1 |
On 5/11/20 8:20 PM, Aisha Tammy wrote: |
2 |
> Hi devs@, |
3 |
> Seems like for some reason the gentoo.org does not publish the |
4 |
> gpg public keys of the senders, even though it is signed correctly. |
5 |
> |
6 |
|
7 |
Sorry, I meant **mail signing**, not commit signing. |
8 |
Just saw that wording was confusing. |
9 |
|
10 |
> Just wanted to know why the devs are required to use gpg keys, glep63 [1] |
11 |
> but even when the server has the public keys, they aren't published properly. |
12 |
> |
13 |
> From a proper security perspective, I would have though something |
14 |
> like WKD[2] would have been implemented on the server side for automated |
15 |
> authentication. |
16 |
> |
17 |
> Maybe I am missing something about how to verify the keys of the maintainers |
18 |
> who are sending announcements but it irks me a teensy bit when i have signed |
19 |
> mails and I can't ~~trust~~ verify the signatures. |
20 |
> |
21 |
> This is tots an aside from normal gentoo stuff. |
22 |
> |
23 |
> Hope ya'll are safe, |
24 |
> Aisha |
25 |
> |
26 |
> |
27 |
> |
28 |
> [1] https://wiki.gentoo.org/wiki/Project:Infrastructure/Generating_GLEP_63_based_OpenPGP_keys |
29 |
> [2] https://wiki.gnupg.org/WKD |
30 |
> |