Open Rights Group Keysigning party – London 2 June 08

The Open Rights Group [1] are holding a keysigning party [2] in London
on Monday the second of June.

It’ll be a chance for those interested in CACert to give and/or gain
some points, as well as get their PGP key signed.

[1]http://www.openrightsgroup.org/
[2]http://tinyurl.com/6z4273

Warning on weak keys and random numbers

Regarding the recently discovered random number vulnerability:

CAcert’s root keys are not affected, since they were created before the bug existed.
CAcert’s internal systems were affected, and are currently being cleaned up.
A lot of our users are affected.
We are currently working on improved methods to detect the vulnerabilities and inform the affected users about them.
In general, digital signatures and certificates are only affected in the case the any of the underlying keys are compromised. Signatures and certificates do not contain any additional random numbers, so they can’t be affected on their own, if the keys are not compromised.

We currently think that the articles in the media hasn’t informed everyone about the whole impact of the problem yet.

The affected distributions contain Debian, Ubuntu, Kubuntu, Knoppix, Grml, and various other Debian based distributions.
Also various embedded systems that are based on Debian are likely affected.

Regarding the applications, OpenSSL, OpenVPN, OpenXPKI, OpenCA, OpenSSH (especially client authorisation keys!), boxbackup and various other software packages are affected.

All systems that are relying on keys that were generated on affected systems are affected.
This means that you should scan all your SuSE, Fedora, Redhat, BSD, … SSH-servers for compromised keys in the authorized keys files of all users, and blacklist the compromised keys accordingly. (And the same for any other services that might rely on the compromised keys.)

If you want to assess the quality of your own random number generator, you can use our free service here:
http://www.cacert.at/random/

We are currently developing a X.509 vulnerability detection system, which will be available for all CA’s, to discover similarly compromised keys as early as possible. If you want to participate and help there, please contact us.
http://wiki.cacert.org/wiki/HashServer

Message to all non-Debian-derived vendors: Please ship blacklists and blacklist-detection software in your security updates. (Port ssh-vuln to your distribution, …) And warn your users too, not to rely on compromised keys anymore.

General information about the vulnerability:

http://wiki.debian.org/SSLkeys
http://www.debian.org/security/key-rollover/
http://www.debian.org/security/2008/dsa-1571

CAcert wieder auf dem Linuxtag 2008 in Berlin

der Linuxtag 2008 vom 28.Mai bis 31.Mai in Berlin steht vor der Tür.
CAcert wird hier auch wieder mit einem Stand vertreten sein an dem sich Interressierte Besucher informieren und assuren lassen können.

Assurer und Interressierte, die gerne helfen wollen sollten sich bitte schnellstmöglich unter http://wiki.cacert.org/wiki/LinuxTag2008 erintragen, damit der Stand und ggf. Eintrittskarten geplant werden kann.

New openssl packages fix predictable random number generator

Luciano Bello discovered that the random number generator in Debian’s openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable.

[…more]

15th May 2008: CAcert Assurance event at NLUUG conf, Ede, Holland

NLUUG logo At the NLUUG (dutch Unix/Linux user group) conference, Ede, Holland on the 15th of May 2008 CAcert will have a special booth for CAcert assurances (information, individual and organisation assurances). See conference details .

PAUSE gets a CAcert certificate

The Perl Authors Upload Server (PAUSE) has had a self signed cert for it’s SSL stuff. As of April 19, 2008 it will use a cert signed by CAcert.

For more information: http://www.cpan.org/modules/04pause.html#ssl

CAcert group on LinkedIn

CAcert group is now approved on LinkedIn, and open to the CAcert community. The group is reachable at http://www.linkedin.com/e/gis/89248/182D4E19701F

CAcert Assurances on the Penguicon Convention, USA, Michigan, Detroit(Troy)

At the Penguin Convention in Michigan there will be a keysigning party for Michigan and the
surrounding cities (Flint, Lansing etc.). Penguicon is open to the public, but registration is now at the door only for this year.  Penguicon will take place next weekend, April 18-20. in Michigan, US and the details can be found on the official website.  The keysigning portion will take place on Saturday.
More information on the Penguicon Website (http://www.penguicon.org/).

CAcert/GnuPG/Thawte Certification & Keysigning in Muenchen – Germany on 25th of April

Certification & Keysigning will be held on 25th of April (Friday evening at 19h local time) in Restaurant & Cafe Rila (changed location) on Balanstrasse 16 in the Muenchen city center. You can submit your attendance and your keys latest by 20th of April (Sunday), the listing will be made on Monday. The official site about the meeting is held on CAcert wiki.

CAcert under GPL Licence

CAcert is now official under the GPL Licence Version 2. More information and the Source Code could be found under http://www.cacert.org/src-lic.php