Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-17 Thread Rob Stradling via Servercert-wg
> When creating a new repository, the GitHub UI provides the option to "import > your project to GitHub". I'm happy to fork if that is the preferred approach. Of those two options I'd prefer forking, so that the origin is clear and so that it's easier to pull in any future upstream changes. >

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-16 Thread Rob Stradling via Servercert-wg
> Rob Stradling: I would like to import your repo to > github.com/cabforum/Debian-weak-keys. May I have your permission to do so? Hi Wayne. I put together the repositories at https://github.com/CVE-2008-0166 a few years ago with the sole aim of providing a resource that would help CAs comply

Re: [Servercert-wg] Compromised/Weak Keys Ballot Proposal

2024-04-09 Thread Rob Stradling via Servercert-wg
> * Aaron Gable commented in the PR with a suggestion that we require CAs to > reject any key found in Hanno Bock's repository at > https://github.com/badkeys/debianopenssl. This includes RSA > 1024/2048/3072/4096 and EC P256/P384 keys. Some of the EC key files in Hanno's repository have ASN.1