Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Brad Warren
> On Feb 9, 2019, at 6:19 AM, Holger Levsen wrote: > > On Sat, Feb 09, 2019 at 02:54:43PM +0100, Ola Lundqvist wrote: >> I can also add that I have looked into this for myself and the number of >> needed dependencies is rather large. So it is not just certbot that need an >> update, we also

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Ola Lundqvist
Hi Holger and Brad Here is a little more extensive list of dependencies: python-certbot (of course as it is the one providing certbot) python3-acme (>= 0.26.0~) - not in jessie, available in backports python3-configargparse - not in jessie, available in backports python3-cryptography (>= 1.2) -

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Ola Lundqvist
Hi I can also add that I have looked into this for myself and the number of needed dependencies is rather large. So it is not just certbot that need an update, we also need to include quite a few other packages too. // Ola On Sat, 9 Feb 2019 at 09:37, Ian Campbell wrote: > [[ Resending to

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Holger Levsen
On Sat, Feb 09, 2019 at 02:54:43PM +0100, Ola Lundqvist wrote: > I can also add that I have looked into this for myself and the number of > needed dependencies is rather large. So it is not just certbot that need an > update, we also need to include quite a few other packages too. how large

Re: PHP 5.6 EOD of Life Support and Debian 8 LTS.

2019-02-09 Thread Ola Lundqvist
Hi Thomas I do not see that anyone else have answered this so I'll try to do that. If nothing else is stated the LTS team plan to support all packages regardless of whether upstream have declared it as end of life or not. Regarding php5 I think it is a must to do so, since transition to php7 is

[SECURITY] [DLA 1666-1] freerdp security update

2019-02-09 Thread Mike Gabriel
Package: freerdp Version: 1.1.0~git20140921.1.440916e+dfsg1-13~deb8u3 CVE ID : CVE-2018-8786 CVE-2018-8787 CVE-2018-8788 CVE-2018-8789 Debian Bug : For the FreeRDP version in Debian jessie LTS a security and functionality update has recently been provided. FreeRDP is

Re: Bug#859122: about 500 DLAs missing from the website

2019-02-09 Thread Holger Levsen
Hi Laura, many many thanks for your work on this, including and especially this writeup! some comments below, where I dont say anything I mean 'yay"! :) On Sat, Feb 09, 2019 at 03:55:44AM +0100, Laura Arjona Reina wrote: > * The /lts/security//index.*.html files show the last advisory for >

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Brad Warren
Thanks for looking into that Ola. I think we could work around the python3-sphinx problem. It’s just used for building the docs and python3-sphinx (>= 1.6) is not in Stretch despite the Certbot package being updated there. It seems to me like something similar could be done here.

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Ola Lundqvist
Hi Here are the reverse dependencies for that. (jessie_chroot)root@tigereye:~/build/certbot/python-certbot-0.28.0# apt-rdepends -r python3-cryptography Reading package lists... Done Building dependency tree Reading state information... Done python3-cryptography Reverse Depends: python3-openssl

Re: concerns about the security reliability of python-gnupg

2019-02-09 Thread Elena ``of Valhalla''
On 2019-02-07 at 11:44:45 -0500, Antoine Beaupré wrote: > Hi, > > Recently, python-gnupg was triaged for maintenance in Debian LTS, which > brought my attention to this little wrapper around GnuPG that I'm > somewhat familiar with. > > Debian is marked as "vulnerable" for CVE-2019-6690 in Jessie

Re: Bug#921663: Please add python-certbot update to jessie-backports

2019-02-09 Thread Ian Campbell
[[ Resending to correct debian-lts, I forgot the "lists." bit... ]] On Fri, 2019-02-08 at 11:18 -0800, Brad Warren wrote: > To provide a little more information as an upstream maintainer of > Certbot, the lack of an upgrade here will affect a lot of Debian > Jessie users. > > Let’s Encrypt