Gentoo Archives: gentoo-dev

From: Brian Dolbec <dolsen@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH v3 10/12] glep-0063: Make 2-yearly expiration term mandatory
Date: Fri, 06 Jul 2018 07:25:48
Message-Id: 20180706002535.06a6e937@professor-x
In Reply to: Re: [gentoo-dev] [PATCH v3 10/12] glep-0063: Make 2-yearly expiration term mandatory by "Michał Górny"
1 On Fri, 06 Jul 2018 08:18:32 +0200
2 Michał Górny <mgorny@g.o> wrote:
3
4 > W dniu pią, 06.07.2018 o godzinie 06∶08 +0000, użytkownik Robin H.
5 > Johnson napisał:
6 > > On Fri, Jul 06, 2018 at 07:43:56AM +0200, Ulrich Mueller wrote:
7 > > > > > > > > On Thu, 5 Jul 2018, Michał Górny wrote:
8 > > > > Replace the disjoint 'minimum' and 'recommendation' for
9 > > > > expiration with a single requirement. Make it 2 years. Also,
10 > > > > remove disjoint expiration recommendation for the primary key
11 > > > > and subkeys since many developers fail at implementing that
12 > > > > anyway.
13 > > >
14 > > > Still NACK. If expiration is exactly 2 years and renewal must
15 > > > happen 2 weeks before the expiry date, then it is not possible to
16 > > > keep the same date.
17 > > >
18 > > > Example: The key will expire at 2018-12-31, so it must be renewed
19 > > > at 2018-12-17 or earlier. This will make it impossible to keep
20 > > > the same month and day (unless one would reset it to 2019-12-31,
21 > > > which is only one year though).
22 > > >
23 > > > So please, make it something like 2 years + 3 months.
24 > >
25 > > option a)
26 > > 2 years + N:
27 > > 2 weeks <= N <= 3 months.
28 > >
29 > > option b)
30 > > Change the wording to be 'at most 2 years' instead of 'exactly 2
31 > > years'.
32 >
33 > That *is* the wording.
34 >
35 > > Separately:
36 > > Is two weeks enough time for a new key distribution to users?
37 >
38 > I originally wanted to specify one month but k_f insisted on something
39 > shorter. 2 weeks were the compromise we agreed on. That said, I'd
40 > say weekly 'gpg --refresh' is what we should recommend as the bare
41 > minimum.
42 >
43 > That said, the point of two weeks is mostly to give us time to remind
44 > developers that their key is expiring and to give them time to
45 > actually read their mail and do it before it actually expires.
46 >
47
48 I have gkeys spec-check start warning at 30 days, and it has been my
49 experience that often it only gets renewed last minute (depends on how
50 active the developer is. As it is one of those things that gets put
51 off thinking there is still lots of time... But also, many of those had
52 keys that did not meet the spec requirements.
53
54 --
55 Brian Dolbec <dolsen>