Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Cc: robbat2@g.o
Subject: Re: [gentoo-dev] [PATCH v4 00/14] GLEP 63 update
Date: Sat, 07 Jul 2018 13:11:19
Message-Id: 1530969065.900.25.camel@gentoo.org
In Reply to: Re: [gentoo-dev] [PATCH v4 00/14] GLEP 63 update by Ulrich Mueller
1 W dniu sob, 07.07.2018 o godzinie 14∶17 +0200, użytkownik Ulrich Mueller
2 napisał:
3 > > > > > > On Sat, 7 Jul 2018, Michał Górny wrote:
4 >
5 > [Section "Bare minimum requirements"]
6 >
7 > > 1. SHA2-series output digest (SHA1 digests internally permitted),
8 > > 256bit or more::
9 > > personal-digest-preferences SHA256
10 >
11 > Is the config line still needed with current GnuPG versions?
12
13 I'll let others answer that. In any case, the point itself (requiring
14 SHA-2 digest) makes sense. The RiseUp standard requires all self-
15 signatures to be SHA-2, and I was planning on verifying that as well.
16
17 > > 2. Signing subkey that is different from the primary key, and does not
18 > > have any other capabilities enabled.
19 > > 3. Primary key and the signing subkey are both of type EITHER:
20 > > a. RSA, >=2048 bits (OpenPGP v4 key format or later only)
21 > > b. ECC curve 25519
22 > > 4. Expiration date on key and all subkeys set to no more than 900 days
23 > > into the future
24 >
25 > s/key/primary key/
26 >
27 > Also be consistent with punctuation, i.e., add a full stop at the end
28 > of the sentence.
29
30 Actually, I aimed to fix punctuation on things I've changed
31 (i.e. no full stop because it's not proper sentence). I suppose I can
32 update the rest.
33
34 >
35 > [Section "Recommendations"]
36 >
37 > > 1. Primary key and the signing subkey are both of type RSA, 2048 bits
38 > > (OpenPGP v4 key format or later)
39 > > 2. Key expiration renewed annually to a fixed day of the year
40 > > 3. Create a revocation certificate & store it hardcopy offsite securely
41 > > (it's about ~300 bytes).
42 >
43 > Ditto for items 1. to 3. here.
44 >
45 > > 4. Encrypted backup of your secret keys.
46 >
47 > [...]
48 >
49 > > Copyright
50 > > =========
51 >
52 > Insert a blank line after the header.
53 >
54 > > Copyright (c) 2013 by Robin Hugh Johnson, Andreas K. Hüttel, Marissa Fischer,
55 > > Michał Górny.
56 >
57 > Update the date to "2013, 2018" (and rewrap the paragraph).
58 >
59 > Ulrich
60
61 --
62 Best regards,
63 Michał Górny

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] [PATCH v4 00/14] GLEP 63 update Ulrich Mueller <ulm@g.o>
Re: [gentoo-dev] [PATCH v4 00/14] GLEP 63 update Kristian Fiskerstrand <k_f@g.o>