This bug was fixed in the package ubuntu-keyring - 2016.10.27 --------------- ubuntu-keyring (2016.10.27) zesty; urgency=medium
* Drop 1024D key fragments. LP: #1363482 * Remove 1024D keys from ubuntu-archive-keyring. * Add 1024D keys to ubuntu-archive-removed-keys.gpg. * Remove the md5sums.asc file, no longer valid. * Regenerate SHA512SUMS.txt.asc file. -- Dimitri John Ledkov <x...@ubuntu.com> Thu, 27 Oct 2016 15:31:35 +0100 ** Changed in: ubuntu-keyring (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to ubuntu-keyring in Ubuntu. https://bugs.launchpad.net/bugs/1363482 Title: ubuntu-keyring includes 1024D keys Status in Ubuntu CD Images: Fix Released Status in ubuntu-keyring package in Ubuntu: Fix Released Bug description: ubuntu-keyring as shipped in trusty contains old 1024D keys dating back to 2004 which are still being trusted for the main archive: % gpg /usr/share/keyrings/ubuntu-archive-keyring.gpg | grep 1024D pub 1024D/437D05B5 2004-09-12 Ubuntu Archive Automatic Signing Key <ftpmas...@ubuntu.com> pub 1024D/FBB75451 2004-12-30 Ubuntu CD Image Automatic Signing Key <cdim...@ubuntu.com> Given that newer 4096R keys are present and have been in precise (through -updates) and trusty, it seems to be about time to drop the older keys. (In the hope that apt does not chose on signatures it cannot verify, otherwise the publisher would need to stop signing with the old key as well.) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu-cdimage/+bug/1363482/+subscriptions -- Mailing list: https://launchpad.net/~touch-packages Post to : touch-packages@lists.launchpad.net Unsubscribe : https://launchpad.net/~touch-packages More help : https://help.launchpad.net/ListHelp