Mailing-List: contact cygwin-help@sourceware.cygnus.com; run by ezmlm
List-Subscribe: <mailto:cygwin-subscribe@sources.redhat.com>
List-Archive: <http://sources.redhat.com/ml/cygwin/>
List-Post: <mailto:cygwin@sources.redhat.com>
List-Help: <mailto:cygwin-help@sources.redhat.com>, <http://sources.redhat.com/ml/#faqs>
Sender: cygwin-owner@sources.redhat.com
Delivered-To: mailing list cygwin@sources.redhat.com
Date: Mon, 12 Feb 2001 10:15:20 +0100
From: Corinna Vinschen <cygwin@cygwin.com>
To: cygwin <cygwin@cygwin.com>
Subject: Re: Authentication By-Pass Vulnerability in OpenSSH 2.3.1 (devel snapshot) (fwd)
Message-ID: <20010212101520.D2107@cygbert.vinschen.de>
Mail-Followup-To: cygwin <cygwin@cygwin.com>
References: <20010209084018.C4880@cygbert.vinschen.de> <3A83A7B3.756449B5@ece.gatech.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
User-Agent: Mutt/1.2.5i
In-Reply-To: <3A83A7B3.756449B5@ece.gatech.edu>; from cwilson@ece.gatech.edu on Fri, Feb 09, 2001 at 03:17:55AM -0500

On Fri, Feb 09, 2001 at 03:17:55AM -0500, Charles Wilson wrote:
> Corinna Vinschen wrote:
> > FYI for those running snapshots.  I have removed the openssh-20010202
> > snapshot from cygwin/latest.
> > 
> > If you are using the openssh-20010202 snapshot PLEASE REVERT BACK TO
> > openssh-20001221 OR openssh-2.3.0p1.!!!
> 
> This means you have to re-regenerate your RSA keys after reverting back
> to the older version, right?

Right, but only the SSH2 RSA keys, not the SSH1 keys. Or you drop
usage of SSH2 RSA until the next official OpenSSH is released.

Corinna

-- 
Corinna Vinschen                  Please, send mails regarding Cygwin to
Cygwin Developer                                mailto:cygwin@cygwin.com
Red Hat, Inc.

--
Want to unsubscribe from this list?
Check out: http://cygwin.com/ml/#unsubscribe-simple

