public inbox for gentoo-project@lists.gentoo.org
 help / color / mirror / Atom feed
* [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications?
@ 2017-01-04 17:58 Kristian Fiskerstrand
  2017-01-04 18:55 ` Rich Freeman
                   ` (6 more replies)
  0 siblings, 7 replies; 90+ messages in thread
From: Kristian Fiskerstrand @ 2017-01-04 17:58 UTC (permalink / raw
  To: gentoo-project


[-- Attachment #1.1: Type: text/plain, Size: 1151 bytes --]

With increasing focus on security in various contexts I'd like to
propose that we start discussing catching up with other distributions
and start requiring new developers' OpenPGP keyblocks to have at least
two signatures from existing developers before applications can be
made[A]. Amongst other things This helps building the Gentoo Web of Trust.


E.g [Debian] has the following requirement: "To maintain the strong Web
of Trust that connects all Debian Developers, Applicants need to
identify themselves by providing an OpenPGP key that is signed by at
least two official Developers. To further ensure their identity,
signatures by other people (who do not need to be DDs, but should be
well connected in the overall Web of Trust) are strongly recommended."


References:

[Debian] https://www.debian.org/devel/join/nm-checklist


Endnotes:

[A] Possibly with an opt-out by application to council, in case there
are certain regions where this is considered non-feasable etc.

-- 
Kristian Fiskerstrand
OpenPGP keyblock reachable at hkp://pool.sks-keyservers.net
fpr:94CB AFDD 3034 5109 5618 35AA 0B7F 8B60 E3ED FAE3


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 488 bytes --]

^ permalink raw reply	[flat|nested] 90+ messages in thread

end of thread, other threads:[~2017-01-10 11:45 UTC | newest]

Thread overview: 90+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-01-04 17:58 [gentoo-project] Require OpenPGP signatures from existing devs on new developer applications? Kristian Fiskerstrand
2017-01-04 18:55 ` Rich Freeman
2017-01-05 18:00   ` William L. Thomson Jr.
2017-01-05 18:19     ` Rich Freeman
2017-01-05 18:40       ` William L. Thomson Jr.
2017-01-05 18:47         ` Yury German
2017-01-05 19:13           ` William L. Thomson Jr.
2017-01-05 19:23             ` Matthew Thode
2017-01-05 19:35               ` Dirkjan Ochtman
2017-01-05 19:41                 ` [gentoo-project] OT " William L. Thomson Jr.
2017-01-05 22:28                 ` [gentoo-project] " Raymond Jennings
2017-01-05 22:39                   ` Yury German
2017-01-05 22:48                     ` M. J. Everitt
2017-01-06  6:34                     ` Kent Fredric
2017-01-06  8:18                       ` Michał Górny
2017-01-06  9:00                         ` Kent Fredric
2017-01-06  9:14                           ` Kristian Fiskerstrand
2017-01-06 21:49                             ` Kent Fredric
2017-01-06 16:15                       ` Rich Freeman
2017-01-06 16:30                         ` Yury German
2017-01-06 17:39                           ` Mart Raudsepp
2017-01-06 18:05                             ` Aaron W. Swenson
2017-01-06 18:17                             ` Rich Freeman
2017-01-06 18:48                               ` Mart Raudsepp
2017-01-06 20:38                             ` William L. Thomson Jr.
2017-01-06 21:01                               ` Rich Freeman
2017-01-06 21:08                                 ` William L. Thomson Jr.
2017-01-06 21:16                                   ` Rich Freeman
2017-01-06 21:49                                     ` William L. Thomson Jr.
2017-01-06 22:22                                       ` Kristian Fiskerstrand
2017-01-07  2:10                                         ` William L. Thomson Jr.
2017-01-07  3:27                                         ` M. J. Everitt
2017-01-07  4:08                                           ` Rich Freeman
2017-01-07  4:21                                             ` M. J. Everitt
2017-01-06 22:48                                       ` Kent Fredric
2017-01-06 23:01                                         ` Rich Freeman
2017-01-07  3:29                                           ` M. J. Everitt
2017-01-07  2:02                                         ` William L. Thomson Jr.
2017-01-06 23:00                                       ` nado
2017-01-10  6:41                                       ` Daniel Campbell
2017-01-06 18:48                         ` Michał Górny
2017-01-05 22:40                   ` Kristian Fiskerstrand
2017-01-05 22:44                     ` Raymond Jennings
2017-01-05 22:46                       ` Kristian Fiskerstrand
2017-01-05 22:50                   ` Rich Freeman
2017-01-05 23:00                     ` Raymond Jennings
2017-01-05 23:09                       ` Kristian Fiskerstrand
2017-01-05 23:29                         ` Raymond Jennings
2017-01-05 23:44                       ` Rich Freeman
2017-01-05 23:56                         ` Raymond Jennings
2017-01-04 19:12 ` Michał Górny
2017-01-04 20:47   ` Kristian Fiskerstrand
2017-01-04 21:17     ` Michał Górny
2017-01-04 21:27       ` Kristian Fiskerstrand
2017-01-04 21:34         ` Rich Freeman
2017-01-04 21:36           ` Kristian Fiskerstrand
2017-01-04 21:58           ` Michał Górny
2017-01-05  9:34             ` Andreas K. Huettel
2017-01-05 13:15   ` Paweł Hajdan, Jr.
2017-01-05 13:46     ` Rich Freeman
2017-01-05 17:46       ` William L. Thomson Jr.
2017-01-05 18:02         ` Rich Freeman
2017-01-05 18:53           ` William L. Thomson Jr.
2017-01-05 19:15             ` Rich Freeman
2017-01-05 17:55     ` William L. Thomson Jr.
2017-01-05 18:04       ` Rich Freeman
2017-01-05 19:03         ` William L. Thomson Jr.
2017-01-10  7:12           ` Daniel Campbell
2017-01-10 11:44             ` Paweł Hajdan, Jr.
2017-01-10  6:54   ` Daniel Campbell
2017-01-04 19:43 ` Dirkjan Ochtman
2017-01-04 20:50   ` Kristian Fiskerstrand
2017-01-04 19:47 ` Kristian Fiskerstrand
2017-01-04 20:14   ` Michael Orlitzky
2017-01-04 20:59     ` Kristian Fiskerstrand
2017-01-04 21:19       ` Michael Orlitzky
2017-01-05 13:10         ` Paweł Hajdan, Jr.
2017-01-05 13:16           ` Michael Orlitzky
2017-01-04 21:02   ` Brian Evans
2017-01-10  7:21   ` Daniel Campbell
2017-01-10  9:38     ` Kristian Fiskerstrand
2017-01-10  9:39     ` Kristian Fiskerstrand
2017-01-04 20:00 ` Alice Ferrazzi
2017-01-04 21:06   ` Kristian Fiskerstrand
2017-01-04 20:46 ` Andrew Savchenko
2017-01-04 20:53   ` Kristian Fiskerstrand
2017-01-05 11:27     ` Ulrich Mueller
2017-01-04 21:26   ` Rich Freeman
2017-01-06  9:44 ` Aaron Bauman
2017-01-10  7:30   ` Daniel Campbell

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox