Re: Fwd: Implications of Debian OpenSSL flaw for MIT PKINIT

2008-05-16 Thread Russ Allbery
Joey Hess <[EMAIL PROTECTED]> writes: > Could you summarise the changes that should be made to the key-rollover > page (or provide a patch)? Absolutely. Here's a patch that I think captures the essence and the important details. --- rollover.html.orig 2008-05-16 15:07:35.0 -0700 +++ ro

Re: Fwd: Implications of Debian OpenSSL flaw for MIT PKINIT

2008-05-16 Thread Joey Hess
Russ Allbery wrote: > Here is the confirmation and analysis from upstream, forwarded with > permission. Another person (not publicly, so I won't mention his name > just in case he didn't wish to be mentioned) also pointed out that since > you can break the encryption used to protect the TGT, you c

Fwd: Implications of Debian OpenSSL flaw for MIT PKINIT

2008-05-16 Thread Russ Allbery
Here is the confirmation and analysis from upstream, forwarded with permission. Another person (not publicly, so I won't mention his name just in case he didn't wish to be mentioned) also pointed out that since you can break the encryption used to protect the TGT, you can also then use that Kerber