Last week, Red Hat security specialists had a problem on their hands when they detected an illegal intrusion on the company’s computer systems. The attack affected both the Red Hat Enterprise Linux servers and the servers of the Fedora Project, a Linux-based operating system supported by Red Hat.
Servers were instantly taken offline. Red Hat issued an advisory to its customers, telling them how to check to see if they had been compromised and offering an updated version of the affected packages, including Red Hat Enterprise Linux 4 and Red Hat Enterprise Linux 5.
“Security specialists and administrators have been working since [they discovered the attack] to analyze the intrusion and the extent of the compromise, as well as reinstall Fedora systems,” said Paul W. Fields, Fedora’s project leader. “We are using the requisite outages as an opportunity to do other upgrades for the sake of functionality as well as security.”
Affected Systems
A system used for signing Fedora packages was compromised, according to Fields. He also said he believes the intruder did not steal the pass phrase used to secure the Fedora package signing key, but had not yet confirmed that.
“While there is no definitive evidence that the Fedora key has been compromised, because Fedora packages are distributed via multiple third-party mirrors and repositories, we have decided to convert to a new Fedora signing key,” Fields said.
Red Hat has built a custom hardware solution to prevent having to disclose private keys to developers. “Assuming that [this was done correctly], there was no risk of their key being compromised,” said Justin Cappos, a post-doc student at the University of Washington who has studied and written papers on the subject. “Someone was able to get a token, but was not actually able to get the key.”
Packages obtained by Red Hat Enterprise Linux…