Comment 60 for bug 305264

Steve Beattie (sbeattie) wrote :

For the gnutls/hardy SRU:

I have reproduced the acceptance of rsa/md2 v1 certificates by the version of gnutls13 in hardy-updates, 2.0.4-1ubuntu2.3, and can confirm that the version of gnutls13 in hardy-proposed does not accept rsa/md2 certificates. I have added a testcase for this situation in the gnutls test script in the lp:qa-regression-testing bzr tree. The package passes the rest of the regression test in the testsuite, with the exception of known bug 292604 which is not a regression (2.0.4-1ubuntu2.3 also fails this test and it looks like it won't get fixed in hardy).