X2Go Bug report logs - #1030
Repository signing uses weak digest algorithm (SHA1)

Package: packages.x2go.org; Maintainer for packages.x2go.org is x2go-dev@lists.x2go.org;

Reported by: Christian Kreidl <debian@chk.cksf.de>

Date: Tue, 26 Apr 2016 12:20:02 UTC

Severity: normal

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


Message #5 received at submit@bugs.x2go.org (full text, mbox, reply):

Received: (at submit) by bugs.x2go.org; 26 Apr 2016 12:19:33 +0000
From debian@chk.cksf.de  Tue Apr 26 14:19:32 2016
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=0.8 required=3.0 tests=BAYES_50,URIBL_BLOCKED
	autolearn=ham version=3.3.2
Received: from localhost (localhost [127.0.0.1])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 563735DA98
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:19:32 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at ymir.das-netzwerkteam.de
Received: from ymir.das-netzwerkteam.de ([127.0.0.1])
	by localhost (ymir.das-netzwerkteam.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id GX-LKN+Js4pa for <submit@bugs.x2go.org>;
	Tue, 26 Apr 2016 14:19:25 +0200 (CEST)
X-Greylist: delayed 397 seconds by postgrey-1.34 at ymir.das-netzwerkteam.de; Tue, 26 Apr 2016 14:19:25 CEST
Received: from cksf.de (cksf.de [85.214.43.174])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTPS id 896C55DA92
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:19:25 +0200 (CEST)
Received: from localhost (localhost [127.0.0.1])
	by cksf.de (Postfix) with ESMTP id 469B91398057
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:12:48 +0200 (CEST)
X-Virus-Scanned: Debian amavisd-new at cksf.de
Received: from cksf.de ([127.0.0.1])
	by localhost (cksf.de [127.0.0.1]) (amavisd-new, port 10024)
	with ESMTP id hKgnE5-bq2Zu for <submit@bugs.x2go.org>;
	Tue, 26 Apr 2016 14:12:46 +0200 (CEST)
Received: from [147.142.41.18] (suspc28.ziti.uni-heidelberg.de [147.142.41.18])
	(using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA (256/256 bits))
	(No client certificate requested)
	by cksf.de (Postfix) with ESMTPSA id D67DD1398054
	for <submit@bugs.x2go.org>; Tue, 26 Apr 2016 14:12:45 +0200 (CEST)
To: submit@bugs.x2go.org
From: Christian Kreidl <debian@chk.cksf.de>
Subject: Repository signing uses weak digest algorithm (SHA1)
Message-ID: <571F5B3D.9070504@chk.cksf.de>
Date: Tue, 26 Apr 2016 14:12:45 +0200
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101
 Icedove/38.6.0
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: 7bit
Package: packages.x2go.org

Hi!

Repository signing with SHA1 is deprecated in testing:

http://packages.x2go.org/debian/dists/stretch/InRelease: Signature by key
972FD88FA0BAFB578D0476DFE1F958385BFE2B6E uses weak digest algorithm (SHA1)

Please update your configuration to use SHA256:
https://wiki.debian.org/SettingUpSignedAptRepositoryWithReprepro#Generating_GnuPG_keys

Thanks!


Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Wed Dec 4 08:34:37 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.