Small update on the upstream issue I opened:
there is no way for GnuPG to support keys larger than 4k, although it's a 
one-line patch. Please read the explanation in the link above.
I see two possible outcomes of this:
1) Just add a tiny patch which increase the secure memory to 128k, keep the 16k 
keys working.
2) Don't do anything, piss off some people, make upstream happy.
What do you think?
By the way, the best way to do 1) would be to add the patch directly into 
Debian, so that Ubuntu receive it automatically instead of patching it in 
Ubuntu and leaving Debian uncovered.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/1371766

Title:
  Latest CVE-2014-5270 patch breaks ElGamal keys of 16k

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/gnupg/+bug/1371766/+subscriptions

-- 
ubuntu-bugs mailing list
ubuntu-bugs@lists.ubuntu.com
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to