-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 13 Jun 2024 19:19:07 +0200 Source: lacme Binary: lacme lacme-accountd Architecture: all Version: 0.8.0-2+deb11u2 Distribution: bullseye Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Guilhem Moulin Description: lacme - ACME client written with process isolation and minimal privileges lacme-accountd - lacme account key manager Closes: 1072847 Changes: lacme (0.8.0-2+deb11u2) bullseye; urgency=medium . * Backport upstream patches to fix post-issuance validation logic. We avoid pinning the intermediate certificates in the bundle and instead validate the leaf certificate with intermediates supplied during issuance as untrusted (used for chain building only). Only the root certificates are used as trust anchor. Not pinning intermediate certificates is in line with Let's Encrypt's latest recommendations. Closes: #1072847 * Adjust test suite against current Let's Encrypt staging environment. Checksums-Sha1: abe782c3948adb240338749649a0739f45fb527e 17524 lacme-accountd_0.8.0-2+deb11u2_all.deb d87f5bbd1265fbbe9ccae5a1dbd1a94ebb232dda 6285 lacme_0.8.0-2+deb11u2_all-buildd.buildinfo be9966430184b3355448bac1f10dac8498ca61b3 47736 lacme_0.8.0-2+deb11u2_all.deb Checksums-Sha256: a3416183880c98df2bf75a882dbcb2b211217df9a382a1204b29b1bfce781a16 17524 lacme-accountd_0.8.0-2+deb11u2_all.deb 06e37d779ff54d61b18400e22d78242d5be014e6e99aa6cf25bf02425f01de4b 6285 lacme_0.8.0-2+deb11u2_all-buildd.buildinfo 1e72b78160d30d05e0081049c56b996aad696c4a8e59d43d7f81fd82a469dbf8 47736 lacme_0.8.0-2+deb11u2_all.deb Files: f980f0c987f9834bb85080702bac73f7 17524 utils optional lacme-accountd_0.8.0-2+deb11u2_all.deb b8c75bde7b2fe39a5ce7ef9a5638b25b 6285 utils optional lacme_0.8.0-2+deb11u2_all-buildd.buildinfo f15ce2d320c7594052a33f935a2bea85 47736 utils optional lacme_0.8.0-2+deb11u2_all.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEgdRoRGwEM09wlaMzOni7ZmUpKEcFAmZwa84ACgkQOni7ZmUp KEfgYQ/+LrhenaD6p5gAvzP3Rheez9+1AsdVBkbfQfRvJBcv+ZzYJQ7uboiPuWGA WJZW9cHVjQCZ+8ktetQyn3H0sve6EPj2KLFKDRFCMBGSKbTdQio5jfa9FUuG+C/g qWOy7RW9EHiskwkYB1DYAXf5nw6zq/5fnFa+KHUwOaqQcbCoiw47I69Ap1AZpX8t tg7W5KXoBIP/xvADVdDyVzNoVZ8GRQmtLfzNQy3D2slXFt3+Oz3mJkaknjTrbqoN vYMuSAhaXhLGTpE626mA3uPGhR70hCbJf/xN7VIDpk17WnivnjTlWgNfw5MuWlj8 3XN3yihTFMm0Xc0e4KeMSJZ/ISF5+1Q4O/IMH1SPBq5x+zInOXhyhXgHy6sXFwop wmkxeLG2BGxwzrhVq4u7gCyY3KUoTjSMvI1lHe8ItF8S9ioy0c7N77zhe+I/VONC fGocIcAPWTH1cgwOb2K8BTBGVedjH8+OflIO/RLBRIlPn9GyisiSyYtiBdVdfkqP Evi6BVEO6oM7O0T636SJHqQ06nhlZORC7SyKSt7JlXZIBmYRJ2vDWcoyb9VfUJZk 2N1MI+U0j4oAus5U8gpnYoWMFOctYRr9ys20zI9iTUfwSiEh6yYMEDpGvIGvkXfg WK9PnbWNZgbW3uTHJx0FzwnQ1QLnPXIAhF2URHQLBRU/Ad+Jwb4= =dUXT -----END PGP SIGNATURE-----