Changes between Initial Version and Version 1 of News/KeysReset


Ignore:
Timestamp:
May 14, 2008, 8:41:00 PM (16 years ago)
Author:
Joseph F. Miklojcik III
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • News/KeysReset

    v1 v1  
     1
     2
     3= SSH Host Keys Reset =
     4During today's maintenance, the host keys for all outward-facing SSH servers (and possibly some others) were reset.  This change was part of a regular security update from the Debian maintainers, related to a recently found bug in the random number generator used to generate the previous host keys.  When you log in to ORBIT servers using SSH, you will probably see a message like the following.
     5
     6{{{
     7@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
     8@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
     9@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
     10IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
     11Someone could be eavesdropping on you right now (man-in-the-middle attack)!
     12It is also possible that the RSA host key has just been changed.
     13}}}
     14
     15To remedy this problem, you must either remove the lines for ORBIT servers from your {{{.ssh/known_hosts}}} file, or simply remove the {{{known_hosts}}} file and start the process of collecting host keys over again.
     16
     17We may likewise regenerate self-signed SSL certificates for secure web services, in which case you may get a stern warning from your browser that you will have to click through.
     18
     19As time allows, we will publish fingerprints for the new host keys.