Re: [email protected]

Uwe Kleine-König <[email protected]> Fri, 24 Jul 2026 19:59:29 +0200
Newsgroups org.kernel.linux.keys
Message-ID <amOm00f_J8bZFw_f@monoceros>
--task6w7uamq2jqqq
Content-Type: text/plain; protected-headers=v1; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable
Subject: Re: [email protected]
MIME-Version: 1.0

Hello Will,

On Fri, Jul 24, 2026 at 02:48:25PM +0100, Will Deacon wrote:
> -----BEGIN PGP PUBLIC KEY BLOCK-----
>=20
> mQINBE6G5s0BEADDGfOcthrGJKfkcrFBdCyduDIsx7Ca02KKtvuNsBrpj5mDGSlf
> [...]
> LFYBaYx/l+Gxzd10OVv2br/umTyBkQB59JlclrCcW7RYl5jbBO0P+PKfTVWV
> =3DFO5n
> -----END PGP PUBLIC KEY BLOCK-----

`sq cert lint` reports:

	Certificate 2DFBF4523E542FD9, key 4687FCE0E1EAD0C4 uses a SHA-1-protected =
binding signature.

I think the script by Konstantin (used to redo all the old signatures
also suffering from using SHA1). If not, `sq cert lint --fix` is the
easiest way to fix that.

Also one of your identities uses a UID comment. See
https://dkg.fifthhorseman.net/blog/openpgp-user-id-comments-considered-harm=
ful.html
for learning why this is bad.

Best regards
Uwe

--task6w7uamq2jqqq
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCgAdFiEEP4GsaTp6HlmJrf7Tj4D7WH0S/k4FAmpjp/4ACgkQj4D7WH0S
/k6IBAf/cI2NZXPI0ml6oC6f+s8Hd14iFg6l91JEA3VJul/DRdvfzFHVqdjKVbmO
E0FjoTX1nkoAyAzwJT8qB1DMXAzXc6esb/T4MfbE4R9h/kP3P+H0GFdysovR/niR
iln3vfvBE+oYPa0iOFAwjVOhzX3zqz/ogeSGdgRI8aNa7b2l8UVhZzV3A6Z2q2ju
SRdl5IUJDfTLZs+p3Qxd4W+CIYebdqmGxnCH7d0HcTO81Sikk/ci7VPpD9L6J4La
ZoYJz3h6EHbtqPanVtmzV6FIPc6GwcKR+k7IoLIAgJaCFVMGzd9WNEUncNEDd/a6
dczVcrQ1UEFo7XH6SDAC1FjpGLKq/A==
=jZ2V
-----END PGP SIGNATURE-----

--task6w7uamq2jqqq--