Your message dated Mon, 21 Jul 2008 10:07:23 +0000 with message-id <[EMAIL PROTECTED]> and subject line Bug#473841: fixed in gnupg2 2.0.9-3 has caused the Debian Bug report #473841, regarding gpgkey2ssh: produces incorrect openssh-style public keys to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [EMAIL PROTECTED] immediately.) -- 473841: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=473841 Debian Bug Tracking System Contact [EMAIL PROTECTED] with problems
--- Begin Message ---Package: gnupg-agent Version: 2.0.9-1 Severity: normal -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 it's hard for me to tell if this is a bug or not, given the complete lack of documentation for the gpgkey2ssh utility (see #380241). But i'm pretty sure gpgkey2ssh is not supposed to be doing what it claims it is doing. In particular, if i take a standard RSA gpg key (4096 or 1024 bits in the cases i've tested) and feed it to gpgkey2ssh, the resulting output appears to be a 17-bit RSA key to OpenSSH, which is obviously wrong: [0 [EMAIL PROTECTED] cdtemp.F22412]$ gpg --fingerprint CCD2ED94D21739E9 | head -n2 pub 4096R/D21739E9 2007-06-02 [expires: 2012-05-31] Key fingerprint = 0EE5 BE97 9282 D80B 9F75 40F1 CCD2 ED94 D217 39E9 [0 [EMAIL PROTECTED] cdtemp.F22412]$ gpgkey2ssh CCD2ED94D21739E9 >x [0 [EMAIL PROTECTED] cdtemp.F22412]$ ssh-keygen -l -f x 17 a0:ad:92:70:16:92:a2:34:3a:7d:50:4a:55:90:78:ac x [0 [EMAIL PROTECTED] cdtemp.F22412]$ (the leading 17 in the output of ssh-keygen -l is supposed to indicate the bit-length of the public key). My guess would be that the multi-precision integers (MPIs) are being output in the wrong order or something, since i believe there is a 17-bit exponent used in most RSA keys (0x10001 or something like that), as determined by: gpg --export "$KEYID" | gpg --list-packets --debug 2 | grep pkey Thanks for your work on gnupg2 in debian! It's much appreciated. --dkg - -- System Information: Debian Release: lenny/sid APT prefers testing APT policy: (500, 'testing'), (200, 'unstable'), (101, 'experimental') Architecture: i386 (i686) Kernel: Linux 2.6.22-3-686 (SMP w/1 CPU core) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/bash Versions of packages gnupg-agent depends on: ii libc6 2.7-6 GNU C Library: Shared libraries ii libgcrypt11 1.4.0-3 LGPL Crypto library - runtime libr ii libgpg-error0 1.4-2 library for common error values an ii libpth20 2.0.7-9 The GNU Portable Threads ii libreadline5 5.2-3 GNU readline and history libraries Versions of packages gnupg-agent recommends: ii gnupg 1.4.6-2.1 GNU privacy guard - a free PGP rep ii gnupg2 2.0.9-1 GNU privacy guard - a free PGP rep ii gpgsm 2.0.9-1 GNU privacy guard - S/MIME version ii pinentry-curses [pinentry] 0.7.5-1 curses-based PIN or pass-phrase en ii pinentry-qt [pinentry] 0.7.5-1 Qt-based PIN or pass-phrase entry - -- no debconf information -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.6 (GNU/Linux) iQIVAwUBR/K0rMzS7ZTSFznpAQLXcw//VTAvibgMtGnm1jmzRRAHR1ZqmFBKU+/z +gCXrpwUNubDaYMbkMNKz8yvfwO0j3A8YX+eSsFf0BlAKE1hQVCU+xhi9fAOhmVh i1ZEgijvfoirr9qeUH3ALux3pybw/ZM3JuVo9Ws/dWvCusqSc5//nnNXCg/ODMcU TnkQJUGBgM7eXeDbRl2Sc0FTAP5HiRBzGmq0OpFL8h0XJbdxTvBe8IDq44BhDF3f If688ef3OOexoRSBTFoikgNhfKPRaM1EEErbJLejrNXewjydtRJAxNjvEJIAhxwE Ra0BMzS5UocHeIkIeW3r+jO4HU0c3sueYClev1YpzSPjmf5pkPh7n6qjkhud48md AwAVZKaDhA9GQcKZvObQZGLa4v3EZ8yAGK8VMlHQWyk71z9A79oaEqxq8anPejr0 HMM5QdAxS4AxtPHp/yR/3gJlIJ/B4MOjBTZ1KzUj3T9veV8UnoTc4OSucN3LSSDH 5YBsGoWCwb9utvxw9GccQC2M/DXogEFM+gtUPH98qX0DB16+ORR9oaWDppZ8SWSu ezTdttgoTzG6VFZPTQB0hhCe3hQB+WY0qjrMmQ46n6ZnAOMfGOKXJO87YpCsIgci ntIhLJROrpkdkFjEMgMUMrCwDu0GCEU4q0VeyB/mhQNekERQODRPqufkR5lFV8U0 GRDsoHwQ4ZA= =HOzd -----END PGP SIGNATURE-----
