<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:blogger='http://schemas.google.com/blogger/2008' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-2518099536690330573</id><updated>2013-03-08T14:19:05.726-06:00</updated><category term='voms-proxy-init'/><category term='pem'/><category term='proposal'/><category term='p12'/><category term='certificates'/><category term='CRL'/><category term='grid-proxy-init'/><category term='errors'/><title type='text'>OSG Security News and Announcements</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>24</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-4071657365253298177</id><published>2013-03-08T14:19:00.000-06:00</published><updated>2013-03-08T14:19:05.733-06:00</updated><title type='text'>Java security updates released this week</title><content type='html'>Oracle has released a new version of Java 6 and Java 7 in response to new vulnerabilities that allow malicious web sites to allow full access to systems when web browsers with Java enabled visit them.&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;This only affects client side use of Java, as in web start apps or the Java plugin in web browsers. It should not be exploitable by server side uses of Java.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;As a precaution, however everyone is recommended to install the latest Java patches. Scientific Linux and Red hat have both released updated Java 6 and 7 packages. New packages for Mac and Windows systems are also available.&amp;nbsp;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/4071657365253298177/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2013/03/java-security-updates-released-this-week.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4071657365253298177'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4071657365253298177'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2013/03/java-security-updates-released-this-week.html' title='Java security updates released this week'/><author><name>Kevin Hill</name><uri>http://www.blogger.com/profile/05132305358078917532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-1136946194130526602</id><published>2013-01-15T09:07:00.000-06:00</published><updated>2013-01-15T09:07:26.068-06:00</updated><title type='text'>New Java Exploit in the Wild</title><content type='html'>&lt;br /&gt;Last week a vulnerability was discovered in Java 7 that allowed compromised web sites to take control of computers visiting the site with a web browser with the Java plugin enabled. This has been reported to be actively exploiting systems in the wild.&lt;br /&gt;&lt;br /&gt;The vulnerability seems to be specific to Java 7, and specifically the web browser plugin, so grid services do not seem to be vulnerable.&lt;br /&gt;&lt;br /&gt;Oracle has released a new version of Java as of Sunday that should fix this vulnerability. It is recommended that people disable the Java browser plugin if its not needed until the update is installed.&lt;br /&gt;&lt;br /&gt;Here's an article that has a good list of FAQs about this vulnerability:&lt;br /&gt;https://krebsonsecurity.com/2013/01/what-you-need-to-know-about-the-java-exploit/</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/1136946194130526602/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2013/01/new-java-exploit-in-wild.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1136946194130526602'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1136946194130526602'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2013/01/new-java-exploit-in-wild.html' title='New Java Exploit in the Wild'/><author><name>Kevin Hill</name><uri>http://www.blogger.com/profile/05132305358078917532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-3010905586925545482</id><published>2012-07-31T14:53:00.000-05:00</published><updated>2012-07-31T15:00:22.585-05:00</updated><title type='text'>Ganglia Vulnerability</title><content type='html'>There is a &lt;a href="http://ganglia.info/?p=549"&gt;Ganglia vulnerability&lt;/a&gt; that potentially allows remote users to execute unauthorized scripts. This &lt;a href="http://dl.fedoraproject.org/pub/epel/6/x86_64/repoview/ganglia-web.html"&gt;has been fixed&lt;/a&gt; in the EPEL Ganglia for EL6, and &lt;a href="https://bugzilla.redhat.com/show_bug.cgi?id=840318"&gt;doesn't seem to affect&lt;/a&gt; the EPEL Ganglia for EL5.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/3010905586925545482/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2012/07/there-is-ganglia-vulnerability-that.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3010905586925545482'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3010905586925545482'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/07/there-is-ganglia-vulnerability-that.html' title='Ganglia Vulnerability'/><author><name>Marko Slyz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-7898399515551506284</id><published>2012-07-17T10:57:00.002-05:00</published><updated>2012-07-17T10:57:43.817-05:00</updated><title type='text'>sudo update</title><content type='html'>An &lt;a href="http://listserv.fnal.gov/scripts/wa.exe?A2=ind1207&amp;amp;L=scientific-linux-errata&amp;amp;T=0&amp;amp;P=4508"&gt;update for sudo&lt;/a&gt;&amp;nbsp; was released yesterday which can prevent privilege escalation in certain situations.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/7898399515551506284/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2012/07/sudo-update.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7898399515551506284'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7898399515551506284'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/07/sudo-update.html' title='sudo update'/><author><name>Marko Slyz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-88720503911245261</id><published>2012-07-10T13:06:00.000-05:00</published><updated>2012-07-10T13:06:31.804-05:00</updated><title type='text'>Scientific Linux Updates</title><content type='html'>Since Thursday there have been 31 Scientific Linux updates announced, mostly for SL6. &lt;a href="http://listserv.fnal.gov/scripts/wa.exe?A1=ind1207&amp;amp;L=scientific-linux-errata&amp;amp;O=D&amp;amp;H=0&amp;amp;D=0&amp;amp;T=0"&gt;The full list is here.