Gentoo Archives: gentoo-dev

From: Marc Schiffbauer <mschiff@g.o>
To: gentoo-dev@l.g.o
Subject: Re: [gentoo-dev] validity of manifest signing key
Date: Sun, 26 Jun 2011 14:23:37
Message-Id: 20110626142117.GD2127@lisa.schiffbauer.lan
In Reply to: Re: [gentoo-dev] validity of manifest signing key by Dane Smith
1 * Dane Smith schrieb am 25.03.11 um 12:35 Uhr:
2 > -----BEGIN PGP SIGNED MESSAGE-----
3 > Hash: SHA1
4 >
5 > On 03/25/2011 05:47 AM, Thomas Kahle wrote:
6 > > Hi,
7 > >
8 > > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that
9 > > the validity should be <6 month. What is the protocol when the expiry
10 > > date is approaching?
11 > >
12 > > -) Extend expiry date and upload again?
13 > > -) Create new key (and sign with ?? ) ?
14 > >
15 > > Cheers,
16 > > Thomas
17 > >
18 >
19 > Traditionally you start using your new key the day your old key expires.
20
21 Do you really mean a new key? This is not required. You can extend
22 the validity once you come close the expiry date (or do it after the
23 key has expired).
24
25 -Marc
26 --
27 8AAC 5F46 83B4 DB70 8317 3723 296C 6CCA 35A6 4134