-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 14 Jun 2024 01:20:13 +0200 Source: lacme Binary: lacme lacme-accountd Architecture: all Version: 0.8.2-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Guilhem Moulin Description: lacme - ACME client written with process isolation and minimal privileges lacme-accountd - lacme account key manager Closes: 1072847 Changes: lacme (0.8.2-1+deb12u1) bookworm; urgency=medium . * Backport upstream patches to fix post-issuance validation logic. We avoid pinning the intermediate certificates in the bundle and instead validate the leaf certificate with intermediates supplied during issuance as untrusted (used for chain building only). Only the root certificates are used as trust anchor. Not pinning intermediate certificates is in line with Let's Encrypt's latest recommendations. Closes: #1072847 * Adjust test suite against current Let's Encrypt staging environment. * d/gbp.conf: Set 'debian-branch = debian/bookworm'. Checksums-Sha1: 926d1b59e5888834313b2285591e0ec78d656506 18828 lacme-accountd_0.8.2-1+deb12u1_all.deb e878b9836e252821084333c09db21ced4bf48720 6251 lacme_0.8.2-1+deb12u1_all-buildd.buildinfo 1c5b8f28af58e0e30b84c9543ddb25cb1ba9a51f 49076 lacme_0.8.2-1+deb12u1_all.deb Checksums-Sha256: 519cf996eff6c7f64429558bbacb29b4218593adee5ecd0b0c8fbb814f54f555 18828 lacme-accountd_0.8.2-1+deb12u1_all.deb 129fd95fec1d26cc8f852cf7e5ade963e1f6d637054f888a7f04fbac3f8b06a5 6251 lacme_0.8.2-1+deb12u1_all-buildd.buildinfo 264f41b84e4c23af85c6aaa4c1e7be51a1b24de4aa675b762bbcc9a7557ea28b 49076 lacme_0.8.2-1+deb12u1_all.deb Files: 76d433204eb1fb9f6c67f19bd4f1e4d6 18828 utils optional lacme-accountd_0.8.2-1+deb12u1_all.deb 4f294963f72b66f30d932019230f10da 6251 utils optional lacme_0.8.2-1+deb12u1_all-buildd.buildinfo e5aece4aff0f4f7bc0cb47977c634277 49076 utils optional lacme_0.8.2-1+deb12u1_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEQsM0t1ygJv2xcx3e4cagXJhOTXsFAmZvU4EACgkQ4cagXJhO TXv0IhAAhV52P61UidxI3N1Sn/k3s17mNGiqcIVe6pFbMFnsSa3l/gDl26KRWPs8 dc9KL7ia8mCqVyzK10e/N15jyQA+B/1pkd9xHrnku+p89qmVL0HnWIu+IlGOpqrp 5lgTZx8QFF7EmLEJHafaj8P0HjSJln+vTRUibCA64x65E2QRdl+wx64tVX8XpY8T 1Tj1fzoT7vGYGio4UTUhl1x3MqfqSruazIYKeny5vn/noktS4/G8KsXttv7bQXWI 01spJ9UKx4KxBOJKxykFh0uFQ5UqoK35y5gWgznP9O4FLGJBvHfvXoL/HwR0/WRS WtaQ6rFu+QTbRwescOrHgdRZqG4Yeqlknvn5JUv9ELX5UpfoLlA0Ydo/DV4pH1ZV BT6PLZFornuQDmk7hrxsHOmol0aNeZ/HC0Bo1jZdqIreontx/1JS30zwuwECQOza 2p6Vf0T4TL9bJhVXMAGdesyzj5+zw2OdIHOzZNL/0lBMpPyrhpO2nkKO/8FDdAhB d47kNHpXs1peKZ3qqCxSGI3OjGeEJurQ2fs8ETHAwP6JBswTAwz2sP4j0XvwcuZR QMLqlnihwR5Naj3zMHkBaQe78JSzYGrZ3WTLNGOvibmy0hhi9g2rBP7hXDRaXkQH lW3XheDMiKBMsi8s1aaOvMpgxZqIKNLWnkXXQQsdJTiFBI1IFNI= =/4Nv -----END PGP SIGNATURE-----