[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: RSA host key of ftp-master changed?



On Wed, Jul 14, 2004 at 12:55:34PM +0200, Andreas Tille wrote:
> On Wed, 14 Jul 2004, Andreas Metzler wrote:
> > Where have you been for the last 6 months?
> > http://lists.debian.org/debian-devel-announce/2003/12/msg00001.html
> 
> This is no news to me.  BTW, the host keys there are for
>     master  (146.82.138.7)
>     gluck   (192.25.206.10)
>     merkel  (192.25.206.16)
> but ftp-master has IP 208.185.25.31 so this URL would not really help.

Quoting the announcement linked to above:

                             How do I upload?
                             ----------------
  
  Use the anonymous upload queue on ftp-master.

anonymous i.e. not over ssh.

                            Where can I login?
                            ------------------
  
  There's been a fair bit of talk post-compromise about restricting
  access to machines running (core) services.  At the moment, the only
  thing I'm (personally) doing is not enabling non-services accounts on
  auric (ftp-master) and klecker (security, non-US, qa, nm, www-master)
  immediately.  Obviously, it's useful for random developers to have
  access to e.g. the postgres database of the archive, so the current
  plan if the restricted nature of auric becomes permanent is to mirror
  the system daily to another box that would be unrestricted.  [This
  would have the added bonus of giving us a hot spare for
  disasters/arson attacks etc.]

> At this time ftp-master was identical to auric (206.246.226.45).  This
> is reflected in my .ssh/known_hosts by having the same RSH key.  But
> it seems that some other host became ftp-master now and I seemed to
> miss this information. That's why I was asking ...

  http://lists.debian.org/debian-devel-announce/2004/01/msg00011.html

-- 
Colin Watson                                  [cjwatson@flatline.org.uk]



Reply to: