Posted Friday 22nd August 2008 16:00 GMT
The truth is out there
https://www.redhat.com/archives/fedora-announce-list/2008-August/msg00012.html
"oops", and also
http://rhn.redhat.com/errata/RHSA-2008-0855.html
"*oops* we let a stranger sign OpenSSH packages"