[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: EC SRM key for bookworm?



Hi Adam,

On 04/03/2023 14:33, Adam D. Barratt wrote:
SRM is considering using an ed25519 GPG key for bookworm. Does anyone
see any issues with that?

We've tested merging signatures from a (different) ed25519 key and an
RSA key using dak's "gpg-merge-signatures" script, and gpgv is happy to
verify the result on an oldoldstable (Debian 9 / stretch) system.

We know that GPG(V) 1.X can't handle EC keys, which means that the
signatures won't be verifiable on jessie. jessie is still supported
externally via ELTS, but I don't know that anyone's trying to use it to
verify signatures from bookworm.

jessie ships gpgv2 from src:gnupg2 alongside gnupg 1.x, so if there was anyone affected by this change, I don't think it would be a big issue.

Cheers,
Emilio


Reply to: