Re: OpenSSH bug workaround

2002-06-26 Thread Anthony E. Greene
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 26-Jun-2002/09:38 -0700, Gordon Messmer <[EMAIL PROTECTED]> wrote: >On Wed, 2002-06-26 at 09:05, M A Young wrote: >> In case people haven't seen it, according to >> http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20584 >> You can

Re: OpenSSH bug workaround *NOT NEEDED*

2002-06-26 Thread Bill Carlson
On Wed, 26 Jun 2002, Bill Carlson wrote: > I haven't grabbed a SRPM yet to absolutely verify this, but I will do so > and I would expect an announcement from Redhat soon as well. Verified, openssh-3.1p1-3 does not use BSD_AUTH or S/KEY. >From the spec file: %configure \ --sysconfd

Re: OpenSSH bug workaround *NOT NEEDED*

2002-06-26 Thread Bill Carlson
On 26 Jun 2002, Gordon Messmer wrote: > On Wed, 2002-06-26 at 09:05, M A Young wrote: > > In case people haven't seen it, according to > > http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20584 > > You can secure your system from the recent ssh security hole by turning > > off "c

Re: OpenSSH bug workaround

2002-06-26 Thread Gordon Messmer
On Wed, 2002-06-26 at 09:05, M A Young wrote: > In case people haven't seen it, according to > http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=20584 > You can secure your system from the recent ssh security hole by turning > off "challenge-response" authentication and restarting