1 |
W dniu pon, 11.05.2020 o godzinie 20∶20 -0400, użytkownik Aisha Tammy |
2 |
napisał: |
3 |
> Hi devs@, |
4 |
> Seems like for some reason the gentoo.org does not publish the |
5 |
> gpg public keys of the senders, even though it is signed correctly. |
6 |
|
7 |
Why do you claim that? How did you verify it? Why are you jumping |
8 |
straight to passive-aggressive accusations without asking nicely first? |
9 |
|
10 |
> |
11 |
> Just wanted to know why the devs are required to use gpg keys, glep63 |
12 |
> [1] |
13 |
> but even when the server has the public keys, they aren't published |
14 |
> properly. |
15 |
> |
16 |
> From a proper security perspective, I would have though something |
17 |
> like WKD[2] would have been implemented on the server side for |
18 |
> automated |
19 |
> authentication. |
20 |
|
21 |
WKD is implemented and I don't know a single case where it wouldn't |
22 |
work. If it doesn't work for you, then I dare say it's more likely to |
23 |
be a problem with your setup. However, if it's a problem on our end, |
24 |
I'd really appreciate a bug report before calling us retarded. |
25 |
|
26 |
In fact, the link you've posted actually lists gentoo.org as one |
27 |
of the few organizations implementing WKD. |
28 |
|
29 |
> |
30 |
> Maybe I am missing something about how to verify the keys of the |
31 |
> maintainers |
32 |
> who are sending announcements but it irks me a teensy bit when i have |
33 |
> signed |
34 |
> mails and I can't ~~trust~~ verify the signatures. |
35 |
> |
36 |
> |
37 |
|
38 |
You are missing that WKD does not provide authentication, and if it |
39 |
were, it would be considered thoroughly insecure. Authentication |
40 |
in OpenPGP is generally provided via web of trust. For Gentoo |
41 |
developers, you can also use our Authority Keys [3,4,5]. |
42 |
|
43 |
> |
44 |
> [1] |
45 |
> https://wiki.gentoo.org/wiki/Project:Infrastructure/Generating_GLEP_63_based_OpenPGP_keys |
46 |
> [2] https://wiki.gnupg.org/WKD |
47 |
|
48 |
[3] https://www.gentoo.org/downloads/signatures/ |
49 |
[4] https://www.gentoo.org/glep/glep-0079.html |
50 |
[5] https://wiki.gentoo.org/wiki/Project:Infrastructure/Authority_Keys |
51 |
|
52 |
|
53 |
-- |
54 |
Best regards, |
55 |
Michał Górny |