There has been a recent security vulnerability in Debian's openssl package that affects us in several different ways. The technical details of the vulnerability, along with how to fix it, are documented at:
- <http://www.ubuntu.com/usn/usn-612-2> - <http://www.us.debian.org/security/2008/dsa-1576> As a result, we have regenerated the SSH keys for all of our systems (deleuze, mire, krunk, and outpost). Please log out of any open ssh sessions to these systems. The next time you log in, ssh may refuse to connect due to the key changing. To fix this, remove the relevant entries in your ~/.ssh/known_hosts file -- the line number of the bad entry will be provided in the error message. You may need to do this for two different entries. Additionally, I have regenerated our CA certificate key, and have revoked and regenerated all keys that were generated with it. If you have previously used our CA certificate key to enable browsing our websites, checking email via SSL IMAP, checking email through SSL POP3, and/or sending email through deleuze.hcoop.net, then you will need to remove the old CA key from your list of trusted certificates and install the new key from <http://hcoop.net/ca/ca.crt>. If you have not previously our CA key, then there is no need to install it: just remove the certificates for any authenticated HCoop site that you have visited in your web browser, such as members.hcoop.net, ssh.hcoop.net, bugzilla.hcoop.net, mail.hcoop.net, mail2.hcoop.net, and rcube.hcoop.net. If you are using SSL IMAP or SSL POP3, you will also need to change the server name from deleuze.hcoop.net to mail.hcoop.net. This is an unrelated change that we lumped together with the rest. -- Michael Olson HCoop System Administrator http://hcoop.net/
pgpZJ3H75Hcbl.pgp
Description: PGP signature
_______________________________________________ HCoop-Announce mailing list [email protected] https://lists.hcoop.net/listinfo/hcoop-announce
