SRU request. Evolution on 10.04 LTS only supports SHA1 for the next 3 years. SHA2 would be nice.

Bug #635937 reported by Nathaniel Homier
6
This bug affects 1 person
Affects Status Importance Assigned to Milestone
evolution (Ubuntu)
Fix Released
Low
Unassigned

Bug Description

Binary package hint: evolution

In the title I mean SRU not SRA.

For the next 3 years Ubuntu 10.04 LTS will only be able to support the SHA1 cipher. Thats 3 long years of using a broken and useless cipher. What are the options for those who require an LTS, there are no options. Upgrading to a non-LTS release defeats the purpose of using an LTS. I am very aware that hell would freeze over before this SRU request would be accepted. It's too bad that the SHA1 patch came too late for 10.04. I don't how easy an attack against SHA1 would be, would it be acceptable to wait 3 years if attacks against SHA1 are still hard enough as to not worry about it?

If SHA1 attacks are trivial, then would Ubuntu please consider an SRU.

ProblemType: Bug
DistroRelease: Ubuntu 10.04
Package: evolution 2.28.3-0ubuntu10
ProcVersionSignature: Ubuntu 2.6.32-24.41-generic 2.6.32.15+drm33.5
Uname: Linux 2.6.32-24-generic x86_64
Architecture: amd64
CheckboxSubmission: f28209556208badd1b7f1481d04b096c
CheckboxSystem: 6ce041aeed0a2c17b3343b66d157175d
Date: Sat Sep 11 12:12:56 2010
ExecutablePath: /usr/bin/evolution
InstallationMedia: Ubuntu 10.04 LTS "Lucid Lynx" - Release amd64 (20100427.1)
ProcEnviron:
 SHELL=/bin/bash
 LANG=en_US.utf8
SourcePackage: evolution

Revision history for this message
Nathaniel Homier (mechamechanism) wrote :
Revision history for this message
Nathaniel Homier (mechamechanism) wrote :

Ah crap, in the title I mean SRU not SRA.

description: updated
summary: - SRA request. Evolution on 10.04 LTS only supports SHA1 for the next 3
+ SRU request. Evolution on 10.04 LTS only supports SHA1 for the next 3
years. SHA2 would be nice.
Revision history for this message
Pedro Villavicencio (pedro) wrote :

Thanks for the report, are you asking for an SRU of the whole new package? is there any commit pointing to the change of SHA2 ? you can read more about SRU here https://wiki.ubuntu.com/StableReleaseUpdates

Changed in evolution (Ubuntu):
importance: Undecided → Low
status: New → Incomplete
Revision history for this message
Nathaniel Homier (mechamechanism) wrote :

This is my first time asking for an SRU and I don't know if the whole package needs to be updated or the patch from here is all thats needed.
https://bugzilla.gnome.org/show_bug.cgi?id=304415

There is this bug report comment from the gnome bug report though, located second to last at the bottom of the comments, it don't look to good though.

"Matthew Barnes [Evolution-Data-Server developer] 2010-06-20 12:10:18 UTC

These patches cannot go into 2.30 because they break API in both libcamel and
libedataserver"

Revision history for this message
Pedro Villavicencio (pedro) wrote :

we cannot SRU it if it breaks API, the bug is being tracked on bug 381290, marking this as a dup.

Revision history for this message
Launchpad Janitor (janitor) wrote :
Download full text (3.3 KiB)

This bug was fixed in the package evolution - 2.32.0-0ubuntu1

---------------
evolution (2.32.0-0ubuntu1) natty; urgency=low

  * Upstream release 2.32.0
    - Empty reply quotation for HTML messages (LP: #630566, #659513)
    - "Encrypt to self" by default on newly created mail (LP: #326979)
    - Backup settings uses unhelpful yes/no dialog (LP: #572985)
    - Can't drag email addresses to Contact List Editor (LP: #282530)
    - Contact List Editor calls wrong EDestination function (LP: #229187)
    - Allow normal, non-vFolder, Trash and Junk folder (LP: #13983, #64762)
      (LP: #135485, #280325, #365270)
    - Allow change of signature hash algorithm (LP: #381290, #381295, #635937)
    - Dialog for mark-all-read always mentions subfolders (LP: #608462)
    - Evolution allows deletion of default views (LP: #498040)
    - Add checks for event->comp_data != NULL (LP: #466415, #546952)
    - Properly free unused message infos periodically (LP: #507972)
    - Calendar compressed weekend print improvement (LP: #88926)
    - Attachment bar causes drawing issues in RTL locales (LP: #545459)
    - [PST] evolution crashed with SIGSEGV (LP: #471852)
    - Swap "Save" and "Save as Draft" accelerators in composer (LP: #424416)
    - Evolution hangs when formatting message - fixes part of it (LP: #175233)
      (LP: #327775)
    - Calendar Day view All Day events print improvements (LP: #88926)
    - Crash on a changed mail filter action removal (LP: #452921)
    - Do not block UI with publish-calendar messages (LP: #594289)
    - Duplicate mnemonic in meeting window (LP: #499418)
    - Hide variable used only with HAVE_LIBNOTIFY (LP: #594289)
  * debian/patches/02_fix_missing_include_for_composer.patch: refreshed
  * debian/patches/03_lpi.patch: refreshed
  * debian/patches/12_remove_not_recommended_for_top_posting.patch: updated.
    The "recommended" text is now a separate label, so removing that object
    entirely.
  * debian/patches/89_express.patch: dropped, applied upstream.
  * debian/patches/90_disable_deprecation_warning.patch: refreshed
  * debian/patches/91_add_u1_email_translations.patch: refreshed
  * debian/patches/91_git_additional_chinese_translations.patch: dropped
  * debian/patches/91_git_fix_e_shell_ref_counting.patch: dropped
  * debian/patches/91_git_fix_untranslatable_list_editor.patch: dropped
  * debian/patches/92_git_fix_proxy_ignore_hosts.patch: dropped
  * debian/patches/92_git_only_hide_signature_on_express.patch: dropped
  * debian/control: update Depends/Build-Depends of all e-d-s parts to 2.32
  * debian/control: libgdata was split out of e-d-s, so updating Build-Depends
    to use the external libgdata library.
  * debian/control: bump libgtkhtml Build-Depends to >= 1:3.31.90
  * debian/*.install: install plugins to /usr/lib/evolution/2.32, not 2.30
  * debian/rules: remove --disable-pilot-conduits, it's not a valid configure
    switch anymore
  * debian/evolution-dev.install: no longer install libeconduit.so
  * debian/control: update Build-Depends with new and updated requirements for
    2.32: adding libpango1.0-dev, libgail-dev, updating libglib2.0-dev,
    libgtk2.0-dev, gnome-icon-theme and libunique-dev
  *...

Read more...

Changed in evolution (Ubuntu):
status: Incomplete → Fix Released
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.