Bug#904686: marked as done (ssl-cert: RSA keylength is getting a bit short)
"Debian Bug Tracking System" <[email protected]> Sat, 01 Aug 2026 15:51:01 +0000
| Newsgroups | gmane.linux.debian.devel.apache |
|---|---|
| Message-ID | <[email protected]> |
This is a multi-part message in MIME format... ------------=_1785599461-1417664-0 Content-Disposition: inline Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" Your message dated Sat, 01 Aug 2026 15:48:57 +0000 with message-id <[email protected]> and subject line Bug#904686: fixed in ssl-cert 1.2.0 has caused the Debian Bug report #904686, regarding ssl-cert: RSA keylength is getting a bit short to be marked as done. This means that you claim that the problem has been dealt with. If this is not the case it is now your responsibility to reopen the Bug report if necessary, and/or fix the problem forthwith. (NB: If you are a system administrator and have no idea what this message is talking about, this may indicate a serious mail system misconfiguration somewhere. Please contact [email protected] immediately.) --=20 904686: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D904686 Debian Bug Tracking System Contact [email protected] with problems ------------=_1785599461-1417664-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at submit) by bugs.debian.org; 26 Jul 2018 16:13:48 +0000 X-Spam-Checker-Version: SpamAssassin 3.4.1-bugs.debian.org_2005_01_02 (2015-04-28) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-14.7 required=4.0 tests=BAYES_00,FOURLA,HAS_PACKAGE, RCVD_IN_DNSWL_NONE,SPF_PASS,TXREP,XMAILER_REPORTBUG autolearn=ham autolearn_force=no version=3.4.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 25; hammy, 149; neutral, 116; spammy, 1. spammytokens:0.998-1--proofing hammytokens:0.000-+--H*x:7.1.7, 0.000-+--H*UA:7.1.7, 0.000-+--H*M:reportbug, 0.000-+--H*MI:reportbug, 0.000-+--H*x:reportbug Return-path: <[email protected]> Received: from bar2.oicr.on.ca ([206.108.124.16]) by buxtehude.debian.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.89) (envelope-from <[email protected]>) id 1fiitO-0001zX-88 for [email protected]; Thu, 26 Jul 2018 16:13:48 +0000 X-ASG-Debug-ID: 1532621608-0787002488171750001-kOlByo Received: from webmail.oicr.on.ca (ex03.ad.oicr.on.ca [10.0.1.54]) by bar2.oicr.on.ca with ESMTP id nwflXPP4ImzPsriM (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NO) for <[email protected]>; Thu, 26 Jul 2018 12:13:28 -0400 (EDT) X-Barracuda-Envelope-From: [email protected] Received: from ex01.ad.oicr.on.ca (10.0.1.52) by EX03.ad.oicr.on.ca (10.0.1.54) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1531.3; Thu, 26 Jul 2018 12:13:28 -0400 Received: from ns1.res.oicr.on.ca (10.0.0.101) by ex01.ad.oicr.on.ca (10.0.1.180) with Microsoft SMTP Server id 15.1.1531.3 via Frontend Transport; Thu, 26 Jul 2018 12:13:28 -0400 Received: from ohs-ns1.oicr.on.ca (ohs-ns1-new.ontariohealthstudy.ca [10.30.96.201]) by ns1.res.oicr.on.ca (Postfix) with ESMTP id 31E98BDC077; Thu, 26 Jul 2018 12:13:28 -0400 (EDT) Received: by ohs-ns1.oicr.on.ca (Postfix, from userid 2025) id 2653D21078; Thu, 26 Jul 2018 12:13:28 -0400 (EDT) Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit From: David Magda <[email protected]> To: Debian Bug Tracking System <[email protected]> Subject: ssl-cert: RSA keylength is getting a bit short Message-ID: <153262160810.3320.11802628204956981268.reportbug@ohs-ns1.oicr.on.ca> X-ASG-Orig-Subj: ssl-cert: RSA keylength is getting a bit short X-Mailer: reportbug 7.1.7 Date: Thu, 26 Jul 2018 12:13:28 -0400 X-Barracuda-Connect: ex03.ad.oicr.on.ca[10.0.1.54] X-Barracuda-Start-Time: 1532621608 X-Barracuda-Encrypted: ECDHE-RSA-AES256-SHA384 X-Barracuda-URL: https://206.108.124.16:443/cgi-mod/mark.cgi X-Virus-Scanned: by bsmtpd at oicr.on.ca X-Barracuda-Scan-Msg-Size: 1562 X-Barracuda-BRTS-Status: 1 X-Barracuda-Spam-Score: 0.00 X-Barracuda-Spam-Status: No, SCORE=0.00 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=9.0 tests= X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.54485 Rule breakdown below pts rule name description ---- ---------------------- -------------------------------------------------- Delivered-To: [email protected] Package: ssl-cert Version: 1.0.39 Severity: wishlist The current default keylength for the snakeoil cert is 2048 bits. However, these certs could now live for ten years (3650 days), which as I type this could be upto 2028. Various technical bodies are recently that for long-lived secrets, a factoring modulus (i.e., RSA key size) of 3072 bits is recommended: https://www.keylength.com/en/4/ https://www.keylength.com/en/compare/ 2048b should be good until the year 2030, but we're approaching that now: https://en.wikipedia.org/wiki/Key_size#Asymmetric_algorithm_key_lengths While most commercial certificate authorities (CAs) give out 2048 bit certficites, those are only valid for 1-2 years (90 days in the case of Let's Encrypt), so the risk is much less in the short term. Can "-newkey rsa:3072" be added to the ssl-cert script for better future proofing? -- System Information: Debian Release: 9.5 APT prefers stable APT policy: (500, 'stable') Architecture: amd64 (x86_64) Kernel: Linux 4.9.0-7-amd64 (SMP w/2 CPU cores) Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8) Shell: /bin/sh linked to /bin/dash Init: systemd (via /run/systemd/system) Versions of packages ssl-cert depends on: ii adduser 3.115 ii debconf [debconf-2.0] 1.5.61 ii openssl 1.1.0f-3+deb9u2 ssl-cert recommends no packages. Versions of packages ssl-cert suggests: pn openssl-blacklist <none> -- debconf information excluded ------------=_1785599461-1417664-0 Content-Type: message/rfc822 Content-Disposition: inline Content-Transfer-Encoding: 7bit Received: (at 904686-close) by bugs.debian.org; 1 Aug 2026 15:49:00 +0000 X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02 (2024-03-25) on buxtehude.debian.org X-Spam-Level: X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00, DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD, HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS, USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no version=4.0.1-bugs.debian.org_2005_01_02 X-Spam-Bayes: score:0.0000 Tokens: new, 101; hammy, 150; neutral, 147; spammy, 0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK, 0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload, 0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo Return-path: <[email protected]> Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:41266) by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wqBxM-005wa0-0P for [email protected]; Sat, 01 Aug 2026 15:49:00 +0000 Received: via submission from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified) by mailly.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256) (Exim 4.96) (envelope-from <[email protected]>) id 1wqBxK-00F4Ak-2g for [email protected]; Sat, 01 Aug 2026 15:48:58 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type: Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID :Content-Description:In-Reply-To:References; bh=jJvnYgwM0G0AZ/cRSOhquCmFHVtR0bflkCkJLvQASNY=; b=MnD/nNw2yS5l4qykxU+yEjdrnw RjLZ1HH7MKsCK6adL0feN7SG71Ya39+3LvKPVdmVgQi0GiKM75LSrEEG75hd46a5LbyITXnDIinBw VTBOaAVg+GwWfXJB+MPW/a/Xiz6cZjiOJ7fWqgtglpRJoobOaIn3wKzMHsjliFqoAOjnFkfQHbIOR WHrAd0fPR/VVuUGEh0KOFwLf3aMsxycQmsXuV+mIfm5dUE26PpjG21DkVK+RB53yJjpGNLXdAom/5 0NERlq6l/5WLOZbupdj6x0OpLbjmo3ZRfeTe0kAv6Ptyx3VbE5DI19eaPVW343+5ImdyxwQqDR6GD exPkXKvQ==; Received: from dak by fasolo.debian.org with local (Exim 4.98.2) (envelope-from <[email protected]>) id 1wqBxJ-0000000FaYA-3TPg; Sat, 01 Aug 2026 15:48:57 +0000 From: Debian FTP Masters <[email protected]> Reply-To: Stefan Fritsch <[email protected]> To: [email protected] X-DAK: dak process-upload X-Debian: DAK X-Debian-Package: ssl-cert Debian: DAK Debian-Changes: ssl-cert_1.2.0_source.changes Debian-Source: ssl-cert Debian-Version: 1.2.0 Debian-Architecture: source Debian-Suite: