Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 659852 - jer: non-conformant OpenPGP key
Summary: jer: non-conformant OpenPGP key
Status: RESOLVED OBSOLETE
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Developer account issues (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Jeroen Roovers (RETIRED)
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 659842
  Show dependency tree
 
Reported: 2018-07-02 13:22 UTC by Michał Górny
Modified: 2018-08-01 19:59 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-07-02 13:22:18 UTC
Your key does not meet minimal requirements set forth in GLEP 63 [1].  glep63-check [2] reports:

556991B2A792A613 [Jeroen Edwin Roovers (JeR \x5c/ ReJ) <jer@xs4all.nl>] [E] algo:dsa:short DSA key too short (has 1024 bits, should be 2048 bits)
556991B2A792A613 [Jeroen Edwin Roovers (JeR \x5c/ ReJ) <jer@xs4all.nl>] [E] expire:none No expiration date on public key (<3 years recommended, 5 years max)
556991B2A792A613 [Jeroen Edwin Roovers (JeR \x5c/ ReJ) <jer@xs4all.nl>] [E] subkey:none Having a dedicated signing subkey is required
556991B2A792A613 [Jeroen Edwin Roovers (JeR \x5c/ ReJ) <jer@xs4all.nl>] [W] uid:nogentoo @gentoo.org e-mail not in key UIDs



It seems that it's about time you generated a new key, and revoked the old one.  While at it, please follow the *recommended* specs in GLEP 63 [1], and make sure to handle the key replacement procedure correctly, see e.g. [3].  Please also include your @gentoo.org e-mail in the UIDs of the new key to make it easier for others to find you.

[1]:https://www.gentoo.org/glep/glep-0063.html
[2]:https://github.com/mgorny/glep63-check
[3]:https://www.apache.org/dev/key-transition.html
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-08-01 19:59:54 UTC
Since GLEP 63 has changed, I'm closing the bugs as OBSOLETE.