-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 13 Jun 2024 19:19:07 +0200 Source: lacme Architecture: source Version: 0.8.0-2+deb11u2 Distribution: bullseye Urgency: medium Maintainer: Guilhem Moulin <guilhem@debian.org> Changed-By: Guilhem Moulin <guilhem@debian.org> Closes: 1072847 Changes: lacme (0.8.0-2+deb11u2) bullseye; urgency=medium . * Backport upstream patches to fix post-issuance validation logic. We avoid pinning the intermediate certificates in the bundle and instead validate the leaf certificate with intermediates supplied during issuance as untrusted (used for chain building only). Only the root certificates are used as trust anchor. Not pinning intermediate certificates is in line with Let's Encrypt's latest recommendations. Closes: #1072847 * Adjust test suite against current Let's Encrypt staging environment. Checksums-Sha1: 0d271783d6a808bc85ce44f7883087b348bad183 1924 lacme_0.8.0-2+deb11u2.dsc 850c8a5ab446ef6a0a26b1682d27d2041a4d5e49 20848 lacme_0.8.0-2+deb11u2.debian.tar.xz 55daa909dc6ea4698a6b5b027e95ff188ec2994e 6546 lacme_0.8.0-2+deb11u2_amd64.buildinfo Checksums-Sha256: 46db26d15c7717c96e26cf10e22df41d8dda6affbf2bcb4eb3bbd2b6ec0b5b44 1924 lacme_0.8.0-2+deb11u2.dsc bb2acb43e92e0cd48712644535cfceb3cbbbc86c412e30f614b9b719d42a1f2c 20848 lacme_0.8.0-2+deb11u2.debian.tar.xz fd63350f932bd59c155ba0590a1ee4b9b2c9d2586ef4710d4e23f8b61eecb150 6546 lacme_0.8.0-2+deb11u2_amd64.buildinfo Files: d5df633a3c5af23efe9d8448f7cc1ac2 1924 utils optional lacme_0.8.0-2+deb11u2.dsc ae2a34e62e9ef21a3e42f5ec7791968d 20848 utils optional lacme_0.8.0-2+deb11u2.debian.tar.xz 3805bc773a9fa600769b9fdacc6af2a7 6546 utils optional lacme_0.8.0-2+deb11u2_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmZt608ACgkQ05pJnDwh pVLh2RAAk7HR8pPXDKJ80pZSYAxT8LeMqmCk741C8re/xinZ5iqLpB9kDH/Wd/Pp 0TODeVlqxV98aaw2FnMs4WaTLy3wL5wKc3FXHsH+J+HFDia56M9ns12gNS66AlFj +VWm1m91OCMd9cSG/AAkIoGMPZQXx+SY4YAji0e58wERg5WGrbZfG3EZM3mixFyb 12dWL0HfqN2GNXGIGwu5WfW1KonN6o4qdmQKVOGMWP945vhtihmvuID6p9BnKNho 0DivbHSjbzXLOMLvf1sJAgm4WDfRknZfxtYQPQNU3KpIDKmXZE28WSN5/XUmDPZ6 WF6uqjotNGqa7kTQCD+8vqTOWqX+UNLzgBziz++8IBD9dolBQzrkwwkfjB6jaTdW HYqZH4Vxh9DCoG5xS4jytNwn+LVf1+/FI1XoRNuEh7WZRZcQ0wTx1LulTJW/oVPp 9wpPgxSJxrBpCOcyn4iif4bFzOvv9AnIOIZ0fT/dE+ihKbN/RzZtmKlbsXkVQpcS TzT50rBmeCqlHRwDW33IduaOaLpxRas1YBwbMxTqrRfj0qjzWO475iGw23yKJUU3 /Fb/5X5UAMkZKrZaVp4QYSw1sn3FEO/22aYxBtS0K131aUmI3OU5sME2kPKz5QL+ a7zxpoiTga/NbALUFi0CCY/R6JoHAyK6ADmwWhFQOCVe3nFd/Hw= =f9JI -----END PGP SIGNATURE-----