On Wed, 29 Jan 2020, Matus UHLAR - fantomas wrote:

On 29.01.20 14:12, Kevin A. McGrail wrote:
On behalf of the Apache SpamAssassin Project, I am pleased to announce
version 3.4.4 is available.

Release Notes -- Apache SpamAssassin -- Version 3.4.4

Introduction
------------

Apache SpamAssassin 3.4.4 is primarily a security release.

In this release, there are bug fixes for two CVEs.

*** On March 1, 2020, we will stop publishing rulesets with SHA-1
signatures.
    If you do not update to 3.4.2 or later, you will be stuck at the last
    ruleset with SHA-1 signatures. ***

I wonder, is it that hard to provide sha-1 signatures together with sha256?

It's not hard to do that. It's insecure.

--
 John Hardin KA7OHZ                    http://www.impsec.org/~jhardin/
 jhar...@impsec.org    FALaholic #11174     pgpk -a jhar...@impsec.org
 key: 0xB8732E79 -- 2D8C 34F4 6411 F507 136C  AF76 D822 E6E6 B873 2E79
-----------------------------------------------------------------------
  Are you a mildly tech-literate politico horrified by the level of
  ignorance demonstrated by lawmakers gearing up to regulate online
  technology they don't even begin to grasp? Cool. Now you have a
  tiny glimpse into a day in the life of a gun owner.   -- Sean Davis
-----------------------------------------------------------------------
 3 days until the 17th anniversary of the loss of STS-107 Columbia

Reply via email to