Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Cc: robbat2@g.o
Subject: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory
Date: Thu, 05 Jul 2018 13:36:22
Message-Id: 1530797769.921.10.camel@gentoo.org
In Reply to: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory by Joshua Kinard
1 W dniu śro, 04.07.2018 o godzinie 18∶48 -0400, użytkownik Joshua Kinard
2 napisał:
3 > On 7/4/2018 5:24 PM, Michał Górny wrote:
4 > > W dniu śro, 04.07.2018 o godzinie 23∶05 +0200, użytkownik Ulrich Mueller
5 > > napisał:
6 > > > > > > > > On Wed, 4 Jul 2018, Michał Górny wrote:
7 > > > >
8 > > > > -3. Key expiry: 5 years maximum
9 > > > > +3. Key expiration:
10 > > > > +
11 > > > > + a. Primary key: 3 years maximum
12 > > > > +
13 > > > > + b. Gentoo subkey: 1 year maximum
14 > > >
15 > > > What problem are you trying to solve here?
16 > > >
17 > >
18 > > The problem of having unjustified double standards.
19 >
20 > IMHO, one year for a signing subkey is too short. I see no problem with three
21 > years like the primary key. Especially since people will typically just change
22 > the expiration and advance it the minimum number of years, lather, rinse, and
23 > repeat. It's a solution looking for a problem.
24 >
25
26 I don't really know the original rationale for this.
27
28 The NIST standard says 1-3 years. If I were to guess, I'd say 1 year
29 was chosen for subkey because subkey expiring is a 'smaller' issue than
30 the whole key expiring, i.e. other users see the primary key as being
31 still valid.
32
33 I suppose the advantage of having disjoint expiration times is that if
34 you forget about it, you'd learn the hard way that you need to renew it
35 before the primary key expired.
36
37 That said, I'm open to using a different recommendation, e.g. 2 years
38 as in riseup [1]. I suppose having the same time for both primary key
39 and subkeys would make the spec simpler, and many developers are
40 mistaking expiration times (as specified now) anyway.
41
42 [1]:https://riseup.net/en/security/message-security/openpgp/best-practices#use-an-expiration-date-less-than-two-years
43
44 --
45 Best regards,
46 Michał Górny

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies