---------- Forwarded message ----------
From: Kevin Fenzi <kevin(a)scrye.com>
Date: Wed, Oct 12, 2011 at 10:14 PM
Subject: Subject: IMPORTANT: Mandatory password and ssh key change by
2011-11-30
To: announce(a)lists.fedoraproject.org, devel-announce(a)lists.fedoraproject.org
Subject: IMPORTANT: Mandatory password and ssh key change by 2011-11-30
Summary:
All existing users of the Fedora Account System (FAS) at
https://admin.fedoraproject.org/accounts are required to change their
password and upload a NEW ssh public key before 2011-11-30.
Failure to do so may result in your account being marked inactive.
Passwords changed and NEW ssh public keys uploaded after 2011-10-10
will meet this requirement.
Backgound and reasoning:
This change event has NOT been triggered by any specific compromise or
vulnerability in Fedora Infrastructure. Rather, we believe, due to the
large number of high profile sites with security breaches in recent
months, that this is a great time for all Fedora contributors and users
to review their security settings and move to "best practices" on their
machines. Additionally, we are putting in place new rules for passwords
to make them harder to guess.
New Password Rules:
* Nine or more characters with lower and upper case letters, digits and
punctuation marks.
* Ten or more characters with lower and upper case letters and digits.
* Twelve or more characters with lower case letters and digits
* Twenty or more characters with all lower case letters.
* No maximum length.
Some Do's and Don'ts:
* NEVER store your ssh private key on a shared or public system.
* ALWAYS use a strong passphrase on your ssh key.
* If you must store passwords, use an application specifically for this
purpose like revelation, gnome-keyring, seahorse, or keepassx.
* Regularly apply your operating system's security related updates.
* Only use ssh agent forwarding when needed ( .ssh/config:
"ForwardAgent no")
* DO verify ssh host keys via dnssec protected dns. ( .ssh/config:
"VerifyHostKeyDNS yes")
* DO consider a seperate ssh key for Fedora Infrastructure.
* Work with and use security features like SELinux and iptables.
* Review the Community Standard Infrastructure security document (link
below)
Q&A:
Q: My password and ssh private key are fine and secure!
Can't I just skip this change?
No. We believe the new guidelines above provide an added measure of
security compared to the previous requirements. We want all users of
our infrastructure to follow the new guidelines to improve one aspect
of security across the systems they share. Awareness is also an
aspect of good security. By requiring these changes, we also hope to
maintain and improve awareness of the process for changing passwords
and keys.
Q: Can I just change my password and re-upload my same ssh public key?
Or upload a bogus ssh public key and then re-upload my old one?
A: No. We've installed safeguards to ensure that your new ssh public
key is different from your old one. Additionally, some of our
contributors may have had accounts on compromised high profile Linux
sites recently, and we want to make sure no ssh private keys or
passwords used in Fedora Infrastructure were obtained via those
incidents.
Q: This is a hassle. How often is this going to happen?
A: The last mass password change in Fedora was more than 3 years ago.
Absent a triggering event, these mass changes will be infrequent.
Q: The new password length requirements/rules are too strict.
How will I remember passwords that are that long?
A: You can employ a password storage application (see above), or
use a method like diceware (see below), or construct a memorable
sentence or phrase.
Q: How do I generate a new ssh key? How do I use it for just Fedora
hosts?
A: See http://fedoraproject.org/wiki/Cryptography and use a
~/.ssh/config file to match fedoraproject.org hosts for that key.
Q: I never uploaded a ssh key to the Fedora Account System, nor am I
in a group that needs one, do I still have to upload a new one?
A: No. If you don't have a ssh public key uploaded or desire to do so,
you can just change your password.
