Gentoo Archives: gentoo-dev

From: Davide Pesavento <pesa@g.o>
To: gentoo-dev@l.g.o
Cc: Mike Gilbert <floppym@g.o>
Subject: Re: [gentoo-dev] [PATCH v2] glep-0063: Add section about the Gentoo keyserver
Date: Thu, 17 Dec 2020 18:44:56
Message-Id: CADfzvvab7E6mcb76KMnz9F7yM+fvxxrx1e_TmmEVMCAu-e14Bg@mail.gmail.com
In Reply to: [gentoo-dev] [PATCH v2] glep-0063: Add section about the Gentoo keyserver by Mike Gilbert
1 On Thu, Dec 17, 2020 at 1:12 PM Mike Gilbert <floppym@g.o> wrote:
2 >
3 > Signed-off-by: Mike Gilbert <floppym@g.o>
4 > ---
5 >
6 > v2: Added "This upload is required in addition to uploading the SKS pool."
7 >
8 > glep-0063.rst | 24 ++++++++++++++++++++----
9 > 1 file changed, 20 insertions(+), 4 deletions(-)
10 >
11 > diff --git a/glep-0063.rst b/glep-0063.rst
12 > index 82541bd..ec465db 100644
13 > --- a/glep-0063.rst
14 > +++ b/glep-0063.rst
15 > @@ -7,10 +7,10 @@ Author: Robin H. Johnson <robbat2@g.o>,
16 > Michał Górny <mgorny@g.o>
17 > Type: Standards Track
18 > Status: Final
19 > -Version: 2.1
20 > +Version: 2.2
21 > Created: 2013-02-18
22 > -Last-Modified: 2019-11-07
23 > -Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24
24 > +Last-Modified: 2020-12-17
25 > +Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24, 2020-12-17
26 > Content-Type: text/x-rst
27 > ---
28 >
29 > @@ -28,6 +28,9 @@ OpenPGP key management policies for the Gentoo Linux distribution.
30 > Changes
31 > =======
32 >
33 > +v2.2
34 > + Added "Gentoo Keyserver" section under "Gentoo Infrastructure" chapter.
35 > +
36 > v2.1
37 > A requirement for an encryption key has been added, in order to extend
38 > the GLEP beyond commit signing and into use of OpenPGP for dev-to-dev
39 > @@ -135,8 +138,11 @@ their primary key).
40 >
41 > 5. Encrypted backup of your secret keys.
42 >
43 > +Gentoo Infrstructure
44
45 Typo.
46
47 > +====================
48 > +
49 > Gentoo LDAP
50 > -===========
51 > +-----------
52 >
53 > All Gentoo developers must list the complete fingerprint for their primary
54 > keys in the "``gpgfingerprint``" LDAP field. It must be exactly 40 hex digits,
55 > @@ -147,6 +153,16 @@ of the fingerprint field. In any place that presently displays
56 > the "``gpgkey``" field, the last 16 hex digits of the fingerprint should
57 > be displayed instead.
58 >
59 > +Gentoo Keyserver
60 > +----------------
61 > +
62 > +Gentoo infrastructure uses a keyserver that is isolated from the SKS pool.
63 > +This keyserver is restricted to accepting uploads from authorized Gentoo hosts.
64 > +A script is provided on dev.gentoo.org to allow developers to upload their
65 > +keys. This upload is required in addition to uploading to the SKS pool.
66 > +
67 > +``gpg --export KEYID | ssh dev.gentoo.org /usr/local/bin/openpgp-key-upload``
68 > +
69 > Backwards Compatibility
70 > =======================
71 >
72 > --
73 > 2.30.0.rc0
74 >
75 >
76
77 The rest LGTM.
78
79 Thanks,
80 Davide

Replies