public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: "Michał Górny" <mgorny@gentoo.org>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory
Date: Fri, 06 Jul 2018 13:38:58 +0200	[thread overview]
Message-ID: <1530877138.869.32.camel@gentoo.org> (raw)
In-Reply-To: <23359.21437.742622.219716@a1i15.kph.uni-mainz.de>

[-- Attachment #1: Type: text/plain, Size: 1766 bytes --]

W dniu pią, 06.07.2018 o godzinie 13∶34 +0200, użytkownik Ulrich Mueller
napisał:
> > > > > > On Fri, 6 Jul 2018, Marc Schiffbauer wrote:
> > * Michał Górny schrieb am 06.07.18 um 11:33 Uhr:
> > > If you don't see it for 5 years, how can you be sure that it is
> > > even still there?
> > Are you serious? Who tells you that I do not check from time to
> > time?
> > I am sure there will always be some scenario which makes a key
> > unacessible in some way. I do not disagree with that. Its a matter
> > of propability.
> > And for the worst case there is a revoke-Certificate which can be
> > used.
> 
> Note that the revocation certificate is still listed under
> recommendations only, so devs need not create one. Making this a
> requirement would be a real improvement, IMHO.

How are you going to enforce it?  I didn't make it a requirement because
we simply can't verify it being met.

> Instead, the GLEP draft is focusing on short expiration times.
> It won't help much if your compromised key will expire within one
> year, but you cannot revoke it.

You're conflating two unrelated concepts.  Expiration is not meant to
replace revocation, or in any way amend it.  Expiration is meant to
cover the case of both the key and the revocation certificate being
destroyed or otherwise becoming inaccessible.

> 
> Suggestions:
> - Change the minimum requirement for key expiry to at most 3 years
>   (which is what in version 1 is recommended).
> - Recommend at most 15 months of key expiry, to be renewed at least
>   2 weeks before the expiry date.
> - Make creation of a revocation certificate (and storing it in a place
>   separate from the key) mandatory.
> 
> Ulrich

-- 
Best regards,
Michał Górny

[-- Attachment #2: This is a digitally signed message part --]
[-- Type: application/pgp-signature, Size: 963 bytes --]

  reply	other threads:[~2018-07-06 11:39 UTC|newest]

Thread overview: 57+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2018-07-04 10:23 [gentoo-dev] [PATCH v2 00/11] Major GLEP 63 update Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 01/11] glep-0063: Use 'OpenPGP' as appropriate Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 02/11] glep-0063: RSAv4 -> OpenPGP v4 key format Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 03/11] glep-0063: Clarify dedicated signing subkey in minimal reqs Michał Górny
2018-07-04 10:35   ` Kristian Fiskerstrand
2018-07-04 10:54     ` Michał Górny
2018-07-04 10:58       ` Kristian Fiskerstrand
2018-07-04 10:59         ` Michał Górny
2018-07-04 11:01           ` Kristian Fiskerstrand
2018-07-04 17:06       ` Matthew Thode
2018-07-04 11:24     ` Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 04/11] glep-0063: Root key → primary key Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 05/11] glep-0063: Explain minimal & recommended sections Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 06/11] glep-0063: Change the recommended RSA key size to 2048 bits Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 07/11] glep-0063: Allow ECC, curve 25519 keys Michał Górny
2018-07-04 23:07   ` Joshua Kinard
2018-07-04 23:22     ` Kristian Fiskerstrand
2018-07-04 23:26       ` Kristian Fiskerstrand
2018-07-05  0:18       ` Joshua Kinard
2018-07-05  1:55         ` R0b0t1
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 08/11] glep-0063: Stop recommending DSA subkeys Michał Górny
2018-07-04 10:23 ` [gentoo-dev] [PATCH v2 09/11] glep-0063: Make recommended expiration terms mandatory Michał Górny
2018-07-04 21:05   ` Ulrich Mueller
2018-07-04 21:24     ` Michał Górny
2018-07-04 22:48       ` Joshua Kinard
2018-07-05 13:36         ` Michał Górny
2018-07-05 13:51           ` Matthias Maier
2018-07-05 15:37             ` Marc Schiffbauer
2018-07-05 18:25               ` Michał Górny
2018-07-06  9:08                 ` Marc Schiffbauer
2018-07-06  9:33                   ` Michał Górny
2018-07-06  9:48                     ` Marc Schiffbauer
2018-07-06 11:34                       ` Ulrich Mueller
2018-07-06 11:38                         ` Michał Górny [this message]
2018-07-06 11:41                         ` Kristian Fiskerstrand
2018-07-06 11:48                         ` Fabian Groffen
2018-07-06 11:00               ` Kristian Fiskerstrand
2018-07-06 14:21                 ` Marc Schiffbauer
2018-07-06 14:32                   ` Michał Górny
2018-07-05 18:24           ` William Hubbs
2018-07-05 18:28             ` Michał Górny
2018-07-05 18:56           ` Matthias Maier
2018-07-04 10:24 ` [gentoo-dev] [PATCH v2 10/11] glep-0063: Require renewal 2 weeks before expiration Michał Górny
2018-07-06  8:11   ` Manuel Rüger
2018-07-06  8:22     ` Michał Górny
2018-07-04 10:24 ` [gentoo-dev] [PATCH v2 11/11] glep-0063: Disallow using DSA keys Michał Górny
2018-07-04 10:28 ` [gentoo-dev] [PATCH v2 00/11] Major GLEP 63 update; full text Michał Górny
2018-07-04 20:26   ` Michał Górny
2018-07-04 21:12     ` Ulrich Mueller
2018-07-04 21:28       ` Michał Górny
2018-07-04 21:43         ` Kristian Fiskerstrand
2018-07-04 22:48           ` Kristian Fiskerstrand
2018-07-05 13:29           ` Michał Górny
2018-07-04 21:31       ` Robin H. Johnson
2018-07-04 21:44         ` Ulrich Mueller
2018-07-04 20:23 ` [gentoo-dev] [PATCH 12/13] glep-0063: 'Gentoo subkey' → 'Signing subkey' Michał Górny
2018-07-04 20:23   ` [gentoo-dev] [PATCH 13/13] glep-0063: Split out the signing subkey into a separation point Michał Górny

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=1530877138.869.32.camel@gentoo.org \
    --to=mgorny@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox