What are the characteristics of a vulnerable DSA key?

What are the characteristics of a vulnerable DSA key?

Characteristics of potentially vulnerable keys: Generated using ‘openssl’, ‘ssh-keygen’, or ‘openvpn –keygen’ (GnuPG and GNUTLS are not affected) In addition, any DSA key must be considered compromised if it has been used on a machine with a ‘bad’ OpenSSL.

Which is vulnerable to an offline OpenSSL attack?

Any tools that relied on OpenSSL’s PRNG to secure the data they transferred may be vulnerable to an offline attack. Any SSH server that uses a host key generated by a flawed system is subject to traffic decryption and a man-in-the-middle attack would be invisible to the users.

Is the Debian SSH key vulnerable to OpenSSL?

This flaw is ugly because even systems that do not use the Debian software need to be audited in case any key is being used that was created on a Debian system. The Debian and Ubuntu projects have released a set of tools for identifying vulnerable keys. You can find these listed in the references section below.

Are there blacklists of vulnerable keys in unstable?

Blacklists of vulnerable keys available in unstable: There is a web-based check available at https://secure.comodo.net/utilities/decodeCSR.html which will identify a CSR with a weak key. This page uses the data from openssl-blacklist.

Is there a blacklist of weak SSH keys?

Updated packages for openssh that have a blacklist of known weak keys are now available; see DSA 1576 for more information. Installing these packages on hosts with weak keys will cause the ssh server to regenerate its keys. Weak user keys being used for a connection will also be rejected where possible.

Are there blacklists for RSA-2048 and dsa-1024?

The current official blacklists (in “openssh-blacklist”) cover RSA-2048 and DSA-1024 keys as generated on 32-bit little-endian, 64-bit little-endian and 32-bit big-endian systems. That’s sufficient to cover users who used the default key length, but not if some of your users decided they wanted a longer keylength.

Where can I find list of weak keys?

Many lists of ‘weak’ keys have been generated by the metasploit project: http://metasploit.com/users/hdm/tools/debian-openssl/ Applications/protocols known to use these keys: