Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Beware of Vulnerable RSA generation (CVE-2017-15361)
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
n05ph3r42
Tux's lil' helper
Tux's lil' helper


Joined: 11 Jul 2016
Posts: 134

PostPosted: Wed Nov 08, 2017 9:17 pm    Post subject: Beware of Vulnerable RSA generation (CVE-2017-15361) Reply with quote

https://crocs.fi.muni.cz/public/papers/rsa_ccs17
https://keychest.net/roca
Back to top
View user's profile Send private message
John R. Graham
Administrator
Administrator


Joined: 08 Mar 2005
Posts: 10589
Location: Somewhere over Atlanta, Georgia

PostPosted: Wed Nov 08, 2017 10:31 pm    Post subject: Reply with quote

This vulnerability is in the news because of a bug in a specific Infineon smartcard chip library, specifically in the code that makes random pseudo-primes as part of RSA private key generation and specifically in their SLE78 family of chips. If you're not using anything with that chip family, there's really not much to see here. Linux software key generation, at least with the well known security libraries, to my knowledge is not affected: openssl doesn't make vulnerable keys, nor does ssh-keygen.

- John
_________________
I can confirm that I have received between 0 and 499 National Security Letters.
Back to top
View user's profile Send private message
n05ph3r42
Tux's lil' helper
Tux's lil' helper


Joined: 11 Jul 2016
Posts: 134

PostPosted: Thu Nov 09, 2017 1:18 pm    Post subject: Reply with quote

Many TPM's affected. This mostly should warn its users.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum