Re: Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-06-01 Thread Amos Shapira
On Sun, Jun 1, 2008 at 10:14 PM, Tzafrir Cohen <[EMAIL PROTECTED]> wrote: > On Sun, Jun 01, 2008 at 09:49:34PM +1000, Amos Shapira wrote: >> On Sun, Jun 1, 2008 at 3:56 PM, Ira Abramov > >> > make sure you did dist-upgrade and not just upgrade. I think without it, >> >> Why "dist-upgrade"? It's a s

Re: Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-06-01 Thread Tzafrir Cohen
On Sun, Jun 01, 2008 at 09:49:34PM +1000, Amos Shapira wrote: > On Sun, Jun 1, 2008 at 3:56 PM, Ira Abramov > > make sure you did dist-upgrade and not just upgrade. I think without it, > > Why "dist-upgrade"? It's a security fix for the same distro (Debian Etch). The "dist-upgrade" is due to the

Re: Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-06-01 Thread Yedidyah Bar-David
On Sun, Jun 01, 2008 at 09:49:34PM +1000, Amos Shapira wrote: > Why "dist-upgrade"? It's a security fix for the same distro (Debian Etch). Contrary to common wisdom (and intuition), dist-upgrade is not related to upgrading between distros. The difference between it and upgrade is that upgrade will

Re: Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-06-01 Thread Amos Shapira
On Sun, Jun 1, 2008 at 3:56 PM, Ira Abramov <[EMAIL PROTECTED]> wrote: > Quoting Amos Shapira, from the post of Fri, 30 May: >> >> All packages on my Debian Etch desktop are up to date, "vulnkeys" >> found old vulnerable keys and I cleaned them up (also from other >> systems). >> >> BUT - I can't g

Re: Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-05-31 Thread Ira Abramov
Quoting Amos Shapira, from the post of Fri, 30 May: > > All packages on my Debian Etch desktop are up to date, "vulnkeys" > found old vulnerable keys and I cleaned them up (also from other > systems). > > BUT - I can't generate good keys on Debian any more: that's odd. are you sure you are not r

Debian still generated bad ssh keys (was: Re: SSH vulnerable key package?

2008-05-29 Thread Amos Shapira
(Sent to Noam in private by mistake - sorry Noam) On Fri, May 16, 2008 at 7:06 PM, Noam Rathaus <[EMAIL PROTECTED]> wrote: > The new ssl and ssh packages don't work if they are given known vulnerable > > During upgrade/update they upgrade/replace bad keys All packages on my Debian Etch desktop ar