Re: ssh-vulnkey and authorized_keys

2008-05-19 Thread Florian Weimer
* James Miller: >From what I understand ssh-vulnkey only check to see if a key is listed >in the blacklist (already compromised). Is there any way to >empirically test whether a key is vulnerable or not? All vulnerable keys should be contained in the blacklist. In other words, the blacklist sho

Re: ssh-vulnkey and authorized_keys

2008-05-19 Thread James Miller
Alex Samad wrote: On Thu, May 15, 2008 at 07:43:13PM -0400, Chris Adams wrote: On May 15, 2008, at 6:25 PM, Alex Samad wrote: is there away to check x509 certs with these tools ? Yes - the wiki has one (http://wiki.debian.org/SSLkeys) but you might prefer the openssl-blacklis

Re: ssh-vulnkey and authorized_keys

2008-05-17 Thread CaT
On Thu, May 15, 2008 at 09:03:24AM -0400, Noah Meyerhans wrote: > On Thu, May 15, 2008 at 11:08:58AM +0300, Mikko Rapeli wrote: > > I think, and hope, Debian openssh packages will be updated too. > > Yes, expect it within hours. I'm curious... is there a way to get ssh-vulnkey to print out the li

Re: Plans to deploy openssl-blacklist in Debian? (was: Re: ssh-vulnkey and authorized_keys)

2008-05-16 Thread Kees Cook
On Thu, May 15, 2008 at 09:31:25PM -0300, Felipe Augusto van de Wiel (faw) wrote: > Speaking about that, are there plans to deploy > openssl-blacklist in Debian as an official package? I'd be happy to get the Ubuntu blacklists into Debian -- honestly I haven't had time yet (travelling, Ubun

Re: Plans to deploy openssl-blacklist in Debian? (was: Re: ssh-vulnkey and authorized_keys)

2008-05-16 Thread Alberto Gonzalez Iniesta
On Thu, May 15, 2008 at 09:31:25PM -0300, Felipe Augusto van de Wiel (faw) wrote: > On 15-05-2008 20:43, Chris Adams wrote: > > > > On May 15, 2008, at 6:25 PM, Alex Samad wrote: > >> is there away to check x509 certs with these tools ? > > > > Yes - the wiki has one (http://wiki.debian.org/SSLk

Re: ssh-vulnkey and authorized_keys

2008-05-15 Thread Alex Samad
On Thu, May 15, 2008 at 07:43:13PM -0400, Chris Adams wrote: > > On May 15, 2008, at 6:25 PM, Alex Samad wrote: >> is there away to check x509 certs with these tools ? > > Yes - the wiki has one (http://wiki.debian.org/SSLkeys) but you might > prefer the openssl-blacklist package which Ubuntu pre

Plans to deploy openssl-blacklist in Debian? (was: Re: ssh-vulnkey and authorized_keys)

2008-05-15 Thread Felipe Augusto van de Wiel (faw)
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 On 15-05-2008 20:43, Chris Adams wrote: > > On May 15, 2008, at 6:25 PM, Alex Samad wrote: >> is there away to check x509 certs with these tools ? > > Yes - the wiki has one (http://wiki.debian.org/SSLkeys) but you might > prefer the openssl-blackl

Re: ssh-vulnkey and authorized_keys

2008-05-15 Thread Chris Adams
On May 15, 2008, at 6:25 PM, Alex Samad wrote: is there away to check x509 certs with these tools ? Yes - the wiki has one (http://wiki.debian.org/SSLkeys) but you might prefer the openssl-blacklist package which Ubuntu prepared: https://launchpad.net/ubuntu/+source/openssl-blacklist/ It

Re: ssh-vulnkey and authorized_keys

2008-05-15 Thread Alex Samad
On Thu, May 15, 2008 at 09:52:10AM +0200, Vladislav Kurz wrote: > Hello all, > > thanks for the quick response to the SSL bug and for providing ssh-vulnkey > and > dokuwd.pl. SSH-VULNKEY produces funny output when processing authorized_keys > with additional options like from="host", command="s

Re: ssh-vulnkey and authorized_keys

2008-05-15 Thread Noah Meyerhans
On Thu, May 15, 2008 at 11:08:58AM +0300, Mikko Rapeli wrote: > > It would be also helpful to print the line as dokuwd.pl does. > > Is there any repository with newer versions of ssh-vulnkey or dokuwd.pl ? > > Try the Ubuntu version which contains a fixed ssh-vulnkey ( > http://www.ubuntu.com/usn/

Re: ssh-vulnkey and authorized_keys

2008-05-15 Thread Mikko Rapeli
On Thu, May 15, 2008 at 09:52:10AM +0200, Vladislav Kurz wrote: > It would be also helpful to print the line as dokuwd.pl does. > Is there any repository with newer versions of ssh-vulnkey or dokuwd.pl ? Try the Ubuntu version which contains a fixed ssh-vulnkey ( http://www.ubuntu.com/usn/usn-612-

ssh-vulnkey and authorized_keys

2008-05-15 Thread Vladislav Kurz
Hello all, thanks for the quick response to the SSL bug and for providing ssh-vulnkey and dokuwd.pl. SSH-VULNKEY produces funny output when processing authorized_keys with additional options like from="host", command="something to do", no-agent-forwarding, etc... Instead of the file name it pr