LWN.net Logo

One week of infrastructure issues

One week of infrastructure issues

Posted Aug 22, 2008 21:18 UTC (Fri) by Brenner (subscriber, #28232)
In reply to: One week of infrastructure issues by Klavs
Parent article: One week of infrastructure issues

Thanks.

Following the link we have http://www.redhat.com/security/data/openssh-blacklist.html, with
this excerpt:

[ In connection with the incident, the intruder was able to sign a small
number of OpenSSH packages relating only to Red Hat Enterprise Linux 4
(i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64
architecture only). ]

Does anyone knows how RH can be sure that _only_ the openssh packages listed in their
openssh-blacklist-1.0.sh checker have been signed by the intruder ?


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds