|
|
Log in / Subscribe / Register

One week of infrastructure issues

One week of infrastructure issues

Posted Aug 22, 2008 15:06 UTC (Fri) by Klavs (guest, #10563)
Parent article: One week of infrastructure issues

They finally leaked some information about what happened: 
https://www.redhat.com/archives/fedora-announce-list/2008...


to post comments

One week of infrastructure issues

Posted Aug 22, 2008 21:18 UTC (Fri) by Brenner (guest, #28232) [Link]

Thanks.

Following the link we have http://www.redhat.com/security/data/openssh-blacklist.html, with
this excerpt:

[ In connection with the incident, the intruder was able to sign a small
number of OpenSSH packages relating only to Red Hat Enterprise Linux 4
(i386 and x86_64 architectures only) and Red Hat Enterprise Linux 5 (x86_64
architecture only). ]

Does anyone knows how RH can be sure that _only_ the openssh packages listed in their
openssh-blacklist-1.0.sh checker have been signed by the intruder ?


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds