Gentoo Archives: gentoo-commits

From: "Michał Górny" <mgorny@g.o>
To: gentoo-commits@l.g.o
Subject: [gentoo-commits] data/glep:master commit in: /
Date: Sun, 29 Jul 2018 20:51:13
Message-Id: 1532894847.7d72d5875be3df130ae3728cf078a8f0434d904b.mgorny@gentoo
1 commit: 7d72d5875be3df130ae3728cf078a8f0434d904b
2 Author: Michał Górny <mgorny <AT> gentoo <DOT> org>
3 AuthorDate: Sun Jul 8 18:33:20 2018 +0000
4 Commit: Michał Górny <mgorny <AT> gentoo <DOT> org>
5 CommitDate: Sun Jul 29 20:07:27 2018 +0000
6 URL: https://gitweb.gentoo.org/data/glep.git/commit/?id=7d72d587
7
8 glep-0063: Extend SHA-2 requirement to self-signatures on subkeys
9
10 glep-0063.rst | 5 ++++-
11 1 file changed, 4 insertions(+), 1 deletion(-)
12
13 diff --git a/glep-0063.rst b/glep-0063.rst
14 index 84d87d2..ae36d36 100644
15 --- a/glep-0063.rst
16 +++ b/glep-0063.rst
17 @@ -45,6 +45,9 @@ v2
18 The ``gpg.conf`` contents have been removed as they were seriously
19 outdated and decreased security over the modern defaults.
20
21 + The requirement of SHA-2 digest has been extended to apply to self-
22 + signatures made on subkeys.
23 +
24 v1.1
25 The recommended RSA key size has been changed from 4096 bits
26 to 2048 bits to match the GnuPG recommendations [#GNUPG-FAQ-11-4]_.
27 @@ -77,7 +80,7 @@ to commit to Gentoo. Keys that do not conform to those requirements can
28 not be used to commit.
29
30 1. SHA-2 series output digest (SHA-1 digests internally permitted),
31 - at least 256-bit.
32 + at least 256-bit. All subkey self-signatures must use this digest.
33
34 2. Signing subkey that is different from the primary key, and does not
35 have any other capabilities enabled