Gentoo Archives: gentoo-dev

From: Aisha Tammy <gentoo.dev@×××××.cc>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] unverifiable GPG keys for @gentoo.org members
Date: Tue, 12 May 2020 00:21:57
Message-Id: 5bd6f715-53f0-4118-f841-d06f4cb92127@aisha.cc
In Reply to: [gentoo-dev] unverifiable GPG keys for @gentoo.org members by Aisha Tammy
1 On 5/11/20 8:20 PM, Aisha Tammy wrote:
2 > Hi devs@,
3 > Seems like for some reason the gentoo.org does not publish the
4 > gpg public keys of the senders, even though it is signed correctly.
5 >
6
7 Sorry, I meant **mail signing**, not commit signing.
8 Just saw that wording was confusing.
9
10 > Just wanted to know why the devs are required to use gpg keys, glep63 [1]
11 > but even when the server has the public keys, they aren't published properly.
12 >
13 > From a proper security perspective, I would have though something
14 > like WKD[2] would have been implemented on the server side for automated
15 > authentication.
16 >
17 > Maybe I am missing something about how to verify the keys of the maintainers
18 > who are sending announcements but it irks me a teensy bit when i have signed
19 > mails and I can't ~~trust~~ verify the signatures.
20 >
21 > This is tots an aside from normal gentoo stuff.
22 >
23 > Hope ya'll are safe,
24 > Aisha
25 >
26 >
27 >
28 > [1] https://wiki.gentoo.org/wiki/Project:Infrastructure/Generating_GLEP_63_based_OpenPGP_keys
29 > [2] https://wiki.gnupg.org/WKD
30 >