-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hmmm, for some reason someone changed the certificte of bugs.debian.org to a unknown certificate issuer so "bts show" does not work anymore. Who the hell is GANDI CA?
However, Pierre-Elliott Bécue wrote: >> The bug is security relevant, it breaks full systems and it renders >> ca-certificate complete useless for most of the people. So it _is_ critical! > >In my opinion, something is security relevant when the security is >compromised any way by this thing. Removing the CACert certificate definitly >breaks user space, and it exposes some security problems that existed >before, but this is not obvious that the system's security is broken by the >update: Well, Yes and now. Yes from a technical point of view. Even from this point of view the security is higher with _every_ removed certificate. But including the user behaviour to not care about checking the certificate of an unknown CA, this lower the overall security. >> - mutt: Asking to prove a certificate that a normal user cannot know how > > * The security flaw seems to be in the user behavior, looks the same with a > self signed certificate. The point is, without any warning, something > which was working is now broken, and many users will probably just say > "trust" without further investigation. (but are mutt users "normal" users?) I just gave the examples I use on a daily base. For normal users there are similar programs. However, I saw also mutt users that just gave a fuck about the fingerprint they are provided with and just accepted it. >> - wget; you have to trust every certificate there without exception if >> there is no root certificate available. > > * That is, in my opinion, also a user behavior problem. No, it's a wget problem that you can only specify to not check any certificate or check any (--no-check-certificate). There is no way to only skip this particular certificate from one side. > But the fact is when you ran some (dist-)?upgrade, there were some > listchange you could (should have) read, and when you see that CACert's > certificate is removed, you are kinda warned. Yes, _I_ got warned and _I_ was able to downgrade to a working ca-certificates package. But unfortunately I am not a normal user. A normal user does not see or even read all the changelogs from an update than just do it. > But, arguing on the bug severity (between important/critical) I accepted the downgrade to important. I was just pissed of by downgrading it to wishlist. That is not a proper solution for such a important bug that is relevant for many if not all debian users. > with the package maintainers seems irrelevant if you wish to find a > (relevant) solution. And exactly that is the problem. But I will not go further into this. > Arguing on the "stupidity" of the initial decision will probably > just push maintainers to ignore your request. Sorry not being able to be diplomatic. I just tell the truth or what I am thinking. I personally don't like false friendliness. > I frankly agree with Thomas Koch about creating some specific packages for > non trusted CA. Would be a possible solution, yes. But this does not change the fact that ca-certificates without cacert is somewhat useless. Regards Klaus - -- Klaus Ethgen http://www.ethgen.ch/ pub 4096R/4E20AF1C 2011-05-16 Klaus Ethgen <[email protected]> Fingerprint: 85D4 CA42 952C 949B 1753 62B3 79D0 B06F 4E20 AF1C -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQGcBAEBCgAGBQJTOmNKAAoJEKZ8CrGAGfastzEL/2sx9la2KdtUwPCKcJ+S+O51 CsO601C0tlJwCd24MBytTpFjy6Wj0GWdjZTUBHAAZxY5Xrxz4C0oNn9sS7N8G+Sp qFXP0ChADpbJQvsAFy8TI59OE1kpL3/9tInSWTDo8XAPEst8rr6EJfdcLuHVoHsD uuEaxfWC3E4b+aA1YjNi6vBxWCWmssIxHL5CMzt2xHUyw2ru/LlznFJlaSty0hqd jHcFbp/eW9mPeTuScADg18xKSP/ED2oPkOp/nDr+jd2odUQYhy9X/I9l21rR4JlI uhy8V5K9D09B6NmL7xqrj9G5UaXyYre6Dk2lE9tz8Eptskhkf0Gqud21kJFEStUp 5fMlKeprLcafMsNNp+W41FOuGmQdVkCLW8TynQuQx+IYQbOa0jW2P77aBtn8sE9n A0BQIKpftqu5IzD6AvXkoPWBO+1SCKSZh6m387o06t4vraCO7vQM0YdMZTR5oD0W keFgInfBYrvSXsCYVWWd3KVRjG1hkZiIOtL8v3eefg== =YhfP -----END PGP SIGNATURE----- -- To UNSUBSCRIBE, email to [email protected] with a subject of "unsubscribe". Trouble? Contact [email protected]

