- Package:
- lists.debian.org
- Source:
- lists.debian.org
- Submitter:
- Nico Golde
- Date:
- 2025-02-08 02:39:05 UTC
- Severity:
- wishlist
- Tags:
Package: lists.debian.org Severity: wishlist Hi, it is a known issue that sometimes DSA ids are reused on debian-security-announce due to human race conditions or not paying enough attention. Also this was recently discussed again on the security list[0]. There is already some sanity checking on the body of the DSA mail and a signature check as far as I know. Is it feasible to reject mails as well if they use a previously allocated DSA id? I would imagine this may be problematic as all current checks can be performed solely by looking at the incoming email instead of looking at the archive. Nonetheless, as there have been more than 20 reuses in the last years, I thought I'd ask if this is possible in the first place. [0] http://lists.debian.org/debian-security/2012/09/msg00016.html Kind regards Nico
Hi,
This ticket is three years old. Is it still valid, or did you solve it
somewhere else?
Sure it is possible to build such a filter, but I wonder if the
announcement-list is a good place to implement it.
Yours,
Cord, Debian Listmaster of the day
Final Notice. You are among the beneficiaries of 2024/2025 grant for all scam victims and relatives reconfirm your email if active for more details Thank You. Regards Mr. Rowland Cole ( Financial Crimes Enforcement Network)