Your message dated Fri, 01 Jan 2021 23:34:07 +0000
with message-id <[email protected]>
and subject line Bug#978990: fixed in haskell-hopenpgp-tools 0.23.5-1
has caused the Debian Bug report #978990,
regarding "hokey lint" fails to identify cross-signature on ed25519 
signing-capable subkey
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
978990: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=978990
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: hopenpgp-tools
Version: 0.23.1-1+b1

my ed25519/cv25519 OpenPGP certificate (attached) gets a complaint from
"hokey lint" that the signing-capable subkey does not have an embedded
cross cert.

In particular, the line is:

   embedded cross-cert: False

which shows up twice. (it should only show up once, for the
encryption-capable cv25519 subkey -- it should *not* show up for the
ed25519 signing-capable subkey)

however, the embedded cross cert is there, because gpg --list-packets
(on the same data) says:

        critical hashed subpkt 32 len 189 (signature: v4, class 0x19, algo 22, 
digest algo 10)


I note that GnuPG typically creates these cross-certs in the unhashed
subpacket section, and doesn't mark them as "critical".  Maybe "hokey
lint" doesn't recognize the cross-cert because of its
placement/positioning?

thanks for working on hopenpgp-tools!

       --dkg

PS here's a transcript with the relevant error message underlined with ^^^^s

```
0 dkg@alice:~$ gpg --export C29F8A0C01F35E34D816AA5CE092EB3A5CA10DBA | hokey 
lint
hokey (hopenpgp-tools) 0.23.1
Copyright (C) 2012-2019  Clint Adams
hokey comes with ABSOLUTELY NO WARRANTY. This is free software, and you are 
welcome to redistribute it under certain conditions.

Key has potential validity: good
Key has fingerprint: C29F 8A0C 01F3 5E34 D816  AA5C E092 EB3A 5CA1 0DBA
Checking to see if key is OpenPGPv4: V4
Checking to see if key is RSA or DSA (>= 2048-bit): EdDSA 256
Checking user-ID- and user-attribute-related items:
  <[email protected]>:
    Self-sig hash algorithms: [SHA-512]
    Preferred hash algorithms: [SHA-512, SHA-256]
    Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023]
    Key usage flags: [[certify-keys]]
  <[email protected]>:
    Self-sig hash algorithms: [SHA-512]
    Preferred hash algorithms: [SHA-512, SHA-256]
    Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023]
    Key usage flags: [[certify-keys]]
  Daniel Kahn Gillmor:
    Self-sig hash algorithms: [SHA-512]
    Preferred hash algorithms: [SHA-512, SHA-256]
    Key expiration times: [2y11m26d59400s = Sun Dec 24 16:22:55 UTC 2023]
    Key usage flags: [[certify-keys]]
Checking subkeys:
  one of the subkeys is encryption-capable: True
  fpr: 2DB5 491C 9DF0 DC8F 4328  63CF 3E9D 7173 71DE 565C
    version: v4
    timestamp: 20201227-162255
    algo/size: EdDSA 256
    binding sig hash algorithms: [SHA-512]
    usage flags: [[sign-data]]
    embedded cross-cert: False
    ^^^^^^^^^^^^^^^^^^^^^^^^^^
    cross-cert hash algorithms: [SHA-512]
  fpr: 61C1 E3C2 410D 201D DB6F  8168 4C39 437E A528 5697
    version: v4
    timestamp: 20201227-162255
    algo/size: ECDH 256
    binding sig hash algorithms: [SHA-512]
    usage flags: [[encrypt-storage, encrypt-communications]]
    embedded cross-cert: False
    cross-cert hash algorithms: [SHA-512]
0 dkg@alice:~$ 
```

Attachment: dkg-openpgp-2021.pgp
Description: application/pgp-keys

Attachment: signature.asc
Description: PGP signature


--- End Message ---
--- Begin Message ---
Source: haskell-hopenpgp-tools
Source-Version: 0.23.5-1
Done: Clint Adams <[email protected]>

