Gentoo Archives: gentoo-dev

From: "Manuel Rüger" <mrueg@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH v2 10/11] glep-0063: Require renewal 2 weeks before expiration
Date: Fri, 06 Jul 2018 08:11:54
Message-Id: 00ea89ca-89c0-18f3-f286-8159b21d84e1@gentoo.org
In Reply to: [gentoo-dev] [PATCH v2 10/11] glep-0063: Require renewal 2 weeks before expiration by "Michał Górny"
1 I disagree with adding this as a requirement.
2
3 Services should explicitly fail to work with expired GPG keys, key
4 renewal times should be at the key owner's descretion.
5 This should still be a recommendation that guarantees the key owner to
6 continue work without interruption.
7
8
9 Thanks,
10 Manuel
11
12 On 04.07.2018 12:24, Michał Górny wrote:
13 > Add a rule requesting renewal of keys at least two weeks before their
14 > expiration date, in order to give services time to refresh.
15 > ---
16 > glep-0063.rst | 9 ++++++++-
17 > 1 file changed, 8 insertions(+), 1 deletion(-)
18 >
19 > diff --git a/glep-0063.rst b/glep-0063.rst
20 > index 7455674..6874b81 100644
21 > --- a/glep-0063.rst
22 > +++ b/glep-0063.rst
23 > @@ -32,6 +32,10 @@ v2
24 > specification. Changing the expiration date of existing keys is possible
25 > in-place so there is no need to provide for transitional 'minimum' value.
26 >
27 > + An additional rule requesting key renewal 2 weeks before expiration
28 > + has been added. This is in order to give services and other developers time
29 > + to refresh the key.
30 > +
31 > v1.1
32 > The recommended RSA key size has been changed from 4096 bits
33 > to 2048 bits to match the GnuPG recommendations [#GNUPG-FAQ-11-4]_.
34 > @@ -82,7 +86,10 @@ not be used to commit.
35 >
36 > b. Gentoo subkey: 1 year maximum
37 >
38 > -4. Upload your key to the SKS keyserver rotation before usage!
39 > +4. Key expiration date renewed at least 2 weeks before the previous
40 > + expiration date.
41 > +
42 > +5. Upload your key to the SKS keyserver rotation before usage!
43 >
44 > Recommendations
45 > ---------------
46 >

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies