1 |
On 08/22/2018 02:26 PM, Alec Warner wrote: |
2 |
> do you have any ideas on how we |
3 |
> can improve the security of our GPG infrastructure? |
4 |
|
5 |
(i) Using it more in our operations to begin with, including but not |
6 |
limited to [bugzilla] |
7 |
|
8 |
(ii) Increase [WoT connectivity] / more fingerprint exchanges |
9 |
|
10 |
(iii) more awareness and use of OpenPGP in general amongst developers, |
11 |
i.e it becomes part of routine to secure communications (how many are |
12 |
signing their emails in this discussion?) and perform integrity |
13 |
verification more extensively. Maybe we should start documenting the |
14 |
results of signature verification as part of package bump commit |
15 |
messages? Or do devs simply bump without verifying integrity of the |
16 |
upstream package to begin with? We should likely also work with |
17 |
upstreams that do not provide signatures for release tarballs to |
18 |
actually do so. |
19 |
|
20 |
References: |
21 |
[bugzilla] |
22 |
https://bugs.gentoo.org/624262 |
23 |
|
24 |
[WoT connectivity] |
25 |
https://download.sumptuouscapital.com/gentoo/openpgp-wot/gentoo-devs.pdf |
26 |
|
27 |
|
28 |
-- |
29 |
Kristian Fiskerstrand |
30 |
OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net |
31 |
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3 |