1 |
On Fri, 06 Jul 2018 08:18:32 +0200 |
2 |
Michał Górny <mgorny@g.o> wrote: |
3 |
|
4 |
> W dniu pią, 06.07.2018 o godzinie 06∶08 +0000, użytkownik Robin H. |
5 |
> Johnson napisał: |
6 |
> > On Fri, Jul 06, 2018 at 07:43:56AM +0200, Ulrich Mueller wrote: |
7 |
> > > > > > > > On Thu, 5 Jul 2018, Michał Górny wrote: |
8 |
> > > > Replace the disjoint 'minimum' and 'recommendation' for |
9 |
> > > > expiration with a single requirement. Make it 2 years. Also, |
10 |
> > > > remove disjoint expiration recommendation for the primary key |
11 |
> > > > and subkeys since many developers fail at implementing that |
12 |
> > > > anyway. |
13 |
> > > |
14 |
> > > Still NACK. If expiration is exactly 2 years and renewal must |
15 |
> > > happen 2 weeks before the expiry date, then it is not possible to |
16 |
> > > keep the same date. |
17 |
> > > |
18 |
> > > Example: The key will expire at 2018-12-31, so it must be renewed |
19 |
> > > at 2018-12-17 or earlier. This will make it impossible to keep |
20 |
> > > the same month and day (unless one would reset it to 2019-12-31, |
21 |
> > > which is only one year though). |
22 |
> > > |
23 |
> > > So please, make it something like 2 years + 3 months. |
24 |
> > |
25 |
> > option a) |
26 |
> > 2 years + N: |
27 |
> > 2 weeks <= N <= 3 months. |
28 |
> > |
29 |
> > option b) |
30 |
> > Change the wording to be 'at most 2 years' instead of 'exactly 2 |
31 |
> > years'. |
32 |
> |
33 |
> That *is* the wording. |
34 |
> |
35 |
> > Separately: |
36 |
> > Is two weeks enough time for a new key distribution to users? |
37 |
> |
38 |
> I originally wanted to specify one month but k_f insisted on something |
39 |
> shorter. 2 weeks were the compromise we agreed on. That said, I'd |
40 |
> say weekly 'gpg --refresh' is what we should recommend as the bare |
41 |
> minimum. |
42 |
> |
43 |
> That said, the point of two weeks is mostly to give us time to remind |
44 |
> developers that their key is expiring and to give them time to |
45 |
> actually read their mail and do it before it actually expires. |
46 |
> |
47 |
|
48 |
I have gkeys spec-check start warning at 30 days, and it has been my |
49 |
experience that often it only gets renewed last minute (depends on how |
50 |
active the developer is. As it is one of those things that gets put |
51 |
off thinking there is still lots of time... But also, many of those had |
52 |
keys that did not meet the spec requirements. |
53 |
|
54 |
-- |
55 |
Brian Dolbec <dolsen> |