Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1222878
| From | Guillem Jover <guillem@debian.org> |
|---|---|
| Newsgroups | linux.debian.bugs.dist |
| Subject | Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior |
| Date | 2024-12-06 01:00 +0100 |
| Message-ID | <JQtVg-e1Ed-17@gated-at.bofh.it> (permalink) |
| References | <IzlMC-ajMq-1@gated-at.bofh.it> <IzlMC-ajMq-1@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
[Multipart message — attachments visible in raw view] - view raw
Hi! On Wed, 2024-05-01 at 19:12:10 +0200, Guillem Jover wrote: > Package: devscripts > Version: 2.23.7 > Severity: wishlist > Tags: patch > X-Debbugs-Cc: Daniel Kahn Gillmor <dkg@fifthhorseman.net> > GnuPG upstream has decided to get out of the standardizing process for > OpenPGP, and instead is trying to push its own proprietary fork based on > an old draft that did not have consensus within the IETF working group. > > This is going to be a source of interoperability problems, but we can > mitigate them somewhat when creating signatures by requiring compliance > with the OpenPGP RFC, even if it's going to be locked into an old version, > as later ones are not planned to get implemented. More so, given that the > latest releases of GnuPG have been switched to default to the proprietary > draft. > > We need to set secure signing preferred algorithms as the current GnuPG > defaults with --openpgp cater for heavy backwards compatibility at the > cost of being insecure but potentially being compatible with very old > programs. > > We care more about secure defaults than backwards compatibility with > ancient programs, so we pass our preferences to gpg when signing. This > should also cover the case for users that have created old keys with > insecure key preferences which might end up producing insecure > signatures. > > Equivalent changes were made to dpkg-buildpackage. > > Attached the patch implementing this. I've rebased the patch against current git main, and re-tested it. It would be nice to get this in, to palliate potential upcoming GnuPG interoperability problems due to the schism. > (Ideally debsign would also grow additional OpenPGP backends, like > dpkg did, or perhaps it could be replaced entirely with the upcoming > dpkg-sign program.) Thanks, Guillem
Back to linux.debian.bugs.dist | Previous | Next — Next in thread | Find similar | Unroll thread
Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior Guillem Jover <guillem@debian.org> - 2024-12-06 01:00 +0100 Bug#1070197: debsign: Ensure future GnuPG interop by forcing OpenPGP compliant behavior Holger Levsen <holger@layer-acht.org> - 2024-12-06 11:30 +0100
csiph-web