Gentoo Archives: gentoo-dev

From: Joshua Kinard <kumba@g.o>
To: gentoo-dev@l.g.o, "Michał Górny" <mgorny@g.o>
Cc: robbat2@g.o
Subject: Re: [gentoo-dev] [PATCH v5 03/16] glep-0063: 'Gentoo subkey' → 'Signing subkey'
Date: Wed, 25 Jul 2018 05:29:01
Message-Id: 317a5bd0-e550-9ff8-07d8-8de8fe84542b@gentoo.org
In Reply to: [gentoo-dev] [PATCH v5 03/16] glep-0063: 'Gentoo subkey' → 'Signing subkey' by "Michał Górny"
1 On 7/8/2018 2:38 PM, Michał Górny wrote:
2 > Replace the 'Gentoo subkey' term that might wrongly suggest that
3 > the developers are expected to create an additional, dedicated subkey
4 > for Gentoo.
5 >
6 > Suggested-by: Kristian Fiskerstrand <k_f@g.o>
7 > ---
8 > glep-0063.rst | 2 +-
9 > 1 file changed, 1 insertion(+), 1 deletion(-)
10 >
11 > diff --git a/glep-0063.rst b/glep-0063.rst
12 > index 0773e3b..f02537d 100644
13 > --- a/glep-0063.rst
14 > +++ b/glep-0063.rst
15 > @@ -116,7 +116,7 @@ Recommendations
16 >
17 > a. Root key: 3 years maximum, expiry date renewed annually.
18 >
19 > - b. Gentoo subkey: 1 year maximum, expiry date renewed every 6 months.
20 > + b. Signing subkey: 1 year maximum, expiry date renewed every 6 months.
21 >
22 > 5. Create a revocation certificate & store it hardcopy offsite securely
23 > (it's about ~300 bytes).
24 >
25
26 I lost track of this due to other priorities, but picking through some of the
27 follow-up messages about the lead time on renewals and all, I don't have a
28 problem with that. But why is the maximum of one year on subkey/signing key
29 expiration still here?
30
31 I'm not seeing a lot of additional follow-up on that, but that is still too
32 short. Two years is perfectly fine in this case. I'd prefer three years
33 myself, but am willing to compromise for two. I am not doing one year unless
34 someone drops some really convincing logic on me. And no, scrawling "logic" on
35 the side of an anvil doesn't count.
36
37 Does anyone know what the other projects require for their keys? Without a
38 proper explanation of //why// one year needs to be the maximum, looking to what
39 other projects use seems sensible for guidance.
40
41 I can't seem to find any specific guidance from Debian, but FreeBSD appears to
42 be fine with three years on their committer keys:
43
44 """
45 A three year key lifespan is short enough to obsolete keys weakened by
46 advancing computer power, but long enough to reduce key management problems.
47 """
48
49 https://www.freebsd.org/doc/en_US.ISO8859-1/articles/committers-guide/article.html#pgpkeys
50
51 --
52 Joshua Kinard
53 Gentoo/MIPS
54 kumba@g.o
55 rsa6144/5C63F4E3F5C6C943 2015-04-27
56 177C 1972 1FB8 F254 BAD0 3E72 5C63 F4E3 F5C6 C943
57
58 "The past tempts us, the present confuses us, the future frightens us. And our
59 lives slip away, moment by moment, lost in that vast, terrible in-between."
60
61 --Emperor Turhan, Centauri Republic

Replies