Bug#904686: marked as done (ssl-cert: RSA keylength is getting a bit short)

"Debian Bug Tracking System" <[email protected]> Sat, 01 Aug 2026 15:51:01 +0000
Newsgroups gmane.linux.debian.devel.apache
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1785599461-1417664-0
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="utf-8"

Your message dated Sat, 01 Aug 2026 15:48:57 +0000
with message-id <[email protected]>
and subject line Bug#904686: fixed in ssl-cert 1.2.0
has caused the Debian Bug report #904686,
regarding ssl-cert: RSA keylength is getting a bit short
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


--=20
904686: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=3D904686
Debian Bug Tracking System
Contact [email protected] with problems

------------=_1785599461-1417664-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at submit) by bugs.debian.org; 26 Jul 2018 16:13:48 +0000
X-Spam-Checker-Version: SpamAssassin 3.4.1-bugs.debian.org_2005_01_02
	(2015-04-28) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-14.7 required=4.0 tests=BAYES_00,FOURLA,HAS_PACKAGE,
	RCVD_IN_DNSWL_NONE,SPF_PASS,TXREP,XMAILER_REPORTBUG autolearn=ham
	autolearn_force=no version=3.4.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 25; hammy, 149; neutral, 116; spammy,
	1. spammytokens:0.998-1--proofing hammytokens:0.000-+--H*x:7.1.7,
	0.000-+--H*UA:7.1.7, 0.000-+--H*M:reportbug, 0.000-+--H*MI:reportbug,
	0.000-+--H*x:reportbug
Return-path: <[email protected]>
Received: from bar2.oicr.on.ca ([206.108.124.16])
	by buxtehude.debian.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256)
	(Exim 4.89)
	(envelope-from <[email protected]>)
	id 1fiitO-0001zX-88
	for [email protected]; Thu, 26 Jul 2018 16:13:48 +0000
X-ASG-Debug-ID: 1532621608-0787002488171750001-kOlByo
Received: from webmail.oicr.on.ca (ex03.ad.oicr.on.ca [10.0.1.54]) by bar2.oicr.on.ca with ESMTP id nwflXPP4ImzPsriM (version=TLSv1.2 cipher=ECDHE-RSA-AES256-SHA384 bits=256 verify=NO) for <[email protected]>; Thu, 26 Jul 2018 12:13:28 -0400 (EDT)
X-Barracuda-Envelope-From: [email protected]
Received: from ex01.ad.oicr.on.ca (10.0.1.52) by EX03.ad.oicr.on.ca
 (10.0.1.54) with Microsoft SMTP Server (version=TLS1_2,
 cipher=TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256_P256) id 15.1.1531.3; Thu, 26
 Jul 2018 12:13:28 -0400
Received: from ns1.res.oicr.on.ca (10.0.0.101) by ex01.ad.oicr.on.ca
 (10.0.1.180) with Microsoft SMTP Server id 15.1.1531.3 via Frontend
 Transport; Thu, 26 Jul 2018 12:13:28 -0400
Received: from ohs-ns1.oicr.on.ca (ohs-ns1-new.ontariohealthstudy.ca [10.30.96.201])
	by ns1.res.oicr.on.ca (Postfix) with ESMTP id 31E98BDC077;
	Thu, 26 Jul 2018 12:13:28 -0400 (EDT)
Received: by ohs-ns1.oicr.on.ca (Postfix, from userid 2025)
	id 2653D21078; Thu, 26 Jul 2018 12:13:28 -0400 (EDT)
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
From: David Magda <[email protected]>
To: Debian Bug Tracking System <[email protected]>
Subject: ssl-cert: RSA keylength is getting a bit short
Message-ID: <153262160810.3320.11802628204956981268.reportbug@ohs-ns1.oicr.on.ca>
X-ASG-Orig-Subj: ssl-cert: RSA keylength is getting a bit short
X-Mailer: reportbug 7.1.7
Date: Thu, 26 Jul 2018 12:13:28 -0400
X-Barracuda-Connect: ex03.ad.oicr.on.ca[10.0.1.54]
X-Barracuda-Start-Time: 1532621608
X-Barracuda-Encrypted: ECDHE-RSA-AES256-SHA384
X-Barracuda-URL: https://206.108.124.16:443/cgi-mod/mark.cgi
X-Virus-Scanned: by bsmtpd at oicr.on.ca
X-Barracuda-Scan-Msg-Size: 1562
X-Barracuda-BRTS-Status: 1
X-Barracuda-Spam-Score: 0.00
X-Barracuda-Spam-Status: No, SCORE=0.00 using global scores of TAG_LEVEL=1000.0 QUARANTINE_LEVEL=1000.0 KILL_LEVEL=9.0 tests=
X-Barracuda-Spam-Report: Code version 3.2, rules version 3.2.3.54485
	Rule breakdown below
	 pts rule name              description
	---- ---------------------- --------------------------------------------------
Delivered-To: [email protected]

Package: ssl-cert
Version: 1.0.39
Severity: wishlist

The current default keylength for the snakeoil cert is 2048 bits. However,
these certs could now live for ten years (3650 days), which as I type
this could be upto 2028.

