There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
 
Tag Cloud
audio avg avg 8 backup bios boot browser bsod computer cpu crash css desktop driver drivers dvd email error excel explorer firefox firefox 3 freeze game graphics hard drive hardware help please hijackthis hjt install internet internet explorer itunes javascript keyboard lan laptop malware missing monitor msn network networking openoffice outlook outlook 2003 outlook express php popups problem router screen seo slow sound sp3 spyware trojan usb video virtumonde virus vista vundo windows windows vista windows xp wireless word
UNIX/Linux
Search
Search in:
 
Advanced Search
Tech Support Guy Forums > Operating Systems > UNIX/Linux >
Debian(affects Ubuntu also) Bug Leaves Private SSL/SSH Keys Guessable


HELLO AND WELCOME! Before you can post your question, you'll have to register -- it's completely free! Click here to join today! We highly recommend that you print a copy of our Guide for New Members. Enjoy!

 
Thread Tools
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
13-May-2008, 07:00 PM #1
Debian(affects Ubuntu also) Bug Leaves Private SSL/SSH Keys Guessable
Slashdot article here.

The solution? Upgrade OpenSSL and re-generate all your SSH and SSL keys. This problem not only affects Debian, but also all its derivatives, such as Ubuntu.

For Ubuntu, this means you must first update your repositories with:
$ sudo apt-get update
Note: you may possibly need to run the command twice to resolve duplicates)

Then do the upgrade.

-- Tom

P.S. Related Ubuntu Security Notices (dated May 13, 2008):
Ubuntu Security Notice USN-612-1 (SSL)
Ubuntu Security Notice USN-612-2 (SSH)
Ubuntu Security Notice USN-612-3 (VPN)
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein

Last edited by lotuseclat79 : 13-May-2008 07:12 PM.
tomdkat's Avatar
Computer Specs
Distinguished Member with 2,746 posts.
 
Join Date: May 2006
Location: S.F. Bay Area, CA
Experience: Intermediate
13-May-2008, 07:23 PM #2
Thanks for the link. I actually updated my Ubuntu system recently with this update.

I wonder what the OpenSSL maintainers think about this. The Slashdot article didn't mention anything about comments from the OpenSSL maintainers.

Peace...
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
14-May-2008, 06:46 AM #3
Ubuntu Security Notice USN-612-4. (dated May 14, 2008)

USN-612-1 fixed vulnerabilities in openssl. This update provides the corresponding updates for ssl-cert -- potentially compromised snake-oil SSL certificates will be regenerated.

-- Tom
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
16-May-2008, 11:23 PM #4
Ubuntu Security Notice USN-612-5.

=========================================================== Ubuntu Security Notice USN-612-5 May 14, 2008 openssh update https://launchpad.net/bugs/230029 http://www.ubuntu.com/usn/usn-612-2 =========================================================== A This security issue affects the following Ubuntu releases:
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.04:
openssh-client 1:4.3p2-8ubuntu1.4
openssh-client-udeb 1:4.3p2-8ubuntu1.4
Ubuntu 7.10:
openssh-client 1:4.6p1-5ubuntu0.5
openssh-client-udeb 1:4.6p1-5ubuntu0.5
Ubuntu 8.04 LTS:
openssh-client 1:4.7p1-8ubuntu1.2
openssh-client-udeb 1:4.7p1-8ubuntu1.2

After performing a standard system upgrade, users are encouraged to re-run ssh-vulnkey on their systems.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
16-May-2008, 11:26 PM #5
=========================================================== Ubuntu Security Notice USN-612-6 May 14, 2008 openvpn regression https://launchpad.net/bugs/230193 https://launchpad.net/bugs/230208 http://www.ubuntu.com/usn/usn-612-3 =========================================================== A This security issue affects the following Ubuntu releases:
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:
Ubuntu 7.04:
openssl-blacklist 0.1-0ubuntu0.7.04.2
openvpn 2.0.9-5ubuntu0.2
Ubuntu 7.10:
openssl-blacklist 0.1-0ubuntu0.7.10.2
openvpn 2.0.9-8ubuntu0.2
Ubuntu 8.04 LTS:
openssl-blacklist 0.1-0ubuntu0.8.04.2
openvpn 2.1~rc7-1ubuntu3.2

After a standard system upgrade you need to restart openvpn to effect the necessary changes.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
21-May-2008, 09:20 AM #6
=========================================================== Ubuntu Security Notice USN-612-7 May 20, 2008 openssh update CVE-2008-0166 ===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS: openssh-server 1:4.2p1-7ubuntu3.4

In general, a standard system upgrade is sufficient to effect the necessary changes.

Details follow:

USN-612-2 introduced protections for OpenSSH, related to the OpenSSL vulnerabilities addressed by USN-612-1. This update provides the corresponding updates for OpenSSH in Ubuntu 6.06 LTS. While the OpenSSL in Ubuntu 6.06 is not vulnerable, this update will block weak keys generated on systems that may have been affected themselves.

Original advisory details:

A weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH, OpenVPN and SSL certificates.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein
lotuseclat79's Avatar
Distinguished Member with 9,279 posts.
 
Join Date: Sep 2003
Location: -71.45091, 42.27841
21-May-2008, 04:31 PM #7
Ubuntu Security Notice USN-612-8.

===========================================================
Ubuntu Security Notice USN-612-8 May 21, 2008
openssl-blacklist update
http://www.ubuntu.com/usn/usn-612-1
http://www.ubuntu.com/usn/usn-612-3 ===========================================================
A security issue affects the following Ubuntu releases:

Ubuntu 6.06 LTS
Ubuntu 7.04
Ubuntu 7.10
Ubuntu 8.04 LTS

This advisory also applies to the corresponding versions of Kubuntu, Edubuntu, and Xubuntu.

The problem can be corrected by upgrading your system to the following package versions:

Ubuntu 6.06 LTS:
openssl-blacklist 0.1-0ubuntu0.6.06.1

Ubuntu 7.04: openssl-blacklist 0.1-0ubuntu0.7.04.4

Ubuntu 7.10: openssl-blacklist 0.1-0ubuntu0.7.10.4

Ubuntu 8.04 LTS: openssl-blacklist 0.1-0ubuntu0.8.04.4

In general, a standard system upgrade is sufficient to effect the necessary changes.

See first link above for further details.

-- Tom
__________________
The independence created by philosophical insight is - in my opinion - the mark of distinction between a mere artisan or specialist and a real seeker after truth. - Einstein wrote in 1944.

Some say knowledge is power, I say knowledge without action is powerless. - lotuseclat79

Don't confuse action with movement. - Hemingway to Gardner

Imagination is more important than knowledge. - Einstein

Last edited by lotuseclat79 : 21-May-2008 04:40 PM.
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are Off
Refbacks are Off

You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 07:10 AM.
Copyright © 1996 - 2008 TechGuy, Inc. All rights reserved.
Powered by vBulletin, Copyright © 2000 - 2008, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.1.0
Powered by Cermak Technologies, Inc.