Your message dated Thu, 13 Nov 2014 10:55:29 +0100
with message-id <[email protected]>
and subject line Re: XCA 1.0.0
has caused the Debian Bug report #686397,
regarding xca: EC self-signed cert incorrectly forces use of SHA-1
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
686397: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=686397
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: xca
Version: 0.9.3-1
Severity: normal

If I create an EC key using a 384-bit curve and try to produce a
self-signed certificate, xca insists on only letting me use SHA-1.
However, ECDSA using a 384-bit curve requires SHA-384 because SHA-1 is
too small.  If xca cannot intuit this natively, I should at least have
the ability to select an appropriate signature algorithm.

-- System Information:
Debian Release: wheezy/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)
Foreign Architectures: i386

Kernel: Linux 3.4-trunk-amd64 (SMP w/4 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash

Versions of packages xca depends on:
ii  libc6        2.13-35
ii  libgcc1      1:4.7.1-7
ii  libltdl7     2.4.2-1.1
ii  libqtcore4   4:4.8.2+dfsg-2
ii  libqtgui4    4:4.8.2+dfsg-2
ii  libssl1.0.0  1.0.1c-4
ii  libstdc++6   4.7.1-7

xca recommends no packages.

xca suggests no packages.

-- no debconf information

-- 
brian m. carlson / brian with sandals: Houston, Texas, US
+1 832 623 2791 | http://www.crustytoothpaste.net/~bmc | My opinion only
OpenPGP: RSA v4 4096b: 88AC E9B2 9196 305B A994 7552 F1BA 225C 0223 B187

Attachment: signature.asc
Description: Digital signature


--- End Message ---
--- Begin Message ---
Source: xca
Source-Version: 1.0.0-1

On Wed, Nov 05, 2014 at 06:38:08 +0100, Christian Hohnstaedt wrote:
> Hi Tino, Gerrit,

[...]

> Please remember XCA 1.0.0 also fixes debian-bug #686397
>  "EC self-signed cert incorrectly forces use of SHA-1"
> 
> Who will close that ?

Le me.

Regards,
Tino

--- End Message ---

Reply via email to