About the vulnerability reporting instructions on the web site

Sergio Gelato <[email protected]> Wed, 30 Aug 2017 12:18:31 +0200
Newsgroups gmane.comp.encryption.kerberos.heimdal.general
Message-ID <[email protected]>
I am under the impression that Heimdal's process for reporting sensitive bugs
is broken. I am referring to the following sentence on https://www.h5l.org/ :

"Security sensitive bug reports should be sent to [email protected] using this PGP key (key id 3B81827E)."

Not only do I get the impression that bug reports sent in this manner are not
being acted on (it could be just a lack of feedback but that's also a problem),
but all subkeys of that PGP key have expired: the ones in the file on the web
site ten years ago, the newer ones available through the PGP keyservers more
recently.

The web site *is* being updated with release information so I don't understand
why it is not also being updated with contact information.
signature.asc (application/pgp-signature, 833 B)
-----BEGIN PGP SIGNATURE-----

iQIzBAABCAAdFiEEdy2TlEpbXQu4A6YbrueYj9pYv8QFAlmmkO4ACgkQrueYj9pY
v8RC6RAAtq/8rfZuvOimrM/SydIUG/7e0oteqR8SG1yq8dik3XuBtqFmy7fWazfg
5C96rICQ9VfWhFsZ0kiSOdH5rZAf0aqJYoczdJ3Xee7EdapMmTPbWmqyv8sfS7xV
3kkRQgo4UTW045eV1rGi7bCKf0nHhfsg0Vt41Y5C0Z4kJ0AYnLXWKxdF9qwIhxMn
9p+9TWQMTWG4Muah4ipEsBCwWK1bCeUe/xDHOxB409CiWfik7Hgs+stt6Rc3jbB2
pd7AxvYBImVbpU9SrFmINM1QT5otjhvNWvOVdpUIA93hV6qNa66qvc4EhM16khmc
lUBUZIdJ5V95A2uLnH/OuHwBbp9/WnrxpS5HxzUYCXKoxYt7n1dn9hq3KwKejQZF
vrRSDsOsBlCcG5Jkh2Pgj/ieF3J3/gbk9k/pd0+cKldlA29aT2Ic/hhEMSniLDBa
t+2jMMDRsEDlHjiY6NG2DNFci8XW85yBFuACiqBb/A0eCz2sqOfKaS+ldQwOcLIA
cJME9eFHnZn8H58FtYQdaUXl6cbfnPjKC5XcIsLDrup+H1+JdklhkKkgujG5AECx
BqPVyanaj6uHyIeUzvC8c2CeDRrkwvOt8ntkA/2e8WUCUAOQ5/udLXSy79mciO5o
uhEQqIt87nd9I9I9baQIxnA/yrFBbLZ00PGnCcYlLEbwDpGJPXc=
=Jq/t
-----END PGP SIGNATURE-----