<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments on: SSH RSA host key changed</title>
	<atom:link href="http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/</link>
	<description>A blog from the staff at NearlyFreeSpeech.NET.</description>
	<pubDate>Tue, 06 Jan 2009 22:14:37 +0000</pubDate>
	
		<item>
		<title>By: GreenReaper</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-8198</link>
		<dc:creator>GreenReaper</dc:creator>
		<pubDate>Fri, 13 Jun 2008 09:15:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-8198</guid>
		<description>The relevant member FAQ entry (q=SSH) needs to be updated, as it does not contain the rs2 key.

&lt;b&gt;The relevant FAQ entry is actually &lt;a href="https://members.nearlyfreespeech.net/support/faq?q=NFSNsshKeys#NFSNsshKeys" rel="nofollow"&gt;this one&lt;/a&gt;; we've changed the one you're referring to to point to it. -jdw&lt;/b&gt;</description>
		<content:encoded><![CDATA[<p>The relevant member FAQ entry (q=SSH) needs to be updated, as it does not contain the rs2 key.</p>
<p><b>The relevant FAQ entry is actually <a href="https://members.nearlyfreespeech.net/support/faq?q=NFSNsshKeys#NFSNsshKeys" rel="nofollow">this one</a>; we&#8217;ve changed the one you&#8217;re referring to to point to it. -jdw</b></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nesman</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7741</link>
		<dc:creator>Nesman</dc:creator>
		<pubDate>Sun, 25 May 2008 03:45:17 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7741</guid>
		<description>Thank you.  The capital letters didn't alarm me too much, since I see them all the time on my home network when I reload a machine.

It's good to see this info posted.  I know some other hosts that would make the change without any kind of announcement. (Sometimes not even telling the support staff about the change, making for some very confused customers)</description>
		<content:encoded><![CDATA[<p>Thank you.  The capital letters didn&#8217;t alarm me too much, since I see them all the time on my home network when I reload a machine.</p>
<p>It&#8217;s good to see this info posted.  I know some other hosts that would make the change without any kind of announcement. (Sometimes not even telling the support staff about the change, making for some very confused customers)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bumpy Light</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7637</link>
		<dc:creator>Bumpy Light</dc:creator>
		<pubDate>Thu, 22 May 2008 19:04:58 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7637</guid>
		<description>A timely warning, since I just now got the ALL CAPITALS WARNING and headed over here to see "What's up, Doc?" :)

As usual, well-done with keeping on top of security.</description>
		<content:encoded><![CDATA[<p>A timely warning, since I just now got the ALL CAPITALS WARNING and headed over here to see &#8220;What&#8217;s up, Doc?&#8221; <img src='http://blog.nearlyfreespeech.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>As usual, well-done with keeping on top of security.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Charlie Melbye</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7537</link>
		<dc:creator>Charlie Melbye</dc:creator>
		<pubDate>Tue, 20 May 2008 00:04:51 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7537</guid>
		<description>Nice work! I haven't gotten an email about a weak key, so I'm assuming that I should be safe :P

&lt;b&gt;That's not necessarily a safe assumption.  If you were running affected Debian versions, you should update and regenerate and replace your keys.  I believe the key blacklist is known to produce both false positives and false negatives, so should not be the sole measure of safety. -jdw&lt;/b&gt;</description>
		<content:encoded><![CDATA[<p>Nice work! I haven&#8217;t gotten an email about a weak key, so I&#8217;m assuming that I should be safe <img src='http://blog.nearlyfreespeech.net/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p><b>That&#8217;s not necessarily a safe assumption.  If you were running affected Debian versions, you should update and regenerate and replace your keys.  I believe the key blacklist is known to produce both false positives and false negatives, so should not be the sole measure of safety. -jdw</b></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7502</link>
		<dc:creator>Brad</dc:creator>
		<pubDate>Mon, 19 May 2008 01:43:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7502</guid>
		<description>You guys run a tight ship. :D</description>
		<content:encoded><![CDATA[<p>You guys run a tight ship. <img src='http://blog.nearlyfreespeech.net/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ken Dreyer</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7471</link>
		<dc:creator>Ken Dreyer</dc:creator>
		<pubDate>Sun, 18 May 2008 06:06:39 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7471</guid>
		<description>I understand that it's important to move quickly when fixing holes, but since this was a policy change and not a reaction to an actual security breach, what do you think about announcing these sort of things a few days before implementing the changes?

&lt;b&gt;We're a fast-moving company.  We try to give appropriate advance notice depending on the significance of a change without turning even the most minor update into a bureaucratic nightmare.  With a trivial (in its effect) change of this nature, we felt that the time most people would want information about it would be at the time they encountered the change. -jdw&lt;/b&gt;</description>
		<content:encoded><![CDATA[<p>I understand that it&#8217;s important to move quickly when fixing holes, but since this was a policy change and not a reaction to an actual security breach, what do you think about announcing these sort of things a few days before implementing the changes?</p>
<p><b>We&#8217;re a fast-moving company.  We try to give appropriate advance notice depending on the significance of a change without turning even the most minor update into a bureaucratic nightmare.  With a trivial (in its effect) change of this nature, we felt that the time most people would want information about it would be at the time they encountered the change. -jdw</b></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alan Linton</title>
		<link>http://blog.nearlyfreespeech.net/2008/05/17/ssh-rsa-host-key-changed/#comment-7454</link>
		<dc:creator>Alan Linton</dc:creator>
		<pubDate>Sat, 17 May 2008 21:15:27 +0000</pubDate>
		<guid isPermaLink="false">http://blog.nearlyfreespeech.net/?p=46#comment-7454</guid>
		<description>I was working away and was, not alarmed, but surprised to find the ssh key had changed.  It is good to know it's not someone actually trying to do something nasty as my ssh client claimed might be happening.</description>
		<content:encoded><![CDATA[<p>I was working away and was, not alarmed, but surprised to find the ssh key had changed.  It is good to know it&#8217;s not someone actually trying to do something nasty as my ssh client claimed might be happening.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
