Re: Bumping apt RSA key length requirements to 3072-bit (2048 w/ warning) for 24.04

2024-01-22 Thread Dimitri John Ledkov
Hi, On Thu, 18 Jan 2024 at 18:02, Julian Andres Klode wrote: > > Hi, > > we just noticed again that we are still trusting 1024R keys for > signing repositories in APT, arguably because we do not have a > means to tell gpgv the minimum key size. > > While the upstream bug[0] is being worked on, >

Re: Bumping apt RSA key length requirements to 3072-bit (2048 w/ warning) for 24.04

2024-01-22 Thread Jeremy Bícha
On Mon, Jan 22, 2024 at 7:36 AM Dimitri John Ledkov wrote: > > Sadly shipping this in 24.04 means that PPAs owned by user > > accounts created prior to 2014-03-11[3] until the key rotation > > mechanism(s) [4][5] have been implemented. > > > > I do wonder how many active old PPA owners remain in a

+1 maintenance report

2024-01-22 Thread Paul Mars
Hello, Here is what I worked on during this +1 maintenance shift: - golang-github-gorilla-websocket - autopkgtest for golang-entgo-ent/0.11.3-4 on amd64 was failing - Some go tests rely on the database result sorting and sqlite does not guaranty any default sorting. - Opened LP: #2049502 an