unstable Debian-Archive-Action: accept MIME-Version: 1.0 Subject: Bug#904686: fixed in ssl-cert 1.2.0 Content-Type: multipart/signed; micalg="pgp-sha256"; protocol="application/pgp-signature"; boundary="===============8985806902082752482==" Message-Id: <[email protected]> Date: Sat, 01 Aug 2026 15:48:57 +0000 --===============8985806902082752482== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Source: ssl-cert Source-Version: 1.2.0 Done: Stefan Fritsch <[email protected]> We believe that the bug you reported is fixed in the latest version of ssl-cert, which is due to be installed in the Debian FTP archive. A summary of the changes between this version and the previous one is attached. Thank you for reporting the bug, which will now be closed. If you have further comments please address them to [email protected], and the maintainer will reopen the bug report if appropriate. Debian distribution maintenance software pp. Stefan Fritsch <[email protected]> (supplier of updated ssl-cert package) (This message was generated automatically at their request; if you believe that there is a problem with it please contact the archive administrators by mailing [email protected]) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sat, 01 Aug 2026 17:20:31 +0200 Source: ssl-cert Architecture: source Version: 1.2.0 Distribution: unstable Urgency: medium Maintainer: Debian Apache Maintainers <[email protected]> Changed-By: Stefan Fritsch <[email protected]> Closes: 904686 929121 Changes: ssl-cert (1.2.0) unstable; urgency=3Dmedium . [ Stefan Fritsch ] * Bump standards-version and remove Priority from control file * Increase default key length to 3072, but don't replace existing 2048 bit keys. Closes: #904686 * Enable Salsa-CI * Allow separate key/cert files for the non generate-default-snakeoil case, too. Closes: #929121 * Allow to override CN and SubjectAltName from command line. . [ Luca Boccassi ] * Install and use sysusers.d config file instead of adduser for the ssl-cert group. Checksums-Sha1: ebfc48d574453dd32e6cf5e6ee6bbbba697eaff7 1645 ssl-cert_1.2.0.dsc 6d07dd27dd09dcacd60d4353616b532364f558a4 33344 ssl-cert_1.2.0.tar.xz d8051d4532fdc130e06840d9c2340ec83ab91b1f 7085 ssl-cert_1.2.0_source.buildinfo Checksums-Sha256: bdb935dd6cb613ac55e0d637738c286e226d76df21f28c48cb9b534582cf4961 1645 ssl-ce= rt_1.2.0.dsc 2615b043c1d692f8ce64e72e3e9acf6c0fff92cfb899e53e98226ef4031f150a 33344 ssl-c= ert_1.2.0.tar.xz 33cb20fc58feb9f8be31efe73f1c307269293aacdad20f473c4a1f55e3ce8738 7085 ssl-ce= rt_1.2.0_source.buildinfo Files: 473cede5d7fad1259844c02a0c711719 1645 utils optional ssl-cert_1.2.0.dsc d3397258772729e57dc86feb18793085 33344 utils optional ssl-cert_1.2.0.tar.xz c3373a38f78801a184ec071d1fb6e304 7085 utils optional ssl-cert_1.2.0_source.b= uildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmpuD3YACgkQxodfNUHO /eAwRBAAhqUzmIF6ywQyuDS+lWkL97U//wqBK9Fo34uvaqsCPOD9W2B9YHq7UYbh T6QCaEa9R+ny1xlR0sYw7KQJdE4rhV3abv1avn30YgoQQk+fcsyWuR6Qb90tJd0W Ha55JspwkhV4IEzmX9VZk9vYvXAhNnBuv+RgVQRSjzajvTOCXMfDGQEMXveU8wbA 0hoH49MoMYc1eYHuD8fw7LHIGwRoE4BSS7hz7aGKLRImnbgZRSDUdlxAZLRaPicY 2TosAYn9euj7uvfifq934bPyvShQEjVmUjzReLWTdl/M5nyFdmOvkWf8JtqWopoY 0UzbF8TJNBMBXfekUsQXwQn/czjDjXiwHDTTB/5fMiTjPGaQA8wS29p3DFvR2m1d kwn03zHpH8mR+UDJnIlAsXAP/cUHtwR9tQXNixUdeYN6IYL5BaHekGa994WkxVn6 uL7fe6UsrVNV2DdH3SN7XjM0/oppr60ziuLkbq4wU6RA2CuAkqcclkmySIFWs6Lu fjcn3YNaBTmru/HxSaP/OLwE5j33S74JktgtEsWEGGhzUdw3dzMJvPawTKZ7V+Qe H4hgm6vMA7b1TllL3cgqoGxa32dNOKQ17dM0SUXwdizyWDD+PPZ92XbK+ISJcPmd 7IY4hbJccHilF27OesuYGeK+30MqJuNlDvhEF5QtAoxQj8qelKs=3D =3DK2RS -----END PGP SIGNATURE----- --===============8985806902082752482== Content-Type: application/pgp-signature -----BEGIN PGP SIGNATURE----- iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCam4VaQAKCRCb9qggYcy5 IfRuAP9c+lnKYfqTtWTkm/Gp02tc1f1AeJaYytr8wwlk/TevAgD+M+mDNVz94x30 PzycnL9uVXFWrUAjcyCHFdR2h3SVHAM= =KlQc -----END PGP SIGNATURE----- --===============8985806902082752482==-- ------------=_1785599461-1417664-0--