Gentoo Archives: gentoo-dev

From: Marc Schiffbauer <mschiff@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory
Date: Thu, 05 Jul 2018 15:37:23
Message-Id: 20180705153711.GD15485@schiffbauer.net
In Reply to: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory by Matthias Maier
1 * Matthias Maier schrieb am 05.07.18 um 15:51 Uhr:
2 >
3 > On Thu, Jul 5, 2018, at 08:36 CDT, Michał Górny <mgorny@g.o> wrote:
4 >
5 > > That said, I'm open to using a different recommendation, e.g. 2 years
6 > > as in riseup [1]. I suppose having the same time for both primary key
7 > > and subkeys would make the spec simpler, and many developers are
8 > > mistaking expiration times (as specified now) anyway.
9 > >
10 > > [1]:https://riseup.net/en/security/message-security/openpgp/best-practices#use-an-expiration-date-less-than-two-years
11 >
12 > Make it at most 2, 3, (or as it has been so far 5) years for both
13 > primary and subkeys.
14
15 +1 for 5 years or at least 3.
16
17 Having to renew/edit the key each year seems crazy to me.
18
19 I have my primary key offline only, so renewing/editing it is a much
20 more time consuming matter than if I had my primary key always with me
21 which I consider a bad idea because you do not need to.
22
23
24 -Marc
25
26 --
27 0xCA3E7BF67F979BE5 - F7FB 78F7 7CC3 79F6 DF07
28 6E9E CA3E 7BF6 7F97 9BE5

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies