Gentoo Archives: gentoo-dev

From: "Robin H. Johnson" <robbat2@g.o>
To: Ulrich Mueller <ulm@g.o>
Cc: gentoo-dev@l.g.o, robbat2@g.o, "Michał Górny" <mgorny@g.o>
Subject: Re: [gentoo-dev] [PATCH v3 10/12] glep-0063: Make 2-yearly expiration term mandatory
Date: Fri, 06 Jul 2018 06:08:15
Message-Id: robbat2-20180706T060350-475538649Z@orbis-terrarum.net
In Reply to: Re: [gentoo-dev] [PATCH v3 10/12] glep-0063: Make 2-yearly expiration term mandatory by Ulrich Mueller
1 On Fri, Jul 06, 2018 at 07:43:56AM +0200, Ulrich Mueller wrote:
2 > >>>>> On Thu, 5 Jul 2018, Michał Górny wrote:
3 >
4 > > Replace the disjoint 'minimum' and 'recommendation' for expiration
5 > > with a single requirement. Make it 2 years. Also, remove disjoint
6 > > expiration recommendation for the primary key and subkeys since many
7 > > developers fail at implementing that anyway.
8 >
9 > Still NACK. If expiration is exactly 2 years and renewal must happen
10 > 2 weeks before the expiry date, then it is not possible to keep the
11 > same date.
12 >
13 > Example: The key will expire at 2018-12-31, so it must be renewed at
14 > 2018-12-17 or earlier. This will make it impossible to keep the same
15 > month and day (unless one would reset it to 2019-12-31, which is only
16 > one year though).
17 >
18 > So please, make it something like 2 years + 3 months.
19 option a)
20 2 years + N:
21 2 weeks <= N <= 3 months.
22
23 option b)
24 Change the wording to be 'at most 2 years' instead of 'exactly 2 years'.
25
26 Separately:
27 Is two weeks enough time for a new key distribution to users?
28
29 --
30 Robin Hugh Johnson
31 Gentoo Linux: Dev, Infra Lead, Foundation Treasurer
32 E-Mail : robbat2@g.o
33 GnuPG FP : 11ACBA4F 4778E3F6 E4EDF38E B27B944E 34884E85
34 GnuPG FP : 7D0B3CEB E9B85B1F 825BCECF EE05E6F6 A48F6136

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies