Re: Tutorial for iptables

2009-01-28 Thread James Miller
Sorry for the top post. Can beat Oskar Andreasson's IPTables Tutorial http://iptables-tutorial.frozentux.net/ Jim Pierre Chifflier wrote: On Wed, Jan 28, 2009 at 12:20:27PM +0100, cyril franke wrote: Hello list, I just started learning firewall setup with iptables and found the

Frustration with randome number generator vuln and ssh

2008-06-04 Thread James Miller
Hi everyone, If I am sending this to the wrong list please let me know! I have a server, details below, that I've updated to address the ssl random number generator issue but after generating the new ssh_host rsa and ssh_host_dsa keys, ssh still complains they're still vulnerable. I would

Re: Frustration with randome number generator vuln and ssh

2008-06-04 Thread James Miller
A n d i k a Triwidada wrote: On Thu, Jun 5, 2008 at 1:29 AM, James Miller [EMAIL PROTECTED] wrote: libssl0.9.8: Installed: 0.9.8e-4 Candidate: 0.9.8e-4 Version table: *** 0.9.8e-4 0 100 /var/lib/dpkg/status 0.9.8c-4etch3 0 500 http://security.debian.org etch/updates/main

Re: ssh-vulnkey and authorized_keys

2008-05-19 Thread James Miller
Alex Samad wrote: On Thu, May 15, 2008 at 07:43:13PM -0400, Chris Adams wrote: On May 15, 2008, at 6:25 PM, Alex Samad wrote: is there away to check x509 certs with these tools ? Yes - the wiki has one (http://wiki.debian.org/SSLkeys) but you might prefer the

public key problem with mirrors.kernel.org

2006-01-06 Thread James Miller
Hello everyone, I hope I'm not doing something 'dumb' on my account here but I get the following error when I run 'apt-get update'. W: GPG error: http://mirrors.kernel.org testing Release: The following signatures couldn't be verified because the public key is not available: NO_PUBKEY

RE: Positive press for Debian's security team

2004-03-30 Thread James Miller
Positive press for Debian's security team. Using numbers from a pair of metrics, Forrester Research's recommendation was businesses that value quick patches look to Microsoft and Debian. Full article at http://story.news.yahoo.com/news?tmpl=storycid=1738e=2u=/zd/200 40330/tc_zd/123143

RE: Positive press for Debian's security team

2004-03-30 Thread James Miller
Positive press for Debian's security team. Using numbers from a pair of metrics, Forrester Research's recommendation was businesses that value quick patches look to Microsoft and Debian. Full article at http://story.news.yahoo.com/news?tmpl=storycid=1738e=2u=/zd/200 40330/tc_zd/123143

RE: Fwd: Re: [ox-en] Walther

2004-02-25 Thread James Miller
I'm on the Debian security list to get Debian related security notifications and info. Could you please take this discussion elsewhere?! -Original Message- From: Jonathan Walther [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 25, 2004 9:56 AM To: [EMAIL PROTECTED] Subject:

RE: Fwd: Re: [ox-en] Walther

2004-02-25 Thread James Miller
I'm on the Debian security list to get Debian related security notifications and info. Could you please take this discussion elsewhere?! -Original Message- From: Jonathan Walther [mailto:[EMAIL PROTECTED] Sent: Wednesday, February 25, 2004 9:56 AM To:

RE: blocking AXFR record query

2004-01-28 Thread James Miller
If memory serves.. AXFR is a zone transfer... So, at your firewall, would want to only allowing TCP queries from your backup (secondary, trinary..etc.) dns servers (on the outside of your firewall) and limit everyone else to UDP queries. And for your bind9 config something like this:

Verisign and Bind update

2003-09-17 Thread James Miller
Will the package maintainers of BIND be integrating the patches from ISC-BIND to negate Verisign's recent shenanigans? --from ISC's web site -- In response to high demand from our users, ISC is releasing a patch for BIND to support the declaration of delegation-only zones in caching/recursive

Verisign and Bind update

2003-09-17 Thread James Miller
Will the package maintainers of BIND be integrating the patches from ISC-BIND to negate Verisign's recent shenanigans? --from ISC's web site -- In response to high demand from our users, ISC is releasing a patch for BIND to support the declaration of delegation-only zones in caching/recursive