openssl

Open-Source Security Idiots

Digg Linux/Unix upcoming  Thu, 08/28/2008 - 10:39

Sometimes, people do such stupid things that words almost fail me. That’s the case with a Debian ‘improvement’ to OpenSSL that rendered this network security program next to useless in Debian, Ubuntu and other related Linux distributions.


 

Debian needs some serious commit review

Digg Linux/Unix upcoming  Fri, 07/11/2008 - 19:11

You’ve probably heard by now about the gaping hole in keys generated by Debian’s OpenSSL. If not, the summary is that your SSH keys and SSL certs were selected from a fixed pool of 215 (32,767) possibilities, and are thus easy to brute-force over the network.

If you have any keys generated on a Debian system, you need to immediately replace them or


 

Installing And Configuring ProFTPd with OpenSSL on Debian Etch

Debian-News.net  Fri, 05/30/2008 - 13:18

FTP has been the standard way to do this for as long as I can remember so to make my server as useful as possible Installing an FTP server is a very important program.

For the purpose of my server I will be using ProFTPD.


 

Distribution Release: PelicanHPC 1.5.1

DistroWatch.com: News  Tue, 05/20/2008 - 10:20

Michael Creel has announced the release of PelicanHPC 1.5.1 (formerly PrallelKnoppix), a Debian-based live CD designed to make it simple to set up a high-performance computing cluster.

This updates fixes the recent "predictable randomness" vulnerability in Debian's build of OpenSSL and all users are strongly encouraged to upgrade.....


 

Linux gets security black eye

Topix - Linux  Fri, 05/16/2008 - 15:31

As has been widely reported, the maintainers of Debian's OpenSSL packages made some errors recently that have potentially compromised the security of any sshd-equipped system used remotely by Debian users.


 

Massive flaw in Debian Linux's Open SSL. Affects thousands.

Digg Linux/Unix upcoming  Fri, 05/16/2008 - 13:17

This is just a little more than a "oops" flaw. This is a huge mistake that WILL affect you Ubuntu users as well!"Moore documents the cause of the bug and explains how easily attackers can create every possible key the flawed OpenSSL implementation can generate."


 

Researcher: Debian cryptography may be flawed

Topix - Unix  Fri, 05/16/2008 - 07:33

A security researcher has warned that cryptographic keys generated in the last year and a half using Debian OpenSSL may be invalid.


 

Major Crypto Bug Cripples Ubuntu Linux Security

Topix - Linux  Thu, 05/15/2008 - 15:52

OpenSSL is a very important package that brought public key cryptography to the masses; prior to OpenSSL, https web sites were expensive and complicated to build.


 

With the Quickness: HD Moore sets new land speed record with...

Topix - Linux  Thu, 05/15/2008 - 00:43

So, for those who haven't heard, a Debian packager modified the source used for OpenSSL on Debian based systems to remove the seed used for PRNG used when creating SSL keys.


 

Weakness in OpenSSL on Debian and Ubuntu Discovered

Digg Linux/Unix upcoming  Wed, 05/14/2008 - 22:05

If you are using Debian or any other distro that's based on it (such as Ubuntu), you are advised to update, because a weakness was discovered in the random number generator used by OpenSSL.

To fix the problem, you will have to update the OpenSSL packages and regenerate any private keys made on Debian (Etch or newer) or Ubuntu 7.04 and higher.