Bug#904641: Please remove local build options in debian/gbp.conf

2018-07-26 Thread Thomas Goirand
Package: apache2 Version: 2.4.33-3 Severity: important Dear maintainer, The Debian package includes a debian/gbp.conf which sets some global options for git-buildpackage. These are very annoying for anyone willing to rebuild the package. Namely, please remove: pristine-tar = True builder = dpkg-

Bug#904684: ssl-cert: HostName length check is too small

2018-07-26 Thread David Magda
Package: ssl-cert Version: 1.0.39 Severity: normal In the make_snakeoil() funtion, the code gets the FQDN of the system via a call to 'hostname -f'. Then it checks if this the FQDN is longer than 64 characters, and if it is, uses the short hostname. However, a FQDN can be up to 255 octets per RFC

Bug#904686: ssl-cert: RSA keylength is getting a bit short

2018-07-26 Thread David Magda
Package: ssl-cert Version: 1.0.39 Severity: wishlist The current default keylength for the snakeoil cert is 2048 bits. However, these certs could now live for ten years (3650 days), which as I type this could be upto 2028. Various technical bodies are recently that for long-lived secrets, a facto