DSA/DSS keys and DSA 1576-1/CVE-2008-0166.
\ Kurt Roeckx (14 May 2008)
. \ Mario 'BitKoenig' Holbe (14 May 2008)
. \ Andrew McGlashan (15 May 2008)
. . \ Mario 'BitKoenig' Holbe (15 May 2008)
. \ Mario 'BitKoenig' Holbe (15 May 2008)

2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?
2 msgdowkd.pl - how the blacklist data is generated ?
9 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
48 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
11 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security
37 msgsecuring server
1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:DSA/DSS keys and DSA 1576-1/CVE-2008-0166.
Group:Debian-security
From:Kurt Roeckx
Date:14 May 2008


 
There seems to be some confusion going around about the effect of the
openssl issue on dsa keys.

>From what I understand, when using a DSA key and the random number used
to generate a signature is known, predictable, or used twice the private
key can be calculated.

So it seem to me that if a DSA key was ever used on a system which had
that openssl version and openssl was used to generate that random
number, you have to revoke that DSA key. Even if that DSA key was
generated with a good version of openssl.

So my question is, does either the ssh client or server use openssl to
generate the random number used to sign?


Kurt


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com