Natalian

Regenerate your .ssh/id_rsa key Debian users

Whoa, this security bug exposed by Luciano Bello (Ola!) is one of the worst I’ve ever seen.

Time to regenerate your key with the updated openssl 0.9.8c packages.

This seems to be Debian specific patch that caused this bug.

Further instructions should be posted on a special Debian key rollover page and the Debian wiki.

Update: key rollover is hard. :/ `ssh-vulnkey` was missing for awhile and only recent updates to openssh-server seem to regenerate the keys for me.

5 Responses to “Regenerate your .ssh/id_rsa key Debian users”

  1. Here we are now, entertain us » Ubuntu-everyone: Your ssh keys should be considered compromised Says:

    [...] Just read this and the security release. There is a checker provided in the security release note, but at any rate, your ssh key was probably generated incorrectly with respect to random time (mine were). Joy. [...]

  2. Luciano Says:

    Hola ;)

  3. Ken Bloom Says:

    If your SSH private key is old enough that it was generated before this bug was introduced, then it might be time to update it anyway.

  4. farslayer Says:

    Debian has posted a more complete instruction set for key regeneration..

    http://wiki.debian.org/SSLkeys

    this affects more than just SSH keys, quite along list actually.

  5. Timon Says:

    Well at least they didn’t leave their laptops unattended ;)

Leave a Reply