SHA1 bindings in your PGP key 4E386D9C9C61702F
Uwe Kleine-König <[email protected]> Tue, 9 Sep 2025 12:03:20 +0200
| Newsgroups | org.kernel.linux.keys |
|---|---|
| Message-ID | <isa35mrnkbzbirunf55qmy2bmxj4jfbcado5o4xi655oa6tawa@azwkdgaggj2g> |
Hello Willy, recently your PGP key 4E386D9C9C61702F was updated in the kernel PGP keyring after you expanded its validity (https://git.kernel.org/pub/scm/docs/kernel/pgpkeys.git/commit/?id=e8a3192d295094087e09f623595c8309b2eac915). Taking this as a hint that you still care about the key: This key suffers from SHA-1 bindings which are not considered on par with typical security recommendations today: $ sq cert lint < keys/4E386D9C9C61702F.asc Certificate 4E386D9C9C61702F is not valid under the standard policy: No binding signature at time 2025-09-09T09:45:16Z Certificate 4E386D9C9C61702F contains a User ID (Willy Tarreau <[email protected]>) protected by SHA-1 Certificate 4E386D9C9C61702F, key 014180C7E8419672 uses a SHA-1-protected binding signature. Examined 1 certificate. 0 certificates are invalid and were not linted. (GOOD) 1 certificate was linted. 1 of the 1 certificates (100%) has at least one issue. (BAD) 0 of the linted certificates were revoked. 0 of the 0 certificates has revocation certificates that are weaker than the certificate and should be recreated. (GOOD) 0 of the linted certificates were expired. 1 of the non-revoked linted certificate has at least one non-revoked User ID: 1 has at least one User ID protected by SHA-1. (BAD) 1 has all User IDs protected by SHA-1. (BAD) 1 of the non-revoked linted certificates has at least one non-revoked, live subkey: 1 has at least one non-revoked, live subkey with a binding signature that uses SHA-1. (BAD) 0 of the non-revoked linted certificates have at least one non-revoked, live, signing-capable subkey: 0 certificates have at least one non-revoked, live, signing-capable subkey with a strong binding signature, but a backsig that uses SHA-1. (GOOD) Error: 1 certificate have at least one issue The issue is that the proofs about your UID and your subkey 014180C7E8419672 belonging to your main key 4E386D9C9C61702F rely on SHA-1 hashes which is considered weak since at least 2005[1]. Practical breakage is not known yet, but still I recommend to update your key to a safer hash algorithm to reduce attacking surface. GnuPG doesn't create such bindings by default any more, but it also doesn't fix these when opportunities arise (e.g. when expanding key validity). Other implementations (e.g. Sequoia PGP) don't even accept these keys any more (while GnuPG continues to be happy about them). Find more details at https://lore.kernel.org/keys/fxotnlhsyl2frp54xtguy7ryrucuwselanazixeax3motyyoo3@7vf7ip6gxyvx/T/#u which also describes a procedure to (hopefully) fix your key. If questions arise, don't hesitate to ask, in private or on the list. Best regards Uwe [1] https://www.schneier.com/blog/archives/2005/02/sha1_broken.html
signature.asc
(application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE----- iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmi/+2UACgkQj4D7WH0S /k5Sbgf/U7YOmwzF3cy9O8jnGs2q+SubanAoFTeRU58PFT2QL67u07eHney2GFa6 EL87/TH1NegEqkScjrRl0A6FBaMm6mBK8GxxL2igQgu0aJO75Gv5ftUuJsQB/lh/ ldt7acq4J8ERCalQiTRgTTTI5pxWJXFE3u11mCpcRQZ78aOXSIPoBAqFit/y46mZ aqSArX2OYq8k0FJGkoARs8U3no0aIQ4QfErgOI9B38ofcT2U6xNPuBkJxlSFhdx3 puWBjL82mmkTcohutoVbUvWsTLXiC22e/hA7F9mQs+hqDb9WXP45ZMl9D7vKTPWb JV2YTguFxwRSXfKYtJ+sf3lWScZCxw== =dnEo -----END PGP SIGNATURE-----