Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-24 Thread Adam D. Barratt
On Thu, 2022-03-24 at 22:00 +0100, Sebastian Andrzej Siewior wrote: > On 2022-03-24 12:39:55 [+], Adam D. Barratt wrote: > > I've added that text to the announcement for the buster point > > release. > Thanks. > > > If anyone has any changes, please yell ASAP. > > The gnutls and perl changes

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-24 Thread Sebastian Andrzej Siewior
On 2022-03-24 12:39:55 [+], Adam D. Barratt wrote: > I've added that text to the announcement for the buster point release. Thanks. > If anyone has any changes, please yell ASAP. The gnutls and perl changes are not yet built. I guess this is intended ;) > Regards, > > Adam Sebastian

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-24 Thread Adam D. Barratt
On Wed, 2022-03-23 at 22:38 +0100, Sebastian Andrzej Siewior wrote: > On 2022-03-23 17:40:59 [+], Adam D. Barratt wrote: > > Right, let's have another go at this then: > > > > " > > OpenSSL signature algorithm check tightening > > = > > > > The

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-23 Thread Sebastian Andrzej Siewior
On 2022-03-23 17:40:59 [+], Adam D. Barratt wrote: > Right, let's have another go at this then: > > " > OpenSSL signature algorithm check tightening > = > > The OpenSSL update provided in this point release includes a > change to ensure that the

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-23 Thread Adam D. Barratt
On Tue, 2022-03-22 at 22:13 +0100, Sebastian Andrzej Siewior wrote: > On 2022-03-22 21:47:52 [+0100], Kurt Roeckx wrote: > > On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > > > OpenSSL signature algorithm check tightening > > > = > > >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Kurt Roeckx
On Tue, Mar 22, 2022 at 10:13:25PM +0100, Sebastian Andrzej Siewior wrote: > On 2022-03-22 21:47:52 [+0100], Kurt Roeckx wrote: > > On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > > > OpenSSL signature algorithm check tightening > > >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Sebastian Andrzej Siewior
On 2022-03-22 21:47:52 [+0100], Kurt Roeckx wrote: > On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > > OpenSSL signature algorithm check tightening > > = > > > > The OpenSSL update included in this point release includes a change to >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Kurt Roeckx
On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > OpenSSL signature algorithm check tightening > = > > The OpenSSL update included in this point release includes a change to > ensure that the requested signature algorithm is supported

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Kurt Roeckx
On Tue, Mar 22, 2022 at 08:19:01PM +, Adam D. Barratt wrote: > Is the note below accurate? Yes. Kurt

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Adam D. Barratt
On Tue, 2022-03-22 at 21:01 +0100, Kurt Roeckx wrote: > On Tue, Mar 22, 2022 at 07:37:00PM +, Adam D. Barratt wrote: > > On Mon, 2022-03-21 at 00:12 +0100, Sebastian Andrzej Siewior wrote: > > > The change in openssl is commit > > >cc7c6eb8135b ("Check that the default signature type is >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Kurt Roeckx
On Tue, Mar 22, 2022 at 07:37:00PM +, Adam D. Barratt wrote: > On Mon, 2022-03-21 at 00:12 +0100, Sebastian Andrzej Siewior wrote: > > The change in openssl is commit > >cc7c6eb8135b ("Check that the default signature type is allowed") > > > > Before the commit in question it connects as:

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-22 Thread Adam D. Barratt
On Mon, 2022-03-21 at 00:12 +0100, Sebastian Andrzej Siewior wrote: > The change in openssl is commit >cc7c6eb8135b ("Check that the default signature type is allowed") > > Before the commit in question it connects as: > - Description: (TLS1.0)-(ECDHE-SECP384R1)-(AES-256-CBC)-(SHA1) > >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Sebastian Andrzej Siewior
On 2022-03-21 22:11:17 [+0100], Julien Cristau wrote: > Hi, Hi, > Specifically, we were hoping to better understand the risk of openssl > changes breaking existing setups. It's possible the issues with gnutls > and libnet-ssleay-perl tests were narrowly scoped enough that that risk > is low, but

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Julien Cristau
Hi, Specifically, we were hoping to better understand the risk of openssl changes breaking existing setups. It's possible the issues with gnutls and libnet-ssleay-perl tests were narrowly scoped enough that that risk is low, but we're just not sure right now. Other input would be welcome.

