-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hmmm, for some reason someone changed the certificte of bugs.debian.org
to a unknown certificate issuer so "bts show" does not work anymore. Who
the hell is GANDI CA?

However,

Pierre-Elliott Bécue wrote:
>> The bug is security relevant, it breaks full systems and it renders
>> ca-certificate complete useless for most of the people. So it _is_ critical!
>
>In my opinion, something is security relevant when the security is
>compromised any way by this thing. Removing the CACert certificate definitly
>breaks user space, and it exposes some security problems that existed
>before, but this is not obvious that the system's security is broken by the
>update:

Well, Yes and now. Yes from a technical point of view. Even from this
point of view the security is higher with _every_ removed certificate.
But including the user behaviour to not care about checking the
certificate of an unknown CA, this lower the overall security.

>> - mutt: Asking to prove a certificate that a normal user cannot know how
>
>  * The security flaw seems to be in the user behavior, looks the same with a
>  self signed certificate. The point is, without any warning, something
>  which was working is now broken, and many users will probably just say
>  "trust" without further investigation. (but are mutt users "normal" users?)

I just gave the examples I use on a daily base. For normal users there
are similar programs. However, I saw also mutt users that just gave a
fuck about the fingerprint they are provided with and just accepted it.

>> - wget; you have to trust every certificate there without exception if
>> there is no root certificate available.
>
>  * That is, in my opinion, also a user behavior problem.

No, it's a wget problem that you can only specify to not check any
certificate or check any (--no-check-certificate). There is no way to
only skip this particular certificate from one side.

> But the fact is when you ran some (dist-)?upgrade, there were some
> listchange you could (should have) read, and when you see that CACert's
> certificate is removed, you are kinda warned.

Yes, _I_ got warned and _I_ was able to downgrade to a working
ca-certificates package. But unfortunately I am not a normal user. A
normal user does not see or even read all the changelogs from an update
than just do it.

> But, arguing on the bug severity (between important/critical)

I accepted the downgrade to important. I was just pissed of by
downgrading it to wishlist. That is not a proper solution for such a
important bug that is relevant for many if not all debian users.

> with the package maintainers seems irrelevant if you wish to find a
> (relevant) solution.

And exactly that is the problem. But I will not go further into this.

> Arguing on the "stupidity" of the initial decision will probably
> just push maintainers to ignore your request.

Sorry not being able to be diplomatic. I just tell the truth or what I
am thinking. I personally don't like false friendliness.

> I frankly agree with Thomas Koch about creating some specific packages for
> non trusted CA.

Would be a possible solution, yes. But this does not change the fact
that ca-certificates without cacert is somewhat useless.

Regards
   Klaus
- -- 
Klaus Ethgen                              http://www.ethgen.ch/
pub  4096R/4E20AF1C 2011-05-16   Klaus Ethgen <[email protected]>
Fingerprint: 85D4 CA42 952C 949B 1753  62B3 79D0 B06F 4E20 AF1C
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQGcBAEBCgAGBQJTOmNKAAoJEKZ8CrGAGfastzEL/2sx9la2KdtUwPCKcJ+S+O51
CsO601C0tlJwCd24MBytTpFjy6Wj0GWdjZTUBHAAZxY5Xrxz4C0oNn9sS7N8G+Sp
qFXP0ChADpbJQvsAFy8TI59OE1kpL3/9tInSWTDo8XAPEst8rr6EJfdcLuHVoHsD
uuEaxfWC3E4b+aA1YjNi6vBxWCWmssIxHL5CMzt2xHUyw2ru/LlznFJlaSty0hqd
jHcFbp/eW9mPeTuScADg18xKSP/ED2oPkOp/nDr+jd2odUQYhy9X/I9l21rR4JlI
uhy8V5K9D09B6NmL7xqrj9G5UaXyYre6Dk2lE9tz8Eptskhkf0Gqud21kJFEStUp
5fMlKeprLcafMsNNp+W41FOuGmQdVkCLW8TynQuQx+IYQbOa0jW2P77aBtn8sE9n
A0BQIKpftqu5IzD6AvXkoPWBO+1SCKSZh6m387o06t4vraCO7vQM0YdMZTR5oD0W
keFgInfBYrvSXsCYVWWd3KVRjG1hkZiIOtL8v3eefg==
=YhfP
-----END PGP SIGNATURE-----


-- 
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]

Reply via email to