Gentoo Archives: gentoo-dev

From: Kacper Kowalik <xarthisius@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] Re: [gentoo-dev-announce] PORTAGE_GPG_KEY strictness
Date: Wed, 17 Oct 2012 17:27:49
Message-Id: 507EEA5B.6080708@gentoo.org
In Reply to: [gentoo-dev] Re: [gentoo-dev-announce] PORTAGE_GPG_KEY strictness by Patrick Lauer
1 On 17.10.2012 03:30, Patrick Lauer wrote:
2 > On 10/17/12 06:54, Robin H. Johnson wrote:
3 >> Hi all,
4 >>
5 >> One of the items that has come up in the Git conversion, and needs some
6 >> attention.
7 >>
8 > [snip]
9 >>
10 >> As such, we've decided to make the PORTAGE_GPG_KEY strictly enforce what
11 >> was originally intended.
12 >>
13 >> - You must specify a key or subkey exactly.
14 >> - The leading "0x" is optional.
15 >> - If you want to use a subkey, per the PGP specifications, you must
16 >> suffix your keyid with "!".
17 >> - Your keyid is exactly: 8, 16, 24, 32 xor 40 hexdigits long.
18 >
19 > That's nice. Can we also add some basic policies on key format (key
20 > length, validity) and get a centrally-hosted keyring?
21 >
22 > Then it'd even make sense for us to start using the whole signing thing
23 > now :)
24
25 Additionally, can any consensus achieved here be documented right away?
26 e.g. here [1] or @devmanual.g.o
27 Cheers,
28 Kacper
29
30 [1] http://www.gentoo.org/proj/en/devrel/handbook/handbook.xml?part=2&chap=6

Attachments

File name MIME type
signature.asc application/pgp-signature