1 |
On Thu, Aug 03, 2017 at 01:13:13PM +0200, Ulrich Mueller wrote: |
2 |
> As discussed with prometheanfire in #gentoo-trustees, I am suggesting |
3 |
> the following as an item for the (September?) Trustees meeting. |
4 |
> |
5 |
> Apparently, the Foundation only has a list of PGP key IDs in |
6 |
> https://wiki.gentoo.org/wiki/Foundation:Member_List. Even worse, most |
7 |
> IDs listed there are only 32 bit IDs, providing no security at all. |
8 |
> |
9 |
> I would like to ask the Foundation to keep a list with the (160 bit) |
10 |
> PGP fingerprints of its members. (For developers, this information |
11 |
> should be readily available in LDAP.) |
12 |
> |
13 |
> Ulrich |
14 |
|
15 |
Great idea. I'm willing to update this information: do I need anything beyond |
16 |
LDAP access + keyserver reference to do this? I also noticed it hasn't been |
17 |
updated since July; do we have a file somewhere that has non-developer members |
18 |
to cross-reference? |
19 |
|
20 |
Changing from Key ID to fingerprint shouldn't be a problem; it'll just |
21 |
be a wider table. |
22 |
|
23 |
-- |
24 |
Daniel Campbell - Gentoo Developer, Trustee, Treasurer |
25 |
OpenPGP Key: 0x1EA055D6 @ hkp://keys.gnupg.net |
26 |
fpr: AE03 9064 AE00 053C 270C 1DE4 6F7A 9091 1EA0 55D6 |