Language Selection

English French German Italian Portuguese Spanish

Red Hat Infrastructure report

Filed under

Last week we discovered that some Fedora servers were illegally
accessed. The intrusion into the servers was quickly discovered, and the
servers were taken offline.

Security specialists and administrators have been working since then to
analyze the intrusion and the extent of the compromise as well as
reinstall Fedora systems. We are using the requisite outages as an
opportunity to do other upgrades for the sake of functionality as well
as security. Work is ongoing, so please be patient. Anyone with
pertinent information relating to this event is asked to contact
fedora-legal redhat com

One of the compromised Fedora servers was a system used for signing
Fedora packages. However, based on our efforts, we have high confidence
that the intruder was not able to capture the passphrase used to secure
the Fedora package signing key. Based on our review to date, the
passphrase was not used during the time of the intrusion on the system
and the passphrase is not stored on any of the Fedora servers.

While there is no definitive evidence that the Fedora key has been
compromised, because Fedora packages are distributed via multiple
third-party mirrors and repositories, we have decided to convert to new
Fedora signing keys. This may require affirmative steps from every
Fedora system owner or administrator. We will widely and clearly
communicate any such steps to help users when available.

More Here

Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.

More in Tux Machines

Yorba Group, Developers of Geary and Shotwell, Is No Longer Active

The Yorba Foundation, a group of developers working on applications like Geary or Shotwell, is no more, and the projects are now available through the GNOME stack. Read more

Cloudy Issues and the Perfect Distro

Today in Linux news, Bruce Byfield hits the cloud nail on the head with his thoughts on the cloud. Are folks sacrificing the independence gained by switching to Linux by trusting cloud vendors? Elsewhere, Bryan Lunduke ponders the perfect Linux distribution and an update on the new Debian Live emerged. Pavlo Rudyi posted a look back at GIMP's 20 years and Samuel Mehrbrodt discussed improving LibreOffice's toolbars. Read more

AMD's Radeon Software Crimson doesn't live up to the hype on Linux

Good news, gamers! AMD just launched Radeon Software Crimson for both Windows and Linux. The Windows drivers saw some serious improvements and contain a slick new control panel. But despite promises of performance improvements for games on Linux, little has changed on open-source operating systems. These are the same old Linux drivers with some new branding. Read more

The Linux approach to human and ecosystem well-being

In the end, what the horizontal economy aims to pursue is a system of distributed governance, reinvigorating citizens’ inputs into both political and economic processes. In a sense, it is the Linux approach to human and ecosystem well being. Read more