  refused
join:2005-10-10 Redding, CA
| reply to evilghost Re: Heads Up: Debian OpenSSL RNG Vuln CVE-2008-0166
quote: Affected keys include SSH keys, OpenVPN keys, DNSSEC keys, and key material for use in X.509 certificates and session keys used in SSL/TLS connections. Keys generated with GnuPG or GNUTLS are not affected, though.
if generated with 0.9.8c-1 or after, yah they should probably be regenerated with a fixed version. the security bulletin says the old stable version Sarge wasn't affected, so depends where your ssh keys came from and what version they came from. better safe than sorry though. -- "Ubuntu" - an African word, meaning "Slackware is too hard for me". |