&lt;/a&gt; Also, a local user privilege escalation bug fix for the SL6 kernel &lt;a href="http://listserv.fnal.gov/scripts/wa.exe?A2=ind1206&amp;amp;L=scientific-linux-errata&amp;amp;T=0&amp;amp;O=D&amp;amp;P=2223"&gt;was announced&lt;/a&gt; a few weeks ago. Please upgrade as needed. &lt;br /&gt;&lt;br /&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/88720503911245261'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/88720503911245261'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/07/scientific-linux-updates.html' title='Scientific Linux Updates'/><author><name>Marko Slyz</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-4831965383541614478</id><published>2012-04-20T15:38:00.000-05:00</published><updated>2012-04-20T15:38:05.071-05:00</updated><title type='text'>Kernel and GridEngine updates this week</title><content type='html'>&lt;h2&gt;Kernel update for Red Hat and Scientific Linux&lt;/h2&gt;Red Hat and Scientific Linux have both released updated kernel packages to address a local denial of service vulnerability in the xfrm6_tunnel kernel module.&lt;br /&gt;&lt;a href="https://rhn.redhat.com/errata/RHSA-2012-0480.html"&gt;The redhat announcement is here.&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;h2&gt;Updates to Oracle Grid Engine&lt;/h2&gt;Oracle has released updates to Oracle Grid Engine to address two local privilege escalation vulnerabilities, one in the qrsh component and the other in sgepasswd.&lt;br /&gt;&lt;a href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html#AppendixSUNS"&gt;Oracle advisory is here.&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/4831965383541614478/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2012/04/kernel-and-gridengine-updates-this-week.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4831965383541614478'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4831965383541614478'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/04/kernel-and-gridengine-updates-this-week.html' title='Kernel and GridEngine updates this week'/><author><name>Kevin Hill</name><uri>http://www.blogger.com/profile/05132305358078917532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-8104723668727516500</id><published>2012-04-06T18:26:00.000-05:00</published><updated>2012-04-06T18:26:19.278-05:00</updated><title type='text'>A Couple Noteworthy Security Updates</title><content type='html'>&lt;h3&gt;Apple Update for Java&lt;/h3&gt;Apple has released an update for Java for Lion and Snow Leopard to     address critical vulnerabilities that can lead to the compromise of     systems using Java, especially in web browsers. Systems are being actively     exploited     in the wild. At this time, we have not yet received reports of     infected Macs from OSG users, however reports estimate over 600,000     Macs have been compromised so far: &lt;a href="http://www.pcworld.com/businesscenter/article/253268/fastgrowing_flashback_botnet_includes_over_600000_macs_malware_experts_say.html"&gt;[PC World Article]&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    Apple's original announcement is here: &lt;a href="http://support.apple.com/kb/HT5228"&gt;[Apple Announcement]&lt;br /&gt;    &lt;/a&gt;&lt;br /&gt;    A good quick guide to checking if your Mac is infected is available     here:     &lt;a href="http://lifehacker.com/5899416/mac-flashback-trojan-find-out-if-youre-one-of-the-600000-infected"&gt;[Lifehacker Article]&lt;/a&gt;&lt;br /&gt;    &lt;br /&gt;    &lt;h3&gt;RHEL/SL Update for RPM&lt;/h3&gt;Red Hat and Scientific Linux have both released updated RPM packages     to address an important vulnerability. It is     possible for maliciously made rpm files to compromise a system     before the rpm     signature is checked. More information is available here:     &lt;a href="https://rhn.redhat.com/errata/RHSA-2012-0451.html"&gt;[Red Hat Announcement]&lt;/a&gt;&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/8104723668727516500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2012/04/couple-noteworthy-security-updates.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/8104723668727516500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/8104723668727516500'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/04/couple-noteworthy-security-updates.html' title='A Couple Noteworthy Security Updates'/><author><name>Kevin Hill</name><uri>http://www.blogger.com/profile/05132305358078917532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-9106295450524249792</id><published>2012-03-30T09:07:00.001-05:00</published><updated>2012-03-30T09:07:30.928-05:00</updated><title type='text'>Moderate vulnerability in OpenSSL packages</title><content type='html'>New OpenSSL packages have been released by Red Hat Enterprise Linux and Scientific Linux to address moderate level vulnerabilities that could be used for remote denial of service attacks and possibly decrypting encrypted messages.&lt;br /&gt;&lt;br /&gt;More information is available at the links below:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;a class="moz-txt-link-freetext" href="https://rhn.redhat.com/errata/RHSA-2012-0426.html"&gt;https://rhn.redhat.com/errata/RHSA-2012-0426.html&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;&lt;a class="moz-txt-link-freetext" href="http://listserv.fnal.gov/scripts/wa.exe?A2=ind1203&amp;amp;L=scientific-linux-errata&amp;amp;T=0&amp;amp;O=D&amp;amp;X=4ADC730E38161FDBDA&amp;amp;Y=listmgr%40fnal.gov&amp;amp;P=4960"&gt;http://listserv.fnal.gov/scripts/wa.exe?A2=ind1203&amp;amp;L=scientific-linux-errata&amp;amp;T=0&amp;amp;O=D&amp;amp;X=4ADC730E38161FDBDA&amp;amp;Y=listmgr%40fnal.gov&amp;amp;P=496&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/9106295450524249792/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2012/03/moderate-vulnerability-in-openssl.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/9106295450524249792'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/9106295450524249792'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2012/03/moderate-vulnerability-in-openssl.html' title='Moderate vulnerability in OpenSSL packages'/><author><name>Kevin Hill</name><uri>http://www.blogger.com/profile/05132305358078917532</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-7139431178200748228</id><published>2011-08-24T11:02:00.006-05:00</published><updated>2011-08-24T11:12:43.077-05:00</updated><title type='text'></title><content type='html'>&lt;span style="color: rgb(204, 102, 0); font-weight: bold;font-size:130%;" &gt;Thunderbird, FireFox and WebKit vulnerabilities fixed on Ubuntu and Fedora&lt;/span&gt;&lt;span style="color: rgb(153, 0, 0); font-weight: bold;font-size:130%;" &gt; &lt;/span&gt;&lt;span style="font-size:130%;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="color: rgb(0, 0, 0);"&gt;Ubuntu has announced that security vulnerabilities affecting WebKit libraries have been fixed and users are encouraged to upgrade. The announcement can be found at http://www.ubuntu.com/usn/usn-1195-1/ &lt;/span&gt;If a user were tricked into viewing a malicious&lt;br /&gt;website, a remote attacker could exploit a variety of issues related to web&lt;br /&gt;browser security, including cross-site scripting attacks, denial of&lt;br /&gt;service attacks, and arbitrary code execution. &lt;span style="color: rgb(0, 0, 0);"&gt; &lt;/span&gt;WebKit is a web content engine, derived from KHTML and KJS from KDE, and used primarily in Apple's Safari browser.  It is made to be embedded in other applications, such as mail readers, or web browsers.&lt;br /&gt;&lt;br /&gt;Fedora released a new version of FireFox and Thunderbird that fixes multiple security vulnerabilities. The details can be found at http://lists.fedoraproject.org/pipermail/package-announce/2011-August/064383.html&lt;br /&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/7139431178200748228/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2011/08/thunderbird-firefox-and-webkit.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7139431178200748228'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7139431178200748228'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2011/08/thunderbird-firefox-and-webkit.html' title=''/><author><name>Mine Altunay</name><uri>http://www.blogger.com/profile/05093575831341354756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-3098031164614584551</id><published>2011-05-20T14:39:00.004-05:00</published><updated>2011-05-20T14:44:28.631-05:00</updated><title type='text'>glibc vulnerability - privilege escalation</title><content type='html'>This is an announcement that should have been posted when it was sent to the site security contact in April.  Posting now to make sure it's included on the blog for everyone.&lt;br /&gt;&lt;br /&gt;In coordination with the EGI CSIRT team.&lt;br /&gt;&lt;br /&gt;Title:       HIGH risk glibc vulnerability - privilege escalation&lt;br /&gt;(CVE-2011-0536) [EGI-ADV-20110412]&lt;br /&gt;Date:        April 12, 2011&lt;br /&gt;Last update: April 12, 2011&lt;br /&gt;URL:         https://wiki.egi.eu/wiki/EGI_CSIRT:Alerts/glibc-2011-04-12&lt;br /&gt;&lt;br /&gt;Introduction&lt;br /&gt;============&lt;br /&gt;&lt;br /&gt;A flaw has been found in the dynamic linker component of the GNU&lt;br /&gt;C library.  A local attacker could use this flaw to escalate their&lt;br /&gt;privileges via a setuid or setgid program which is dynamically linked&lt;br /&gt;to a library with certain properties.&lt;br /&gt;&lt;br /&gt;This vulnerability affects both RH5 and RH6 and their variants.&lt;br /&gt;&lt;br /&gt;EGI CSIRT considers this to be a HIGH vulnerability for now and might&lt;br /&gt;raise it to CRITICAL if a working exploit is made public&lt;br /&gt;&lt;br /&gt;Details&lt;br /&gt;=======&lt;br /&gt;&lt;br /&gt;The fix for CVE-2010-3847 introduced a regression in the way the dynamic&lt;br /&gt;loader expanded the $ORIGIN dynamic string token specified in the RPATH and&lt;br /&gt;RUNPATH entries in the ELF library header. A local attacker could use this&lt;br /&gt;flaw to escalate their privileges via a setuid or setgid program using&lt;br /&gt;such a library. (CVE-2011-0536)&lt;br /&gt;&lt;br /&gt;RH security team confirmed that reporter (of this vulnerability)&lt;br /&gt;indicated an intention to make exploit public after waiting some time&lt;br /&gt;&lt;br /&gt;to give users and downstream distros an opportunity to pick up the fix.&lt;br /&gt;&lt;br /&gt;Mitigation&lt;br /&gt;==========&lt;br /&gt;&lt;br /&gt;The only known mitigation is to apply the security patch from the software&lt;br /&gt;vendor.&lt;br /&gt;&lt;br /&gt;Recommendations&lt;br /&gt;===============&lt;br /&gt;&lt;br /&gt;It is STRONGLY recommended to immediately apply vendor patches when they&lt;br /&gt;become available.&lt;br /&gt;&lt;br /&gt;Vendor patches are now available from&lt;br /&gt;&lt;br /&gt;* Ubuntu&lt;br /&gt;* Debian&lt;br /&gt;* RHEL5/6&lt;br /&gt;* SL5/6&lt;br /&gt;&lt;br /&gt;To be released:&lt;br /&gt;&lt;br /&gt;* CentOS5/6&lt;br /&gt;&lt;br /&gt;References&lt;br /&gt;==========&lt;br /&gt;RedHat bugzilla:&lt;br /&gt;https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2011-0536&lt;br /&gt;&lt;br /&gt;RHEL5 update:&lt;br /&gt;https://rhn.redhat.com/errata/RHSA-2011-0412.html&lt;br /&gt;&lt;br /&gt;RHEL6 update:&lt;br /&gt;https://rhn.redhat.com/errata/RHSA-2011-0413.html&lt;br /&gt;&lt;br /&gt;SL5/6 update:&lt;br /&gt;http://listserv.fnal.gov/scripts/wa.exe?A2=ind1104&amp;L=scientific-linux-errata&lt;br /&gt;&amp;T=0&amp;P=583&lt;br /&gt;&lt;br /&gt;SLC5 update:&lt;br /&gt;http://linux.web.cern.ch/linux/updates/updates-slc5.shtml&lt;br /&gt;&lt;br /&gt;SLC6 update:&lt;br /&gt;http://linux.web.cern.ch/linux/updates/updates-slc6.shtml&lt;br /&gt;&lt;br /&gt;Debian update:&lt;br /&gt;http://lists.debian.org/debian-security-announce/2011/msg00005.html&lt;br /&gt;&lt;br /&gt;Ubuntu update:&lt;br /&gt;https://lists.ubuntu.com/archives/ubuntu-security-announce/2011-January/0012&lt;br /&gt;26.html&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;&lt;br /&gt;Mingchao, EGI CSIRT security officer on duty</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/3098031164614584551/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2011/05/glibc-vulnerability-privilege.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3098031164614584551'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3098031164614584551'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2011/05/glibc-vulnerability-privilege.html' title='glibc vulnerability - privilege escalation'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-3001483085229908644</id><published>2010-11-23T16:34:00.002-06:00</published><updated>2010-11-23T16:37:52.373-06:00</updated><title type='text'>Various vulnerability notices and updates</title><content type='html'>There is a vulnerability in the libsdp package which is used to enablean&lt;br /&gt;application to communicate over the Infiniband SDP protocol instead of&lt;br /&gt;ordinary TCP:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://bugzilla.redhat.com/show_bug.cgi?id=647941"&gt;https://bugzilla.redhat.com/show_bug.cgi?id=647941                                       &lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Sites that use infiniband will want to look at the measures in the&lt;br /&gt;notification above.&lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Updated openssl packages that fix one security issue are now available for&lt;br /&gt;Red Hat Enterprise Linux 6.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://www.redhat.com/security/data/cve/CVE-2010-3864.html"&gt;https://www.redhat.com/security/data/cve/CVE-2010-3864.html&lt;/a&gt;                              &lt;br /&gt;&lt;a href="https://rhn.redhat.com/errata/RHSA-2010-0888.html"&gt;https://rhn.redhat.com/errata/RHSA-2010-0888.html&lt;/a&gt;                                        &lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;Updated systemtap packages that fix two security issues are now available&lt;br /&gt;for Red Hat Enterprise Linux 5 and 6.&lt;br /&gt;&lt;br /&gt;&lt;a href="https://rhn.redhat.com/errata/RHSA-2010-0894.html"&gt;https://rhn.redhat.com/errata/RHSA-2010-0894.html&lt;/a&gt;                                        &lt;br /&gt;&lt;br /&gt;&lt;hr /&gt;&lt;br /&gt;&lt;br /&gt;There is a security vulnerability in PGP Desktop versions 10.0.3 and&lt;br /&gt;earlier, as well as the upcoming 10.1 release.  This vulnerability&lt;br /&gt;may allow someone to spoof emails signed by the OSG security team.&lt;br /&gt;For OSG users who use this version there is a knowledge base page,&lt;br /&gt;as well as remediation steps at:&lt;br /&gt;&lt;br /&gt;&lt;a href="https://pgp.custhelp.com/app/answers/detail/a_id/2290"&gt;https://pgp.custhelp.com/app/answers/detail/a_id/2290&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/3001483085229908644/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/11/various-vulnerability-notices-and.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3001483085229908644'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/3001483085229908644'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/11/various-vulnerability-notices-and.html' title='Various vulnerability notices and updates'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-690703144426288502</id><published>2010-10-19T16:00:00.002-05:00</published><updated>2010-10-19T16:03:13.365-05:00</updated><title type='text'>GNU libc vulnerability</title><content type='html'>The OSG Security Team wants you to be aware of a vulnerability impacting the glibc library.&lt;br /&gt;&lt;br /&gt;Introduction&lt;br /&gt;============&lt;br /&gt;&lt;br /&gt;Tavis Ormandy recently released information about a vulnerability in GNU libc, complete with an exploit that on many systems can give any local user root privileges. (For full details, see the link below in the References section.)&lt;br /&gt;&lt;br /&gt;This vulnerability has been labelled CVE-2010-3847, and is present on many Linux distributions, including RHEL/CentOS/SL 5 (but *not* RHEL 3 and 4 and their derivatives). Vendor patches are not yet available.&lt;br /&gt;&lt;br /&gt;Details&lt;br /&gt;=======&lt;br /&gt;&lt;br /&gt;As far as is known, the vulnerability can only be exploited if users can write to a file system that contains binaries with suid root permissions. (Since it is necessary for the attacker to create a hard link to a suid root binary.)&lt;br /&gt;&lt;br /&gt;This is, for instance, the case if /bin is located on the same filesystem as /tmp (or any other user writable location, like /var/tmp, /home, /var/lib/texmf, and so on). This is unfortunately a common configuration.&lt;br /&gt;  &lt;br /&gt;Mitigation&lt;br /&gt;==========&lt;br /&gt;&lt;br /&gt;To make it impossible to make the required hard link, directories containing suid/sgid binaries can be made to appear to as separate file systems by doing&lt;br /&gt;&lt;br /&gt; mount -o bind /sbin /sbin&lt;br /&gt;&lt;br /&gt;for each such directory.&lt;br /&gt;       &lt;br /&gt;Please note that these commands must be re-run whenever the system is rebooted, for example by adding them to a suitable init script.&lt;br /&gt;&lt;br /&gt;A baseline list of directories with suid/sgid binaries on a typical RHEL 5 system is:&lt;br /&gt;&lt;br /&gt; /bin&lt;br /&gt; /sbin&lt;br /&gt; /usr/bin&lt;br /&gt; /usr/libexec&lt;br /&gt; /usr/lpp&lt;br /&gt; /usr/sbin&lt;br /&gt;&lt;br /&gt;You should check for any additional site specific locations using a command like&lt;br /&gt;&lt;br /&gt; find / -type f \( -perm /u+s -o -perm /g+s \)&lt;br /&gt;&lt;br /&gt;that will list all files with suid/sgid permissions.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Recommendations&lt;br /&gt;===============&lt;br /&gt;&lt;br /&gt;Apply the mitigation method above for all relevant locations.&lt;br /&gt;&lt;br /&gt;You may wish to suspend user logins and job submission until these steps have been taken; please refer to your local site policy.&lt;br /&gt;&lt;br /&gt;Apply vendor updates as soon as they become available.&lt;br /&gt;&lt;br /&gt;References&lt;br /&gt;==========&lt;br /&gt;  &lt;br /&gt;[3]http://seclists.org/fulldisclosure/2010/Oct/257                                       &lt;br /&gt;&lt;br /&gt;The majority of this announcement was put together by Nuno Dias - EGI CSIRT</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/690703144426288502/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/10/gnu-libc-vulnerability.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/690703144426288502'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/690703144426288502'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/10/gnu-libc-vulnerability.html' title='GNU libc vulnerability'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-4116709140324517046</id><published>2010-09-29T17:51:00.002-05:00</published><updated>2010-09-29T18:09:26.034-05:00</updated><title type='text'>Linux Kernel "snd_ctl_new()" Integer Overflow Vulnerability SA41650</title><content type='html'>&lt;span style="font-weight: bold;"&gt;From Secunia:&lt;/span&gt;&lt;br /&gt;&lt;a href="http://secunia.com/advisories/41650/"&gt;http://secunia.com/advisories/41650/&lt;/a&gt;&lt;br /&gt;&lt;span class="Apple-style-span" style="border-collapse: separate; color: rgb(17, 17, 17); font-family: Verdana,Arial,san-serif; font-size: 11px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: 14px; orphans: 2; text-indent: 0px; text-transform: none; white-space: normal; widows: 2; word-spacing: 0px;"&gt;&lt;span class="Apple-style-span" style="color: rgb(68, 68, 68); line-height: 13px;"&gt;&lt;b&gt;Description&lt;/b&gt;&lt;br /&gt;A vulnerability has been reported in the Linux Kernel, which can be exploited by malicious, local users to cause a DoS (Denial of Service) or potentially gain escalated privileges.