[Bug 2065932] Re: Only adds the weak key for PPAs dual-signed with both weak and strong keys

2024-06-19 Thread Mario
In my opinion, a weak key indirectly (not far from "almost directly") compromises the whole system. This is highest possible level Importance / priority. Security urgency. That goes for any other weak RSA in any launchpad PPAs. TODO: replace all Launchpad weak keys with at least RSA4096 and

[Bug 2065932] Re: Only adds the weak key for PPAs dual-signed with both weak and strong keys

2024-05-21 Thread Charlie Wong
** Description changed: After running ‘add-apt-repository ppa:git-core/ppa’ on Ubuntu 24.04, ‘apt update’ gives this warning: W: https://ppa.launchpadcontent.net/git- core/ppa/ubuntu/dists/noble/InRelease: Signature by key E1DD270288B4E6030699E45FA1715D88E1DF1F24 uses weak algorithm

[Bug 2065932] Re: Only adds the weak key for PPAs dual-signed with both weak and strong keys

2024-05-21 Thread Launchpad Bug Tracker
Status changed to 'Confirmed' because the bug affects multiple users. ** Changed in: software-properties (Ubuntu) Status: New => Confirmed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2065932