Package: dns-root-data Version: 2018091102 Severity: serious Control: found -1 2014060201+2 2017072601~deb8u1 2017072601~deb8u2 2017072601~deb9u1 2017072601~deb9u1 Control: fixed -1 2019031302
The versions of dns-root-data marked as "found" above ship a hash for a root zone key that was retired earlier this month. I'm marking this as serious because it is the equivalent of shipping a certificate for a no-longer valid CA in ca-certificates. That key is no longer being used to sign anything that i have been aware of, and hopefully the private elements of it have been destroyed, but we shouldn't ship it any longer. Those of us on the dns team should have gotten this done earlier, but we all appear to have just missed it -- sorry about that! --dkg
signature.asc
Description: PGP signature