Unix Technical Forum

Re: RSA fingerprint list for anoncvs servers

This is a discussion on Re: RSA fingerprint list for anoncvs servers within the mailing.openbsd.tech forums, part of the OpenBSD category; --> On Tue, Jun 22, 2004 at 03:18:42PM -0400, Will Backman wrote: > http://www.openbsd.org/anoncvs.html#CVSROOT lists anoncvs servers. > When I ...


Go Back   Unix Technical Forum > Unix Operating Systems > OpenBSD > mailing.openbsd.tech

Register FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 02-18-2008, 07:06 AM
Alexander von Gernler
 
Posts: n/a
Default Re: RSA fingerprint list for anoncvs servers

On Tue, Jun 22, 2004 at 03:18:42PM -0400, Will Backman wrote:
> http://www.openbsd.org/anoncvs.html#CVSROOT lists anoncvs servers.
> When I connect, cvs uses ssh as the RSH (thanks), but it gives me the
> RSA fingerprint and asks me if I want to continue. I'd love to know if
> I should, as this the the most vulnerable portion of a ssh connection.
> Would it be helpful to have the RSA fingerprints included in the list of
> information for the servers?


As I run a mirror myself, I feel obliged to answer although you should
have used misc@ or openbsd-mirrors@list.rt.fm for your question.

The point is that if an attacker has the possibility to impersonate an
official CVS mirror (thereby having a different ssh fingerprint), he
would most likely also be able to impersonate a web mirror or the main
site where the fingerprints are served, e. g. via anoncvs.html.
This way, he could assure you that the false fingerprint you get is the
official one, thus making you use his trojaned mirror.

If you say now that we have HTTPS, then do not overlook that having
a secure connection does not mean to have the connection to the genuine
OpenBSD mirror resp. master server. For this, we should distribute some
certificates or RSA fingerprints on the official CD sets, for example.
(But hey, how do you know that your CDs haven't been tampered with?

Honestly, I agree that a list of fingerprints on anoncvs.html could be
helpful, but nonetheless no guarantee for not being tricked.

Perhaps your question could be subject to further discussion on
openbsd-mirrors@list.rt.fm. I will cc it to that list, as that is the
right place for the topic.

Greets,
--
Alexander "grunk" von Gernler PGP-Key 0xEBC27515
https://openbsd.informatik.uni-erlangen.de - Free, functional, secure.

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On
Forum Jump


All times are GMT. The time now is 02:34 AM.


Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0
www.UnixAdminTalk.com