Gentoo Archives: gentoo-dev

From: Joshua Kinard <kumba@g.o>
To: gentoo-dev@l.g.o, "Michał Górny" <mgorny@g.o>
Cc: robbat2@g.o
Subject: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory
Date: Wed, 04 Jul 2018 22:48:43
Message-Id: bbe8a36c-aa92-88ea-9fd0-d3441d1e428e@gentoo.org
In Reply to: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory by "Michał Górny"
1 On 7/4/2018 5:24 PM, Michał Górny wrote:
2 > W dniu śro, 04.07.2018 o godzinie 23∶05 +0200, użytkownik Ulrich Mueller
3 > napisał:
4 >>>>>>> On Wed, 4 Jul 2018, Michał Górny wrote:
5 >>> -3. Key expiry: 5 years maximum
6 >>> +3. Key expiration:
7 >>> +
8 >>> + a. Primary key: 3 years maximum
9 >>> +
10 >>> + b. Gentoo subkey: 1 year maximum
11 >>
12 >> What problem are you trying to solve here?
13 >>
14 >
15 > The problem of having unjustified double standards.
16
17 IMHO, one year for a signing subkey is too short. I see no problem with three
18 years like the primary key. Especially since people will typically just change
19 the expiration and advance it the minimum number of years, lather, rinse, and
20 repeat. It's a solution looking for a problem.
21
22 NAK on this.
23
24 --
25 Joshua Kinard
26 Gentoo/MIPS
27 kumba@g.o
28 rsa6144/5C63F4E3F5C6C943 2015-04-27
29 177C 1972 1FB8 F254 BAD0 3E72 5C63 F4E3 F5C6 C943
30
31 "The past tempts us, the present confuses us, the future frightens us. And our
32 lives slip away, moment by moment, lost in that vast, terrible in-between."
33
34 --Emperor Turhan, Centauri Republic

Replies