Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.bugs.dist > #1222878

Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior

From Guillem Jover <guillem@debian.org>
Newsgroups linux.debian.bugs.dist
Subject Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior
Date 2024-12-06 01:00 +0100
Message-ID <JQtVg-e1Ed-17@gated-at.bofh.it> (permalink)
References <IzlMC-ajMq-1@gated-at.bofh.it> <IzlMC-ajMq-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi!

On Wed, 2024-05-01 at 19:12:10 +0200, Guillem Jover wrote:
> Package: devscripts
> Version: 2.23.7
> Severity: wishlist
> Tags: patch
> X-Debbugs-Cc: Daniel Kahn Gillmor <dkg@fifthhorseman.net>

> GnuPG upstream has decided to get out of the standardizing process for
> OpenPGP, and instead is trying to push its own proprietary fork based on
> an old draft that did not have consensus within the IETF working group.
> 
> This is going to be a source of interoperability problems, but we can
> mitigate them somewhat when creating signatures by requiring compliance
> with the OpenPGP RFC, even if it's going to be locked into an old version,
> as later ones are not planned to get implemented. More so, given that the
> latest releases of GnuPG have been switched to default to the proprietary
> draft.
> 
> We need to set secure signing preferred algorithms as the current GnuPG
> defaults with --openpgp cater for heavy backwards compatibility at the
> cost of being insecure but potentially being compatible with very old
> programs.
> 
> We care more about secure defaults than backwards compatibility with
> ancient programs, so we pass our preferences to gpg when signing. This
> should also cover the case for users that have created old keys with
> insecure key preferences which might end up producing insecure
> signatures.
> 
> Equivalent changes were made to dpkg-buildpackage.
> 
> Attached the patch implementing this.

I've rebased the patch against current git main, and re-tested it. It
would be nice to get this in, to palliate potential upcoming GnuPG
interoperability problems due to the schism.

> (Ideally debsign would also grow additional OpenPGP backends, like
> dpkg did, or perhaps it could be replaced entirely with the upcoming
> dpkg-sign program.)

Thanks,
Guillem

Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior Guillem Jover <guillem@debian.org> - 2024-12-06 01:00 +0100
  Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior Holger Levsen <holger@layer-acht.org> - 2024-12-06 11:30 +0100

csiph-web