Your message dated Fri, 01 Jan 2021 23:34:07 +0000 with message-id <[email protected]> and subject line Bug#978990: fixed in haskell-hopenpgp-tools 0.23.5-1 has caused the Debian Bug report #978990, regarding "hokey lint" fails to identify cross-signature on ed25519 signing-capable subkey to be marked as done.
This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) -- 978990: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978990 Debian Bug Tracking System Contact [email protected] with problems
--- Begin Message ---Package: hopenpgp-tools Version: 0.23.1-1+b1 my ed25519/cv25519 OpenPGP certificate (attached) gets a complaint from "hokey lint" that the signing-capable subkey does not have an embedded cross cert. In particular, the line is: embedded cross-cert: False which shows up twice. (it should only show up once, for the encryption-capable cv25519 subkey -- it should *not* show up for the ed25519 signing-capable subkey) however, the embedded cross cert is there, because gpg --list-packets (on the same data) says: critical hashed subpkt 32 len 189 (signature: v4, class 0x19, algo 22, digest algo 10) I note that GnuPG typically creates these cross-certs in the unhashed subpacket section, and doesn't mark them as "critical". Maybe "hokey lint" doesn't recognize the cross-cert because of its placement/positioning? thanks for working on hopenpgp-tools! --dkg PS here's a transcript with the relevant error message underlined with ^^^^s ``` 0 dkg@alice:~$ gpg --export C29F8A0C01F35E34D816AA5CE092EB3A5CA10DBA | hokey lint hokey (hopenpgp-tools) 0.23.1 Copyright (C) 2012-2019 Clint Adams hokey comes with ABSOLUTELY NO WARRANTY. This is free software, and you are welcome to redistribute it under certain conditions. Key has potential validity: good Key has fingerprint: C29F 8A0C 01F3 5E34 D816 AA5C E092 EB3A 5CA1 0DBA Checking to see if key is OpenPGPv4: V4 Checking to see if key is RSA or DSA (>= 2048-bit): EdDSA 256 Checking user-ID- and user-attribute-related items: <[email protected]>: Self-sig hash algorithms: [SHA-512] Preferred hash algorithms: [SHA-512, SHA-256] Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023] Key usage flags: [[certify-keys]] <[email protected]>: Self-sig hash algorithms: [SHA-512] Preferred hash algorithms: [SHA-512, SHA-256] Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023] Key usage flags: [[certify-keys]] Daniel Kahn Gillmor: Self-sig hash algorithms: [SHA-512] Preferred hash algorithms: [SHA-512, SHA-256] Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023] Key usage flags: [[certify-keys]] Checking subkeys: one of the subkeys is encryption-capable: True fpr: 2DB5 491C 9DF0 DC8F 4328 63CF 3E9D 7173 71DE 565C version: v4 timestamp: 20201227-162255 algo/size: EdDSA 256 binding sig hash algorithms: [SHA-512] usage flags: [[sign-data]] embedded cross-cert: False ^^^^^^^^^^^^^^^^^^^^^^^^^^ cross-cert hash algorithms: [SHA-512] fpr: 61C1 E3C2 410D 201D DB6F 8168 4C39 437E A528 5697 version: v4 timestamp: 20201227-162255 algo/size: ECDH 256 binding sig hash algorithms: [SHA-512] usage flags: [[encrypt-storage, encrypt-communications]] embedded cross-cert: False cross-cert hash algorithms: [SHA-512] 0 dkg@alice:~$ ```
dkg-openpgp-2021.pgp
Description: application/pgp-keys
signature.asc
Description: PGP signature
--- End Message ---
