Detecting and replacing weak Debian OpenSSL keys
Summary
Manuel Schmitt warns customers about predictable keys from faulty Debian and Ubuntu versions and names check tools and replacement steps. Keys for OpenSSH and web server certificates, among others, were affected. The article points to the Debian tool vulnkey and other ways of checking.
Ideas
- A faulty distribution can weaken the keys of many dependent applications at once.
- A software update does not repair keys already generated with low entropy.
- Other systems also remain affected if they take over keys from a vulnerable Debian system.
- Customer communication must clearly separate who is affected, the limits and concrete ways of checking.
Insights
- A key carries its cryptographic origin with it across operating system boundaries.
- Supply chain errors in random number generation require an inventory and complete key rotation.
Facts
- An addendum makes clear that keys generated on Debian and used elsewhere also remain weak.
Recommendations
- Check all keys generated during the affected period against known lists of weak keys.
- Generate replacements on a secure system and revoke old certificates and access.
References
Read the original article on Hostblogger
Links to the original source and the Web Archive open in a new tab.