Some of you may be running a Debian distro on your mainframe under VM. If so, you may be interested in closing this Debian-specific vulnerability.
http://lists.debian.org/debian-security-announce/2008/msg00152.html "Luciano Bello discovered that the random number generator in Debian's openssl package is predictable. This is caused by an incorrect Debian-specific change to the openssl package (CVE-2008-0166). As a result, cryptographic key material may be guessable. This is a Debian-specific vulnerability which does not affect other operating systems which are not based on Debian. However, other systems can be indirectly affected if weak keys are imported into them. (continue s)" -- Gary Eheman
