There has been a recent security vulnerability in Debian's openssl
package that affects us in several different ways.  The technical
details of the vulnerability, along with how to fix it, are documented
at:

 - <http://www.ubuntu.com/usn/usn-612-2>
 - <http://www.us.debian.org/security/2008/dsa-1576>

As a result, we have regenerated the SSH keys for all of our systems
(deleuze, mire, krunk, and outpost).  Please log out of any open ssh
sessions to these systems.  The next time you log in, ssh may refuse to
connect due to the key changing.  To fix this, remove the relevant
entries in your ~/.ssh/known_hosts file -- the line number of the bad
entry will be provided in the error message.  You may need to do this
for two different entries.

Additionally, I have regenerated our CA certificate key, and have
revoked and regenerated all keys that were generated with it.  If you
have previously used our CA certificate key to enable browsing our
websites, checking email via SSL IMAP, checking email through SSL POP3,
and/or sending email through deleuze.hcoop.net, then you will need to
remove the old CA key from your list of trusted certificates and install
the new key from <http://hcoop.net/ca/ca.crt>.  If you have not
previously our CA key, then there is no need to install it: just remove
the certificates for any authenticated HCoop site that you have visited
in your web browser, such as members.hcoop.net, ssh.hcoop.net,
bugzilla.hcoop.net, mail.hcoop.net, mail2.hcoop.net, and
rcube.hcoop.net.

If you are using SSL IMAP or SSL POP3, you will also need to change the
server name from deleuze.hcoop.net to mail.hcoop.net.  This is an
unrelated change that we lumped together with the rest.

-- 
Michael Olson
HCoop System Administrator
http://hcoop.net/

Attachment: pgpZJ3H75Hcbl.pgp
Description: PGP signature

_______________________________________________
HCoop-Announce mailing list
[email protected]
https://lists.hcoop.net/listinfo/hcoop-announce

Reply via email to