Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Cc: Mike Gilbert <floppym@g.o>
Subject: Re: [gentoo-dev] [PATCH v3] glep-0063: Add section about the Gentoo keyserver
Date: Fri, 18 Dec 2020 16:08:46
Message-Id: 00bbc8734268eb31c27bc1dd76c0b287a7e09382.camel@gentoo.org
In Reply to: [gentoo-dev] [PATCH v3] glep-0063: Add section about the Gentoo keyserver by Mike Gilbert
1 On Fri, 2020-12-18 at 10:56 -0500, Mike Gilbert wrote:
2 > Signed-off-by: Mike Gilbert <floppym@g.o>
3 > ---
4 >
5 > v3: Fixed typo.
6 >     Added link to keys.gentoo.org.
7 >     Moved SKS upload advice to Recommendations section.
8 >     Added Gentoo keyserver advice to Bare minimum requirements
9 > section.
10 >
11 >  glep-0063.rst | 32 ++++++++++++++++++++++++--------
12 >  1 file changed, 24 insertions(+), 8 deletions(-)
13 >
14 > diff --git a/glep-0063.rst b/glep-0063.rst
15 > index 82541bd..6997044 100644
16 > --- a/glep-0063.rst
17 > +++ b/glep-0063.rst
18 > @@ -7,10 +7,10 @@ Author: Robin H. Johnson <robbat2@g.o>,
19 >          Michał Górny <mgorny@g.o>
20 >  Type: Standards Track
21 >  Status: Final
22 > -Version: 2.1
23 > +Version: 2.2
24 >  Created: 2013-02-18
25 > -Last-Modified: 2019-11-07
26 > -Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24
27 > +Last-Modified: 2020-12-17
28 > +Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24, 2020-
29 > 12-17
30 >  Content-Type: text/x-rst
31 >  ---
32 >  
33 > @@ -28,6 +28,9 @@ OpenPGP key management policies for the Gentoo
34 > Linux distribution.
35 >  Changes
36 >  =======
37 >  
38 > +v2.2
39 > +  Added information about the Gentoo keyserver.
40 > +
41 >  v2.1
42 >    A requirement for an encryption key has been added, in order to
43 > extend
44 >    the GLEP beyond commit signing and into use of OpenPGP for dev-to-
45 > dev
46 > @@ -114,7 +117,7 @@ Keys that do not conform to them can not be used
47 > to commit.
48 >  
49 >  6. UID using your ``@gentoo.org`` e-mail included in the key.
50 >  
51 > -7. Upload your key to the SKS keyserver rotation before usage!
52 > +7. Keys must be uploaded to the Gentoo keyserver.
53 >  
54 >  Recommendations
55 >  ---------------
56 > @@ -135,8 +138,13 @@ their primary key).
57 >  
58 >  5. Encrypted backup of your secret keys.
59 >  
60 > +6. Upload to SKS or another public keyserver pool.
61 > +
62 > +Gentoo Infrastructure
63 > +=====================
64 > +
65 >  Gentoo LDAP
66 > -===========
67 > +-----------
68 >  
69 >  All Gentoo developers must list the complete fingerprint for their
70 > primary
71 >  keys in the "``gpgfingerprint``" LDAP field. It must be exactly 40
72 > hex digits,
73 > @@ -147,6 +155,14 @@ of the fingerprint field. In any place that
74 > presently displays
75 >  the "``gpgkey``" field, the last 16 hex digits of the fingerprint
76 > should
77 >  be displayed instead.
78 >  
79 > +Gentoo Keyserver
80 > +----------------
81 > +
82 > +Gentoo infrastructure uses a keyserver that is isolated from the SKS
83 > pool.
84 > +This keyserver is restricted to accepting uploads from authorized
85 > Gentoo hosts.
86 > +Instructions for uploading keys to this server may be found at
87 > +https://keys.gentoo.org/.
88 > +
89 >  Backwards Compatibility
90 >  =======================
91 >  
92 > @@ -212,6 +228,6 @@ Copyright
93 >  Copyright (c) 2013-2019 by Robin Hugh Johnson, Andreas K. Hüttel,
94 >  Marissa Fischer, Michał Górny.
95 >  
96 > -This work is licensed under the Creative Commons Attribution-
97 > ShareAlike 3.0
98 > -Unported License.  To view a copy of this license, visit
99 > -https://creativecommons.org/licenses/by-sa/3.0/.
100 > +This work is licensed under the Creative Commons Attribution-
101 > ShareAlike 4.0
102 > +International License.  To view a copy of this license, visit
103 > +https://creativecommons.org/licenses/by-sa/4.0/.
104
105 LGTM. Thanks!
106
107 --
108 Best regards,
109 Michał Górny