[Pkg-openssl-devel] [SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator

Christoph Martin martin at uni-mainz.de
Tue May 20 14:48:43 UTC 2008


Hi Alberto,

Alberto Gonzalez Iniesta schrieb:
> On Mon, May 19, 2008 at 01:13:46PM +0200, Christoph Martin wrote:
>> The Ubuntu openssl maintainers released a openssl-blacklist equivalent
>> to the openssh-blacklist package. It includes a blacklist with
>> compromised openssl key hashes and a program with a openssl-vulnkey
>> program suitable to test your openssl key files.
>>
>> I think it would be a good think to coordinate the work between debian
>> and ubuntu and to incorporate this package into debian main.
> 
> The coordination has already started and the package will be in Debian
> soon.

I am somewhat irritated. Who is building the package and who is
coordinating with whom? I am on the
pkg-openssl-devel at lists.alioth.debian.org list (and one of the
Maintainers of Debian openssl) and did not get any message about this.

So please coordinate with the Debian openssl maintainers.

Christoph

-- 
============================================================================
Christoph Martin, Leiter der EDV der Verwaltung, Uni-Mainz, Germany
 Internet-Mail:  Christoph.Martin at Verwaltung.Uni-Mainz.DE
  Telefon: +49-6131-3926337
      Fax: +49-6131-3922856

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 252 bytes
Desc: OpenPGP digital signature
Url : http://lists.alioth.debian.org/pipermail/pkg-openssl-devel/attachments/20080520/c14a2bb0/attachment.pgp 


More information about the Pkg-openssl-devel mailing list