/srv/irclogs.ubuntu.com/2019/11/09/#ubuntustudio.txt

=== oerheks1 is now known as oerheks
sakrecoerre: gpg i seem to have som  stale lockfile preventing gpg from being invoked by anything..13:41
sakrecoerhttps://tech.michaelaltfield.net/2019/07/14/mitigating-poisoned-pgp-certificates/ i think it is this...13:46
sakrecoerarf...13:46
sakrecoerseems to be keyid:79BE3E4300411886 Linus Torvald :(15:18
sakrecoertakes forever to delete it also...15:19
tomreynsakrecoer: https://bugs.launchpad.net/ubuntu/+source/gnupg2/+bug/184405918:33
ubottuLaunchpad bug 1844059 in gnupg2 (Ubuntu) "Please apply mitigations for CVE-2019-13050" [Undecided,Confirmed]18:33
tomreyn"the specific updates to address this are not complete so" ... the ubuntu packages remain unfixed for now.18:35
tomreynand then there is https://bugs.launchpad.net/ubuntu/+source/gnupg2/+bug/1844055 in Ubuntu which is why you cannot use the only 'safe' keyserver there is now18:37
ubottuLaunchpad bug 1844055 in gnupg2 (Ubuntu) "Importing public key from keys.openpgp.org fails with "no user ID" " [Undecided,Confirmed]18:37
sakrecoer[m]Thanks, Tomreyn! :)18:43
sakrecoer[m]I suppose I will just have to unsubscribe until the fix is out.18:47
tomreynsakrecoer[m]: to unsubscribe from what?18:49
sakrecoerthe keyservers18:49
tomreynoh, right, no longer using keyservers or importing keys or signatures will prevent your keyring from becoming infected.18:54
tomreynit will, of course, also make it impossible to use gpg in a safe manner where you'd need to regularly update all the keys in your public keyring to not miss out on revocations and to get copies of keys whose expiry was extended.18:55
sakrecoeryes, i imagine this is a pretty serious issue for quirte a few production environements18:56
sakrecoerbut the few people and projects where i use gpg are small enough to be able to verify eachother without server18:57
sakrecoer^ not sure why i had torvalds key though lol :) i've probably sent fanmail haha!19:02
tomreynmaybe you tried to verify the authenticity of his git commits19:08
studiobot<designbybeck> If I install 19.04, I can update to 19.10 via software update?21:12
studiobot<designbybeck> Studio21:12
sakrecoer@designbybeck yes22:02

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!