Bug#737921: [TLS1.2] gnutls only likes SHA1 and SHA256 certificates

Andreas Metzler ametzler at bebt.de
Fri Feb 7 18:02:47 UTC 2014


On 2014-02-07 Jan Nordholz <jnordholz at sec.t-labs.tu-berlin.de> wrote:
[...] 
>> Have you tested this against libgnutls28?  GnuTLS 3.2.10-2 is the latest
>> version in jessie and sid, and 3.2.8.1-2~bpo70+1 is in wheezy-backports.
>>  I believe you'll find it resolved in this version.

> well, I tested against gnutls-serv, which indeed seems to work (and that
> one's linked to gnutls28).

Thank you for testing and for the detailed bug report.

> However my original problem occurred with exim,
> and I was reluctant to recompile those packages as I don't know how much of
> the gnutls API has changed and would need fixing in exim.

Recent exim stable releases should work perfectly fine against gnutls
v3.

> Good to know that the library migration will eventually take care of this.

Exim will probably switch after the next gmp version is released and
uploaded to Debian.

cu Andreas

-- 
`What a good friend you are to him, Dr. Maturin. His other friends are
so grateful to you.'
`I sew his ears on from time to time, sure'



More information about the Pkg-gnutls-maint mailing list