--- End Message ---
--- Begin Message ---Source: gnupg2 Source-Version: 2.0.9-3 We believe that the bug you reported is fixed in the latest version of gnupg2, which is due to be installed in the Debian FTP archive: gnupg-agent_2.0.9-3_amd64.deb to pool/main/g/gnupg2/gnupg-agent_2.0.9-3_amd64.deb gnupg2_2.0.9-3.diff.gz to pool/main/g/gnupg2/gnupg2_2.0.9-3.diff.gz gnupg2_2.0.9-3.dsc to pool/main/g/gnupg2/gnupg2_2.0.9-3.dsc gnupg2_2.0.9-3_amd64.deb to pool/main/g/gnupg2/gnupg2_2.0.9-3_amd64.deb gpgsm_2.0.9-3_amd64.deb to pool/main/g/gnupg2/gpgsm_2.0.9-3_amd64.deb A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [EMAIL PROTECTED], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Eric Dorland <[EMAIL PROTECTED]> (supplier of updated gnupg2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [EMAIL PROTECTED]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Format: 1.8 Date: Mon, 21 Jul 2008 03:48:11 -0400 Source: gnupg2 Binary: gnupg-agent gpgsm gnupg2 Architecture: source amd64 Version: 2.0.9-3 Distribution: unstable Urgency: medium Maintainer: Eric Dorland <[EMAIL PROTECTED]> Changed-By: Eric Dorland <[EMAIL PROTECTED]> Description: gnupg-agent - GNU privacy guard - password agent gnupg2 - GNU privacy guard - a free PGP replacement gpgsm - GNU privacy guard - S/MIME version Closes: 473841 Changes: gnupg2 (2.0.9-3) unstable; urgency=medium . * Urgency medium to try to beat the release. * tools/gpgkey2ssh.c: Patch from Daniel Kahn Gillmor to fix broken ssh key generation. (Closes: #473841) Checksums-Sha1: cb9987be2dc64d75122f40d535f978e95bef82ed 1346 gnupg2_2.0.9-3.dsc afaef52c772a8c2e111c11c0b20fb14b3ebf3552 39780 gnupg2_2.0.9-3.diff.gz c569f451f730916698810a22ba0584bb2915f55a 315770 gnupg-agent_2.0.9-3_amd64.deb 434b846d5f7a197e5b8f6013ff46b29a245e040f 462330 gpgsm_2.0.9-3_amd64.deb 62e8e310308490b1be46f7bf08da4aefa1643e7a 2173688 gnupg2_2.0.9-3_amd64.deb Checksums-Sha256: e9646e9310e1401f55522c5bf1647b447fd1437c2aa0f1bfa82bbc327817e46f 1346 gnupg2_2.0.9-3.dsc a8ede7f817a9cad7d5b84390f2186c76ba2fcbfc30628ff279a366b928d60beb 39780 gnupg2_2.0.9-3.diff.gz 9594e706c1e5b6987d9cecbe68de1ad7864f5a63f409a8e7c686bb62db308e30 315770 gnupg-agent_2.0.9-3_amd64.deb 77dc56116f811772e70ab667eab05b8c508bdd8a0f468a9760db5982074ae137 462330 gpgsm_2.0.9-3_amd64.deb d3045a66f7b56024632299606f77d6cf98f5fc7c6340b8d6563b1af261a177f3 2173688 gnupg2_2.0.9-3_amd64.deb Files: d68b0e9198d8e139cc1bbb28392b0002 1346 utils optional gnupg2_2.0.9-3.dsc 63a62124d6991278e01346550c8410eb 39780 utils optional gnupg2_2.0.9-3.diff.gz 7f2120bee464293a3b30a8d936764043 315770 utils optional gnupg-agent_2.0.9-3_amd64.deb 9ad7296c929064ba1011a407a5c454e0 462330 utils optional gpgsm_2.0.9-3_amd64.deb d6f6b248d79bb2eaed3de97bb25efe40 2173688 utils optional gnupg2_2.0.9-3_amd64.deb -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.9 (GNU/Linux) iD8DBQFIhEFyYemOzxbZcMYRAvUgAJ9fRJ9GMgeUcnM7tPOw7PCX63xA2wCguei6 gkBa6iFaCcxKuQNRdv89wtA= =wQ23 -----END PGP SIGNATURE-----
--- End Message ---

