Gentoo Archives: gentoo-nfp

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-nfp@l.g.o, Alec Warner <antarus@g.o>
Subject: Re: [gentoo-nfp] Developer Crypto Hardware (AGM)
Date: Wed, 22 Aug 2018 12:53:12
Message-Id: 2f76e66e-8658-282c-8fbf-1fb55619af2f@gentoo.org
In Reply to: Re: [gentoo-nfp] Developer Crypto Hardware (AGM) by Alec Warner
1 On 08/22/2018 02:26 PM, Alec Warner wrote:
2 > do you have any ideas on how we
3 > can improve the security of our GPG infrastructure?
4
5 (i) Using it more in our operations to begin with, including but not
6 limited to [bugzilla]
7
8 (ii) Increase [WoT connectivity] / more fingerprint exchanges
9
10 (iii) more awareness and use of OpenPGP in general amongst developers,
11 i.e it becomes part of routine to secure communications (how many are
12 signing their emails in this discussion?) and perform integrity
13 verification more extensively. Maybe we should start documenting the
14 results of signature verification as part of package bump commit
15 messages? Or do devs simply bump without verifying integrity of the
16 upstream package to begin with? We should likely also work with
17 upstreams that do not provide signatures for release tarballs to
18 actually do so.
19
20 References:
21 [bugzilla]
22 https://bugs.gentoo.org/624262
23
24 [WoT connectivity]
25 https://download.sumptuouscapital.com/gentoo/openpgp-wot/gentoo-devs.pdf
26
27
28 --
29 Kristian Fiskerstrand
30 OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
31 fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies

Subject Author
Re: [gentoo-nfp] Developer Crypto Hardware (AGM) Kristian Fiskerstrand <k_f@g.o>