OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Volker Kuhlmann (kuhlmavelec.canterbury.ac.nz)
Date: Mon Feb 19 2001 - 00:07:53 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    > suse cd, or oddly enough the suse website (imagine that).
    >
    > http://www.suse.de/en/support/security/index.html

    Yes thanks for making fun at my expense, I did actually check the web
    site and couldn't find anything. Still can't. (Of course it's on the
    7.1 CDs, but I haven't got any.)

    I should have mentioned that the suse security team key on that page is
    not the one:

    > rpm -Kvv ssh-1.2.27-220.i386.rpm
    D: New Header signature
    D: Signature size: 156
    D: Signature pad : 4
    D: sigsize : 160
    D: Header + Archive: 450623
    D: expected size : 450623
    ssh-1.2.27-220.i386.rpm:
    MD5 sum OK: 517365d17ca1475e06addc76d1e30bff
    gpg: Warning: using insecure memory!
    gpg: Signature made Thu 15 Feb 2001 23:43:43 NZDT using DSA key ID 9C800ACA
    gpg: Can't check signature: public key not found

    The rpm is signed with a key ID of 9C800ACA, the key on that web page has

    Type Bits/KeyID Date User ID
    pub 2048/3D25D3D9 1999/03/06 SuSE Security Team <securitysuse.de>

    which isn't quite the same.

    A search on the web site for "gpg key" doesn't show anything either.

    Sorry Kurt... :-)

    Volker

    ---------------------------------------------------------------------
    To unsubscribe, e-mail: suse-security-unsubscribesuse.com
    For additional commands, e-mail: suse-security-helpsuse.com