[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: libgcrypt's RSA-1024 and RSA-2048 broken



On Wed, Jul 05, 2017 at 06:42:12PM +0100, Howard Chu wrote:
I believe most deployments of GnuTLS now use nettle instead of libgcrypt. But if you're on an older Debian or Ubuntu, using their packaged OpenLDAP built with GnuTLS, you should check what version of GnuTLS and libgcrypt you're using.

For the record, "older" means Debian 7 (wheezy) or Ubuntu 14.04 (trusty). Debian 8 (jessie) and Ubuntu 16.04 (xenial) and later are using nettle.

Advisories and patches have been released for both wheezy and trusty,so if you're running either of those, please update.

https://lists.debian.org/debian-lts-announce/2017/07/msg00007.html
https://www.ubuntu.com/usn/usn-3347-1/