Your message dated Fri, 17 Jun 2016 00:18:43 +0000 with message-id <[email protected]> and subject line Bug#826273: fixed in gnupg2 2.1.13-1 has caused the Debian Bug report #826273, regarding gnupg2: Defaults to using insecure short key IDs (32 bits) to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 826273: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=826273 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Package: gnupg2 Version: 2.1.11-7 Severity: normal Tags: security GnuPG2 defaults to returning short key IDs when listing keys. Short key IDs are quite vulnerable to collisions, and their use should be strongly discouraged. I wrote the following with a progression of attacks; this is all well-known for years. http://gwolf.org/node/4070 So, in short: Please add "keyid-format 0xlong" to /usr/share/gnupg2/gpg-conf.skel -- System Information: Debian Release: stretch/sid APT prefers unstable APT policy: (500, 'unstable') Architecture: amd64 (x86_64) Kernel: Linux 4.5.0-2-amd64 (SMP w/4 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages gnupg2 depends on: ii dpkg 1.18.7 ii gnupg-agent 2.1.11-7 ii install-info 6.1.0.dfsg.1-8 ii libassuan0 2.4.2-3 ii libbz2-1.0 1.0.6-8 ii libc6 2.22-10 ii libgcrypt20 1.7.0-2 ii libgpg-error0 1.22-2 ii libksba8 1.3.4-3 ii libreadline6 6.3-8+b4 ii libsqlite3-0 3.13.0-1 ii zlib1g 1:1.2.8.dfsg-2+b1 Versions of packages gnupg2 recommends: ii dirmngr 2.1.11-7 Versions of packages gnupg2 suggests: pn gnupg-doc <none> ii parcimonie 0.10.1-1 pn xloadimage <none> -- no debconf information
--- End Message ---
--- Begin Message ---Source: gnupg2 Source-Version: 2.1.13-1 We believe that the bug you reported is fixed in the latest version of gnupg2, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Daniel Kahn Gillmor <[email protected]> (supplier of updated gnupg2 package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 16 Jun 2016 18:30:36 -0400 Source: gnupg2 Binary: gnupg-agent scdaemon gpgsm gnupg gnupg2 gpgv gpgv2 dirmngr gpgv-udeb gpgv-win32 Architecture: source Version: 2.1.13-1 Distribution: experimental Urgency: medium Maintainer: Debian GnuPG Maintainers <[email protected]> Changed-By: Daniel Kahn Gillmor <[email protected]> Description: dirmngr - server for managing certificate revocation lists gnupg - GNU privacy guard - a free PGP replacement gnupg-agent - GNU privacy guard - cryptographic agent gnupg2 - GNU privacy guard - a free PGP replacement (dummy transitional pa gpgsm - GNU privacy guard - S/MIME version gpgv - GNU privacy guard - signature verification tool gpgv-udeb - minimal signature verification tool (udeb) gpgv-win32 - GNU privacy guard - signature verification tool (win32 build) gpgv2 - GNU privacy guard - signature verification tool (dummy transition scdaemon - GNU privacy guard - smart card support Closes: 826273 Changes: gnupg2 (2.1.13-1) experimental; urgency=medium . * New upstream release - new keyid-format "none", used by default (Closes: #826273) * Build-depend on libusb-1.0.0-dev to ensure smartcards work (Thanks, gniibe!) Checksums-Sha1: bdde018104bd0df82c8afc22fa10a5bbc5341027 3112 gnupg2_2.1.13-1.dsc 6ec1ae6db7815fdbd4151fb6b0b7197b65b05d1f 5545361 gnupg2_2.1.13.orig.tar.bz2 922ce9946d391eb1aa224f2fdc729c0d0026a9c9 36335 gnupg2_2.1.13-1.debian.tar.bz2 Checksums-Sha256: 569be734615fc3092873dc79aa950ee3fc79b134c6de2334d49484da16d5d2ca 3112 gnupg2_2.1.13-1.dsc 4f9d83a6221daa60130fa79f0b1d37d6c20fffdd0320b640c7a597c5b6219675 5545361 gnupg2_2.1.13.orig.tar.bz2 0c9f7371ffdece84eac229f53805f85e0a1cf23d2767a01f31be7af074c3c40a 36335 gnupg2_2.1.13-1.debian.tar.bz2 Files: bdf3eff3ccb737ef45c7cb0dd90aef6c 3112 utils optional gnupg2_2.1.13-1.dsc 6aa46856e4f39b1b559792f003aae986 5545361 utils optional gnupg2_2.1.13.orig.tar.bz2 f6d932e0c2abad0a0f151eb5fdfb493e 36335 utils optional gnupg2_2.1.13-1.debian.tar.bz2 -----BEGIN PGP SIGNATURE----- Version: GnuPG v2 iQKTBAEBCgB9BQJXYzsVXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFREIyRTc0RjU2RkNGMkI2NzI5N0I3MzUy NEVDRkY1QUZGNjgzNzBBFhxka2dAZmlmdGhob3JzZW1hbi5uZXQACgkQJOz/Wv9o NwoXzhAAhhn+5dN8YE9Hxn026oUhXGpV0lrt7X5RKLnW6WU6hNc//dL+8YxsOHaK evuwOoYLhfuhoDZsv51Dfsrawi+a7c34veoJWICGGbTxHMgelAaI7/SlLjL2KovT l3RqKNcHDVj9TkmH+v0W/sxLHpll8q2FSRZos2zhMOxojM56eGpzFT7hGOJg8JX5 iupV5DAVfHJICWWEFazy3tneLsHIssDMuvBu6t0xjLMDX9m8qG/HcZAUeJLLGmDe kS3hKzI6YNN0CsxwfLQT054dJAgApuFMct2irUiUVR0Ah/JxI2cZ7Ez804rcVD35 kBJhlu2sGKE2jM0O2mxqaNMuTmLzWBugVJHcBRUYQHZIi6i//GMtU/MMSetqvI9Y Jif357p8EzP01U0V9Qan3XRkaDAWKZgN4BBCdLP8c4+/uMwvVGgHGOZfENjaScHI Kt4DFizBP4KUpccfsmi+mYZqrPJzlTQEDTj1njYBxNHKMu629nglhpT6XjuLYGf3 0LAlfzKRmX4PlXkJOafByKbGjWMJacTAcY72XYakMQUCyzlYAAHQr3r0QLPZxEDS PM8jL1vkijVtmjNCNKFnPPK7b3LAyx30Udc7Kb1SlNnIRJKbaPE/AGH7+JDvzqct MBXxDgl/eNF2VZh8hehAdGJU310hs+FEo+B05vkS0hkFMyRDzYg= =8nOW -----END PGP SIGNATURE-----
--- End Message ---

