the openssh packages listed in their
openssh-blacklist-1.0.sh checker have been signed by the intruder ?

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds