On 25.04.2019 14:32, Rich Freeman wrote: > [snip]
> Patch follows: > > > diff --git a/glep-0063-v3.rst b/glep-0063-v3.rst > index 5895873..86e5fd9 100644 > --- a/glep-0063-v3.rst > +++ b/glep-0063-v3.rst > @@ -12,6 +12,12 @@ OpenPGP key management policies for the Gentoo > Linux distribution. > Changes > ======= > > +v3 > + The requirement to have a separate signing and primary key was removed > + in the case of keys generated/stored on smartcards, to encourage the use > + of these keys, and acknowledging that the main use case for a separate > + primary key is largely fulfilled by having all the keys stay offline. > + > v2 > The distinct minimal and recommended expirations have been replaced > by a single requirement. The rules have been simplified to use > @@ -69,7 +75,8 @@ not be used to commit. > at least 256-bit. All subkey self-signatures must use this digest. > > 2. Signing subkey that is different from the primary key, and does not > - have any other capabilities enabled. > + have any other capabilities enabled. This requirement does not apply > + if the primary key was generated on a smartcard. > > 3. Primary key and the signing subkey are both of type EITHER: > > > I strongly disagree with this change. If you generated your keys straight on the device you are not able to make a backup later. The best practice here is to have a separate USB stick that is never used for purposes other than private keys storing. Also paperkey backups should serve as the last resort.
signature.asc
Description: OpenPGP digital signature
