From unknown Sat May 16 01:40:51 2026
MIME-Version: 1.0
X-Mailer: MIME-tools 5.502 (Entity 5.502)
X-Loop: owner@bugs.x2go.org
From: owner@bugs.x2go.org (X2Go Bug Tracking System)
Subject: Bug#1030 closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
 (Re: [X2Go-Dev] Bug#1030: Repository signing uses weak digest algorithm
 (SHA1))
Message-ID: <handler.1030.b1030.146797082429662.notifdone@bugs.x2go.org>
References: <20160708094000.Horde.pxMVD0BwJTL3RgjFwFvVOFp@mail.das-netzwerkteam.de>
X-X2go-PR-Message: they-closed 1030
X-X2go-PR-Package: packages.x2go.org
Date: Fri, 08 Jul 2016 09:45:03 +0000
Content-Type: multipart/mixed; boundary="----------=_1467971103-31520-0"

This is a multi-part message in MIME format...

------------=_1467971103-31520-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset=utf-8

This is an automatic notification regarding your Bug report
which was filed against the packages.x2go.org package:

#1030: Repository signing uses weak digest algorithm (SHA1)

It has been closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>.

Their explanation is attached below along with your original report.
If this explanation is unsatisfactory and you have not received a
better one in a separate message then please contact Mike Gabriel <mike.gab=
riel@das-netzwerkteam.de> by
replying to this email.


--=20
1030: http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=3D1030
X2Go Bug Tracking System
Contact owner@bugs.x2go.org with problems

------------=_1467971103-31520-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 1030) by bugs.x2go.org; 8 Jul 2016 09:40:24 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=3.0 tests=BAYES_00,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from localhost (localhost [127.0.0.1])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 34DD45DDF5
	for <1030@bugs.x2go.org>; Fri,  8 Jul 2016 11:40:22 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at ymir.das-netzwerkteam.de
Received: from ymir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (ymir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id WFbiclDoikdj for <1030@bugs.x2go.org>;
	Fri,  8 Jul 2016 11:40:15 +0200 (CEST)
Received: from freya.das-netzwerkteam.de (freya.das-netzwerkteam.de [88.198.48.199])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 53ED55DDD0
	for <1030@bugs.x2go.org>; Fri,  8 Jul 2016 11:40:15 +0200 (CEST)
Received: from grimnir.das-netzwerkteam.de (grimnir.das-netzwerkteam.de [IPv6:2a01:4f8:131:20c1:5254:ff:fe24:f0dd])
	by freya.das-netzwerkteam.de (Postfix) with ESMTPS id E025FB0B;
	Fri,  8 Jul 2016 11:40:14 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTP id 1DD0D400C8;
	Fri,  8 Jul 2016 11:40:14 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at grimnir.das-netzwerkteam.de
Received: from grimnir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (grimnir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id QaT93lGlfQV3; Fri,  8 Jul 2016 11:40:07 +0200 (CEST)
Received: from das-netzwerkteam.de (localhost [127.0.0.1])
	by grimnir.das-netzwerkteam.de (Postfix) with ESMTPS id B88A9400C6;
	Fri,  8 Jul 2016 11:40:00 +0200 (CEST)
Received: from listrac.informatik.uni-kiel.de
 (listrac.informatik.uni-kiel.de [134.245.252.114]) by
 mail.das-netzwerkteam.de (Horde Framework) with HTTP; Fri, 08 Jul 2016
 09:40:00 +0000
Date: Fri, 08 Jul 2016 09:40:00 +0000
Message-ID: <20160708094000.Horde.pxMVD0BwJTL3RgjFwFvVOFp@mail.das-netzwerkteam.de>
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: Christian Kreidl <debian@chk.cksf.de>, 1030@bugs.x2go.org
Subject: Re: [X2Go-Dev] Bug#1030: Repository signing uses weak digest
 algorithm (SHA1)
In-Reply-To: <571F5B3D.9070504@chk.cksf.de>
User-Agent: Horde Application Framework 5
Accept-Language: de,en
Organization: DAS-NETZWERKTEAM
X-Originating-IP: 134.245.252.114
X-Remote-Browser: Mozilla/5.0 (X11; Linux i686; rv:38.0) Gecko/20100101
 Firefox/38.0 Iceweasel/38.7.1
Content-Type: multipart/signed; boundary="=_hPkQreWo9wgu-iPm1cN2S7d";
 protocol="application/pgp-signature"; micalg=pgp-sha256
MIME-Version: 1.0

This message is in MIME format and has been PGP signed.

