public inbox for gentoo-dev@lists.gentoo.org
 help / color / mirror / Atom feed
From: Stefan Behte <craig@gentoo.org>
To: gentoo-dev@lists.gentoo.org
Subject: Re: [gentoo-dev] RFC: Gentoo GPG key policies
Date: Wed, 20 Feb 2013 01:34:57 +0100	[thread overview]
Message-ID: <51241A31.7070005@gentoo.org> (raw)
In-Reply-To: <robbat2-20130218T224715-868658579Z@orbis-terrarum.net>

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Just some quick thoughts on this:

> 2. root key & signing subkey of EITHER: 2.1. DSA, 1024 or 2048 bits
> 2.2. RSA, >=2048 bits

I don't really agree. From your own link
(https://we.riseup.net/riseuplabs+paow/openpgp-best-practices#dont-use-pgp-mit-edu):

"Many people still have 1024-bit DSA keys. You really should consider
transitioning to a stronger bit-length and hashing algo. This size is
known now to be within Well Funded Organizations’ ability to break.
Also the hashing algo is showing its age."

Some more opinions from different studies: keylength.com.

1024 DSA keys seem pretty short to me. Surely it might be inconvenient
for some (2-3? please write a mail here!) people with smart cards. But
then again, especially people going through the hell of using a
physical token would understand the need for decent crypto. ;)

I think key rotation is overdoing it and pretty annoying. Better use a
non-annoying, long key from the start?

> 4. If you intend to sign on a slow alternative-arch, you may find 
> adding a DSA1024 subkey significantly speeds up the signing.

How slow is that actually? Does it make signing very inconvenient?
Maybe someone with a slow machine can write about performance and the
"annoyence-factor"... ;)

Best regards,

Craig
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.19 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iEYEARECAAYFAlEkGjEACgkQuiczp+KMe7SkWACgrioKjFkuPwJOxUCmhGKcC4Ib
uyQAmwUfM7u3x6sD1rmQJrEjjUu7C6ok
=OyqH
-----END PGP SIGNATURE-----


  parent reply	other threads:[~2013-02-20  0:35 UTC|newest]

Thread overview: 44+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2013-02-18 23:27 [gentoo-dev] RFC: Gentoo GPG key policies Robin H. Johnson
2013-02-18 23:41 ` Robin H. Johnson
2013-02-19  3:36   ` Kent Fredric
2013-02-19  4:09     ` Robin H. Johnson
2013-02-19  4:46       ` Brian Dolbec
2013-02-19  7:38       ` Kent Fredric
2013-02-19 15:52         ` Alec Warner
2013-02-19  4:25     ` [gentoo-dev] " Ryan Hill
2013-02-19  6:51 ` [gentoo-dev] " Eray Aslan
2013-02-20  0:34 ` Stefan Behte [this message]
2013-02-20  3:12   ` Robin H. Johnson
2013-02-20  6:32     ` Alec Warner
2013-02-20 17:05       ` Robin H. Johnson
2013-02-20 18:41 ` James Cloos
2013-02-20 19:36   ` Robin H. Johnson
2013-02-20 20:22     ` Andreas K. Huettel
2013-02-20 21:31       ` Robin H. Johnson
2013-02-20 20:38 ` Luis Ressel
2013-02-20 21:37   ` Robin H. Johnson
2013-02-20 21:55     ` Luis Ressel
2013-02-21  9:09 ` Michał Górny
2013-02-21  9:41   ` Markos Chandras
2013-02-26 10:10 ` grozin
2013-02-27 15:12   ` Luis Ressel
2013-02-27 19:04     ` Robin H. Johnson
2013-02-27 20:27       ` Alec Warner
2013-03-14  3:50       ` grozin
2013-03-14  7:19         ` justin
2013-03-14  9:12         ` Robin H. Johnson
2013-03-14 15:26           ` Zac Medico
2013-03-14 16:14             ` Michał Górny
2013-03-14 16:30               ` Zac Medico
2013-03-15  0:58                 ` Robin H. Johnson
2013-03-15  1:01               ` Robin H. Johnson
2013-03-15  2:32                 ` Michael Mol
2013-03-15  3:18                   ` Robin H. Johnson
2013-03-15  3:33                     ` Michael Mol
2013-03-15  5:12                       ` Robin H. Johnson
2013-03-15  4:44                     ` Michał Górny
2013-03-15  5:01                       ` Robin H. Johnson
2013-03-22  6:37           ` grozin
2013-03-22  8:36             ` Panagiotis Christopoulos
2013-03-22  8:47               ` grozin
2013-03-22 14:19                 ` David Abbott

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=51241A31.7070005@gentoo.org \
    --to=craig@gentoo.org \
    --cc=gentoo-dev@lists.gentoo.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox