[Git-commits] [grml/grml-debian-keyring] 0c9f04: keyring: remove DSA signing key

Chris Hofstaedtler noreply at github.com
Mon Jan 20 11:54:26 CET 2025


  Branch: refs/heads/master
  Home:   https://github.com/grml/grml-debian-keyring
  Commit: 0c9f041ae450b6229b6f004a60971769a99c12d3
      https://github.com/grml/grml-debian-keyring/commit/0c9f041ae450b6229b6f004a60971769a99c12d3
  Author: Chris Hofstaedtler <ch at grml.org>
  Date:   2025-01-20 (Mon, 20 Jan 2025)

  Changed paths:
    M keyrings/grml-archive-keyring.gpg

  Log Message:
  -----------
  keyring: remove DSA signing key

The DSA key is used only for some old releases, but these are
also signed with the 4096bit key. Distributing both adds no value
but only introduces possible attack vectors when the DSA key
can be factored.

Old key was:

pub   dsa1024/F61E2E7CECDEA787 2006-11-19 [SC]
      709BCE51568573EBC160E590F61E2E7CECDEA787
uid                           GRML Archive Automatic Signing Key (http://www.grml.org/) <ftpmaster at grml.org>
sub   elg2048/896CF7B9B1F9C73E 2006-11-19 [E]


  Commit: 6ad7d571b8417eab54611c0163b62e62eac0f578
      https://github.com/grml/grml-debian-keyring/commit/6ad7d571b8417eab54611c0163b62e62eac0f578
  Author: Chris Hofstaedtler <zeha at users.noreply.github.com>
  Date:   2025-01-20 (Mon, 20 Jan 2025)

  Changed paths:
    M keyrings/grml-archive-keyring.gpg

  Log Message:
  -----------
  Merge pull request #8 from grml/zeha/remove-old-key

keyring: remove DSA signing key


Compare: https://github.com/grml/grml-debian-keyring/compare/f97bedc01b2c...6ad7d571b841

To unsubscribe from these emails, change your notification settings at https://github.com/grml/grml-debian-keyring/settings/notifications


More information about the Git-commits mailing list