Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 659846 - asturm: non-conformant OpenPGP key
Summary: asturm: non-conformant OpenPGP key
Status: RESOLVED OBSOLETE
Alias: None
Product: Gentoo Infrastructure
Classification: Unclassified
Component: Developer account issues (show other bugs)
Hardware: All Linux
: Normal normal
Assignee: Andreas Sturmlechner
URL:
Whiteboard:
Keywords:
Depends on:
Blocks: 659842
  Show dependency tree
 
Reported: 2018-07-02 13:01 UTC by Michał Górny
Modified: 2018-08-01 19:59 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-07-02 13:01:36 UTC
Your key does not meet minimal requirements set forth in GLEP 63 [1].  glep63-check [2] reports:

0AF8B3A860381DD4 [Andreas Sturmlechner <andreas.sturmlechner@gmail.com>] [E] expire:none No expiration date on public key (<3 years recommended, 5 years max)
0AF8B3A860381DD4:E7255695D8BA079E [Andreas Sturmlechner <andreas.sturmlechner@gmail.com>] [W] subkey:multipurpose Subkey has multiple capabilities enabled (has: [esa]; use dedicated subkeys!)
0AF8B3A860381DD4:E7255695D8BA079E [Andreas Sturmlechner <andreas.sturmlechner@gmail.com>] [E] expire:none No expiration date on public key (<3 years recommended, 5 years max)
0AF8B3A860381DD4 [Andreas Sturmlechner <andreas.sturmlechner@gmail.com>] [E] subkey:none Having a dedicated signing subkey is required
0AF8B3A860381DD4 [Andreas Sturmlechner <andreas.sturmlechner@gmail.com>] [W] uid:nogentoo @gentoo.org e-mail not in key UIDs


Please revoke that multi-purpose subkey, create *dedicated* subkeys for encryption and signing (I honestly doubt you use auth) and set expiration dates according to GLEP 63 [1].


[1]:https://www.gentoo.org/glep/glep-0063.html
[2]:https://github.com/mgorny/glep63-check
Comment 1 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-07-02 13:30:18 UTC
Oh, and also please add your @gentoo.org address to UIDs.
Comment 2 Andreas Sturmlechner gentoo-dev 2018-07-02 14:48:07 UTC
(In reply to Michał Górny from comment #0)
> (I honestly doubt you use auth)
That fear is unwarranted.
Comment 3 Michał Górny archtester Gentoo Infrastructure gentoo-dev Security 2018-08-01 19:59:42 UTC
Since GLEP 63 has changed, I'm closing the bugs as OBSOLETE.