Gentoo Archives: gentoo-dev

From: Kumba <kumba@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: rejecting unsigned commits
Date: Mon, 28 Mar 2011 02:49:20
Message-Id: 4D8FF6D0.5050008@gentoo.org
In Reply to: [gentoo-dev] Re: rejecting unsigned commits by Mike Frysinger
1 On 03/25/2011 14:30, Mike Frysinger wrote:
2 > for people who dont have a key yet:
3 > http://www.gentoo.org/proj/en/devrel/handbook/handbook.xml?part=2&chap=6
4 >
5 > for people interested, bugs to get repoman extended to make the gpg
6 > process smoother:
7 > http://bugs.gentoo.org/360459
8 > http://bugs.gentoo.org/360461
9 > -mike
10
11 So I'm one of those that became a dev before GPG keys were required (I think).
12 at some point, though, I created one on an old machine I had, which was my
13 primary dev machine at the time. But the machine died, and I never got the key
14 off (I never used it). The drive is still good, but it's lost in a pile of
15 boxes somewhere.
16
17 Rather than mounting an expedition to find it, it's probably easier for me to
18 generate a new key, but this raises a few questions, because I'm a complete
19 idiot when it comes to GPG/PGP stuff:
20
21 1. How can I revoke the old key? The revocation cert is probably on the same drive.
22
23 2. The dev manual states not to create a key with an expiration longer than 6
24 months. How does this impact items signed already if the key has to be replaced
25 bi-annually? (I suspect I'm not fully grasping something here w/r to GPG).
26
27 3. If I'm going to start using GPG, I might as well use it for a few things.
28 Anyone got pointers for cross-platform use, i.e., Thunderbird on Windows?
29
30 --
31 Joshua Kinard
32 Gentoo/MIPS
33 kumba@g.o
34
35 "The past tempts us, the present confuses us, the future frightens us. And our
36 lives slip away, moment by moment, lost in that vast, terrible in-between."
37
38 --Emperor Turhan, Centauri Republic

Replies