Debian OpenSSL vulnerability

Discussion in 'Technical' started by quaker, May 15, 2008.

  quaker

    quaker

    Mar 28, 2004
    
    Hi John,

    I wanted to give you a heads up on a recent Debian OpenSSL vulnerability since you're using Debian on the new servers. The bug is relatively recent, so I'm not sure if your installation is already patched or not.

    Basically, all OpenSSL keys generated on a Debian-based system for the last two years are predictably random and thus vulnerable to attack. The site I linked has info on blacklisted keys and patches for the problem.

    Hopefully you aren't affected, but if so it should be relatively painless to fix.
  John Stone

    John Stone
    Owner

    Jan 20, 2004
    
    Oh, yeah, that was patched before the servers were even launched. That sort of thing is part of my regular job, so I'm on all kinds of security mailing lists. :)

