Skip to content

Release signing key only supports SHA-1 #548

@andy-bower

Description

@andy-bower

Is it time for a key rotation?

From the Debian build:

dpkg-source: info: verifying ../getdns_1.7.3.orig.tar.gz.asc
Signing key on DC34EE5DB2417BCC151E5100E5F8F8212F77A498 is not bound:
           No binding signature at time 2022-12-22T14:34:22Z
  because: Policy rejected non-revocation signature (PositiveCertification) requiring second pre-image resistance
  because: SHA1 is not considered secure since 2023-02-01T00:00:00Z
dpkg-source: warning: cannot verify upstream tarball signature for ../getdns_1.7.3.orig.tar.gz: no acceptable signature found

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions