1 |
On Sun, Nov 26, 2017 at 4:06 PM, Daniel Campbell <zlg@g.o> wrote: |
2 |
> On Thu, Aug 03, 2017 at 01:13:13PM +0200, Ulrich Mueller wrote: |
3 |
>> As discussed with prometheanfire in #gentoo-trustees, I am suggesting |
4 |
>> the following as an item for the (September?) Trustees meeting. |
5 |
>> |
6 |
>> Apparently, the Foundation only has a list of PGP key IDs in |
7 |
>> https://wiki.gentoo.org/wiki/Foundation:Member_List. Even worse, most |
8 |
>> IDs listed there are only 32 bit IDs, providing no security at all. |
9 |
>> |
10 |
>> I would like to ask the Foundation to keep a list with the (160 bit) |
11 |
>> PGP fingerprints of its members. (For developers, this information |
12 |
>> should be readily available in LDAP.) |
13 |
>> |
14 |
>> Ulrich |
15 |
> |
16 |
> Great idea. I'm willing to update this information: do I need anything beyond |
17 |
> LDAP access + keyserver reference to do this? I also noticed it hasn't been |
18 |
> updated since July; do we have a file somewhere that has non-developer members |
19 |
> to cross-reference? |
20 |
|
21 |
Not that I am aware, their email is stored somewhere, Robin should know. |
22 |
I keep a local copy but its not posted anywhere so the spam bots don't get them. |
23 |
|
24 |
> |
25 |
> Changing from Key ID to fingerprint shouldn't be a problem; it'll just |
26 |
> be a wider table. |
27 |
> |
28 |
> -- |
29 |
> Daniel Campbell - Gentoo Developer, Trustee, Treasurer |
30 |
> OpenPGP Key: 0x1EA055D6 @ hkp://keys.gnupg.net |
31 |
> fpr: AE03 9064 AE00 053C 270C 1DE4 6F7A 9091 1EA0 55D6 |
32 |
|
33 |
|
34 |
|
35 |
-- |
36 |
David Abbott (dabbott) |
37 |
Gentoo Foundation Secretary |
38 |
http://dev.gentoo.org/~dabbott/ |