Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] validity of manifest signing key
Date: Fri, 25 Mar 2011 19:27:22
Message-Id: robbat2-20110325T163301-507898828Z@orbis-terrarum.net
In Reply to: [gentoo-dev] validity of manifest signing key by Thomas Kahle
1 On Fri, Mar 25, 2011 at 10:47:19AM +0100, Thomas Kahle wrote:
2 > Hi,
3 >
4 > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that
5 > the validity should be <6 month. What is the protocol when the expiry
6 > date is approaching?
7 >
8 > -) Extend expiry date and upload again?
9 Extend it and make sure you upload.
10
11 Also, I propose we change the suggested validity time to 1 or 2 years,
12 due to the implications on key-signing (certifications):
13 Specifically, GPG/PGP as a protocol, requires that your certification
14 expires on or before the key at the time of signing the key.
15
16 --
17 Robin Hugh Johnson
18 Gentoo Linux: Developer, Trustee & Infrastructure Lead
19 E-Mail : robbat2@g.o
20 GnuPG FP : 11AC BA4F 4778 E3F6 E4ED F38E B27B 944E 3488 4E85

Replies

Subject Author
Re: [gentoo-dev] validity of manifest signing key Mike Frysinger <vapier@g.o>