I've been monitoring it on the alg news group.  It appears to have been
a problem for awhile.  But it does appear to be a significant problem
with ssl certificates and ssh keys.  The problem is that even corrected,
certificates and keys made with small random function will still exit on
yours and other systems that you have shared you keys with.  So if you
are running a redhat and debian servers with knowhosts and share keys,
you will still need to regenerate new keys and redistribute them to the
 redhat box.  So this bug just does not effect the debian/ubuntu box, it
also effects any other box that you have share your ssh public keys.  So
now heres the fun part.  If I am running a solaris or redhat box, I
don't know if your system was a debian/ubuntu box or another solaris
box.  I will have to get rid of my knownhosts files in the /etc/ssh
directory but also the ones in the users $HOME/.ssh directories.  Worst
yet I also need to get rid of the authorized_keys files from the usres
$HOME/.ssh diretories.  All because I don't know if they cam from a
redhat or solaris or a debian/ubuntu box.

No wonder there is a reported increase in ssh attacks.


- From the movie airplane:  "I pick the wrong time to quit smoking ....."


