New PPA URL for Ubuntu users

Olly Betts olly at survex.com
Fri Jul 5 02:56:24 BST 2019


If you're installing Survex versions for Ubuntu via the PPA, please
update to this new PPA:

https://launchpad.net/~survex-devs/+archive/ubuntu/ppa

You should also remove the existing PPA when you do.  You can remove the
old and then add the new with these commands:

sudo add-apt-repository --remove ppa:survex-developers/ppa
sudo add-apt-repository ppa:survex-devs/ppa
sudo apt-get update

Both the old and new PPA are maintained by teams consisting of Wookey
and me.  Currently they contain exactly the same packages (which I
updated to 1.2.40 a few hours ago), but I'm not intending to update the
old PPA further.  My plan is to remove it completely once people have
had a chance to upgrade - then at least people who don't see this
message will get an error when they try to update.

The reason for this change is that Launchpad used to create 1024 bit
keys to sign PPAs.  These are not secure now, but there's unfortunately
currently no way to make an existing PPA use a new signing key, and
even more unfortunately there's no sign of a fix 5 years on:

https://bugs.launchpad.net/launchpad/+bug/1331914

Each user and team has a single PPA signing key, which is why we've
switched from team "survex-developers" to "survex-devs" - just
creating a new PPA under survex-developers would reuse the insecure 1024
bit key:

https://bugs.launchpad.net/launchpad/+bug/1700167

Cheers,
    Olly
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.survex.com/pipermail/survex/attachments/20190705/331fdedd/attachment.sig>


More information about the Survex mailing list