All of lore.kernel.org
 help / color / mirror / Atom feed
* SHA1 bindings in your PGP key 4E386D9C9C61702F
@ 2025-09-09 10:03 Uwe Kleine-König
  2025-09-10  6:40 ` Willy Tarreau
  0 siblings, 1 reply; 5+ messages in thread
From: Uwe Kleine-König @ 2025-09-09 10:03 UTC (permalink / raw)
  To: Willy Tarreau; +Cc: keys

[-- Attachment #1: Type: text/plain, Size: 2806 bytes --]

Hello Willy,

recently your PGP key 4E386D9C9C61702F was updated in the kernel PGP
keyring after you expanded its validity
(https://git.kernel.org/pub/scm/docs/kernel/pgpkeys.git/commit/?id=e8a3192d295094087e09f623595c8309b2eac915). 

Taking this as a hint that you still care about the key:

This key suffers from SHA-1 bindings which are not considered on par with
typical security recommendations today:

	$ sq cert lint < keys/4E386D9C9C61702F.asc
	Certificate 4E386D9C9C61702F is not valid under the standard policy: No binding signature at time 2025-09-09T09:45:16Z
	Certificate 4E386D9C9C61702F contains a User ID (Willy Tarreau <w@1wt.eu>) protected by SHA-1
	Certificate 4E386D9C9C61702F, key 014180C7E8419672 uses a SHA-1-protected binding signature.
	Examined 1 certificate.
	  0 certificates are invalid and were not linted. (GOOD)
	  1 certificate was linted.
	  1 of the 1 certificates (100%) has at least one issue. (BAD)
	0 of the linted certificates were revoked.
	  0 of the 0 certificates has revocation certificates that are weaker than the certificate and should be recreated. (GOOD)
	0 of the linted certificates were expired.
	1 of the non-revoked linted certificate has at least one non-revoked User ID:
	  1 has at least one User ID protected by SHA-1. (BAD)
	  1 has all User IDs protected by SHA-1. (BAD)
	1 of the non-revoked linted certificates has at least one non-revoked, live subkey:
	  1 has at least one non-revoked, live subkey with a binding signature that uses SHA-1. (BAD)
	0 of the non-revoked linted certificates have at least one non-revoked, live, signing-capable subkey:
	  0 certificates have at least one non-revoked, live, signing-capable subkey with a strong binding signature, but a backsig that uses SHA-1. (GOOD)

	  Error: 1 certificate have at least one issue

The issue is that the proofs about your UID and your subkey
014180C7E8419672 belonging to your main key 4E386D9C9C61702F rely on
SHA-1 hashes which is considered weak since at least 2005[1]. Practical
breakage is not known yet, but still I recommend to update your key to a
safer hash algorithm to reduce attacking surface.

GnuPG doesn't create such bindings by default any more, but it also
doesn't fix these when opportunities arise (e.g. when expanding key
validity). Other implementations (e.g. Sequoia PGP) don't even accept
these keys any more (while GnuPG continues to be happy about them).

Find more details at
https://lore.kernel.org/keys/fxotnlhsyl2frp54xtguy7ryrucuwselanazixeax3motyyoo3@7vf7ip6gxyvx/T/#u
which also describes a procedure to (hopefully) fix your key.

If questions arise, don't hesitate to ask, in private or on the list.

Best regards
Uwe

[1] https://www.schneier.com/blog/archives/2005/02/sha1_broken.html

[-- Attachment #2: signature.asc --]
[-- Type: application/pgp-signature, Size: 488 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2025-09-11  8:36 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2025-09-09 10:03 SHA1 bindings in your PGP key 4E386D9C9C61702F Uwe Kleine-König
2025-09-10  6:40 ` Willy Tarreau
2025-09-10 13:16   ` Konstantin Ryabitsev
2025-09-10 13:23     ` Willy Tarreau
2025-09-11  8:36   ` Uwe Kleine-König

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.