newsNews: Announce: SSL certificates renewed

 
 
Show feedback again
Latest News
Gna! hardware failure posted by zerodeux, Tue 14 Feb 2012 06:55:00 PM UTC - 1108 replies
20 minutes downtime posted by beuc, Thu 26 Jan 2012 07:59:58 PM UTC - 397 replies
Subversion upgrade posted by beuc, Sun 06 Nov 2011 11:37:27 AM UTC - 596 replies
Upgrades posted by beuc, Sun 19 Dec 2010 07:59:58 PM UTC - 578 replies
Gna! frontend back - change your passwords posted by beuc, Thu 02 Dec 2010 10:24:16 PM UTC - 458 replies
[110 news in archive]

Security Announce: SSL certificates renewed

Item posted by Mathieu Roy <yeupou> on Sun 15 Feb 2004 12:07:47 PM UTC.

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

SSL certificates for gna.org and mail.gna.org has been renewed for 1200 days.

These certificates are not signed by a real certificate authority: their purpose is not to confirm our identity but to provide you a way to be sure that https://gna.org and https://mail.gna.org today are running on the same machine they were yesterday. Also, certificates are required for an https server to run, and https is a way to secure all the data transiting between your computer and our servers, like authentication information.

Mathieu Roy <yeupou@gnu.org> for Gna!
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFAL2A4Nl9/9y2hmbkRAiPcAJ9Xiga+gQ3id7tXOSD/1Hb/P6U/XQCfTHMy
TfHV7PRmo+hxCvkaoAa5ces=
=e0N+
-----END PGP SIGNATURE-----

Comments:

Message: 108
RE: GPG signing (posted by yeupou, Mon 16 Feb 2004 06:55:35 PM UTC)

1) The signature is not valid because savane add < and > around email address and I had the bad idea to add my address.

If you remove the < >, I bet it would be ok.

2) Getting an Savane account cracked is possible. I guess that a gpg key may be cracked too, however I think it is a way tougher job, if not impossible. Security announces should definitely rely on a very secure signature, like GPG, unlike being logged on Gna! Also, security announces at Gna! should not depends on the Gna! structure itself to confirm it is validity: if Gna! was cracked, it would be easy to make false announces if the checks on the announces are made with Gna! specific stuff itself.
In this case, it would takes Gna! to be cracked and my own GPG key to be cracked, two things unlikely to happen at the same time.

Thread Author Date
GPG signingzerodeuxMon 16 Feb 2004 01:11:50 PM UTC
      RE: GPG signingyeupouMon 16 Feb 2004 06:55:35 PM UTC
            RE: GPG signingvincent3Sun 19 May 2013 12:43:36 PM UTC
      RE: GPG signing 2yeupouMon 16 Feb 2004 07:01:47 PM UTC
            RE: GPG signing 2yeupouMon 16 Feb 2004 07:02:22 PM UTC
      RE: GPG signingjordearmessTue 23 Oct 2012 09:38:42 AM UTC

 

Post a followup to this message

You could post if you were logged in
Show feedback again

Back to the top


Powered by Savane 3.1-cleanup