--=_hPkQreWo9wgu-iPm1cN2S7d
Content-Type: text/plain; format=flowed; DelSp=Yes
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Control: close -1

On  Di 26 Apr 2016 14:12:45 CEST, Christian Kreidl wrote:

> Package: packages.x2go.org
>
> Hi!
>
> Repository signing with SHA1 is deprecated in testing:
>
> http://packages.x2go.org/debian/dists/stretch/InRelease: Signature by key
> 972FD88FA0BAFB578D0476DFE1F958385BFE2B6E uses weak digest algorithm (SHA1=
)
>
> Please update your configuration to use SHA256:
> https://wiki.debian.org/SettingUpSignedAptRepositoryWithReprepro#Generati=
ng_GnuPG_keys
>
> Thanks!

Done. Actually, digest-algo is now SHA512.

Mike

--=20

DAS-NETZWERKTEAM
mike=20gabriel, herweg 7, 24357 fleckeby
mobile: +49 (1520) 1976 148
landline: +49 (4354) 8390 139

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de


--=_hPkQreWo9wgu-iPm1cN2S7d
Content-Type: application/pgp-signature
Content-Description: Digitale PGP-Signatur
Content-Disposition: inline

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAABCAAGBQJXf3TwAAoJEJr0azAldxsxJ4QQAIv3o3EHnMEVa7Q7rdUuEAHy
dif9Ah/yhT4V+sXZp9QPcLzuaueBW59/yUYFQkkJY8Kt14f+OfpdUqDNM5gjwLZT
YMlETrBDmWgq5jEVx/eGYiTooQ5xZE6ETFxgYIqPU+hWvvF1xkfbzRoAdpYdip/G
X3rQ2GrI4lMtfYUXOGwwYvH/1qEEUU4q8fJik/VgV9KDg/PnsibWre0DHbxUiVKx
Ct6woeMD2jKYABZsTTR5K0JNjhlfpAbON6qV6NWDOjdZZwaY9HUtQLKAXyQzQByy
k+hlsfseAPvVYXJ00NoYGrOwXQbxyLV4ayUHRmPJsn5ho1I0CCrxj2Vqe1lD2S+Z
JvS67JFXlXAx989h9ps1/y3Ebpn4WERmJZ0R8TkwLKAF8d/EGUH9Hcs2LHg7jfa6
BtOql5l3WhN8zNzhnC1AkCd7AV06J/nGiMSBdS6uGm/umYUppUL0pHnTvBSP9F5L
/VHX3OrC6FzwWEF2MdopFv4MG+NJBXzt+3smX3iHO/fIc5NFe/Z3poBe/vAtH9mB
Sb/TqWuiBt2Eag3eemIEa7MmjDuccBCX+SkIn0blB7ANjTaL0DodpBJecIjxY9DF
IaX7z20WE+SApH8rtsbDyBr2C8QepTfWYdsv+fGq7ilzqmcr6HhydinyvxZMA6Nf
2lXOAC/Zh/2cWwObDObs
=BdBD
-----END PGP SIGNATURE-----

--=_hPkQreWo9wgu-iPm1cN2S7d--


------------=_1467971103-31520-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.x2go.org; 26 Apr 2016 12:19:33 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=0.8 required=3.0 tests=BAYES_50,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from localhost (localhost [127.0.0.1])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 563735DA98
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:19:32 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at ymir.das-netzwerkteam.de
Received: from ymir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (ymir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id GX-LKN+Js4pa for <submit@bugs.x2go.org>;
	Tue, 26 Apr 2016 14:19:25 +0200 (CEST)
X-Greylist: delayed 397 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Tue, 26 Apr 2016 14:19:25 CEST
Received: from cksf.de (cksf.de [85.214.43.174])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 896C55DA92
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:19:25 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
	by cksf.de (Postfix) with ESMTP id 469B91398057
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:12:48 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at cksf.de
Received: from cksf.de ([127.0.0.1])
	by localhost (cksf.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id hKgnE5-bq2Zu for <submit@bugs.x2go.org>;
	Tue, 26 Apr 2016 14:12:46 +0200 (CEST)
Received: from [147.142.41.18] (suspc28.ziti.uni-heidelberg.de [147.142.41.18])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by cksf.de (Postfix) with ESMTPSA id D67DD1398054
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:12:45 +0200 (CEST)
To: submit@bugs.x2go.org
From: Christian Kreidl <debian@chk.cksf.de>
Subject: Repository signing uses weak digest algorithm (SHA1)
Message-ID: <571F5B3D.9070504@chk.cksf.de>
Date: Tue, 26 Apr 2016 14:12:45 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101
 Icedove/38.6.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit

Package: packages.x2go.org

Hi!

Repository signing with SHA1 is deprecated in testing:

http://packages.x2go.org/debian/dists/stretch/InRelease: Signature by key
972FD88FA0BAFB578D0476DFE1F958385BFE2B6E uses weak digest algorithm (SHA1)

Please update your configuration to use SHA256:
https://wiki.debian.org/SettingUpSignedAptRepositoryWithReprepro#Generating_GnuPG_keys

Thanks!

------------=_1467971103-31520-0--