--- Begin Message ---Source: haskell-hopenpgp-tools Source-Version: 0.23.5-1 Done: Clint Adams <[email protected]> We believe that the bug you reported is fixed in the latest version of haskell-hopenpgp-tools, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Clint Adams <[email protected]> (supplier of updated haskell-hopenpgp-tools package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 01 Jan 2021 18:03:39 -0500 Source: haskell-hopenpgp-tools Architecture: source Version: 0.23.5-1 Distribution: unstable Urgency: medium Maintainer: Debian Haskell Group <[email protected]> Changed-By: Clint Adams <[email protected]> Closes: 812944 978990 978991 Changes: haskell-hopenpgp-tools (0.23.5-1) unstable; urgency=medium . * New upstream version. - hokey lint: warn about some cryptographic weaknesses related to subkeys. closes: #812944. - hokey lint: check both hashed and unhashed signature subpackets for embedded cross-signatures. closes: #978990. - hokey lint: do not complain about EdDSA keys of 256-bit size. closes: #978991. Checksums-Sha1: ab90467057712d4f03ea7c740274c99a055fbc73 3021 haskell-hopenpgp-tools_0.23.5-1.dsc fae7b2cb6f85d747d83328643054d88ccb5e4d15 104821 haskell-hopenpgp-tools_0.23.5.orig.tar.gz 3640d248583d82ea97089b16f0014359b884efbd 14240 haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz b14b75f62c3fb9bd680de9f107c94dd63021b6eb 11248 haskell-hopenpgp-tools_0.23.5-1_source.buildinfo Checksums-Sha256: 808d6d8ad770272f833eae5242cdfba94cb65a45fdddef19a73ac0d037489d5c 3021 haskell-hopenpgp-tools_0.23.5-1.dsc 0412e75caec74862bf8e3c80bd364c96c17b19eca1fa6afcca4dd7aeb56b898d 104821 haskell-hopenpgp-tools_0.23.5.orig.tar.gz 8acdbaea50116b225431782219701fc0c284fe387d7dda06061ab49d8b57d319 14240 haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz 5c590395befe70d363cc23cf8278c98752628dcd8a4ce3ea45070d9a9c2e64a4 11248 haskell-hopenpgp-tools_0.23.5-1_source.buildinfo Files: 064b4c43ca0ff29cb89b71097e7db32d 3021 haskell optional haskell-hopenpgp-tools_0.23.5-1.dsc 482c02e1712079dbbd2ee6f6f9bfd766 104821 haskell optional haskell-hopenpgp-tools_0.23.5.orig.tar.gz 784b5d22dcb255d9e4f26cdddadc9b41 14240 haskell optional haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz 8faef4f39c1d69ce3acb52d0486b4726 11248 haskell optional haskell-hopenpgp-tools_0.23.5-1_source.buildinfo -----BEGIN PGP SIGNATURE----- iQJFBAEBCgAvFiEEdYHsh0BT5sgHeRubVZIzHhmdOKgFAl/vrNkRHGNsaW50QGRl Ymlhbi5vcmcACgkQVZIzHhmdOKjTpQ/9HOTPYxKu+UglI9HUuW287X4CEnai9+hu Dxjt5v07kged1R8nuRLK74kjpVzzrGG0ltwIkF+o3+849yYvuZtDJwTd98k/QbVR n0v5/lWrQ30v2unXPO6ZKc7RoudGjJ8pokYGHHfClAJUmGYfFCoauf4+oBUL7luI J/tLy1vaa4xZFMtAPV0LChuaP8LbP0yu3RJrZ5tYLj6m+3U70EpL5F5P6kTuGsLE bFFnIAVPJ1IZ+K0e0w8+gg5DV0Oa7GDx7UpKG3SeFIoYjwKPewcAIzy8UT0HbFDa PhM7+z6MD6TuGiVlt+NDUQTXcn4/5qJB6xJA3DpdgUOJvbEaMEvNZzA4tV4GezGo b/YvyjUeMVyusB4e6icEclk9rJ9jOOOeR2IyoZGPluJP1RtvkGNrejkc7eCOvOdq kVvePkYsacDmNI1xWTYqI3B5f3jpe4npLZYVJlGNFKsVtX/MUmVJ5XSL9MZy2fau F/qGHLcQp2k8v3wq3leSCDgvkhPkgjZUxhsFClpa9C8lSzVFtjhHalVAXN7cYC1p zMjksq9ljfovna+Yf6712Rih6PavEAp8stHc5NtEmtP1Cdx+49d9v6B6hApNEz16 Zw2/7RJAHeS1UOB3TUiuGAIdXH7l4bfgGGw7icmmTymAZIk4cC+gEXTfE9sKHzSi /zgwRgwpiK0= =yRo4 -----END PGP SIGNATURE-----
--- End Message ---
_______________________________________________ Pkg-haskell-maintainers mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-haskell-maintainers
