X2Go Bug report logs - #1030
Repository signing uses weak digest algorithm (SHA1)

Package: packages.x2go.org; Maintainer for packages.x2go.org is x2go-dev@lists.x2go.org;

Reported by: Christian Kreidl <debian@chk.cksf.de>

Date: Tue, 26 Apr 2016 12:20:02 UTC

Severity: normal

Done: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>

Bug is archived. No further changes may be made.

Full log


🔗 View this message in rfc822 format

MIME-Version: 1.0
X-Mailer: MIME-tools 5.502 (Entity 5.502)
X-Loop: owner@bugs.x2go.org
From: owner@bugs.x2go.org (X2Go Bug Tracking System)
Subject: Bug#1030 closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
 (Re: [X2Go-Dev] Bug#1030: Repository signing uses weak digest algorithm
 (SHA1))
Message-ID: <handler.1030.b1030.146797082429662.notifdone@bugs.x2go.org>
References: <20160708094000.Horde.pxMVD0BwJTL3RgjFwFvVOFp@mail.das-netzwerkteam.de>
X-X2go-PR-Message: they-closed 1030
X-X2go-PR-Package: packages.x2go.org
Date: Fri, 08 Jul 2016 09:45:03 +0000
Content-Type: multipart/mixed; boundary="----------=_1467971103-31520-0"
[Message part 1 (text/plain, inline)]
This is an automatic notification regarding your Bug report
which was filed against the packages.x2go.org package:

#1030: Repository signing uses weak digest algorithm (SHA1)

It has been closed by Mike Gabriel <mike.gabriel@das-netzwerkteam.de>.

Their explanation is attached below along with your original report.
If this explanation is unsatisfactory and you have not received a
better one in a separate message then please contact Mike Gabriel <mike.gabriel@das-netzwerkteam.de> by
replying to this email.


-- 
1030: http://bugs.x2go.org/cgi-bin/bugreport.cgi?bug=1030
X2Go Bug Tracking System
Contact owner@bugs.x2go.org with problems
[Message part 2 (message/rfc822, inline)]
From: Mike Gabriel <mike.gabriel@das-netzwerkteam.de>
To: Christian Kreidl <debian@chk.cksf.de>, 1030@bugs.x2go.org
Subject: Re: [X2Go-Dev] Bug#1030: Repository signing uses weak digest algorithm (SHA1)
Date: Fri, 08 Jul 2016 09:40:00 +0000
[Message part 3 (text/plain, inline)]
Control: close -1

On  Di 26 Apr 2016 14:12:45 CEST, Christian Kreidl wrote:

> Package: packages.x2go.org
>
> Hi!
>
> Repository signing with SHA1 is deprecated in testing:
>
> http://packages.x2go.org/debian/dists/stretch/InRelease: Signature by key
> 972FD88FA0BAFB578D0476DFE1F958385BFE2B6E uses weak digest algorithm (SHA1)
>
> Please update your configuration to use SHA256:
> https://wiki.debian.org/SettingUpSignedAptRepositoryWithReprepro#Generating_GnuPG_keys
>
> Thanks!

Done. Actually, digest-algo is now SHA512.

Mike

-- 

DAS-NETZWERKTEAM
mike gabriel, herweg 7, 24357 fleckeby
mobile: +49 (1520) 1976 148
landline: +49 (4354) 8390 139

GnuPG Fingerprint: 9BFB AEE8 6C0A A5FF BF22  0782 9AF4 6B30 2577 1B31
mail: mike.gabriel@das-netzwerkteam.de, http://das-netzwerkteam.de

[Message part 4 (application/pgp-signature, inline)]
[Message part 5 (message/rfc822, inline)]
From: Christian Kreidl <debian@chk.cksf.de>
To: submit@bugs.x2go.org
Subject: Repository signing uses weak digest algorithm (SHA1)
Date: Tue, 26 Apr 2016 14:12:45 +0200
Package: packages.x2go.org

Hi!

Repository signing with SHA1 is deprecated in testing:

http://packages.x2go.org/debian/dists/stretch/InRelease: Signature by key
972FD88FA0BAFB578D0476DFE1F958385BFE2B6E uses weak digest algorithm (SHA1)

Please update your configuration to use SHA256:
https://wiki.debian.org/SettingUpSignedAptRepositoryWithReprepro#Generating_GnuPG_keys

Thanks!

Send a report that this bug log contains spam.


X2Go Developers <owner@bugs.x2go.org>. Last modified: Fri Apr 26 22:22:59 2024; Machine Name: ymir.das-netzwerkteam.de

X2Go Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.