Redhat’s Fedora Project servers compromised

Posted by Tahir 23 August, 2008 (0) Comment

Fedora Project Leader, Paul W. Frields, in announcement released yesterday, said that some Fedora servers were “illegally accessed” last week.

Here’s more from the announcement:

One of the compromised Fedora servers was a system used for signing Fedora packages. However, based on our efforts, we have high confidence that the intruder was not able to capture the passphrase used to secure the Fedora package signing key. Based on our review to date, the passphrase was not used during the time of the intrusion on the system and the passphrase is not stored on any of the Fedora servers.

While there is no definitive evidence that the Fedora key has been compromised, because Fedora packages are distributed via multiple third-party mirrors and repositories, we have decided to convert to new Fedora signing keys. This may require affirmative steps from every Fedora system owner or administrator. We will widely and clearly communicate any such steps to help users when available.

Read the rest of this entry

Share/Save/Bookmark

Categories : general, news Tags :