tests: Use long key IDs
authorJustus Winter <justus@sequoia-pgp.org>
Fri, 16 Feb 2024 15:23:49 +0000 (16:23 +0100)
committerJustus Winter <justus@sequoia-pgp.org>
Fri, 16 Feb 2024 15:24:18 +0000 (16:24 +0100)
Short key IDs are not secure, and may be rejected by OpenPGP
implementations.  See https://evil32.com/

Signed-off-by: Justus Winter <justus@sequoia-pgp.org>
tests/test-gpg-verify-result.c

index e7171a8994a4b50cdd84159ff392d85904d41db5..5844c668d26c23a9e3fe46795fd26692a4c0b2ff 100644 (file)
@@ -183,7 +183,7 @@ test_signature_lookup (TestFixture *fixture, gconstpointer user_data)
   /* Lookup abbreviated key ID. */
   signature_index = 999999;
   signature_found
-      = ostree_gpg_verify_result_lookup (fixture->result, fingerprint + 32, &signature_index);
+      = ostree_gpg_verify_result_lookup (fixture->result, fingerprint + 24, &signature_index);
   g_assert_true (signature_found);
   g_assert_cmpint (signature_index, ==, expected_signature_index);