*** This bug is a security vulnerability ***

Private security bug reported:

http://archive.ubuntu.com/ubuntu/dists/xenial/InRelease uses SHA512
digest algorithm

However http://archive.ubuntu.com/ubuntu/project/ubuntu-archive-
keyring.gpg.sig uses SHA1 digest algorithm.

Shouldn't it be updated to SHA512?

** Affects: ubuntu
     Importance: Undecided
         Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1624377

Title:
  old-school signatures used for project keyring

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+bug/1624377/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
  • [Bug 1624377] [NEW] old-school signatures ... Dimitri John Ledkov

Reply via email to