(I think you might already know, but in any case «sq cert lint» provides
a --fix mode that should be able to fix these issues for the owner of
the keys.)
It would be nice to stop accepting new updates that regress on this
front. And ideally to start a new campaign like had been done in the
past for other issues about weak keys/certificates.
Hello,
On Tue, Mar 18, 2025 at 02:20:26AM +0100, Guillem Jover wrote:
It would be nice to stop accepting new updates that regress on this
front. And ideally to start a new campaign like had been done in the
past for other issues about weak keys/certificates.
Something like this might implement the "stop accepting new updates"
part. It's a bit more strict than suggested because it refuses all
updates if the new key is broken.
On Tue, Mar 18, 2025 at 09:43:33AM +0100, Uwe Kleine-König wrote:
On Tue, Mar 18, 2025 at 02:20:26AM +0100, Guillem Jover wrote:
It would be nice to stop accepting new updates that regress on this front. And ideally to start a new campaign like had been done in the
past for other issues about weak keys/certificates.
Something like this might implement the "stop accepting new updates"
part. It's a bit more strict than suggested because it refuses all
updates if the new key is broken.
The other problem is that "sq cert" is not available in bookworm. We
have a requirement that we can build the keyring under a machine
running stable. Recent versions of sequoia can't even be built on
bookworm machine (they want a newer Rust compiler), so unfortunately
we're not going to be able to build that sort of check into our
pipelines until trixie is released and deployed in the right places.
I see Guillem has already taken this to -devel. While I agree we
want to get rid of SHA-1 self-signatures on keys, I'm not clear on
exactly what problem this is causing with new dpkg, given that I'd
expect the signatures it cares about are from the unaffected role
keys?
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 482 |
Nodes: | 16 (0 / 16) |
Uptime: | 75:01:28 |
Calls: | 9,572 |
Calls today: | 3 |
Files: | 13,666 |
Messages: | 6,142,509 |