Gentoo Archives: gentoo-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-dev@l.g.o
Cc: Mike Gilbert <floppym@g.o>
Subject: Re: [gentoo-dev] [PATCH v2] glep-0063: Add section about the Gentoo keyserver
Date: Thu, 17 Dec 2020 19:27:52
Message-Id: fd080a346d4e8db7b090f235f8bfef71d4434d2b.camel@gentoo.org
In Reply to: [gentoo-dev] [PATCH v2] glep-0063: Add section about the Gentoo keyserver by Mike Gilbert
1 On Thu, 2020-12-17 at 13:12 -0500, Mike Gilbert wrote:
2 > Signed-off-by: Mike Gilbert <floppym@g.o>
3 > ---
4 >
5 > v2: Added "This upload is required in addition to uploading the SKS
6 > pool."
7 >
8 >  glep-0063.rst | 24 ++++++++++++++++++++----
9 >  1 file changed, 20 insertions(+), 4 deletions(-)
10 >
11 > diff --git a/glep-0063.rst b/glep-0063.rst
12 > index 82541bd..ec465db 100644
13 > --- a/glep-0063.rst
14 > +++ b/glep-0063.rst
15 > @@ -7,10 +7,10 @@ Author: Robin H. Johnson <robbat2@g.o>,
16 >          Michał Górny <mgorny@g.o>
17 >  Type: Standards Track
18 >  Status: Final
19 > -Version: 2.1
20 > +Version: 2.2
21 >  Created: 2013-02-18
22 > -Last-Modified: 2019-11-07
23 > -Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24
24 > +Last-Modified: 2020-12-17
25 > +Post-History: 2013-11-10, 2018-07-03, 2018-07-21, 2019-02-24, 2020-
26 > 12-17
27 >  Content-Type: text/x-rst
28 >  ---
29 >  
30 > @@ -28,6 +28,9 @@ OpenPGP key management policies for the Gentoo
31 > Linux distribution.
32 >  Changes
33 >  =======
34 >  
35 > +v2.2
36 > +  Added "Gentoo Keyserver" section under "Gentoo Infrastructure"
37 > chapter.
38 > +
39 >  v2.1
40 >    A requirement for an encryption key has been added, in order to
41 > extend
42 >    the GLEP beyond commit signing and into use of OpenPGP for dev-to-
43 > dev
44 > @@ -135,8 +138,11 @@ their primary key).
45 >  
46 >  5. Encrypted backup of your secret keys.
47 >  
48 > +Gentoo Infrstructure
49
50 T
51
52 > +====================
53 > +
54 >  Gentoo LDAP
55 > -===========
56 > +-----------
57 >  
58 >  All Gentoo developers must list the complete fingerprint for their
59 > primary
60 >  keys in the "``gpgfingerprint``" LDAP field. It must be exactly 40
61 > hex digits,
62 > @@ -147,6 +153,16 @@ of the fingerprint field. In any place that
63 > presently displays
64 >  the "``gpgkey``" field, the last 16 hex digits of the fingerprint
65 > should
66 >  be displayed instead.
67 >  
68 > +Gentoo Keyserver
69 > +----------------
70 > +
71 > +Gentoo infrastructure uses a keyserver that is isolated from the SKS
72 > pool.
73 > +This keyserver is restricted to accepting uploads from authorized
74 > Gentoo hosts.
75 > +A script is provided on dev.gentoo.org to allow developers to upload
76 > their
77 > +keys. This upload is required in addition to uploading to the SKS
78 > pool.
79 > +
80 > +``gpg --export KEYID | ssh dev.gentoo.org /usr/local/bin/openpgp-
81 > key-upload``
82 > +
83 >  Backwards Compatibility
84 >  =======================
85
86 Thank you for doing this.
87
88 That said, I'm wondering if we should keep SKS pool at all. Did anyone
89 have any success interacting with it lately? All my attempts of
90 fetching keys are resulting in server errors.
91
92 --
93 Best regards,
94 Michał Górny

Replies