From owner-freebsd-security Sat Feb 10 4:13:55 2001 Delivered-To: freebsd-security@freebsd.org Received: from mta5.snfc21.pbi.net (mta5.snfc21.pbi.net [206.13.28.241]) by hub.freebsd.org (Postfix) with ESMTP id BF31437B67D for ; Sat, 10 Feb 2001 04:13:19 -0800 (PST) Received: from xor.obsecurity.org ([63.207.60.67]) by mta5.snfc21.pbi.net (Sun Internet Mail Server sims.3.5.2000.01.05.12.18.p9) with ESMTP id <0G8I000UTBP5D8@mta5.snfc21.pbi.net> for security@FreeBSD.ORG; Fri, 9 Feb 2001 12:31:57 -0800 (PST) Received: by xor.obsecurity.org (Postfix, from userid 1000) id 1B75566B62; Fri, 09 Feb 2001 12:34:37 -0800 (PST) Date: Fri, 09 Feb 2001 12:34:37 -0800 From: Kris Kennaway Subject: Re: FreeBSD Ports Security Advisory: FreeBSD-SA-01:INSERT_NUMBER_HERE In-reply-to: <2488141552.981740685@[192.168.1.2]>; from cholet@logilune.com on Fri, Feb 09, 2001 at 05:44:45PM +0100 To: Eric Cholet Cc: security@FreeBSD.ORG Message-id: <20010209123436.A64466@mollari.cthul.hu> MIME-version: 1.0 Content-type: multipart/signed; micalg=pgp-md5; protocol="application/pgp-signature"; boundary="RnlQjJ0d97Da+TV1" Content-disposition: inline User-Agent: Mutt/1.2.5i References: <200102082014.PAA29877@vws3.interlog.com> <2488141552.981740685@[192.168.1.2]> Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk X-Loop: FreeBSD.org --RnlQjJ0d97Da+TV1 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline On Fri, Feb 09, 2001 at 05:44:45PM +0100, Eric Cholet wrote: > I received the following, what worries me is that the PGP signature > verified, and it's not April 1st. WTF ?? Checking the mail headers shows you that it's spoofed - it's trivial to do this with email, which is why we PGP sign them. All advisories released by FreeBSD are signed with the security officer's PGP key, anything which is not is a fake. Kris --RnlQjJ0d97Da+TV1 Content-Type: application/pgp-signature Content-Disposition: inline -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.4 (FreeBSD) Comment: For info see http://www.gnupg.org iD8DBQE6hFRcWry0BWjoQKURArG9AJ9K4JYcIq1wSmJFfJeEKef15P50iwCgoZs9 VmapZK+inKheyvC6jP3CjUQ= =XFpX -----END PGP SIGNATURE----- --RnlQjJ0d97Da+TV1-- To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message