Bug#1142014: Can no longer parse RSA private keys with additional text
gregor herrmann
gregoa at debian.org
Wed Jul 15 18:43:17 BST 2026
Control: severity -1 serious
Control: tag -1 + sid
On Mon, 13 Jul 2026 22:53:44 +0200, Christoph Biedl wrote:
>Package: libcrypt-openssl-rsa-perl
>Version: 0.41-1
>Severity: important
>Tags: upstream
>X-Debbugs-Cc: debian.axhn at manchmal.in-ulm.de
>
>Greetings,
>
>it seems Crypt::OpenSSL::RSA::new_private_key can no longer handle a
>private key in the PEM format with additional text - like it used to
>since possibly the last ten years.
Raising the severity to serious. I suspect (without having tested)
that this is also the reasons for the autopkgtest failures in
libjson-webtoken-perl and libnet-oauth-perl which we are seeing at
https://tracker.debian.org/pkg/libcrypt-openssl-rsa-perl (and which
keeps libcrypt-openssl-rsa-perl out of testing anyway).
Cheers,
gregor
--
.''`. https://info.comodo.priv.at -- Debian Developer https://www.debian.org
: :' : OpenPGP fingerprint D1E1 316E 93A7 60A8 104D 85FA BB3A 6801 8649 AA06
`. `' Member VIBE!AT & SPI Inc. -- Supporter Free Software Foundation Europe
`-
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 963 bytes
Desc: Digital Signature
URL: <http://alioth-lists.debian.net/pipermail/pkg-perl-maintainers/attachments/20260715/e7e7ba13/attachment.sig>
More information about the pkg-perl-maintainers
mailing list