Hi,

Daniel A. Nagy:
> RSA signature-only keys are rejected as invalid, and so are signatures
> signed using such keys.
> 
Thanks for spotting this.

> I have fixed the problem myself, see the attached pubkey.c file. Actually, I
> have prepared a 0.5.5-11 package, too. Please let me know, if you need it.
> 
Would you please send me a patch from -10 to 11? Thanks.

> Being a security related package, I'd suggest to publish a security update
> for older versions.
> 
Umm, no. Security updates are only done when something "breaks open",
i.e. allows somebody unauthorized to gain access.

-- 
Matthias Urlichs   |   {M:U} IT Design @ m-u-it.de   |  [EMAIL PROTECTED]
Disclaimer: The quote was selected randomly. Really. | http://smurf.noris.de
 - -
Indifference will certainly be the downfall of mankind, but who cares?

Attachment: signature.asc
Description: Digital signature

Reply via email to