LinuxQuestions.org
Register a domain and help support LQ
Go Back   LinuxQuestions.org > Forums > Linux > Linux - Distributions > Debian
User Name
Password
Debian This forum is for the discussion of Debian Linux.

Notices

Reply
 
Thread Tools
Old 05-14-2008, 09:17 AM   #1
farslayer
Guru
 
Registered: Oct 2005
Location: Willoughby, Ohio
Distribution: Debian Lenny / Squeeze / Sid
Posts: 7,213
Blog Entries: 5
Thanked: 246
How-To regenerate your SSH/SSL Keys - Debian Security Advisory 1571


[Log in to get rid of this advertisement]
I'm sure everyone else is working on this today no ?

Quote:
In Debian Security Advisory 1571 (New openssl packages fix predictable random number generator), the Debian Security Team disclosed a vulnerability in the openssl package that makes many cryptographic keys that are used for authentication (e.g. through SSH) or signing (e.g. web server certificates) potentially vulnerable.
Debian has posted a wiki HOW-TO for the key regeneration process.
http://wiki.debian.org/SSLkeys


I also think the following page will be of value once it has some content..
How-To implement Key Rollover in various Debian applications

//edit: The KEY ROLLOVER page has been updated with content.


//moderator.note: WD for posting, I stickied it for the moment.

Last edited by farslayer; 05-15-2008 at 02:38 PM..
farslayer is offline     Reply With Quote
Old 05-15-2008, 09:34 AM   #2
Telemachos
Member
 
Registered: May 2007
Distribution: Debian
Posts: 686
Thanked: 47
Here's a quick howto on generating new keys: http://www.softec.st/en/OpenSource/D...ateNewSsh.html
Telemachos is offline     Reply With Quote
Old 06-11-2008, 02:44 PM   #3
leibniz
LQ Newbie
 
Registered: Aug 2003
Posts: 11
Thanked: 0
I've read the security advisory and many how-tos, as well as the links in the post above.

However, when I regenerate the host keys, blacklisted keys are regenerated !

What's up with that ??

Code:
debian:~# rm /etc/ssh/ssh_host*
debian:~# dpkg-reconfigure openssh-server
Creating SSH2 RSA key; this may take some time ...
Creating SSH2 DSA key; this may take some time ...
Host key 39:82:2c:e2:b0:de:88:1e:49:ff:a4:33:XX:XX:XX:XX blacklisted (see ssh-vulnkey(1))
Host key 6e:92:88:e0:de:10:03:86:60:7c:1d:b1:XX:XX:XX:XX blacklisted (see ssh-vulnkey(1))
Restarting OpenBSD Secure Shell server: sshdHost key 39:82:2c:e2:b0:de:88:1e:49:ff:a4:33:XX:XX:XX:XX blacklisted (see ssh-vulnkey(1))
Host key 6e:92:88:e0:de:10:03:86:60:7c:1d:b1:3e:ee:27:c8 blacklisted (see ssh-vulnkey(1))
.
Thoughts?

EDIT: Etch / 4.0 stable, x86_64 version. Yes, I'm up2date.

Code:
debian:~# apt-get install openssh-server
Reading package lists... Done
Building dependency tree... Done
openssh-server is already the newest version.
0 upgraded, 0 newly installed, 0 to remove and 4 not upgraded.
debian:~# dpkg -l | grep -e openss
ii  openssh-blacklist                        0.1.1                                list of blacklisted OpenSSH RSA and DSA keys
ii  openssh-client                           4.3p2-9etch2                         Secure shell client, an rlogin/rsh/rcp repla
ii  openssh-server                           4.3p2-9etch2                         Secure shell server, an rshd replacement
ii  openssl                                  0.9.8c-4etch3                        Secure Socket Layer (SSL) binary and related
ii  ssl-cert                                 1.0.14                               Simple debconf wrapper for openssl
debian:~#

Last edited by leibniz; 06-11-2008 at 04:31 PM..
leibniz is offline     Reply With Quote
Old 06-12-2008, 09:08 PM   #4
leibniz
LQ Newbie
 
Registered: Aug 2003
Posts: 11
Thanked: 0
Never mind. I found the problem. Thanks anyway.
leibniz is offline     Reply With Quote
Old 06-12-2008, 10:09 PM   #5
farslayer
Guru
 
Registered: Oct 2005
Location: Willoughby, Ohio
Distribution: Debian Lenny / Squeeze / Sid
Posts: 7,213
Blog Entries: 5
Thanked: 246

Original Poster
would you care to share your solution so others may benefit if they run into the same issue ?
farslayer is offline     Reply With Quote
Old 07-07-2008, 07:51 AM   #6
mcs
LQ Newbie
 
Registered: Jan 2006
Posts: 10
Thanked: 0
Quote:
Originally Posted by leibniz View Post
Never mind. I found the problem. Thanks anyway.
Hi,
I have exactly the same problem. Could you please tell us your solution???

Thank you very much
Michael
mcs is offline     Reply With Quote
Old 07-07-2008, 10:11 AM   #7
leibniz
LQ Newbie
 
Registered: Aug 2003
Posts: 11
Thanked: 0
The problem is that the Debian system was too up to date.

Downgrade libssl (and linbssl-dev, an openssl if necessary) exactly to version 0.9.8c (as noted in the security advisory) version and it should then work.

You still have to regenerate keys, but at least the system will generate good keys.
leibniz is offline     Reply With Quote

Reply

Bookmarks


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Kernel Security Advisory? shadowsnipes Slackware 13 02-18-2008 12:51 PM
LXer: How not to respond to a security advisory LXer Syndicated Linux News 0 01-19-2006 06:31 PM
SSH Security and keys colabus Linux - Newbie 2 10-08-2004 02:15 PM
Slackware Security Advisory php Linux - Security 0 11-04-2003 10:44 PM
Red Hat Security Advisory Aussie Linux - Security 0 02-28-2002 01:12 AM


All times are GMT -5. The time now is 10:06 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
RSS2  LQ Podcast
RSS2  LQ Radio
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: @linuxquestions
Open Source Consulting | Domain Registration