* Daniel Pocock:
> Just out of interest, a CA can re-issue their root cert with the same
> key pair but a stronger hash. This type of thing has happened before.
That's possible because the self-signature is not actually
meaningful. 8-)
It's different further down the tree, and some protocols (i
On 28/06/13 09:34, Thijs Kinkhorst wrote:
> On Thu, June 27, 2013 22:16, Daniel Pocock wrote:
>> On 27/06/13 21:44, Florian Weimer wrote:
>>> * Daniel Pocock:
>>>
However, are such issues at the discretion of package maintainers and
upstream, or is it useful to have a uniform Debian app
On Thu, Jun 27, 2013 at 10:16 PM, Daniel Pocock wrote:
> 2. http://www.dsd.gov.au/publications/csocprotect/sha-1_deprecated.htm
>
When you read gov or NIST recommendation you need to take into account the
fact that they need to keep the current signatures to be still
cryptographically strong in 1
On Thu, June 27, 2013 22:16, Daniel Pocock wrote:
> On 27/06/13 21:44, Florian Weimer wrote:
>> * Daniel Pocock:
>>
>>> However, are such issues at the discretion of package maintainers and
>>> upstream, or is it useful to have a uniform Debian approach to
>>> cryptographic strength?
>>
>> Keep in
On 27/06/13 21:44, Florian Weimer wrote:
> * Daniel Pocock:
>
>> However, are such issues at the discretion of package maintainers and
>> upstream, or is it useful to have a uniform Debian approach to
>> cryptographic strength?
>
> Keep in mind that RFC 4880 (OpenPGP) hard-codes SHA-1 in severa
* Daniel Pocock:
> However, are such issues at the discretion of package maintainers and
> upstream, or is it useful to have a uniform Debian approach to
> cryptographic strength?
Keep in mind that RFC 4880 (OpenPGP) hard-codes SHA-1 in several
places, notably for key fingerprints. If there's a
There have been various discussions about GnuPG's default use of SHA1, e.g.
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=612657
which impacts the archive pseudo-package but is also relevant for the
gnupg* packages
However, are such issues at the discretion of package maintainers and
upstre
7 matches
Mail list logo