1 |
On 7/8/2018 2:38 PM, Michał Górny wrote: |
2 |
> Replace the 'Gentoo subkey' term that might wrongly suggest that |
3 |
> the developers are expected to create an additional, dedicated subkey |
4 |
> for Gentoo. |
5 |
> |
6 |
> Suggested-by: Kristian Fiskerstrand <k_f@g.o> |
7 |
> --- |
8 |
> glep-0063.rst | 2 +- |
9 |
> 1 file changed, 1 insertion(+), 1 deletion(-) |
10 |
> |
11 |
> diff --git a/glep-0063.rst b/glep-0063.rst |
12 |
> index 0773e3b..f02537d 100644 |
13 |
> --- a/glep-0063.rst |
14 |
> +++ b/glep-0063.rst |
15 |
> @@ -116,7 +116,7 @@ Recommendations |
16 |
> |
17 |
> a. Root key: 3 years maximum, expiry date renewed annually. |
18 |
> |
19 |
> - b. Gentoo subkey: 1 year maximum, expiry date renewed every 6 months. |
20 |
> + b. Signing subkey: 1 year maximum, expiry date renewed every 6 months. |
21 |
> |
22 |
> 5. Create a revocation certificate & store it hardcopy offsite securely |
23 |
> (it's about ~300 bytes). |
24 |
> |
25 |
|
26 |
I lost track of this due to other priorities, but picking through some of the |
27 |
follow-up messages about the lead time on renewals and all, I don't have a |
28 |
problem with that. But why is the maximum of one year on subkey/signing key |
29 |
expiration still here? |
30 |
|
31 |
I'm not seeing a lot of additional follow-up on that, but that is still too |
32 |
short. Two years is perfectly fine in this case. I'd prefer three years |
33 |
myself, but am willing to compromise for two. I am not doing one year unless |
34 |
someone drops some really convincing logic on me. And no, scrawling "logic" on |
35 |
the side of an anvil doesn't count. |
36 |
|
37 |
Does anyone know what the other projects require for their keys? Without a |
38 |
proper explanation of //why// one year needs to be the maximum, looking to what |
39 |
other projects use seems sensible for guidance. |
40 |
|
41 |
I can't seem to find any specific guidance from Debian, but FreeBSD appears to |
42 |
be fine with three years on their committer keys: |
43 |
|
44 |
""" |
45 |
A three year key lifespan is short enough to obsolete keys weakened by |
46 |
advancing computer power, but long enough to reduce key management problems. |
47 |
""" |
48 |
|
49 |
https://www.freebsd.org/doc/en_US.ISO8859-1/articles/committers-guide/article.html#pgpkeys |
50 |
|
51 |
-- |
52 |
Joshua Kinard |
53 |
Gentoo/MIPS |
54 |
kumba@g.o |
55 |
rsa6144/5C63F4E3F5C6C943 2015-04-27 |
56 |
177C 1972 1FB8 F254 BAD0 3E72 5C63 F4E3 F5C6 C943 |
57 |
|
58 |
"The past tempts us, the present confuses us, the future frightens us. And our |
59 |
lives slip away, moment by moment, lost in that vast, terrible in-between." |
60 |
|
61 |
--Emperor Turhan, Centauri Republic |