&lt;br /&gt;&lt;br /&gt;The vulnerability is caused due to an integer overflow error when allocating memory within the "snd_ctl_new()" function in sound/core/control.c, which can be exploited to cause a heap-based buffer overflow.&lt;br /&gt;&lt;br /&gt;Criticality: Less Critical&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;OSG Recommendation:&lt;/span&gt;&lt;br /&gt;If you think your systems may have this vulnerability you can consider removing or limiting access to the sound (or audio) subsystem.&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/4116709140324517046/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/09/linux-kernel-sndctlnew-integer-overflow.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4116709140324517046'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4116709140324517046'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/09/linux-kernel-sndctlnew-integer-overflow.html' title='Linux Kernel &quot;snd_ctl_new()&quot; Integer Overflow Vulnerability SA41650'/><author><name>Doug</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-1876711078537604351</id><published>2010-09-22T10:36:00.002-05:00</published><updated>2010-09-22T10:41:36.931-05:00</updated><title type='text'>Kernel updates for CVE-2010-3081</title><content type='html'>The OSG security team announced last week an important kernel vulnerabilitythat affected 64 bit systems (announcement OSG-SEC-2010-09-16).  Most of the vendors have now come out with patched kernels and the OSG security team is encouraging all sites to update any kernels that are currently affected.&lt;br /&gt;&lt;br /&gt;Here are the links or instructions to the patched kernels for the following OS versions:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;RedHat&lt;/span&gt;&lt;br /&gt;https://rhn.redhat.com/errata/RHSA-2010-0704.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Fedora&lt;/span&gt;&lt;br /&gt;https://admin.fedoraproject.org/updates/search/CVE-2010-3081&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Scientific Linux&lt;/span&gt;&lt;br /&gt;Dear SLC5 x86_64 (64 bit) platform users.&lt;br /&gt;We have released in production a new SLC5 kernel addressing the locally exploitable security issue CVE-2010-3081. This kernel 2.6.18-194.11.4.el5 superseeds the "hotfix" kernel 2.6.18-194.11.3.el5.cve20103081 released last Thursday.&lt;br /&gt;&lt;br /&gt;In order to protect your system please apply urgently following update by running as root:&lt;br /&gt;&lt;br /&gt;# yum install kernel&lt;br /&gt;&lt;br /&gt;and if your system is an Xen virtual machine or hypervisor also run:&lt;br /&gt;&lt;br /&gt;# yum install kernel-xen&lt;br /&gt;&lt;br /&gt;and reboot your system for the update to take effect.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;Ubuntu&lt;/span&gt;&lt;br /&gt;https://lists.ubuntu.com/archives/ubuntu-security-announce/2010-September/001159.html&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;SUSE&lt;/span&gt;&lt;br /&gt;http://lists.opensuse.org/opensuse-security-announce/2010-09/msg00004.html</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/1876711078537604351/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/09/kernel-updates-for-cve-2010-3081.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1876711078537604351'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1876711078537604351'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/09/kernel-updates-for-cve-2010-3081.html' title='Kernel updates for CVE-2010-3081'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-2751846601798583380</id><published>2010-04-29T18:08:00.003-05:00</published><updated>2010-04-30T11:10:58.125-05:00</updated><title type='text'>RedHat xorg-x11-server important security vulnerability</title><content type='html'>An important vulnerability regarding RedHat xorg-x11-server has been&lt;span style="font-weight: bold;"&gt; &lt;/span&gt;reported. The vulnerability could lead to a root-level compromise. RedHat has classified the severity level as "important" and detailed information is available at &lt;a href="https://rhn.redhat.com/errata/RHSA-2010-0382.html"&gt;https://rhn.redhat.com/errata/RHSA-2010-0382.html&lt;/a&gt;&lt;br /&gt;Although the vulnerability is not likely to affect the grid environment, we recommend all site admins to apply the patch on their systems as soon as possible for their site's protection.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/2751846601798583380/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/04/redhat-xorg-x11-server-important.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/2751846601798583380'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/2751846601798583380'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/04/redhat-xorg-x11-server-important.html' title='RedHat xorg-x11-server important security vulnerability'/><author><name>Mine Altunay</name><uri>http://www.blogger.com/profile/05093575831341354756</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-4150425968594075742</id><published>2010-03-18T16:09:00.010-05:00</published><updated>2010-03-22T12:37:27.521-05:00</updated><title type='text'>Make sure your service is getting updates of CA certificates</title><content type='html'>We have received information about storage services which had failed data transfers (FTS and srm services) because the CA certificates package has not been updated and the old CA package has an expired CA and not the new CA certificate that replaced the expired one.&lt;br /&gt;The best way to update the CA certificates is using vdt-update-certs.  Read about this and other important CA certificates information at &lt;a href="https://twiki.grid.iu.edu/bin/view/Security/CADistribution"&gt;https://twiki.grid.iu.edu/bin/view/Security/CADistribution&lt;/a&gt;.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/4150425968594075742/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/03/make-sure-your-service-is-getting.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4150425968594075742'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4150425968594075742'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/03/make-sure-your-service-is-getting.html' title='Make sure your service is getting updates of CA certificates'/><author><name>Doug</name><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-1202679571775118446</id><published>2010-02-17T15:39:00.003-06:00</published><updated>2010-02-17T19:11:52.856-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CRL'/><category scheme='http://www.blogger.com/atom/ns#' term='errors'/><category scheme='http://www.blogger.com/atom/ns#' term='proposal'/><title type='text'>CRL update problems</title><content type='html'>&lt;p&gt;&lt;br /&gt;As you probably know, CRLs are a vital part of the x509 security model; they are the only way CAs can invalidate compromised, or otherwise revoked certificates. Every time a user credential is presented to Grid-aware software, the appropriate CRL is checked to make sure the credential was not revoked.