Various technical bodies are recently that for long-lived secrets,
a factoring modulus (i.e., RSA key size) of 3072 bits is recommended:

	https://www.keylength.com/en/4/
	https://www.keylength.com/en/compare/

2048b should be good until the year 2030, but we're approaching that now:

	https://en.wikipedia.org/wiki/Key_size#Asymmetric_algorithm_key_lengths

While most commercial certificate authorities (CAs) give out 2048 bit
certficites, those are only valid for 1-2 years (90 days in the case
of Let's Encrypt), so the risk is much less in the short term.


Can "-newkey rsa:3072" be added to the ssl-cert script for better
future proofing?


-- System Information:
Debian Release: 9.5
  APT prefers stable
  APT policy: (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 4.9.0-7-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_US.UTF-8, LC_CTYPE=en_US.UTF-8 (charmap=UTF-8), LANGUAGE=en_US.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages ssl-cert depends on:
ii  adduser                3.115
ii  debconf [debconf-2.0]  1.5.61
ii  openssl                1.1.0f-3+deb9u2

ssl-cert recommends no packages.

Versions of packages ssl-cert suggests:
pn  openssl-blacklist  <none>

-- debconf information excluded

------------=_1785599461-1417664-0
Content-Type: message/rfc822
Content-Disposition: inline
Content-Transfer-Encoding: 7bit

Received: (at 904686-close) by bugs.debian.org; 1 Aug 2026 15:49:00 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
	(2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-114.2 required=4.0 tests=ALL_TRUSTED,BAYES_00,
	DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,DKIM_VALID_EF,FVGT_m_MULTI_ODD,
	HAS_BUG_NUMBER,MD5_SHA1_SUM,PGPSIGNATURE,SPF_HELO_PASS,SPF_PASS,
	USER_IN_DKIM_WELCOMELIST autolearn=ham autolearn_force=no
	version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 101; hammy, 150; neutral, 147; spammy,
	0. spammytokens: hammytokens:0.000-+--HX-Debian:DAK,
	0.000-+--H*rp:D*ftp-master.debian.org, 0.000-+--HX-DAK:process-upload,
	0.000-+--H*r:sk:fasolo., 0.000-+--H*MI:fasolo
Return-path: <[email protected]>
Received: from mailly.debian.org ([2001:41b8:202:deb:6564:a62:52c3:4b72]:41266)
	by buxtehude.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wqBxM-005wa0-0P
	for [email protected];
	Sat, 01 Aug 2026 15:49:00 +0000
Received: via submission
	from C=NA,ST=NA,L=Ankh Morpork,O=Debian SMTP,OU=Debian SMTP CA,CN=fasolo.debian.org,[email protected] (verified)
	by mailly.debian.org with esmtps (TLS1.3:ECDHE_SECP256R1__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
	(Exim 4.96)
	(envelope-from <[email protected]>)
	id 1wqBxK-00F4Ak-2g
	for [email protected];
	Sat, 01 Aug 2026 15:48:58 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
	d=ftp-master.debian.org; s=smtpauto.fasolo; h=Date:Message-Id:Content-Type:
	Subject:MIME-Version:To:Reply-To:From:Cc:Content-Transfer-Encoding:Content-ID
	:Content-Description:In-Reply-To:References;
	bh=jJvnYgwM0G0AZ/cRSOhquCmFHVtR0bflkCkJLvQASNY=; b=MnD/nNw2yS5l4qykxU+yEjdrnw
	RjLZ1HH7MKsCK6adL0feN7SG71Ya39+3LvKPVdmVgQi0GiKM75LSrEEG75hd46a5LbyITXnDIinBw
	VTBOaAVg+GwWfXJB+MPW/a/Xiz6cZjiOJ7fWqgtglpRJoobOaIn3wKzMHsjliFqoAOjnFkfQHbIOR
	WHrAd0fPR/VVuUGEh0KOFwLf3aMsxycQmsXuV+mIfm5dUE26PpjG21DkVK+RB53yJjpGNLXdAom/5
	0NERlq6l/5WLOZbupdj6x0OpLbjmo3ZRfeTe0kAv6Ptyx3VbE5DI19eaPVW343+5ImdyxwQqDR6GD
	exPkXKvQ==;
Received: from dak by fasolo.debian.org with local (Exim 4.98.2)
	(envelope-from <[email protected]>)
	id 1wqBxJ-0000000FaYA-3TPg;
	Sat, 01 Aug 2026 15:48:57 +0000
From: Debian FTP Masters <[email protected]>
Reply-To: Stefan Fritsch <[email protected]>
To: [email protected]
X-DAK: dak process-upload
X-Debian: DAK
X-Debian-Package: ssl-cert
Debian: DAK
Debian-Changes: ssl-cert_1.2.0_source.changes
Debian-Source: ssl-cert
Debian-Version: 1.2.0
Debian-Architecture: source
Debian-Suite: unstable
Debian-Archive-Action: accept
MIME-Version: 1.0
Subject: Bug#904686: fixed in ssl-cert 1.2.0
Content-Type: multipart/signed; micalg="pgp-sha256";
 protocol="application/pgp-signature";
 boundary="===============8985806902082752482=="
Message-Id: <[email protected]>
Date: Sat, 01 Aug 2026 15:48:57 +0000

