[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#1099596: marked as done (bookworm-pu: package igtf-policy-bundle/1.133)



Your message dated Sat, 17 May 2025 09:37:57 +0000
with message-id <E1uGDzR-005KH3-Ks@coccia.debian.org>
and subject line Close 1099596
has caused the Debian Bug report #1099596,
regarding bookworm-pu: package igtf-policy-bundle/1.133
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact owner@bugs.debian.org
immediately.)


-- 
1099596: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1099596
Debian Bug Tracking System
Contact owner@bugs.debian.org with problems
--- Begin Message ---
Package: release.debian.org
Severity: normal
Tags: bookworm
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: igtf-policy-bundle@packages.debian.org
Control: affects -1 + src:igtf-policy-bundle

[ Reason ]

The GEANT TCS Generation 4 contract ended quite suddenly
with little warning from the vendor. The new Generation 5
was put together quite quickly, but the necessary CAs
and intermediate CAs from HARICA were only accredited with
version 1.133 of this bundle.

For a smooth transition for users, I propose to update
the package in stable (bookworm). 


[ Impact ]

Without this update, sites are unable to verify the identity of users
with certificates issued under the new contract, and vice versa users
are unable to assert the identity of servers with such certificates.

[ Tests ]

Since the package includes no code per se, testing consists of
installing on systems with (test or pre-production) services
and checking TLS interactions.

[ Risks ]

The risk is low, as the bundle is issued under the oversight
of the Interoperable Global Trust Federation (igtf.net) who
issue regular reviews to maintain the accredited status
of the associated CAs. The updates of the bundle are usually
of a nature that would not require immediate updates.

[ Checklist ]
  [*] *all* changes are documented in the d/changelog
  [*] I reviewed all changes and I approve them
  [*] attach debdiff against the package in (old)stable
  [*] the issue is verified as fixed in unstable

[ Changes ]

Changes to the bundle are documented in the upstream CHANGES
file.

--- End Message ---
--- Begin Message ---
Version: 12.11
This update has been released as part of 12.10. Thank you for your contribution.

--- End Message ---

Reply to: