-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Fri, 14 Jun 2024 01:20:13 +0200 Source: lacme Architecture: source Version: 0.8.2-1+deb12u1 Distribution: bookworm Urgency: medium Maintainer: Guilhem Moulin Changed-By: Guilhem Moulin Closes: 1072847 Changes: lacme (0.8.2-1+deb12u1) bookworm; urgency=medium . * Backport upstream patches to fix post-issuance validation logic. We avoid pinning the intermediate certificates in the bundle and instead validate the leaf certificate with intermediates supplied during issuance as untrusted (used for chain building only). Only the root certificates are used as trust anchor. Not pinning intermediate certificates is in line with Let's Encrypt's latest recommendations. Closes: #1072847 * Adjust test suite against current Let's Encrypt staging environment. * d/gbp.conf: Set 'debian-branch = debian/bookworm'. Checksums-Sha1: 051e827418d8770dd035dec70908a8c20f8442ec 1924 lacme_0.8.2-1+deb12u1.dsc 6dd086cc20310c19d03d6d5e7cdb6a6ec97b93bd 20416 lacme_0.8.2-1+deb12u1.debian.tar.xz fbc6baf0c58dc3d3b35f8b7d327f609d7a2b74c7 6629 lacme_0.8.2-1+deb12u1_amd64.buildinfo Checksums-Sha256: 7ea7374110fa43c0e2b3244cbe5367a24970b86dc776a0e2127a6de8c751b93c 1924 lacme_0.8.2-1+deb12u1.dsc 8deb6fd49826fb1f5a22064501625036f5b1ccf02d30ef49c15ad77e9109c59b 20416 lacme_0.8.2-1+deb12u1.debian.tar.xz f44f990308e9c4a02b1f697912802878ba067cbd78252f65113a09a4ad7dc7aa 6629 lacme_0.8.2-1+deb12u1_amd64.buildinfo Files: b0e13e4cd251c3cd42e7224866f2ac03 1924 utils optional lacme_0.8.2-1+deb12u1.dsc 843e36466c83ebae55d92dac6a74df3c 20416 utils optional lacme_0.8.2-1+deb12u1.debian.tar.xz 6baa3274b0144a91dd07e57de5b32821 6629 utils optional lacme_0.8.2-1+deb12u1_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEERpy6p3b9sfzUdbME05pJnDwhpVIFAmZuEZMACgkQ05pJnDwh pVJ40Q/+IIcWUd9+C3WWyVz2ED/DSJraTZhSHf20Z37wxki4LoERdw/2cfJiHcSc mLPGutrvmDQ6mh4hM0j7o7ObD8jX7JBM5LOhrc9/D3QvQo06uL94grxl2zzYrlPw 8aG6zf8Wp+QGCpBBvo7bq7P4ToEBsyJhQ6Dwqo6p7E8YHrRECUQ/bAiDE62ApTAI JYl406u6H4o1jJXhVnnAyuY0o+txr89pssmtx/k2scgQPBYM/Zyr5HmiV0Dtr4kS YfyM16x5U1bgJ6Pf0HMPr3x14jDfQl8rmE9x9yjrMQCOCyRHrVM6V3Adoup/IuCK 5He3ng+cpLsPAKdci3hAdryzmstbqlxdvaMGtvH0cbnekOJyHqNOO6zl8b5m6NrQ Vm6Wq9FhmPtqxSsnVZueyzG8bvBYPTap+Wf6R4sn2bt/gxIyWBaglyXr1FOBcOSW CVW0jZkQBFxM4eWcjARiqoTQSh7lkdT9LreDox14RuJzcLQ6LpJwZwfvwKCNXdyc bEFd6fapWZYKARdzFNo7spcrYdQUQRerW2430UI5fncUOhpIKuTMXyUxjXbdSHWQ t6gqfJv0qTzBDQJH2BMm+QLTvJ/vshoc24bwlVVhehMF5zDr3iQXF8aPbKgvD3BY w7lGy6zlodXVVoHr5SUIgtak7UT8Nyez/FslHUd08fbIGyejYLY= =CeM8 -----END PGP SIGNATURE-----