Bastien Lacoste
2017-10-10 22:51:26 UTC
Hi all,
Any plans to change the OpenPGP CA Cert Signing Authority key which is DSA 1024? It should have been considered as insecure since a long time ago for CA usage. The key was generated in 2003.
A bug was reported : http://bugs.cacert.org/view.php?id=1278
but no activity.
For instance, OpenKeychain application (Android) displays it as insecure.
As CACert only signs the users keys for a one-year period (which is very short), I don't think the change would break a long-term chain of trust.
OpenPGP WoT is a great feature of CACert but I think that with such security parameters it is not safe to use it and would better be removed if not updated.
CACert OpenPGP Key listed here: https://www.cacert.org/index.php?id=3
By the way, thanks to everybody who built and maintained this project across the years.
Regards.
Any plans to change the OpenPGP CA Cert Signing Authority key which is DSA 1024? It should have been considered as insecure since a long time ago for CA usage. The key was generated in 2003.
A bug was reported : http://bugs.cacert.org/view.php?id=1278
but no activity.
For instance, OpenKeychain application (Android) displays it as insecure.
As CACert only signs the users keys for a one-year period (which is very short), I don't think the change would break a long-term chain of trust.
OpenPGP WoT is a great feature of CACert but I think that with such security parameters it is not safe to use it and would better be removed if not updated.
CACert OpenPGP Key listed here: https://www.cacert.org/index.php?id=3
By the way, thanks to everybody who built and maintained this project across the years.
Regards.
--
Bastien
Bastien