1 |
>>>>> On Sat, 7 Jul 2018, Michał Górny wrote: |
2 |
|
3 |
[Section "Bare minimum requirements"] |
4 |
|
5 |
> 1. SHA2-series output digest (SHA1 digests internally permitted), |
6 |
> 256bit or more:: |
7 |
|
8 |
> personal-digest-preferences SHA256 |
9 |
|
10 |
Is the config line still needed with current GnuPG versions? |
11 |
|
12 |
> 2. Signing subkey that is different from the primary key, and does not |
13 |
> have any other capabilities enabled. |
14 |
|
15 |
> 3. Primary key and the signing subkey are both of type EITHER: |
16 |
|
17 |
> a. RSA, >=2048 bits (OpenPGP v4 key format or later only) |
18 |
|
19 |
> b. ECC curve 25519 |
20 |
|
21 |
> 4. Expiration date on key and all subkeys set to no more than 900 days |
22 |
> into the future |
23 |
|
24 |
s/key/primary key/ |
25 |
|
26 |
Also be consistent with punctuation, i.e., add a full stop at the end |
27 |
of the sentence. |
28 |
|
29 |
[Section "Recommendations"] |
30 |
|
31 |
> 1. Primary key and the signing subkey are both of type RSA, 2048 bits |
32 |
> (OpenPGP v4 key format or later) |
33 |
|
34 |
> 2. Key expiration renewed annually to a fixed day of the year |
35 |
|
36 |
> 3. Create a revocation certificate & store it hardcopy offsite securely |
37 |
> (it's about ~300 bytes). |
38 |
|
39 |
Ditto for items 1. to 3. here. |
40 |
|
41 |
> 4. Encrypted backup of your secret keys. |
42 |
|
43 |
[...] |
44 |
|
45 |
> Copyright |
46 |
> ========= |
47 |
|
48 |
Insert a blank line after the header. |
49 |
|
50 |
> Copyright (c) 2013 by Robin Hugh Johnson, Andreas K. Hüttel, Marissa Fischer, |
51 |
> Michał Górny. |
52 |
|
53 |
Update the date to "2013, 2018" (and rewrap the paragraph). |
54 |
|
55 |
Ulrich |