1 |
W dniu pią, 06.07.2018 o godzinie 06∶08 +0000, użytkownik Robin H. |
2 |
Johnson napisał: |
3 |
> On Fri, Jul 06, 2018 at 07:43:56AM +0200, Ulrich Mueller wrote: |
4 |
> > > > > > > On Thu, 5 Jul 2018, Michał Górny wrote: |
5 |
> > > Replace the disjoint 'minimum' and 'recommendation' for expiration |
6 |
> > > with a single requirement. Make it 2 years. Also, remove disjoint |
7 |
> > > expiration recommendation for the primary key and subkeys since many |
8 |
> > > developers fail at implementing that anyway. |
9 |
> > |
10 |
> > Still NACK. If expiration is exactly 2 years and renewal must happen |
11 |
> > 2 weeks before the expiry date, then it is not possible to keep the |
12 |
> > same date. |
13 |
> > |
14 |
> > Example: The key will expire at 2018-12-31, so it must be renewed at |
15 |
> > 2018-12-17 or earlier. This will make it impossible to keep the same |
16 |
> > month and day (unless one would reset it to 2019-12-31, which is only |
17 |
> > one year though). |
18 |
> > |
19 |
> > So please, make it something like 2 years + 3 months. |
20 |
> |
21 |
> option a) |
22 |
> 2 years + N: |
23 |
> 2 weeks <= N <= 3 months. |
24 |
> |
25 |
> option b) |
26 |
> Change the wording to be 'at most 2 years' instead of 'exactly 2 years'. |
27 |
|
28 |
That *is* the wording. |
29 |
|
30 |
> Separately: |
31 |
> Is two weeks enough time for a new key distribution to users? |
32 |
|
33 |
I originally wanted to specify one month but k_f insisted on something |
34 |
shorter. 2 weeks were the compromise we agreed on. That said, I'd say |
35 |
weekly 'gpg --refresh' is what we should recommend as the bare minimum. |
36 |
|
37 |
That said, the point of two weeks is mostly to give us time to remind |
38 |
developers that their key is expiring and to give them time to actually |
39 |
read their mail and do it before it actually expires. |
40 |
|
41 |
-- |
42 |
Best regards, |
43 |
Michał Górny |