Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Vincent Bernat
❦ 12 août 2017 06:29 GMT, "Dr. Bas Wijnen"  : > That is a disservice to our users. While for many users this is true, those > users will have contrib (and probably non-free) enabled in their sources.list. > So moving the package to contrib doesn't change anything for them. The only > people who

Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Dr. Bas Wijnen
First of all, a clarification: This post (like most in this thread) is primarily about Debian's philosophy, not about certspotter (but I do talk about that at the end as well). For this reason, I'm not CC'ing the bug. On Fri, Aug 11, 2017 at 05:26:58PM -0400, Faidon Liambotis wrote: > On Fri, Aug

Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Jonas Smedegaard
Quoting Faidon Liambotis (2017-08-11 17:26:58) > As for certspotter, the conversation has derailed quite a bit -- in part > because Jonas forwarded this to debian-project while stripping almost > the entirety of my reply on the bug, then stripping again all of the > context when days later, he star

Re: Welcome team progress, local groups interest

2017-08-11 Thread MENGUAL Jean-Philippe
Hi, Very happy with knowing the group exists and will progress. Welcome to you! Personally I am very intetested in these matters as I think free software is so much technical-focus, and not user enough. The result is that our ethical is not growing up. There are technical things to fix sure, but e

Re: wanted: educate us please on key dongles

2017-08-11 Thread Jonathan McDowell
On Fri, Aug 11, 2017 at 04:52:36PM -0300, Henrique de Moraes Holschuh wrote: > On Fri, 11 Aug 2017, Jonathan McDowell wrote: > > I see no reason why the master key should ever be used for > > signatures in such a scenario, so it seems sensible to indicate that > > it is purely for certification. >

Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Faidon Liambotis
On Fri, Aug 11, 2017 at 08:03:09AM -0400, Wouter Verhelst wrote: > If a free software implementation of the remote service exists that a > package can work with, then it can remain in main. If not, it cannot. There are no free software server-side implementation of e.g. the ICQ protocol, as far as

Welcome team progress, local groups interest

2017-08-11 Thread Fabián Rodríguez
Hello, I am at DebConf 17 in Montreal (my first DebConf), it has been a fantastic week to meet many people I have interacted with online (or not). My focus was on making the Welcome team progress and increase membership (welcome ClaraTrT!). After attending several BoFs and talking to many of you

Re: wanted: educate us please on key dongles

2017-08-11 Thread Henrique de Moraes Holschuh
On Fri, 11 Aug 2017, Jonathan McDowell wrote: > On Fri, Aug 11, 2017 at 10:08:16AM -0700, Sean Whitton wrote: > > On Fri, Aug 11 2017, Jonathan McDowell wrote: > > > * If you don't want to buy hardware, use an offline master > > > key. Create > > >a certification only master key using somethi

Re: wanted: educate us please on key dongles

2017-08-11 Thread Christian Seiler
Hi there, On 08/11/2017 07:29 PM, Sean Whitton wrote: > On Fri, Aug 11 2017, Christian Seiler wrote: > >> - on the computers I use daily the filesystem doesn't contain any >> private keys, but only stubs for the subkeys so that GnuPG >> automatically tells me to insert the key > > I th

Re: wanted: educate us please on key dongles

2017-08-11 Thread Sean Whitton
On Fri, Aug 11 2017, Christian Seiler wrote: > - on the computers I use daily the filesystem doesn't contain any > private keys, but only stubs for the subkeys so that GnuPG > automatically tells me to insert the key I think I know what you mean by "stub", but what gpg command generates

Re: wanted: educate us please on key dongles

2017-08-11 Thread Jonathan McDowell
On Fri, Aug 11, 2017 at 10:08:16AM -0700, Sean Whitton wrote: > Thank you for the explanation. > > On Fri, Aug 11 2017, Jonathan McDowell wrote: > > > * If you don't want to buy hardware, use an offline master > > key. Create > >a certification only master key using something like PGP Clean

Re: wanted: educate us please on key dongles

2017-08-11 Thread Sean Whitton
Hello, Thank you for the explanation. On Fri, Aug 11 2017, Jonathan McDowell wrote: > * If you don't want to buy hardware, use an offline master > key. Create >a certification only master key using something like PGP Clean Room >on a non-networked host [...] By default, GnuPG creates

Re: wanted: educate us please on key dongles

2017-08-11 Thread Christian Seiler
Hi, Am 2017-08-11 14:41, schrieb Jonathan McDowell: * Yubikey. I'm not sure about this; it's entirely closed these days I believe. However they're easily available and I understand they're pretty robust in terms of living on a keyring all the time. I bought a YubiKey 4 a

Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Sean Whitton
On Fri, Aug 11 2017, Wouter Verhelst wrote: > On Mon, Aug 07, 2017 at 08:48:53PM -0700, Sean Whitton wrote: >> Hello, >> >> On Mon, Aug 07 2017, Dr. Bas Wijnen wrote: >> >> >> Example: [s3cmd] >> > >> > How is this not in contrib? This software is useless without the >> > non-free service (whic

Re: wanted: educate us please on key dongles

2017-08-11 Thread Jonathan McDowell
On Wed, Aug 02, 2017 at 10:16:29PM +0200, Adam Borowski wrote: > It would be nice if someone knowledgeable could educate the rest of us > about physical key dongles -- a number of DDs/DMs/contributors still > keep their secret keys on a regular disk, and could use a primer. Me > included. I do ha

Re: Request for official help

2017-08-11 Thread MENGUAL Jean-Philippe
Hi, Just to be sure I ded not miss any message: does this thread has a follow-up after my reply? What would be the process to get a such doc with an official signatureN Thanks very much Best regards, Le 01/08/2017 à 19:36, MENGUAL Jean-Philippe a écrit : > Hi, > > Thanks, indeed it may hav

Re: [pkg-go] Bug#856139: certspotter: long description advertises commercial service

2017-08-11 Thread Wouter Verhelst
On Mon, Aug 07, 2017 at 08:48:53PM -0700, Sean Whitton wrote: > Hello, > > On Mon, Aug 07 2017, Dr. Bas Wijnen wrote: > > >> Example: [s3cmd] > > > > How is this not in contrib? This software is useless without the > > non-free service (which is also software, and it is not in main) from > > Ama