- From report to PMB " A security problem was discovered last week and is still ongoing. The details of the compromise and the status of the follow up are still internal to the security teams. By way of summary, rootkits have been found installed on machines within three (sites and) countries. In some cases root has been compromised and ssh keys taken. There have been many ssh connections attempted subsequent to the keys being compromised. The earliest known breach happened at a UK site and a user's ssh key was taken and used to access their central account. As a precaution his grid certificates were revoked. Investigations at most sites are ongoing and compromised machines rebuilt. This incident has highlighted several areas of the process to be improved - for example what the user should do once their accounts are suspended, how grid security interfaces with site CERTs and group admins. Information flow between grid contacts and services is also to be looked at more closely."
- Raises questions about local procedures
- Raises questions about user actions/limitations (why is A still not able to work)
- Have all sites responded that they have carried out checks?