Heartbleed bug
Last update: 2014-04-16 12:20:32
Introduction
A serious bug in the OpenSSL library, known as the "Heartbleed bug" has been recently discovered.
The bug in OpenSSL library affected many sites worldwide for nearly two years. Although the Anselm cluster itself was exposed only for two weeks and other systems for approximately three months, IT4I didn't take this situation lightly and with full responsibility responded immediately. At this moment, there is no evidence that any abuse of data took place at IT4I.
For more information about the Heartbleed bug, please see: http://heartbleed.com/
Response
OpenSSL fix
IT4I has taken all necessary steps to fix the OpenSSL library on all it's systems.
Server keys change
Due to a safety preventive action, the fingerprint of Anselm login nodes has changed.
You are advised to remove the deprecated fingerprint from your local SSH known_hosts file:
local $ ssh-keygen -R anselm.it4i.cz
local $ ssh-keygen -R login1.anselm.it4i.cz
local $ ssh-keygen -R login2.anselm.it4i.cz
local $ ssh-keygen -R 195.113.250.82
local $ ssh-keygen -R 195.113.250.83
new fingerprints for both login nodes are:
29:b3:f4:64:b0:73:f5:6f:a7:85:0f:e0:0d:be:76:bf (DSA)
d4:6f:5c:18:f4:3f:70:ef:bc:fc:cc:2b:fd:13:36:b7 (RSA)
You have to reconnect on Anselm to apply this change.
Login credentials change
There is no evidence that any abuse of data took place at IT4I, however as a safety preventive action, all users will be issued new login credentials.
In order to ensure the security and integrity of IT4I systems, all users will be issued new login credentials, including password and ssh kyes.
We will use your original digital signatures to deliver the login credential in a secure way.
In case that you're using a new digital signature since getting access to Anselm, please let us know by writing to support [at] it4i.cz . Don't forget to digitally sign your message and please include the string "Digital Signature Change" in the subject line.
We'll be collecting new digital signatures till Friday, 18th April.