1 |
commit: 7d72d5875be3df130ae3728cf078a8f0434d904b |
2 |
Author: Michał Górny <mgorny <AT> gentoo <DOT> org> |
3 |
AuthorDate: Sun Jul 8 18:33:20 2018 +0000 |
4 |
Commit: Michał Górny <mgorny <AT> gentoo <DOT> org> |
5 |
CommitDate: Sun Jul 29 20:07:27 2018 +0000 |
6 |
URL: https://gitweb.gentoo.org/data/glep.git/commit/?id=7d72d587 |
7 |
|
8 |
glep-0063: Extend SHA-2 requirement to self-signatures on subkeys |
9 |
|
10 |
glep-0063.rst | 5 ++++- |
11 |
1 file changed, 4 insertions(+), 1 deletion(-) |
12 |
|
13 |
diff --git a/glep-0063.rst b/glep-0063.rst |
14 |
index 84d87d2..ae36d36 100644 |
15 |
--- a/glep-0063.rst |
16 |
+++ b/glep-0063.rst |
17 |
@@ -45,6 +45,9 @@ v2 |
18 |
The ``gpg.conf`` contents have been removed as they were seriously |
19 |
outdated and decreased security over the modern defaults. |
20 |
|
21 |
+ The requirement of SHA-2 digest has been extended to apply to self- |
22 |
+ signatures made on subkeys. |
23 |
+ |
24 |
v1.1 |
25 |
The recommended RSA key size has been changed from 4096 bits |
26 |
to 2048 bits to match the GnuPG recommendations [#GNUPG-FAQ-11-4]_. |
27 |
@@ -77,7 +80,7 @@ to commit to Gentoo. Keys that do not conform to those requirements can |
28 |
not be used to commit. |
29 |
|
30 |
1. SHA-2 series output digest (SHA-1 digests internally permitted), |
31 |
- at least 256-bit. |
32 |
+ at least 256-bit. All subkey self-signatures must use this digest. |
33 |
|
34 |
2. Signing subkey that is different from the primary key, and does not |
35 |
have any other capabilities enabled |