We believe that the bug you reported is fixed in the latest version of
haskell-hopenpgp-tools, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Clint Adams <[email protected]> (supplier of updated haskell-hopenpgp-tools 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Fri, 01 Jan 2021 18:03:39 -0500
Source: haskell-hopenpgp-tools
Architecture: source
Version: 0.23.5-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Haskell Group 
<[email protected]>
Changed-By: Clint Adams <[email protected]>
Closes: 812944 978990 978991
Changes:
 haskell-hopenpgp-tools (0.23.5-1) unstable; urgency=medium
 .
   * New upstream version.
     - hokey lint: warn about some cryptographic weaknesses
       related to subkeys.  closes: #812944.
     - hokey lint: check both hashed and unhashed signature
       subpackets for embedded cross-signatures.  closes: #978990.
     - hokey lint: do not complain about EdDSA keys of 256-bit size.
       closes: #978991.
Checksums-Sha1:
 ab90467057712d4f03ea7c740274c99a055fbc73 3021 
haskell-hopenpgp-tools_0.23.5-1.dsc
 fae7b2cb6f85d747d83328643054d88ccb5e4d15 104821 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 3640d248583d82ea97089b16f0014359b884efbd 14240 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 b14b75f62c3fb9bd680de9f107c94dd63021b6eb 11248 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo
Checksums-Sha256:
 808d6d8ad770272f833eae5242cdfba94cb65a45fdddef19a73ac0d037489d5c 3021 
haskell-hopenpgp-tools_0.23.5-1.dsc
 0412e75caec74862bf8e3c80bd364c96c17b19eca1fa6afcca4dd7aeb56b898d 104821 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 8acdbaea50116b225431782219701fc0c284fe387d7dda06061ab49d8b57d319 14240 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 5c590395befe70d363cc23cf8278c98752628dcd8a4ce3ea45070d9a9c2e64a4 11248 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo
Files:
 064b4c43ca0ff29cb89b71097e7db32d 3021 haskell optional 
haskell-hopenpgp-tools_0.23.5-1.dsc
 482c02e1712079dbbd2ee6f6f9bfd766 104821 haskell optional 
haskell-hopenpgp-tools_0.23.5.orig.tar.gz
 784b5d22dcb255d9e4f26cdddadc9b41 14240 haskell optional 
haskell-hopenpgp-tools_0.23.5-1.debian.tar.xz
 8faef4f39c1d69ce3acb52d0486b4726 11248 haskell optional 
haskell-hopenpgp-tools_0.23.5-1_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJFBAEBCgAvFiEEdYHsh0BT5sgHeRubVZIzHhmdOKgFAl/vrNkRHGNsaW50QGRl
Ymlhbi5vcmcACgkQVZIzHhmdOKjTpQ/9HOTPYxKu+UglI9HUuW287X4CEnai9+hu
Dxjt5v07kged1R8nuRLK74kjpVzzrGG0ltwIkF+o3+849yYvuZtDJwTd98k/QbVR
n0v5/lWrQ30v2unXPO6ZKc7RoudGjJ8pokYGHHfClAJUmGYfFCoauf4+oBUL7luI
J/tLy1vaa4xZFMtAPV0LChuaP8LbP0yu3RJrZ5tYLj6m+3U70EpL5F5P6kTuGsLE
bFFnIAVPJ1IZ+K0e0w8+gg5DV0Oa7GDx7UpKG3SeFIoYjwKPewcAIzy8UT0HbFDa
PhM7+z6MD6TuGiVlt+NDUQTXcn4/5qJB6xJA3DpdgUOJvbEaMEvNZzA4tV4GezGo
b/YvyjUeMVyusB4e6icEclk9rJ9jOOOeR2IyoZGPluJP1RtvkGNrejkc7eCOvOdq
kVvePkYsacDmNI1xWTYqI3B5f3jpe4npLZYVJlGNFKsVtX/MUmVJ5XSL9MZy2fau
F/qGHLcQp2k8v3wq3leSCDgvkhPkgjZUxhsFClpa9C8lSzVFtjhHalVAXN7cYC1p
zMjksq9ljfovna+Yf6712Rih6PavEAp8stHc5NtEmtP1Cdx+49d9v6B6hApNEz16
Zw2/7RJAHeS1UOB3TUiuGAIdXH7l4bfgGGw7icmmTymAZIk4cC+gEXTfE9sKHzSi
/zgwRgwpiK0=
=yRo4
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
Pkg-haskell-maintainers mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-haskell-maintainers

Reply via email to