Re: [Hampshire] OpenSSL in Debian is broken

Top Page

Reply to this message
Author: Paul Tansom
Date:  
To: hampshire
Subject: Re: [Hampshire] OpenSSL in Debian is broken
** Nick Chalk <nick@???> [2008-05-15 22:46]:
> Paul Tansom <paul@???> wrote:
> > As a quick aside on that, I rather liked the
> > Ubuntu upgrade process compared to that used by
> > Debian. It's only a very minor difference, but
> > having the upgrade regenerate the server keys
> > for you was a nice touch.
>
> Debian started pushing that out around the middle
> of Wednesday.
>
> The downside of that approach is that it changed
> keys out of the sequence I'd adopted. I had to be
> very careful not to lock myself out of systems, or
> suffer hours of walking between sites. :-)

** end quote [Nick Chalk]

It hasn't made the Bytemark or UK mirrors yet then as these upgrades
happened today. This particular key change wouldn't lock you out of the
servers though, you'd simply have to delete the relevant entry in the
known_hosts file (or click yes from a PuTTY client message prompt). All
it does is warn you that the identity has changed (ask you if you are
happy that this should be the case if you're using PuTTY). I was quite
please to have the fallback of PuTTY keys that wouldn't be locked out to
give me an emergency fall back when refreshing the autorized_keys files
though. Thankfully I didn't need the fallback, but it didn't make it any
less welcome :)

--
Paul Tansom | Aptanet Ltd. | http://www.aptanet.com/ | 023 9238 0001
======================================================================
Registered in England | Company No: 4905028 | Registered Office:
Crawford House, Hambledon Road, Denmead, Waterlooville, Hants, PO7 6NU