Bug#831302: Vagrant box allows root login with insecure default key

2016-07-14 Thread Felix Dreissig
On 14 Jul 2016, at 15:16, Emmanuel Kasper wrote: > A fix for this issue has been committed yesterday, see > http://anonscm.debian.org/cgit/cloud/debian-vm-templates.git/commit/ Whoa, that's good timing I guess. Thanks and regards, Felix

Bug#831302: Vagrant box allows root login with insecure default key

2016-07-14 Thread Emmanuel Kasper
On 07/14/2016 03:04 PM, Felix Dreissig wrote: > Package: cloud.debian.org > Severity: normal > Tags: security > > Dear Debian cloud maintainers, > > in the "jessie64" Vagrant box (and presumably the other Vagrant boxes as > well), the insecure Vagrant default SSH key is installed as authorized ke

Bug#831302: Vagrant box allows root login with insecure default key

2016-07-14 Thread Felix Dreissig
Package: cloud.debian.org Severity: normal Tags: security Dear Debian cloud maintainers, in the "jessie64" Vagrant box (and presumably the other Vagrant boxes as well), the insecure Vagrant default SSH key is installed as authorized key for the root user and root login using SSH keys is permitted