1 |
I disagree with adding this as a requirement. |
2 |
|
3 |
Services should explicitly fail to work with expired GPG keys, key |
4 |
renewal times should be at the key owner's descretion. |
5 |
This should still be a recommendation that guarantees the key owner to |
6 |
continue work without interruption. |
7 |
|
8 |
|
9 |
Thanks, |
10 |
Manuel |
11 |
|
12 |
On 04.07.2018 12:24, Michał Górny wrote: |
13 |
> Add a rule requesting renewal of keys at least two weeks before their |
14 |
> expiration date, in order to give services time to refresh. |
15 |
> --- |
16 |
> glep-0063.rst | 9 ++++++++- |
17 |
> 1 file changed, 8 insertions(+), 1 deletion(-) |
18 |
> |
19 |
> diff --git a/glep-0063.rst b/glep-0063.rst |
20 |
> index 7455674..6874b81 100644 |
21 |
> --- a/glep-0063.rst |
22 |
> +++ b/glep-0063.rst |
23 |
> @@ -32,6 +32,10 @@ v2 |
24 |
> specification. Changing the expiration date of existing keys is possible |
25 |
> in-place so there is no need to provide for transitional 'minimum' value. |
26 |
> |
27 |
> + An additional rule requesting key renewal 2 weeks before expiration |
28 |
> + has been added. This is in order to give services and other developers time |
29 |
> + to refresh the key. |
30 |
> + |
31 |
> v1.1 |
32 |
> The recommended RSA key size has been changed from 4096 bits |
33 |
> to 2048 bits to match the GnuPG recommendations [#GNUPG-FAQ-11-4]_. |
34 |
> @@ -82,7 +86,10 @@ not be used to commit. |
35 |
> |
36 |
> b. Gentoo subkey: 1 year maximum |
37 |
> |
38 |
> -4. Upload your key to the SKS keyserver rotation before usage! |
39 |
> +4. Key expiration date renewed at least 2 weeks before the previous |
40 |
> + expiration date. |
41 |
> + |
42 |
> +5. Upload your key to the SKS keyserver rotation before usage! |
43 |
> |
44 |
> Recommendations |
45 |
> --------------- |
46 |
> |