Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 659850 - ultrabug: non-conformant OpenPGP keys
Summary: ultrabug: non-conformant OpenPGP keys
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Developer account issues (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Ultrabug
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 659842
  Show dependency tree
 
Reported: 2018-07-02 13:20 UTC by Michał Górny
Modified: 2018-08-01 19:27 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-07-02 13:20:41 UTC
Your key does not meet minimal requirements set forth in GLEP 63 [1].  glep63-check [2] reports:

2A24124BB658FA13 [Ultrabug (Gentoo GPG Key) <ultrabug@ultrabug.net>] [W] algo:dsa:discouraged 4096-bit RSA key is recommended (DSA is being used)
2A24124BB658FA13 [Ultrabug (Gentoo GPG Key) <ultrabug@ultrabug.net>] [E] expire:none No expiration date on public key (<3 years recommended, 5 years max)
2A24124BB658FA13 [Ultrabug (Gentoo GPG Key) <ultrabug@ultrabug.net>] [E] subkey:none Having a dedicated signing subkey is required
2A24124BB658FA13 [Ultrabug (Gentoo GPG Key) <ultrabug@ultrabug.net>] [W] uid:nogentoo @gentoo.org e-mail not in key UIDs

Please transition to a new key (2048- or 4096-bit RSA) and revoke the old one.  While at it, please follow the *recommended* specs in GLEP 63 [1], and make sure to handle the key replacement procedure correctly, see e.g. [3].  Please also include your @gentoo.org e-mail in the UIDs of the new key to make it easier for others to find you.

[1]:https://www.gentoo.org/glep/glep-0063.html
[2]:https://github.com/mgorny/glep63-check
[3]:https://www.apache.org/dev/key-transition.html
Comment 1 Ultrabug gentoo-dev 2018-07-21 21:29:23 UTC
new key F30FAFEE3BD598228B24CB121A3A8C89C56D610B uploaded and LDAP updated!

hope I didn't screw up, thanks