On 25.04.2019 14:32, Rich Freeman wrote:
> [snip]

> Patch follows:
>
>
> diff --git a/glep-0063-v3.rst b/glep-0063-v3.rst
> index 5895873..86e5fd9 100644
> --- a/glep-0063-v3.rst
> +++ b/glep-0063-v3.rst
> @@ -12,6 +12,12 @@ OpenPGP key management policies for the Gentoo
> Linux distribution.
>  Changes
>  =======
>
> +v3
> +  The requirement to have a separate signing and primary key was removed
> +  in the case of keys generated/stored on smartcards, to encourage the use
> +  of these keys, and acknowledging that the main use case for a separate
> +  primary key is largely fulfilled by having all the keys stay offline.
> +
>  v2
>    The distinct minimal and recommended expirations have been replaced
>    by a single requirement. The rules have been simplified to use
> @@ -69,7 +75,8 @@ not be used to commit.
>     at least 256-bit.  All subkey self-signatures must use this digest.
>
>  2. Signing subkey that is different from the primary key, and does not
> -   have any other capabilities enabled.
> +   have any other capabilities enabled.  This requirement does not apply
> +   if the primary key was generated on a smartcard.
>
>  3. Primary key and the signing subkey are both of type EITHER:
>
>
>
I strongly disagree with this change. If you generated your keys
straight on the device you are not able to make a backup later.
The best practice here is to have a separate USB stick that is never
used for purposes other than private keys storing.
Also paperkey backups should serve as the last resort.




Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to