RFS: bouncycastle/1.48+dfsg-1 (new upstream release for experimental)

2013-03-29 Thread Emmanuel Bourg
Hi all, I upgraded the Bouncy Castle package for the latest version 1.48 released last month. This version fixes a security issue. Starting with the version 1.47 there is no longer a bctsp jar shipped upstream but a bcpkix jar with a broader scope. So the libbctsp-java package has been replaced w

Re: RFS: bouncycastle/1.48+dfsg-1 (new upstream release for experimental)

2013-03-29 Thread Hilko Bengen
* Emmanuel Bourg: > I upgraded the Bouncy Castle package for the latest version 1.48 > released last month. This version fixes a security issue. What kind of security issue is that? Cheers, -Hilko -- To UNSUBSCRIBE, email to debian-java-requ...@lists.debian.org with a subject of "unsubscribe"

Re: RFS: bouncycastle/1.48+dfsg-1 (new upstream release for experimental)

2013-03-29 Thread Emmanuel Bourg
Le 29/03/2013 22:38, Hilko Bengen a écrit : > What kind of security issue is that? It's described here: http://www.isg.rhul.ac.uk/tls/ The related bug is: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699885 https://security-tracker.debian.org/tracker/CVE-2013-1624 https://security-tracker

RFS: eclipse-wtp 3.4.2-1 (for experimental)

2013-03-29 Thread Jakub Adam
Dear java packagers, I am looking for a sponsor for package "eclipse-wtp". * Package name: eclipse-wtp Version : 3.4.2-1 Upstream Author : Eclipse Web Tools Platform team * URL : http://www.eclipse.org/webtools/ * License : EPL-1.0 Section : de

RFS: libitext-java/2.1.7-5 (for experimental)

2013-03-29 Thread Emmanuel Bourg
Hi all, Following the update of Bouncy Castle here is the necessary update of iText 2.x. The recent updates of Bouncy Castle broke the binary compatibility and the old version of iText was affected (Bug #687694). I patched it to compile against the new version of Bouncy Castle. I'm preparing a sim

Re: RFS: bouncycastle/1.48+dfsg-1 (new upstream release for experimental)

2013-03-29 Thread Charles Plessy
Le Fri, Mar 29, 2013 at 03:09:06PM +0100, Emmanuel Bourg a écrit : > > Is there anything special to do to get the old libbctsp-java 1.46 > package removed from the archive when the new libbcpkix-java package is > uploaded? Dear Emmanuel, if I understand correctly, it will be removed automaticall