newrelic / newrelic-php-agent

The New Relic PHP Agent
https://opensource.newrelic.com/projects/newrelic/newrelic-php-agent
Apache License 2.0
119 stars 62 forks source link

Signature by key B60A3EC9BC013B9C23790EC8B31B29E5548C16BF uses weak algorithm (dsa1024) #973

Open tbjornli opened 3 days ago

tbjornli commented 3 days ago

I'm sorry for filing this as an issue on the newrelic-php-agent repository, but I could not not find a way to report it via the New Relic website.

The New Relic GPG key is using a weak algorithm and Debian based systems like Ubuntu 24.04 are now displaying a warning when using apt.

W: http://apt.newrelic.com/debian/dists/newrelic/Release.gpg: Signature by key 60A3EC9BC013B9C23790EC8B31B29E5548C16BF uses weak algorithm (dsa1024)

I looked around and I was unable to find another, stronger, gpg key.

My hopes are that someone from the New Relic team sees this and can forward the information to the proper department or someone with access to the support system can file a ticket.

workato-integration[bot] commented 3 days ago

https://new-relic.atlassian.net/browse/NR-325850