Gentoo Archives: gentoo-project

From: Daniel Campbell <zlg@g.o>
To: gentoo-project@l.g.o
Subject: Re: [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications?
Date: Tue, 10 Jan 2017 07:21:35
Message-Id: 7f531d55-b973-6242-1497-13fda4f567bf@gentoo.org
In Reply to: Re: [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications? by Kristian Fiskerstrand
1 On 01/04/2017 11:47 AM, Kristian Fiskerstrand wrote:
2 > On 01/04/2017 06:58 PM, Kristian Fiskerstrand wrote:
3 >> With increasing focus on security in various contexts I'd like to
4 >> propose that we start discussing catching up with other distributions
5 >> and start requiring new developers' OpenPGP keyblocks to have at least
6 >> two signatures from existing developers before applications can be
7 >> made[A]. Amongst other things This helps building the Gentoo Web of Trust.
8 >>
9 >
10 > Since the qa-report one is down, this is the current Gentoo WoT:
11 > https://download.sumptuouscapital.com/gentoo/gentoo-devs.png
12 >
13
14 Strange, I don't see myself or chutzpah on that image, but we exchanged
15 keys in person and signed each other's keys. Is there something off in
16 the relation of our keys?
17
18 --
19 Daniel Campbell - Gentoo Developer
20 OpenPGP Key: 0x1EA055D6 @ hkp://keys.gnupg.net
21 fpr: AE03 9064 AE00 053C 270C 1DE4 6F7A 9091 1EA0 55D6

Attachments

File name MIME type
signature.asc application/pgp-signature

Replies