Your message dated Fri, 17 Jun 2016 00:18:43 +0000
with message-id <[email protected]>
and subject line Bug#826273: fixed in gnupg2 2.1.13-1
has caused the Debian Bug report #826273,
regarding gnupg2: Defaults to using insecure short key IDs (32 bits)
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
826273: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=826273
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: gnupg2
Version: 2.1.11-7
Severity: normal
Tags: security

GnuPG2 defaults to returning short key IDs when listing keys. Short
key IDs are quite vulnerable to collisions, and their use should be
strongly discouraged.

I wrote the following with a progression of attacks; this is all
well-known for years.

    http://gwolf.org/node/4070

So, in short: Please add "keyid-format 0xlong" to
/usr/share/gnupg2/gpg-conf.skel

-- System Information:
Debian Release: stretch/sid
  APT prefers unstable
  APT policy: (500, 'unstable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.5.0-2-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages gnupg2 depends on:
ii  dpkg           1.18.7
ii  gnupg-agent    2.1.11-7
ii  install-info   6.1.0.dfsg.1-8
ii  libassuan0     2.4.2-3
ii  libbz2-1.0     1.0.6-8
ii  libc6          2.22-10
ii  libgcrypt20    1.7.0-2
ii  libgpg-error0  1.22-2
ii  libksba8       1.3.4-3
ii  libreadline6   6.3-8+b4
ii  libsqlite3-0   3.13.0-1
ii  zlib1g         1:1.2.8.dfsg-2+b1

Versions of packages gnupg2 recommends:
ii  dirmngr  2.1.11-7

Versions of packages gnupg2 suggests:
pn  gnupg-doc   <none>
ii  parcimonie  0.10.1-1
pn  xloadimage  <none>

-- no debconf information

--- End Message ---
--- Begin Message ---
Source: gnupg2
Source-Version: 2.1.13-1

We believe that the bug you reported is fixed in the latest version of
gnupg2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Daniel Kahn Gillmor <[email protected]> (supplier of updated gnupg2 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 16 Jun 2016 18:30:36 -0400
Source: gnupg2
Binary: gnupg-agent scdaemon gpgsm gnupg gnupg2 gpgv gpgv2 dirmngr gpgv-udeb 
gpgv-win32
Architecture: source
Version: 2.1.13-1
Distribution: experimental
Urgency: medium
Maintainer: Debian GnuPG Maintainers <[email protected]>
Changed-By: Daniel Kahn Gillmor <[email protected]>
Description:
 dirmngr    - server for managing certificate revocation lists
 gnupg      - GNU privacy guard - a free PGP replacement
 gnupg-agent - GNU privacy guard - cryptographic agent
 gnupg2     - GNU privacy guard - a free PGP replacement (dummy transitional pa
 gpgsm      - GNU privacy guard - S/MIME version
 gpgv       - GNU privacy guard - signature verification tool
 gpgv-udeb  - minimal signature verification tool (udeb)
 gpgv-win32 - GNU privacy guard - signature verification tool (win32 build)
 gpgv2      - GNU privacy guard - signature verification tool (dummy transition
 scdaemon   - GNU privacy guard - smart card support
Closes: 826273
Changes:
 gnupg2 (2.1.13-1) experimental; urgency=medium
 .
   * New upstream release
    - new keyid-format "none", used by default (Closes: #826273)
   * Build-depend on libusb-1.0.0-dev to ensure smartcards work (Thanks,
     gniibe!)
Checksums-Sha1:
 bdde018104bd0df82c8afc22fa10a5bbc5341027 3112 gnupg2_2.1.13-1.dsc
 6ec1ae6db7815fdbd4151fb6b0b7197b65b05d1f 5545361 gnupg2_2.1.13.orig.tar.bz2
 922ce9946d391eb1aa224f2fdc729c0d0026a9c9 36335 gnupg2_2.1.13-1.debian.tar.bz2
Checksums-Sha256:
 569be734615fc3092873dc79aa950ee3fc79b134c6de2334d49484da16d5d2ca 3112 
gnupg2_2.1.13-1.dsc
 4f9d83a6221daa60130fa79f0b1d37d6c20fffdd0320b640c7a597c5b6219675 5545361 
gnupg2_2.1.13.orig.tar.bz2
 0c9f7371ffdece84eac229f53805f85e0a1cf23d2767a01f31be7af074c3c40a 36335 
gnupg2_2.1.13-1.debian.tar.bz2
Files:
 bdf3eff3ccb737ef45c7cb0dd90aef6c 3112 utils optional gnupg2_2.1.13-1.dsc
 6aa46856e4f39b1b559792f003aae986 5545361 utils optional 
gnupg2_2.1.13.orig.tar.bz2
 f6d932e0c2abad0a0f151eb5fdfb493e 36335 utils optional 
gnupg2_2.1.13-1.debian.tar.bz2

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQKTBAEBCgB9BQJXYzsVXxSAAAAAAC4AKGlzc3Vlci1mcHJAbm90YXRpb25zLm9w
ZW5wZ3AuZmlmdGhob3JzZW1hbi5uZXRFREIyRTc0RjU2RkNGMkI2NzI5N0I3MzUy
NEVDRkY1QUZGNjgzNzBBFhxka2dAZmlmdGhob3JzZW1hbi5uZXQACgkQJOz/Wv9o
NwoXzhAAhhn+5dN8YE9Hxn026oUhXGpV0lrt7X5RKLnW6WU6hNc//dL+8YxsOHaK
evuwOoYLhfuhoDZsv51Dfsrawi+a7c34veoJWICGGbTxHMgelAaI7/SlLjL2KovT
l3RqKNcHDVj9TkmH+v0W/sxLHpll8q2FSRZos2zhMOxojM56eGpzFT7hGOJg8JX5
iupV5DAVfHJICWWEFazy3tneLsHIssDMuvBu6t0xjLMDX9m8qG/HcZAUeJLLGmDe
kS3hKzI6YNN0CsxwfLQT054dJAgApuFMct2irUiUVR0Ah/JxI2cZ7Ez804rcVD35
kBJhlu2sGKE2jM0O2mxqaNMuTmLzWBugVJHcBRUYQHZIi6i//GMtU/MMSetqvI9Y
Jif357p8EzP01U0V9Qan3XRkaDAWKZgN4BBCdLP8c4+/uMwvVGgHGOZfENjaScHI
Kt4DFizBP4KUpccfsmi+mYZqrPJzlTQEDTj1njYBxNHKMu629nglhpT6XjuLYGf3
0LAlfzKRmX4PlXkJOafByKbGjWMJacTAcY72XYakMQUCyzlYAAHQr3r0QLPZxEDS
PM8jL1vkijVtmjNCNKFnPPK7b3LAyx30Udc7Kb1SlNnIRJKbaPE/AGH7+JDvzqct
MBXxDgl/eNF2VZh8hehAdGJU310hs+FEo+B05vkS0hkFMyRDzYg=
=8nOW
-----END PGP SIGNATURE-----

--- End Message ---

Reply via email to