Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] unverifiable GPG keys for @gentoo.org members
Date: Tue, 12 May 2020 05:24:47
Message-Id: 049c0b1eedd2c4b71021efb76c72f8cef0f14328.camel@gentoo.org
In Reply to: [gentoo-dev] unverifiable GPG keys for @gentoo.org members by Aisha Tammy
1 W dniu pon, 11.05.2020 o godzinie 20∶20 -0400, użytkownik Aisha Tammy
2 napisał:
3 > Hi devs@,
4 > Seems like for some reason the gentoo.org does not publish the
5 > gpg public keys of the senders, even though it is signed correctly.
6
7 Why do you claim that? How did you verify it? Why are you jumping
8 straight to passive-aggressive accusations without asking nicely first?
9
10 >
11 > Just wanted to know why the devs are required to use gpg keys, glep63
12 > [1]
13 > but even when the server has the public keys, they aren't published
14 > properly.
15 >
16 > From a proper security perspective, I would have though something
17 > like WKD[2] would have been implemented on the server side for
18 > automated
19 > authentication.
20
21 WKD is implemented and I don't know a single case where it wouldn't
22 work. If it doesn't work for you, then I dare say it's more likely to
23 be a problem with your setup. However, if it's a problem on our end,
24 I'd really appreciate a bug report before calling us retarded.
25
26 In fact, the link you've posted actually lists gentoo.org as one
27 of the few organizations implementing WKD.
28
29 >
30 > Maybe I am missing something about how to verify the keys of the
31 > maintainers
32 > who are sending announcements but it irks me a teensy bit when i have
33 > signed
34 > mails and I can't ~~trust~~ verify the signatures.
35 >
36 >
37
38 You are missing that WKD does not provide authentication, and if it
39 were, it would be considered thoroughly insecure. Authentication
40 in OpenPGP is generally provided via web of trust. For Gentoo
41 developers, you can also use our Authority Keys [3,4,5].
42
43 >
44 > [1]
45 > https://wiki.gentoo.org/wiki/Project:Infrastructure/Generating_GLEP_63_based_OpenPGP_keys
46 > [2] https://wiki.gnupg.org/WKD
47
48 [3] https://www.gentoo.org/downloads/signatures/
49 [4] https://www.gentoo.org/glep/glep-0079.html
50 [5] https://wiki.gentoo.org/wiki/Project:Infrastructure/Authority_Keys
51
52
53 --
54 Best regards,
55 Michał Górny

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-dev] unverifiable GPG keys for @gentoo.org members Aisha Tammy <gentoo.dev@×××××.cc>
Re: [gentoo-dev] unverifiable GPG keys for @gentoo.org members desultory <desultory@g.o>