--===============8985806902082752482==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable

Source: ssl-cert
Source-Version: 1.2.0
Done: Stefan Fritsch <[email protected]>

We believe that the bug you reported is fixed in the latest version of
ssl-cert, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Stefan Fritsch <[email protected]> (supplier of updated ssl-cert package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sat, 01 Aug 2026 17:20:31 +0200
Source: ssl-cert
Architecture: source
Version: 1.2.0
Distribution: unstable
Urgency: medium
Maintainer: Debian Apache Maintainers <[email protected]>
Changed-By: Stefan Fritsch <[email protected]>
Closes: 904686 929121
Changes:
 ssl-cert (1.2.0) unstable; urgency=3Dmedium
 .
   [ Stefan Fritsch ]
   * Bump standards-version and remove Priority from control file
   * Increase default key length to 3072, but don't replace existing
     2048 bit keys. Closes: #904686
   * Enable Salsa-CI
   * Allow separate key/cert files for the non generate-default-snakeoil
     case, too. Closes: #929121
   * Allow to override CN and SubjectAltName from command line.
 .
   [ Luca Boccassi ]
   * Install and use sysusers.d config file instead of adduser for the
     ssl-cert group.
Checksums-Sha1:
 ebfc48d574453dd32e6cf5e6ee6bbbba697eaff7 1645 ssl-cert_1.2.0.dsc
 6d07dd27dd09dcacd60d4353616b532364f558a4 33344 ssl-cert_1.2.0.tar.xz
 d8051d4532fdc130e06840d9c2340ec83ab91b1f 7085 ssl-cert_1.2.0_source.buildinfo
Checksums-Sha256:
 bdb935dd6cb613ac55e0d637738c286e226d76df21f28c48cb9b534582cf4961 1645 ssl-ce=
rt_1.2.0.dsc
 2615b043c1d692f8ce64e72e3e9acf6c0fff92cfb899e53e98226ef4031f150a 33344 ssl-c=
ert_1.2.0.tar.xz
 33cb20fc58feb9f8be31efe73f1c307269293aacdad20f473c4a1f55e3ce8738 7085 ssl-ce=
rt_1.2.0_source.buildinfo
Files:
 473cede5d7fad1259844c02a0c711719 1645 utils optional ssl-cert_1.2.0.dsc
 d3397258772729e57dc86feb18793085 33344 utils optional ssl-cert_1.2.0.tar.xz
 c3373a38f78801a184ec071d1fb6e304 7085 utils optional ssl-cert_1.2.0_source.b=
uildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEOpiNza8JqByyYYsxxodfNUHO/eAFAmpuD3YACgkQxodfNUHO
/eAwRBAAhqUzmIF6ywQyuDS+lWkL97U//wqBK9Fo34uvaqsCPOD9W2B9YHq7UYbh
T6QCaEa9R+ny1xlR0sYw7KQJdE4rhV3abv1avn30YgoQQk+fcsyWuR6Qb90tJd0W
Ha55JspwkhV4IEzmX9VZk9vYvXAhNnBuv+RgVQRSjzajvTOCXMfDGQEMXveU8wbA
0hoH49MoMYc1eYHuD8fw7LHIGwRoE4BSS7hz7aGKLRImnbgZRSDUdlxAZLRaPicY
2TosAYn9euj7uvfifq934bPyvShQEjVmUjzReLWTdl/M5nyFdmOvkWf8JtqWopoY
0UzbF8TJNBMBXfekUsQXwQn/czjDjXiwHDTTB/5fMiTjPGaQA8wS29p3DFvR2m1d
kwn03zHpH8mR+UDJnIlAsXAP/cUHtwR9tQXNixUdeYN6IYL5BaHekGa994WkxVn6
uL7fe6UsrVNV2DdH3SN7XjM0/oppr60ziuLkbq4wU6RA2CuAkqcclkmySIFWs6Lu
fjcn3YNaBTmru/HxSaP/OLwE5j33S74JktgtEsWEGGhzUdw3dzMJvPawTKZ7V+Qe
H4hgm6vMA7b1TllL3cgqoGxa32dNOKQ17dM0SUXwdizyWDD+PPZ92XbK+ISJcPmd
7IY4hbJccHilF27OesuYGeK+30MqJuNlDvhEF5QtAoxQj8qelKs=3D
=3DK2RS
-----END PGP SIGNATURE-----


--===============8985806902082752482==
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----

iHUEABYIAB0WIQTziqJOuF8J+ZI8pJSb9qggYcy5IQUCam4VaQAKCRCb9qggYcy5
IfRuAP9c+lnKYfqTtWTkm/Gp02tc1f1AeJaYytr8wwlk/TevAgD+M+mDNVz94x30
PzycnL9uVXFWrUAjcyCHFdR2h3SVHAM=
=KlQc
-----END PGP SIGNATURE-----

--===============8985806902082752482==--
------------=_1785599461-1417664-0--