Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

static keys from hetzner rescue systems and tarballs #88

Merged
merged 1 commit into from
Aug 24, 2022

Conversation

hannob
Copy link
Collaborator

@hannob hannob commented Aug 23, 2022

These are various keys in hetzner install images and rescue system images that are or were accessible by booting the hetzner rescue system.

I looked into this and none of them look particularly serious, it seems their current installation routine replaces the keys, but some legacy systems may still have host keys that can be found here. Also some older install images seem to have installed example certs that at least in one case I could tie to a valid (but expired) TLS certificate. So nothing particularly interesting, but good to keep them for auditing purposes.

@BenBE
Copy link
Collaborator

BenBE commented Aug 24, 2022

Anything related to #4 included?

@hannob
Copy link
Collaborator Author

hannob commented Aug 24, 2022

No, I checked that. It seems they have removed all images that contained those keys.

@BenBE BenBE merged commit fc5d0eb into SecurityFail:master Aug 24, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants