Debian/Ubuntu - OpenSSH 보안 위험

lacovnk의 이미지

http://www.ubuntu.com/usn/usn-612-2

Quote:
weakness has been discovered in the random number generator used by OpenSSL on Debian and Ubuntu systems. As a result of this weakness, certain encryption keys are much more common than they should be, such that an attacker could guess the key through a brute-force attack given minimal knowledge of the system. This particularly affects the use of encryption keys in OpenSSH.

1. Install the security updates
2. Update OpenSSH known_hosts files
3. Check all OpenSSH user keys
4. Regenerate any affected user keys
5. Update authorized_keys files (if necessary)

알아서 openssh-blacklist 등 패키지 설치하면서, 호스트키를 재생성하는군요. 예전 호스트키를 갖고 있는 클라이언트들이 당황하겠습니다.