APT currently rejects all non-SHA2 hashes, which excludes 1024 bit DSA
keys (the only 1024 bit keys in use, really). All repositories were told
to update to 2048 or 4096 bit RSA keys.

GPG does not provide a way for APT to validate key lengths when the
signature is verified, so we did all we could do here. Any future change
needs to be made in gpg (reject all DSA/RSA keys less than 2048 bit).

** Changed in: apt (Ubuntu)
       Status: Confirmed => Invalid

** Also affects: gnupg2 (Ubuntu)
   Importance: Undecided
       Status: New

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1461834

Title:
  1024-bit signing keys should be deprecated

To manage notifications about this bug go to:
https://bugs.launchpad.net/launchpad/+bug/1461834/+subscriptions

-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to