1 |
On 5/12/20 1:24 AM, Michał Górny wrote: |
2 |
> W dniu pon, 11.05.2020 o godzinie 20∶20 -0400, użytkownik Aisha Tammy |
3 |
> napisał: |
4 |
>> Hi devs@, |
5 |
>> Seems like for some reason the gentoo.org does not publish the |
6 |
>> gpg public keys of the senders, even though it is signed correctly. |
7 |
> |
8 |
|
9 |
Oh, very sorry if I came out that way. I wasn't being passive aggressive. |
10 |
Sometimes I write things the wrong way. I should have definitely written |
11 |
it better :( |
12 |
|
13 |
>> |
14 |
>> Just wanted to know why the devs are required to use gpg keys, glep63 |
15 |
>> [1] |
16 |
>> but even when the server has the public keys, they aren't published |
17 |
>> properly. |
18 |
>> |
19 |
>> From a proper security perspective, I would have though something |
20 |
>> like WKD[2] would have been implemented on the server side for |
21 |
>> automated |
22 |
>> authentication. |
23 |
> |
24 |
> WKD is implemented and I don't know a single case where it wouldn't |
25 |
> work. If it doesn't work for you, then I dare say it's more likely to |
26 |
> be a problem with your setup. However, if it's a problem on our end, |
27 |
> I'd really appreciate a bug report before calling us retarded. |
28 |
> |
29 |
> In fact, the link you've posted actually lists gentoo.org as one |
30 |
> of the few organizations implementing WKD. |
31 |
> |
32 |
Oh my, now I really feel bad. I definitely don't want to call anyone retarded |
33 |
or any such words. I never like to use very strong words such as those. |
34 |
While I agree I should've worded it better, please don't make it look like |
35 |
I am name calling and insulting everybody, and being a jerk in general. |
36 |
So I would really love it if you don't put those words in my mouth for me. |
37 |
|
38 |
I actually thought that this was the proper channel to ask for these things. |
39 |
Maybe the dev mailing list was not the proper place, I didn't think about |
40 |
it being perceived as accusatory. I mostly thought it would be related to |
41 |
a bug or an oversight. |
42 |
|
43 |
|
44 |
It is 110% possible for my setup to have mistakes. I even said as much. |
45 |
I would love to fix that. |
46 |
|
47 |
Indeed, because the link actually mentioned that gentoo.org has setup |
48 |
WKD that is why I was a bit surprised when some of the keys were not found. |
49 |
|
50 |
>> Why do you claim that? How did you verify it? |
51 |
|
52 |
I am using enigmail + thunderbird which I thought would have should be making |
53 |
proper requests for the WKD keys and it reported that for some of the emails |
54 |
sent from devs they keys were not found on the keyserver. |
55 |
|
56 |
I will be doing a lot more debugging today and will try to see where things went |
57 |
wrong on my end. Now that you say it has been implemented properly, I feel that |
58 |
I should do a lot more work on my side :) |
59 |
|
60 |
>> |
61 |
>> Maybe I am missing something about how to verify the keys of the |
62 |
>> maintainers |
63 |
>> who are sending announcements but it irks me a teensy bit when i have |
64 |
>> signed |
65 |
>> mails and I can't ~~trust~~ verify the signatures. |
66 |
>> |
67 |
>> |
68 |
> |
69 |
> You are missing that WKD does not provide authentication, and if it |
70 |
> were, it would be considered thoroughly insecure. Authentication |
71 |
> in OpenPGP is generally provided via web of trust. For Gentoo |
72 |
> developers, you can also use our Authority Keys [3,4,5]. |
73 |
> |
74 |
|
75 |
This is actually an interesting point. It might be better to discuss that over irc. |
76 |
The web of trust is actually a topic which I have some weird thoughts over. |
77 |
|
78 |
Best, |
79 |
Aisha |
80 |
|
81 |
>> |
82 |
>> [1] |
83 |
>> https://wiki.gentoo.org/wiki/Project:Infrastructure/Generating_GLEP_63_based_OpenPGP_keys |
84 |
>> [2] https://wiki.gnupg.org/WKD |
85 |
> |
86 |
> [3] https://www.gentoo.org/downloads/signatures/ |
87 |
> [4] https://www.gentoo.org/glep/glep-0079.html |
88 |
> [5] https://wiki.gentoo.org/wiki/Project:Infrastructure/Authority_Keys |
89 |
> |
90 |
> |