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;CRLs has expiration dates like everything else in the x509 world. A side effect of this is that if a CRL is not updated locally (by being downloaded from the CA site) before it expires, all credentials from that CA will be treated as invalid. So sites must download fresh updates frequently; the recommended policy in OSG is to do it once every 6 hours. The tool &lt;span style="font-weight: bold;"&gt;fetch-crl&lt;/span&gt; is used for the task.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Several OSG site admins have notified us that fetch-crl occasionally fails to download a CRL one or more CAs, and has asked up (the security team) for guidance on what to do in those events.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Ideally, we would like to debug each and every such event and make sure it is just a transient error, but given the distributed nature of the Grid this will not scale. OSG has hundreds of sites and there are hundreds of CAs, and problem is combinatorial. Unless such errors are very rare events, we need an alternative approach.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;One possibility would be for OSG to centrally serve the CRLs from all the supported CAs; this would allow us to more easily track problems since we can separately debug CA and site problems, thus going from a quadratical to a linear problem. Of course we still want to allow sites to go directly to the CAs for the CRLs if they want, for example when they are supporting a CA that is not part of the official OSG CA distribution; but we offer only limited support in such cases anyhow.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;However, the above solution is likely to create its own set of problems (still to be determined), so before we start any design and implementation effort we would like to know how important is to solve this for sites.&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;Right now we don't even have clear statistics on how often sites have problems with their CRLs, nor if the problems are due to specific CAs. So input from sites is highly desirable.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/1202679571775118446/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/02/crl-update-problems.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1202679571775118446'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1202679571775118446'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/02/crl-update-problems.html' title='CRL update problems'/><author><name>Igor</name><uri>http://www.blogger.com/profile/02777268248206873408</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-7693892887337255753</id><published>2010-01-21T15:14:00.003-06:00</published><updated>2010-01-21T15:22:47.148-06:00</updated><title type='text'>Changes in new version of OpenSSL</title><content type='html'>This is an informational notice only, there is no current action that is needed to be taken for OSG sites.&lt;br /&gt;&lt;br /&gt;This is a notice that OpenSSL 1.x is changing the way they name the certificate files in the trust anchor store (the certificate files for grid middleware are usually stored in the "/etc/grid-security/certificates/" directory).&lt;br /&gt;&lt;br /&gt;Traditionally OpenSSL was using a MD5 hash for naming the certificate files (which would look something like 9ff26ea4.0).  The new version has moved to using a SHA1 hash to create the certificate names.  Installing the new openSSL version on a machine would mean that openSSL   will NOT find the certificates installed in the trust stores due to different naming used by IGTF distribution. In short, the authentication on the installed machine will stop working.  IGTF distribution has proposed changes which will fix this issue and a new distribution will be released once these changes have been completed.&lt;br /&gt;&lt;br /&gt;If you have other concerns related to this, please let us know. We are also investigating how other pieces of our distribution may be affected by this change.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/7693892887337255753/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2010/01/changes-in-new-version-of-openssl.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7693892887337255753'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7693892887337255753'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2010/01/changes-in-new-version-of-openssl.html' title='Changes in new version of OpenSSL'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-1090869187243992836</id><published>2009-12-18T15:05:00.007-06:00</published><updated>2009-12-18T15:26:18.125-06:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='grid-proxy-init'/><category scheme='http://www.blogger.com/atom/ns#' term='voms-proxy-init'/><category scheme='http://www.blogger.com/atom/ns#' term='pem'/><category scheme='http://www.blogger.com/atom/ns#' term='p12'/><category scheme='http://www.blogger.com/atom/ns#' term='certificates'/><title type='text'>Using p12 files with user commands (grid-proxy-init and voms-proxy-init)</title><content type='html'>&lt;pre  wrap="" style="font-family:arial;"&gt;Most of the Grid users have been generally instructed to convert the p12 certificate files they get from CA on their browser to &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_0"&gt;pem&lt;/span&gt;&lt;/span&gt; format (i.e. &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_1"&gt;usercert&lt;/span&gt;&lt;/span&gt;.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_2"&gt;pem&lt;/span&gt;&lt;/span&gt; and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_3"&gt;userkey&lt;/span&gt;&lt;/span&gt;.&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_4"&gt;pem&lt;/span&gt;&lt;/span&gt;). This conversion requires the use of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_5"&gt;openssl&lt;/span&gt;&lt;/span&gt; command &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_6"&gt;which&lt;/span&gt; could be &lt;span class="blsp-spelling-corrected" id="SPELLING_ERROR_7"&gt;challenge&lt;/span&gt; to a novice Grid user. Users are not required to do this any more. Client commands used by most &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_6"&gt;OSG&lt;/span&gt;&lt;/span&gt; users (i.e. grid-proxy-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_7"&gt;init&lt;/span&gt;&lt;/span&gt; and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_8"&gt;voms&lt;/span&gt;&lt;/span&gt;-proxy-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_9"&gt;init&lt;/span&gt;&lt;/span&gt;) are capable of accepting p12 certificates. Here are some instructions of how they may be used&lt;br /&gt;&lt;/pre&gt;&lt;ol style="font-family: arial;"&gt;&lt;li&gt;Make sure the p12 certificate has restrictive permissions (read-only by user i.e. 400)&lt;/li&gt;&lt;li&gt; Example invocations:&lt;br /&gt;&lt;/li&gt;&lt;/ol&gt;&lt;pre  wrap="" style="font-family:arial;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;       &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_10"&gt;voms&lt;/span&gt;&lt;/span&gt;-proxy-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_11"&gt;init&lt;/span&gt;&lt;/span&gt; -cert $HOME/.globus/mycert.p12 -key $HOME/.globus/mycert.p12 -&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_12"&gt;voms&lt;/span&gt;&lt;/span&gt; &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;myVO&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:78%;"&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;&lt;br /&gt;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="font-size:100%;"&gt;&lt;span style="font-family:courier new;"&gt;       grid-proxy-&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_13"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_14"&gt;init&lt;/span&gt;&lt;/span&gt; -cert $HOME/.globus/mycert.p12 -key $HOME/.globus/mycert.p12&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;The users can still continue using &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_15"&gt;pem&lt;/span&gt;&lt;/span&gt; certificates, this post is designed to make users and &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_18"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_16"&gt;VOs&lt;/span&gt;&lt;/span&gt; aware of an alternative that may remove some challenges experienced by our users and improve their overall experience of &lt;span class="blsp-spelling-error" id="SPELLING_ERROR_19"&gt;&lt;span class="blsp-spelling-error" id="SPELLING_ERROR_17"&gt;OSG&lt;/span&gt;&lt;/span&gt;.&lt;/pre&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/1090869187243992836/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/12/using-p12-files-with-user-commands-grid.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1090869187243992836'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/1090869187243992836'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/12/using-p12-files-with-user-commands-grid.html' title='Using p12 files with user commands (grid-proxy-init and voms-proxy-init)'/><author><name>Anand</name><uri>http://www.blogger.com/profile/11211609360437004601</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-6162155419969614756</id><published>2009-11-17T11:48:00.002-06:00</published><updated>2009-11-17T11:52:49.835-06:00</updated><title type='text'>New KCA (Kerberos certificate Authority) server</title><content type='html'>Since Monday morning Nov. 16, Fermilab has switched to a new KCA (Kerberos certificate Authority) server. The old KCA server will be dropped from IGTF CA distribution bundle on Dec 1st of 2009.  The new server has a different public/private key pair, certificates issued by old KCA will not be valid.&lt;br /&gt;&lt;br /&gt;Site security contacts do not need to take any additional steps; a new bundle will be automatically fetched by your gatekeeper (if you enabled the cron jobs for fetching certificates -- see &lt;a href="https://twiki.grid.iu.edu/bin/view/ReleaseDocumentation/ComputeElementInstall#Install_the_CA_Certificate_Updat"&gt;https://twiki.grid.iu.edu/bin/view/ReleaseDocumentation/ComputeElementInstall#Install_the_CA_Certificate_Updat&lt;/a&gt;)&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;If you run web servers that uses Fermi KCA for authentication, please follow:&lt;br /&gt;&lt;br /&gt;    &lt;a href="http://security.fnal.gov/pki/new2kcafaq.html#1_16"&gt;http://security.fnal.gov/pki/new2kcafaq.html#1_16&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;which will explain how to properly update the web servers to accept the new certificates.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;VO security contacts, if your users rely on certificates issued by Fermi KCA, you may get some questions from the users. There are basically two types of things that can go wrong:&lt;br /&gt;&lt;br /&gt;1) Users may experience some problems in getting certificates.&lt;br /&gt;&lt;br /&gt;In most cases this will be because the clients on their desktops which request the certificates have not been updated so that they can successfully talk to the new KCA software.  Please direct users to the web page:&lt;br /&gt;&lt;br /&gt;    &lt;a href="http://computing.fnal.gov/xms/Services/Getting_Services/Certificates/Certificate_Client_Update_Instructions"&gt;http://computing.fnal.gov/xms/Services/Getting_Services/Certificates/Certificate_Client_Update_Instructions&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;which explains how to make sure their client software is properly updated. Users can go to the web page:&lt;br /&gt;&lt;br /&gt;    &lt;a href="http://security.fnal.gov/pki/browsercerttest.html"&gt;http://security.fnal.gov/pki/browsercerttest.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;to check whether or not they have a certificate (and whether it is one of the newly issued certificates).&lt;br /&gt;&lt;br /&gt;2) Users may have no problem getting certificates but discover that the certificates are not allowing them to access services that they were formerly able to access.  In most cases this is because the service admin (typically not the user making the complaint) has not properly updated their servers to recognize the newly issued certificates. On grid machines that enabled automated cert updates, this should not be an issue. If problem persists, please open a ticket with OSG GOC.&lt;br /&gt;&lt;br /&gt;For any other problems, please urge your users to either submit a ticket to OSG GOC or directly call Fermilab Service Desk. Contacting Fermilab Service Desk may speed up the process.&lt;br /&gt;&lt;br /&gt;Regards,&lt;br /&gt;OSG Security Team</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/6162155419969614756/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/11/new-kca-kerberos-certificate-authority.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/6162155419969614756'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/6162155419969614756'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/11/new-kca-kerberos-certificate-authority.html' title='New KCA (Kerberos certificate Authority) server'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-4956977207285101866</id><published>2009-11-09T15:39:00.003-06:00</published><updated>2009-11-10T12:37:55.787-06:00</updated><title type='text'>OSG-SEC-2009-11-09</title><content type='html'>Another linux kernel vulnerability has been discovered that could lead to a local root exploit.  This is in reference to &lt;a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547"&gt;CVE-2009-3547&lt;/a&gt;, and there currently is proof-of-concept code that has been released.  Security team contacts can view the information by looking at the following security notification ticket:&lt;br /&gt;&lt;br /&gt;   &lt;a href="https://ticket.grid.iu.edu/goc/viewer?id=7720"&gt;https://ticket.grid.iu.edu/goc/viewer?id=7720&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If there are any questions on this notification ticket please contact the OSG security team.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/4956977207285101866/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/11/osg-sec-2009-11-09.html#comment-form' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4956977207285101866'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/4956977207285101866'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/11/osg-sec-2009-11-09.html' title='OSG-SEC-2009-11-09'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-5961404792499402575</id><published>2009-11-09T14:21:00.003-06:00</published><updated>2009-11-09T14:29:23.848-06:00</updated><title type='text'>OpenSSL vulnerability has been announced</title><content type='html'>This is a notice that a recent vulnerability has been discovered in the&lt;br /&gt;OpenSSL protocol.  The vulnerability is a man-in-the-middle attack upon&lt;br /&gt;renegotiation of an SSL session and a good summary of the problem can&lt;br /&gt;be found at:&lt;br /&gt;&lt;br /&gt;  &lt;a href="http://www.theregister.co.uk/2009/11/05/serious_ssl_bug/"&gt;http://www.theregister.co.uk/2009/11/05/serious_ssl_bug/&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://www.sslshopper.com/article-ssl-and-tls-renegotiation-vulnerability-discovered.html"&gt;http://www.sslshopper.com/article-ssl-and-tls-renegotiation-vulnerability-discovered.html&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;For more technical details you can look at:&lt;br /&gt;&lt;br /&gt; &lt;a href="http://www.tombom.co.uk/blog/?p=85"&gt; http://www.tombom.co.uk/blog/?p=85&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://extendedsubset.com/?p=8"&gt;http://extendedsubset.com/?p=8&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://www.links.org/?p=780"&gt;http://www.links.org/?p=780&lt;/a&gt;&lt;br /&gt;  &lt;a href="http://www.links.org/?p=786"&gt;http://www.links.org/?p=786&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;The OSG security team is has been following this announcement and you can find additional information for that at:&lt;br /&gt;&lt;br /&gt;  &lt;a href="https://ticket.grid.iu.edu/goc/viewer?id=7714"&gt;https://ticket.grid.iu.edu/goc/viewer?id=7714&lt;/a&gt;</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/5961404792499402575/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/11/openssl-vulnerability-has-been.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/5961404792499402575'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/5961404792499402575'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/11/openssl-vulnerability-has-been.html' title='OpenSSL vulnerability has been announced'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-7599897974069505390</id><published>2009-11-02T10:51:00.004-06:00</published><updated>2009-11-02T11:00:58.123-06:00</updated><title type='text'>OSG-SEC-2009-10-19</title><content type='html'>Active exploitation of kernel vulnerabilities has resulted in a security announcement to all OSG security contacts.  Security team contacts can view the information by looking at the following security notification ticket:&lt;br /&gt;&lt;br /&gt;     &lt;a href="https://ticket.grid.iu.edu/goc/viewer?id=7640"&gt;https://ticket.grid.iu.edu/goc/viewer?id=7640&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;If there are any questions on this notification ticket please contact the OSG security team.</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/7599897974069505390/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/11/osg-sec-2009-10-19.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7599897974069505390'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/7599897974069505390'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/11/osg-sec-2009-10-19.html' title='OSG-SEC-2009-10-19'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-2518099536690330573.post-777948671503362089</id><published>2009-10-20T13:13:00.002-05:00</published><updated>2009-10-20T16:29:25.114-05:00</updated><title type='text'>New OSG Security blog</title><content type='html'>This is a new Open Science Grid (OSG) Security News and Announcement blog.  The OSG Security team will be posting news and announcements that are pertinent to members of the OSG community.  Be sure to check back often or subscribe to the blog for the latest announcements.&lt;br /&gt;&lt;br /&gt; - OSG Security Team</content><link rel='replies' type='application/atom+xml' href='http://osgsec.blogspot.com/feeds/777948671503362089/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://osgsec.blogspot.com/2009/10/new-osg-security-blog.html#comment-form' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/777948671503362089'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/2518099536690330573/posts/default/777948671503362089'/><link rel='alternate' type='text/html' href='http://osgsec.blogspot.com/2009/10/new-osg-security-blog.html' title='New OSG Security blog'/><author><name>James J. Barlow</name><uri>http://www.blogger.com/profile/11762781191374880582</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>