More reading:
http://infrastructure.fedoraproject.org/csi/security-policy/en-US/html-sing…https://fedoraproject.org/wiki/Infrastructure_mass_password_updatehttp://xkcd.com/936/http://www.iusmentis.com/security/passphrasefaq/http://world.std.com/~reinhold/diceware.htmlhttp://fedoraproject.org/wiki/Cryptography
--
announce mailing list
announce(a)lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/announce
--
Regards,
*Buddhike Chandradeepa Kurera(bckurera)*
Fedora Ambassador Sri Lanka
Event Liaison - Design Team
*Email*: bckurera(a)fedoraproject.org | *IRC*: bckurera
*
*
Greetings, FUDCon friends, near and far:
As you are probably aware, the 2012 North American FUDCon will be held
in Blacksburg, Virginia, on the campus of Virginia Tech. If you are
planning on attending, it's never too early to pre-register, and to
start thinking about your travel plans. FUDCon Blacksburg will take
place January 13-15, 2012.
https://fedoraproject.org/wiki/FUDCon:Blacksburg_2012
I'm happy to announce that we are officially accepting subsidy requests
for travel to Blacksburg. If you are requesting a subsidy, we just have
a few steps that we ask you to follow:
1: Register on the FUDCon: Blacksburg wiki page in the pre-registration
area.
https://fedoraproject.org/wiki/FUDCon:Blacksburg_2012#Pre-registration
2: Put an X in the $$$ column.
3: Create a funding request ticket in the FUDCon trac at:
https://fedorahosted.org/fudcon-planning/wiki/FundingRequest
General information about being sponsored can be found at
http://fedoraproject.org/wiki/Sponsoring_event_attendees .
Requests are processed in a first-come, first-served manner, though
generally prioritization is giving to local travel over international
travel first. Requests will be reviewed by fellow Fedora community
members at FUDCon subsidy request meetings over the next few weeks.
The first subsidy meeting will take place on Wednesday, November 9th.
The time and IRC channel will be announced as we approach that day.
As always, participation both in planning as well as subsidy granting is
ALWAYS welcome. Please join us on the fudcon-planning mailing list for
information about meetings, as well as for general FUDCon updates, and
see the "meetings" section of your FUDCon's wiki page for meeting
information.
Mailing list:
https://admin.fedoraproject.org/mailman/listinfo/fudcon-planning
FUDCon Blacksburg Meetings:
https://fedoraproject.org/wiki/FUDCon:Blacksburg_2012#Meetings
Hello FAms!
I'm glad to announce that Fedora will be represented at the 8th Latin
American Free Software Conference - Latinoware [1].
I'll deliver a talk entitled "Fedora Project: building an open,
collaborative and transparent future" that intends to present our core
values and shows our experiences as a global open source community.
Also, our fellow ambassador Valentin Basel [2] from Argentina will
deliver a talk and a hackfest, both intending to demonstrate how to use
Fedora for robotics under an educational perspective.
[1] https://fedoraproject.org/wiki/Latinoware_2011
[2] http://fedoraproject.org/wiki/User:Valentinbasel
Regards,
--
Igor Pires Soares
Fedora Ambassador (Brazil) - Member of FAmSCo
Fedora I18N/L10N QA
https://fedoraproject.org/wiki/User:Igor
This mail is a reminder for today's meeting for the French speaking community.
2011-10-10 / 18:30 UTC
IRC: freenode
#fedora-meeting
Ce mail est un rappel pour la réunion de la communauté francophone, qui aura lieu ce lundi (10 octobre) à 20h30 heure de Paris sur IRC (freenode) #fedora-meeting .
L'ordre du jour est disponible depuis cette page :
http://fedoraproject.org/wiki/Réunions_hebdomadaires_de_la_French_team
N'hésitez pas à le modifier pour rajouter des sujets qui vous semblent intéressants.
Merci de répondre à ce message en cas d'indisponibilité.
This week was a good meeting because we had 13 people participating.
Thanks everybody for coming!
Minutes:
http://meetbot.fedoraproject.org/fedora-meeting/2011-10-05/emea_ambassadors…
Minutes (text):
http://meetbot.fedoraproject.org/fedora-meeting/2011-10-05/emea_ambassadors…
Log:
http://meetbot.fedoraproject.org/fedora-meeting/2011-10-05/emea_ambassadors…
Meet you again on
Wednesday, October 19th (two weeks from now)
at 20:00 UTC
in #fedora-meeting!
