Bug#867461: should ca-certificates certdata.txt synchronize across all suites?

2017-10-02 Thread Jacob Hoffman-Andrews
What's the latest status on this? Thanks, Jacob

Bug#721976: ca-certificates contains both server and email certificates

2017-07-21 Thread Jacob Hoffman-Andrews
Hi, sending you a gentle ping on this. Would love to get this fix landed. Thanks!

Bug#721976: (no subject)

2017-05-26 Thread Jacob Hoffman-Andrews
Hi, just checking in on the status of this. I provided a patch above; does it look good to you?

Bug#721976: (no subject)

2017-04-19 Thread Jacob Hoffman-Andrews
Hi! Any updates on this? Thanks!

Bug#721976: (no subject)

2017-03-20 Thread Jacob Hoffman-Andrews
Great! Here's my proposed patch. It winds up being pretty small, just removing the lines from certdata2pem.py that pull in email certificates. Thanks, Jacob >From 68bc5e229a474fc2815dea530cc246e3d3b55008 Mon Sep 17 00:00:00 2001 From: Jacob Hoffman-Andrews <git...@hoffman-andrews.com>

Bug#858064: (no subject)

2017-03-20 Thread Jacob Hoffman-Andrews
What are the next steps for the package to get released? Is there anything we can help with? Thanks!

Bug#721976: (no subject)

2017-03-17 Thread Jacob Hoffman-Andrews
Sorry, meant to address my previous message to Michael. :-) I've done a little digging, and according to the first-level results from: apt-rdepends --reverse --show=Depends,Recommends,Suggests ca-certificates The only MUAs that depend, recommend, or suggest ca-certificates are mutt and

Bug#721976: ca-certificates contains both server and email certificates

2017-03-17 Thread Jacob Hoffman-Andrews
Hi Marc, I work on EFF's Encrypt the Web project and the Let's Encrypt certificate authority. I'd like to lend support to what Andrew's saying: It's both urgent and important to remove the email roots from the default set of certificates trusted on Debian. I think Andrew's proposal is good;

Bug#856698: (no subject)

2017-03-04 Thread Jacob Hoffman-Andrews
Also, how many files and directories do you have under /etc/letsencrypt/archive? find /etc/letsencrypt/archive | wc -l ls /etc/letsencrypt/archive | wc -l There is a known issue with Certbot performing poorly when many old certificates are present.

Bug#856698: (no subject)

2017-03-04 Thread Jacob Hoffman-Andrews
What is the command that is running when certbot consumes a lot of memory? Can you provide the contents of /etc/cron.d/certbot, and /var/log/letsencrypt.log from a run where certbot consumed a lot of memory? If you're using the Nginx or Apache configurators, can you provide your Nginx or Apache

Bug#764512: postfix: Outbound STARTTLS disabled in default config

2014-10-08 Thread Jacob Hoffman-Andrews
Package: postfix Version: 2.9.6-2 Severity: normal Dear Maintainer, The default config for a newly installed Postfix supports inbound STARTTLS, but it does not support outbound STARTTLS, even if the remote host advertises support. I think the default Postfix config in Debian should have this