Your message dated Fri, 01 Jan 2021 23:34:07 +0000
with message-id <[email protected]>
and subject line Bug#812944: fixed in haskell-hopenpgp-tools 0.23.5-1
has caused the Debian Bug report #812944,
regarding hokey lint: please warn about cryptographic weaknesses related to 
subkeys
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
812944: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=812944
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: hopenpgp-tools
Version: 0.17-1
Severity: normal

currently, hokey lint does some verification about the quality of the
primary key and the cryptographic details of the user-id and
user-attribute binding signatures.

However, the subkey binding signatures (and related cross-signatures)
are not reviewed.  They should be.

Things to look for:

 * no encryption-capable subkey (this means people can't send you
   confidential messages)

 * any RSA or DSA or El Gamal subkey < 2048 bits should be red.  <
   3072 should probably be yellow (use the same rules as for strength
   of primary keys for simplicity).

 * subkeys that combined usage flags.  only one of signing,
   authentication, or encryption should be present.  (encryption is
   actually two flags itself because "messages" and "data" are an
   unclear division)

 * certification-capable subkeys are probably a bad idea.

 * signing-capable subkeys that have no embedded cross-certification
   (https://tools.ietf.org/html/rfc4880#section-5.2.3.26) should have a
   red alert advising them to have one.

 * authentication-capable subkeys that have no embedded cross
   certification should probably have a yellow alert.

 * subkey binding signatures should be made with a reasonable digest
   (definitely not MD5 or SHA1 -- maybe avoid SHA224)

 * cross-certifications should be made with a reasonable digest too

 * timestamps of subkey binding signatures and their embedded
   cross-certs should be sane (e.g. the cross-cert should be at the
   same time or slightly before the subkey binding signature; their
   expiration dates should probably match)

 * we might want some guidelines on suggested lifetimes of subkeys,
   but i'm not sure what to specify here, and this is probably more
   subjective than the other proposals above.

i hope this is a useful set of suggestions.

Thanks for hopenpgp-tools!

  --dkg
 
-- System Information:
Debian Release: stretch/sid
  APT prefers unstable-debug
  APT policy: (500, 'unstable-debug'), (500, 'testing'), (200, 'unstable'), (1, 
'experimental-debug'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 4.3.0-1-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages hopenpgp-tools depends on:
ii  libbz2-1.0    1.0.6-8
ii  libc6         2.21-6
ii  libffi6       3.2.1-4
ii  libgmp10      2:6.1.0+dfsg-2
ii  libncursesw5  6.0+20151024-2
ii  libnettle6    3.1.1-4
ii  libtinfo5     6.0+20151024-2
ii  libyaml-0-2   0.1.6-3
ii  zlib1g        1:1.2.8.dfsg-2+b1

hopenpgp-tools recommends no packages.

hopenpgp-tools suggests no packages.

-- debconf-show failed

--- End Message ---
--- Begin Message ---
Source: haskell-hopenpgp-tools
Source-Version: 0.23.5-1
Done: Clint Adams <[email protected]>

We believe that the bug you reported is fixed in the latest version of
haskell-hopenpgp-tools, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Clint Adams <[email protected]> (supplier of updated haskell-hopenpgp-tools 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 01 Jan 2021 18:03:39 -0500
Source: haskell-hopenpgp-tools
Architecture: source
Version: 0.23.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Haskell Group 
<[email protected]>
Changed-By: Clint Adams <[email protected]>
Closes: 812944 978990 978991
Changes:
 haskell-hopenpgp-tools (0.23.5-1) unstable; urgency=medium
 .
   * New upstream version.
     - hokey lint: warn about some cryptographic weaknesses
       related to subkeys.  closes: #812944.
     - hokey lint: check both hashed and unhashed signature
       subpackets for embedded cross-signatures.  closes: #978990.
     - hokey lint: do not complain about EdDSA keys of 256-bit size.
       closes: #978991.
Checksums-Sha1:
 ab90467057712d4f03ea7c740274c99a055fbc73 3021 
haskell-hopenpgp-tools_0.23.5-1.dsc
 fae7b2cb6f85d747d83328643054d88ccb5e4d15 104821 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 3640d248583d82ea97089b16f0014359b884efbd 14240 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 b14b75f62c3fb9bd680de9f107c94dd63021b6eb 11248 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo
Checksums-Sha256:
 808d6d8ad770272f833eae5242cdfba94cb65a45fdddef19a73ac0d037489d5c 3021 
haskell-hopenpgp-tools_0.23.5-1.dsc
 0412e75caec74862bf8e3c80bd364c96c17b19eca1fa6afcca4dd7aeb56b898d 104821 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 8acdbaea50116b225431782219701fc0c284fe387d7dda06061ab49d8b57d319 14240 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 5c590395befe70d363cc23cf8278c98752628dcd8a4ce3ea45070d9a9c2e64a4 11248 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo
Files:
 064b4c43ca0ff29cb89b71097e7db32d 3021 haskell optional 
haskell-hopenpgp-tools_0.23.5-1.dsc
 482c02e1712079dbbd2ee6f6f9bfd766 104821 haskell optional 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 784b5d22dcb255d9e4f26cdddadc9b41 14240 haskell optional 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 8faef4f39c1d69ce3acb52d0486b4726 11248 haskell optional 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEdYHsh0BT5sgHeRubVZIzHhmdOKgFAl/vrNkRHGNsaW50QGRl
Ymlhbi5vcmcACgkQVZIzHhmdOKjTpQ/9HOTPYxKu+UglI9HUuW287X4CEnai9+hu
Dxjt5v07kged1R8nuRLK74kjpVzzrGG0ltwIkF+o3+849yYvuZtDJwTd98k/QbVR
n0v5/lWrQ30v2unXPO6ZKc7RoudGjJ8pokYGHHfClAJUmGYfFCoauf4+oBUL7luI
J/tLy1vaa4xZFMtAPV0LChuaP8LbP0yu3RJrZ5tYLj6m+3U70EpL5F5P6kTuGsLE
bFFnIAVPJ1IZ+K0e0w8+gg5DV0Oa7GDx7UpKG3SeFIoYjwKPewcAIzy8UT0HbFDa
PhM7+z6MD6TuGiVlt+NDUQTXcn4/5qJB6xJA3DpdgUOJvbEaMEvNZzA4tV4GezGo
b/YvyjUeMVyusB4e6icEclk9rJ9jOOOeR2IyoZGPluJP1RtvkGNrejkc7eCOvOdq
kVvePkYsacDmNI1xWTYqI3B5f3jpe4npLZYVJlGNFKsVtX/MUmVJ5XSL9MZy2fau
F/qGHLcQp2k8v3wq3leSCDgvkhPkgjZUxhsFClpa9C8lSzVFtjhHalVAXN7cYC1p
zMjksq9ljfovna+Yf6712Rih6PavEAp8stHc5NtEmtP1Cdx+49d9v6B6hApNEz16
Zw2/7RJAHeS1UOB3TUiuGAIdXH7l4bfgGGw7icmmTymAZIk4cC+gEXTfE9sKHzSi
/zgwRgwpiK0=
=yRo4
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
Pkg-haskell-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-haskell-maintainers

Reply via email to