Regards,
Christoph
====================================================
#fedora-meeting: EMEA ambassadors meeting 2011-10-05
====================================================
Meeting started by cwickert at 20:02:01 UTC. The full logs are available
at
http://meetbot.fedoraproject.org/fedora-meeting/2011-10-05/emea_ambassadors…
Meeting summary
---------------
* role call (cwickert, 20:03:00)
* Announcements (cwickert, 20:05:12)
* No more ambassadors polos in EMEA left but we are going to place a
new order soon (cwickert, 20:09:13)
* ACTION: cwickert to make sure from now on we only get polos in the
'new' color because it matches the light blue on the Fedora logo
(cwickert, 20:11:41)
* Ambassadors Schedule (cwickert, 20:12:04)
* ACTION: cwickert to make a poll on the media meeting time and
announce it (cwickert, 20:17:03)
* ACTION: gnokii to nag the design-team about F16 media artwork. we
need it earlier this time (cwickert, 20:19:47)
* LINK:
http://lists.fedoraproject.org/pipermail/ambassadors/2011-August/018152.html
(cwickert, 20:22:58)
* please add your release events to
https://fedoraproject.org/wiki/F16_release_events (cwickert,
20:23:42)
* F16 media production (cwickert, 20:24:37)
* Events (cwickert, 20:46:23)
* Fedora 16 release is on 2011-11-08, so don't expect any F16 media
for events till ~ 2011-11-20 (cwickert, 20:50:36)
* ACTION: jsmith to send Fedora branded USB keys to delhage for fscons
(cwickert, 20:51:43)
* ACTION: sesivany to get a quote for branded USB keys (cwickert,
20:55:14)
* Action items from previous meetings (cwickert, 20:57:01)
* ACTION: cwickert to ask rel-eng how fast we can get the F16 ISOs
(cwickert, 20:59:54)
* Open floor (cwickert, 21:02:34)
* Vote now for your favorite Fedora 17 release name at Vote now for
your favorite Fedora 17 release name (cwickert, 21:03:58)
* vote for the BEEFY MIRACLE!!! (cwickert, 21:04:13)
* Vote now for your favorite Fedora 17 release name at
https://admin.fedoraproject.org/voting/about/relnamef17 (cwickert,
21:06:22)
* ACTION: sesivany and cwickert to investigate the chance of having a
FAD or Mini-FUDCon at the Brno developer conference (cwickert,
21:09:32)
Meeting ended at 21:16:25 UTC.
Action Items
------------
* cwickert to make sure from now on we only get polos in the 'new' color
because it matches the light blue on the Fedora logo
* cwickert to make a poll on the media meeting time and announce it
* gnokii to nag the design-team about F16 media artwork. we need it
earlier this time
* jsmith to send Fedora branded USB keys to delhage for fscons
* sesivany to get a quote for branded USB keys
* cwickert to ask rel-eng how fast we can get the F16 ISOs
* sesivany and cwickert to investigate the chance of having a FAD or
Mini-FUDCon at the Brno developer conference
Action Items, by person
-----------------------
* cwickert
* cwickert to make sure from now on we only get polos in the 'new'
color because it matches the light blue on the Fedora logo
* cwickert to make a poll on the media meeting time and announce it
* cwickert to ask rel-eng how fast we can get the F16 ISOs
* sesivany and cwickert to investigate the chance of having a FAD or
Mini-FUDCon at the Brno developer conference
* delhage
* jsmith to send Fedora branded USB keys to delhage for fscons
* gnokii
* gnokii to nag the design-team about F16 media artwork. we need it
earlier this time
* sesivany
* sesivany to get a quote for branded USB keys
* sesivany and cwickert to investigate the chance of having a FAD or
Mini-FUDCon at the Brno developer conference
* **UNASSIGNED**
* (none)
hello dear APAC Fams,
The next APAC FAD Special meeting will be held on
Day : Saturday, October 8th, 2011
Time : 04:00 UTC
Place: #fedora-meeting on irc.freenode.net
Please update the agenda[1] and it needs lot of love to be smart, please do
update it as per the need.
thanks for your time and looking forward to see you on Saturday.
[1] https://fedoraproject.org/wiki/Meeting:APAC_Ambassadors_2011-10-08
--
Regards,
*Buddhike Chandradeepa Kurera(bckurera)*
Fedora Ambassador Sri Lanka
Event Liaison - Design Team
*Email*: bckurera(a)fedoraproject.org | *IRC*: bckurera
*
*