tags 555668 + help thanks On Sat, Jan 23, 2010 at 04:17:19PM +0100, Alexander Reichle-Schmehl wrote: > Hi! > > * Andrew Pollock <apoll...@debian.org> [091115 16:47] > > > What's the status of elfsign? It doesn't look like you've made a new release > > in nearly 5 years. Are you planning on addressing the deficiencies of MD5 by > > releasing a new version with SHA1 support? > > Any news regarding this bug? Maybe it would be a good idea to remove > the package from testing as there is no immediate fix possible. >
No, I haven't heard anything back. I imagine (although I'm incapable) that it'd be relatively easy to switch to SHA1, given it's using OpenSSL to do the MD5 calculation. The popcon numbers for elfsign are pretty low, so it's probably not worth the effort. If no one comes out of the woodwork with a patch to switch it to generate SHA1 signatures, I'll request its removal altogether.
signature.asc
Description: Digital signature