Bug 852964

Summary: openssh-blacklist is broken and doesn't do anything useful at all
Product: [Fedora] Fedora Reporter: Kurt Seifried <kseifried>
Component: openssh-blacklistAssignee: Petr Lautrbach <plautrba>
Status: CLOSED NEXTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: medium Docs Contact:
Priority: medium    
Version: 17CC: plautrba
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2012-09-14 16:11:28 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Kurt Seifried 2012-08-30 06:12:25 UTC
Description of problem:

openssh-blacklist is the "Downloader of the openssh keys affected by CVE-2008-0166" (the Debian OpenSSL key generation issue). It no longer works as the site it tries to download from is 

The url in rpm -qpi:

http://www.benhur.prf.cuni.cz/medved-7/wydobitki/?path=openssh-blacklist

is server not found. 

The server URL listed for the actual download:

http://jfch2222.fedorapeople.org/openssh-blacklist/

is 403 forbidden.

This program no longer works at all, it should probably be removed from Fedora.

Comment 1 Petr Lautrbach 2012-09-07 14:40:00 UTC
You're right, I've retired openssh-blacklist package from all current Fedora releases and filled rel-eng ticket [1].

Thanks for the report.

[1] https://fedorahosted.org/rel-eng/ticket/5325