On Tue, 2019-04-02 at 08:02 -0600, Rich Freeman wrote: > On Sun, Feb 24, 2019 at 3:35 AM Michał Górny <[email protected]> wrote: > > Following the recent mailing list discussion indicating that developers > > are taking GLEP 63 as only source of truth about OpenPGP keys, and can > > make assumption that if encryption key is not listed there they should > > not have one. Amend the specification to extend it beyond the previous > > limited scope of commit signing, and require an encryption key > > appropriately. This matches the GnuPG defaults. > > Does GLEP 63 actually match the gpg defaults? That is, if you > generate a gpg key and accept every default value will the key be > acceptable? > > If not, could we get some updated documentation as to how to generate > a minimally compliant key, similar to: > https://www.gentoo.org/glep/glep-0063.html#bare-minimum-requirements >
There's: https://wiki.gentoo.org/wiki/Project:Gentoo-keys/Generating_GLEP_63_based_OpenPGP_keys It doesn't follow the best practices but is good enough to pass minimal GLEP 63 requirements. -- Best regards, Michał Górny
signature.asc
Description: This is a digitally signed message part
