From ionic@ionic.de  Thu Jul  2 01:49:58 2015
Received: (at 897) by bugs.x2go.org; 1 Jul 2015 23:50:00 +0000
X-Spam-Checker-Version: SpamAssassin 3.3.2 (2011-06-06) on
	ymir.das-netzwerkteam.de
X-Spam-Level: 
X-Spam-Status: No, score=-1.9 required=5.0 tests=BAYES_00,T_DKIM_INVALID,
	URIBL_BLOCKED autolearn=ham version=3.3.2
Received: from Root24.de (powered.by.root24.eu [5.135.3.88])
	by ymir.das-netzwerkteam.de (Postfix) with ESMTP id 576595DA85
	for <897@bugs.x2go.org>; Thu,  2 Jul 2015 01:49:58 +0200 (CEST)
Received: from nopileos.local (home.ionic.de [217.92.117.31])
	by mail.ionic.de (Postfix) with ESMTPSA id 1B2B64F04FFC
	for <897@bugs.x2go.org>; Thu,  2 Jul 2015 01:49:58 +0200 (CEST)
DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=ionic.de; s=default;
	t=1435794598; bh=NEYb7eZCHWhVO6w1DtLTFLLeUL1Bd5fxQs4xyunZS2I=;
	h=Subject:Reply-To:References:To:From:Date:In-Reply-To:From;
	b=eD6X8JiOg/KLbx26WrHmea6KNa8A5tXeE5FfOFWlMjmONYjIvsTi4inWSMjH+8i4x
	 2uYYLEjWvReka0md0/Q+CyKMzYiZZqK5BF3qOC7EPGOlzKLnhC2izrzHG4bjO870LU
	 0E9mej4GDJdrkjl+BJ2+pSCdoA8NLget4bSpsJs8=
Subject: Re: [X2Go-Dev] Bug#897: epel 5 repos have signature errors
Reply-To: Mihai Moldovan <ionic@ionic.de>, 897@bugs.x2go.org
References: <55925FB9.4070405@nxp.com> <5592E97E.4020704@ionic.de>
 <5593B2FE.405@nxp.com> <5593C4D1.5070609@gmx.de> <559411C6.2060808@ionic.de>
To: 897@bugs.x2go.org
From: Mihai Moldovan <ionic@ionic.de>
X-Enigmail-Draft-Status: N1110
Message-ID: <55947CA0.4030209@ionic.de>
Date: Thu, 2 Jul 2015 01:49:52 +0200
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.9; rv:38.0)
 Gecko/20100101 Thunderbird/38.0.1
MIME-Version: 1.0
In-Reply-To: <559411C6.2060808@ionic.de>
Content-Type: multipart/signed; micalg=pgp-sha512;
 protocol="application/pgp-signature";
 boundary="UKvo2xIPq998nB3JxbjiS435kwBHhwdFO"

This is an OpenPGP/MIME signed message (RFC 4880 and 3156)
--UKvo2xIPq998nB3JxbjiS435kwBHhwdFO
Content-Type: text/plain; charset=windows-1252
Content-Transfer-Encoding: quoted-printable

On 01.07.2015 06:13 PM, Mihai Moldovan wrote:
> BUT we do sign the packages with an 2048 bit RSA key. While this is=20
> not a bad idea per se, I've read that RHEL5's rpm only supports 1024=20
> bit RSA or DSA keys...
>=20
>=20
> Looks like I have to create an 1024 bit subkey, upload that to the=20
> keyservers, put it into the Debian keyring, add it to=20
> http://packages.x2go.org/pub.key and sign all RHEL 5 packages with=20
> that weak one?

Created a VM and tested this hunch with one package. Looks like I was rig=
ht. Will update the buildscript now and re-sign manually for now...


Mihai


--UKvo2xIPq998nB3JxbjiS435kwBHhwdFO
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iQIcBAEBCgAGBQJVlHygAAoJEB/WLtluJTqHWIAQANdeNN0QKBXRF6+URk1UsMg6
2rf2DvkJJcUwv521SPJwWlzZuzfuiONU0hXsi76/b/EdBbGHv2F/lg01rdKrsuvj
wi8RwJPXsnXpGUm9q0d+8NEd2A8GWWdaaKuyyEM4LnBunCr0OFhoiV1jlsDbzKvV
4uwHu+eNmaywVsf3AyZjfC3RTZEe6eMhJAIvZp5oF81dvSlawU2wxyKQnXFLG0iu
5ddsDJYvzYJcEN4ezo0BG7G22Gn4valIjkgCtvUu5zyhc5rmZd633uns01GY4VQz
BcBv/r4CSTRNXvHWGGZLcdvaz/mQ2G9WVzvD4pZBz1414pmvKWxB4cBnJlDE1uZR
U4b5D6VShLx9M9Psy/QHlnPxRmGXp1t+/On2VbLER4osca3bwDZ2JJan3smQLzi3
SK8MSavHWzLuuJXWMvcvI540Ipkv1BwwAo4Tli9RD/0J68a3LmkVCwgxydXEfbEc
dUyuj4ZAiOUwy31vhLxx9iCTNjh/qRWsd+lXlpO29hA4d9XqyrKTgn7d/J3/2wLT
hwUcE1o86kIlv7ix/A60ryhHpGJWKyYmH36dHqUIpGJgJc5mkTLQTVpv0ptvUCjk
xNK4ANSZOSwCb5Bs3Oi2RD/JKHrG+jevBbZsCawTtA2613WA1iaUu4yq5c9lg8R3
8rqq2bzxZ3cdYUHqIePr
=g9HH
-----END PGP SIGNATURE-----

--UKvo2xIPq998nB3JxbjiS435kwBHhwdFO--

