Subject: CAcert Code Development list.
List archive
- From: Bernhard Fröhlich <bernhard AT cacert.org>
- To: CAcert-devel <cacert-devel AT lists.cacert.org>
- Cc: Sascha Ternes <sat AT cacert.org>
- Subject: Security Issue https://bugs.cacert.org/view.php?id=1473
- Date: Mon, 6 Jan 2020 13:04:44 +0100
Hi fellows, the basic problem with SHA-1 has already been known for some
time, but now in https://bugs.cacert.org/view.php?id=1473 there is
a report about a feasible collition attack costing only several
10k US-$ per signature. As also reported in this issue, we still use SHA-1 for PGP/GPG key signatures, and though this specific attack won't work for CAcert keys the current situation IMHO is not acceptable for much longer anymore. Now it has been quite some time when I worked wit GPG, so can anyone make some proposal about how to proceed? Specifically I have the following questions:
An alternative to fixing the problem would also be to disable GPG signing, temporarily or forever. This would be a "political" decision made by board or policy group, but they'll need some "technical opinions" to discuss about. As far as I am concerned, GPG signing is not very useful for me. And some chatter seems to imply that at least key servers and "large scale key signing" is being deprecated more and more. So are there any other opinions? Kind regardsTed
|
Attachment:
smime.p7s
Description: S/MIME Cryptographic Signature
- Security Issue https://bugs.cacert.org/view.php?id=1473, Bernhard Fröhlich, 01/06/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Gero Treuner, 01/06/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Sascha Ternes, 01/06/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Karl-Heinz Gödderz, 01/07/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Bernhard Fröhlich, 01/08/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Karl-Heinz Gödderz, 01/07/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Sascha Ternes, 01/06/2020
- Re: Security Issue https://bugs.cacert.org/view.php?id=1473, Gero Treuner, 01/06/2020
Archive powered by MHonArc 2.6.18.