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Wesley Redondo
How do I stop these emails On Mon, Mar 21, 2022, 3:27 PM Adam D. Barratt wrote: > On Sun, 2022-03-20 at 22:00 +0100, Paul Gevers wrote: > > Dear Sebastian, Kurt, > > > > On 19-03-2022 12:33, Adam D Barratt wrote: > > > Upload details > > > == > > > > > > Package: openssl > > >

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Adam D. Barratt
On Sun, 2022-03-20 at 22:00 +0100, Paul Gevers wrote: > Dear Sebastian, Kurt, > > On 19-03-2022 12:33, Adam D Barratt wrote: > > Upload details > > == > > > > Package: openssl > > Version: 1.1.1n-0+deb10u1 > > > > Explanation: new upstream release > > We're seeing a regression in

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Andreas Metzler
X-Debbugs-Cc: gnutl...@packages.debian.org, Kurt Roeckx , Paul Gevers , Sebastian Andrzej Siewior On 2022-03-21 Sebastian Andrzej Siewior wrote: > On 2022-03-21 00:12:11 [+0100], To Kurt Roeckx wrote: > > doesn't help here but > > -cipher "ALL:@SECLEVEL=1" > > does. > Only debci is

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-21 Thread Sebastian Andrzej Siewior
On 2022-03-21 00:12:11 [+0100], To Kurt Roeckx wrote: > doesn't help here but >-cipher "ALL:@SECLEVEL=1" > > does. Only debci is affected. The package builds because this testsuite is not part of the build process. I prepared a NMU against Buster for gnutls. I can open later today a

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-20 Thread Kurt Roeckx
On Mon, Mar 21, 2022 at 12:12:11AM +0100, Sebastian Andrzej Siewior wrote: > > The change in openssl is commit >cc7c6eb8135b ("Check that the default signature type is allowed") So that's: commit cc7c6eb8135be665d0acc176a5963e1eaf52e4e2 Author: Kurt Roeckx Date: Thu Jan 2 22:53:32 2020

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-20 Thread Sebastian Andrzej Siewior
On 2022-03-20 23:15:57 [+0100], Kurt Roeckx wrote: > > https://ci.debian.net/data/autopkgtest/oldstable/amd64/g/gnutls28/20199677/log.gz > > > > Checking TLS 1.0 with ECDHE-ECDSA (SECP384R1)... > > %COMPAT: Checking TLS 1.0 with ECDHE-ECDSA (SECP384R1)... > > *** Fatal error: A TLS fatal alert

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-20 Thread Kurt Roeckx
On Sun, Mar 20, 2022 at 10:00:15PM +0100, Paul Gevers wrote: > Dear Sebastian, Kurt, > > On 19-03-2022 12:33, Adam D Barratt wrote: > > Upload details > > == > > > > Package: openssl > > Version: 1.1.1n-0+deb10u1 > > > > Explanation: new upstream release > > We're seeing a

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-20 Thread Paul Gevers
Dear Sebastian, Kurt, On 19-03-2022 12:33, Adam D Barratt wrote: Upload details == Package: openssl Version: 1.1.1n-0+deb10u1 Explanation: new upstream release We're seeing a regression in buster in the autopkgtest of gnutls28 with the new version of openssl on all tested

Bug#959469: openssl 1.1.1n-0+deb10u1 flagged for acceptance

2022-03-19 Thread Adam D Barratt
package release.debian.org tags 959469 = buster pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian buster. Thanks for your contribution! Upload details == Package: openssl Version: