  jdong Eat A Beaver, Save A Tree. Premium join:2002-07-09 Rochester, MI clubs:  
| reply to jdong Re: (SERIOUS) Debian/Ubuntu OpenSSL/OpenSSH weak keys
Sorry, posted this in a hurry. So, in plain english:
(1) All SSH servers installed on Debian/Ubuntu systems since the described date should have their host keys regenerated after the update.
(2) Any SSH private keys (RSA) you generated on affected systems must also be regenerated.
(3) If you've communicated with affected systems, you must assume that those communications could've been eavesdropped/MITMed.
This is really a nasty vulnerability. -- Ubuntu MOTU Developer and Forums Council |