Re: 1024 bit key used to sign GLPK distribution package

Andrew Makhorin <[email protected]>
Newsgroups gmane.comp.gnu.glpk
Message-ID <1485163978.16332.1.camel@corvax>
> you are using a 1024 bit key for signing GLPK distribution tar balls.
> 
> 1024 bit is no longer considered safe. Cf.
> http://csrc.nist.gov/publications/nistpubs/800-57/sp800-57-Part1-revised2_Mar08-2007.pdf
> 
> Furthermore you are using SHA-1 for signing.
> SHA1 is also regarded as unsafe.
> 

AFAIK, many other GNU packages use a similar signature. See for example,
ftp://ftp.gnu.org/gnu/gcc/gcc-6.3.0/ .
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.