Gentoo Archives: gentoo-portage-dev

From: "Michał Górny" <mgorny@g.o>
To: gentoo-portage-dev@l.g.o
Cc: "Michał Górny" <mgorny@g.o>
Subject: [gentoo-portage-dev] [PATCH 2/2] repos.conf: Default to using Gentoo keyservers
Date: Fri, 05 Jul 2019 05:19:38
Message-Id: 20190705051925.5070-2-mgorny@gentoo.org
In Reply to: [gentoo-portage-dev] [PATCH 1/2] sync: Split key refresh into explicit WKD/keyserver phases by "Michał Górny"
1 Default to using hkps://keys.gentoo.org which are guaranteed to hold
2 the newest copies of Gentoo keys, are secured against key poisoning
3 and are more reliable than SKS.
4
5 Signed-off-by: Michał Górny <mgorny@g.o>
6 ---
7 cnf/repos.conf | 1 +
8 1 file changed, 1 insertion(+)
9
10 diff --git a/cnf/repos.conf b/cnf/repos.conf
11 index e84840bf2..2d73b3e35 100644
12 --- a/cnf/repos.conf
13 +++ b/cnf/repos.conf
14 @@ -10,6 +10,7 @@ sync-rsync-verify-jobs = 1
15 sync-rsync-verify-metamanifest = yes
16 sync-rsync-verify-max-age = 24
17 sync-openpgp-key-path = /usr/share/openpgp-keys/gentoo-release.asc
18 +sync-openpgp-keyserver = hkps://keys.gentoo.org
19 sync-openpgp-key-refresh-retry-count = 40
20 sync-openpgp-key-refresh-retry-overall-timeout = 1200
21 sync-openpgp-key-refresh-retry-delay-exp-base = 2
22 --
23 2.22.0

Replies