SSL in non-browser code

2012-10-23 Thread Kurt Roeckx
Hi, I just found this paper: http://www.cs.utexas.edu/~shmat/shmat_ccs12.pdf Does anybody know if all the problems mentioned in that document are tracked somewhere? Kurt -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact

Re: [SECURITY] [DSA 2563-1] viewvc security update

2012-10-23 Thread Jon Dowland
Hi, This DSA was signed with key 0x401DAC04, which is not in any debian-keyring package I can find, nor on pgp.mit.edu. Is this a mistake? Thanks! -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org

Re: [SECURITY] [DSA 2563-1] viewvc security update

2012-10-23 Thread Florian Weimer
* Jon Dowland: This DSA was signed with key 0x401DAC04, which is not in any debian-keyring package I can find, nor on pgp.mit.edu. Is this a mistake? Thanks! It's a signing subkey of E1C21845, some software might have problems with that. The entire key is available from the developer LDAP.