[Bug 1461834] Re: 1024-bit signing keys should be deprecated

Jake Lepere 1461834 at bugs.launchpad.net
Wed May 8 17:53:41 UTC 2024


Enabling FIPS on Ubuntu Pro 22.04+ machines [1] drops rsa1024 as an
available encryption key because rsa1024 isn't FIPS compliant.
Therefore, adding rsa1024 signed apt keys here isn't possible.


Does anyone have suggestions to work around this? I've asked if maintainers could resign apt keys for relevant repos but haven't heard back. Additionally, adding apt keys before enabling FIPS works, but future apt updates unfortunately fail afterwards.

[1] https://ubuntu.com/security/certifications/docs/fips-enablement

-- 
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to gnupg2 in Ubuntu.
https://bugs.launchpad.net/bugs/1461834

Title:
  1024-bit signing keys should be deprecated

Status in Launchpad itself:
  New
Status in apt package in Ubuntu:
  Invalid
Status in gnupg2 package in Ubuntu:
  Confirmed

Bug description:
  1024-bit RSA was deprecated  years ago by NIST[1], Microsoft[2] and
  more recently by others[3].

  1024-bit signing keys are insufficient to guarantee the authenticity
  of software distributed from Launchpad.net including PPAs. There
  should be a mechanism to refuse signing keys below a minimum key
  length based on key type. 1024-bit signing keys should be deprecated
  and removed from Launchpad.net itself ASAP.  Future projects and PPAs
  should be disallowed from using 1024-bit signing keys.

  1. http://csrc.nist.gov/publications/nistpubs/800-131A/sp800-131A.pdf
  2. http://blogs.technet.com/b/pki/archive/2012/06/12/rsa-keys-under-1024-bits-are-blocked.aspx
  3. https://threatpost.com/mozilla-1024-bit-cert-deprecation-leaves-107000-sites-untrusted/108114

To manage notifications about this bug go to:
https://bugs.launchpad.net/launchpad/+bug/1461834/+subscriptions




More information about the foundations-bugs mailing list