On Tue, 2019-04-02 at 08:02 -0600, Rich Freeman wrote:
> On Sun, Feb 24, 2019 at 3:35 AM Michał Górny <[email protected]> wrote:
> > Following the recent mailing list discussion indicating that developers
> > are taking GLEP 63 as only source of truth about OpenPGP keys, and can
> > make assumption that if encryption key is not listed there they should
> > not have one.  Amend the specification to extend it beyond the previous
> > limited scope of commit signing, and require an encryption key
> > appropriately.  This matches the GnuPG defaults.
> 
> Does GLEP 63 actually match the gpg defaults?  That is, if you
> generate a gpg key and accept every default value will the key be
> acceptable?
> 
> If not, could we get some updated documentation as to how to generate
> a minimally compliant key, similar to:
> https://www.gentoo.org/glep/glep-0063.html#bare-minimum-requirements
> 

There's:

https://wiki.gentoo.org/wiki/Project:Gentoo-keys/Generating_GLEP_63_based_OpenPGP_keys

It doesn't follow the best practices but is good enough to pass minimal
GLEP 63 requirements.

-- 
Best regards,
Michał Górny

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to