Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-02-01 Thread Björn Persson
Paul Wouters wrote: >On Sun, 1 Feb 2015, Björn Persson wrote: > >> Paul Wouters wrote: >>> paul@bofh:~$ openpgpkey --fetch pwout...@fedoraproject.org >> >> openpgpkey: /var/lib/unbound/root.anchor is not a file. Unable to use >> it as rootanchor >> >> Huh? > >turns out a bug in %post of unbound-lib

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-02-01 Thread Paul Wouters
On Sun, 1 Feb 2015, Björn Persson wrote: Paul Wouters wrote: paul@bofh:~$ openpgpkey --fetch pwout...@fedoraproject.org openpgpkey: /var/lib/unbound/root.anchor is not a file. Unable to use it as rootanchor Huh? turns out a bug in %post of unbound-libs. I pushed a fix into rawhide. I've al

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-02-01 Thread Björn Persson
Paul Wouters wrote: >paul@bofh:~$ openpgpkey --fetch pwout...@fedoraproject.org openpgpkey: /var/lib/unbound/root.anchor is not a file. Unable to use it as rootanchor Huh? >2) most people don't have their fedoraproject.org as uid on their key Perhaps they are like me in that they want to be kno

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Petr Spacek
On 29.1.2015 15:27, Paul Wouters wrote: > On Thu, 29 Jan 2015, Petr Spacek wrote: > >>> Fedora is probably the First to use OPENPGPKEY at a large scale. >>> >>> https://tools.ietf.org/html/draft-ietf-dane-openpgpkey-01 >> >> Paul, thank you for doing this experiment! I definitely support it. >> >>

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Paul Wouters
On Thu, 29 Jan 2015, Petr Spacek wrote: Fedora is probably the First to use OPENPGPKEY at a large scale. https://tools.ietf.org/html/draft-ietf-dane-openpgpkey-01 Paul, thank you for doing this experiment! I definitely support it. For people who do not watch dane-list closely, please keep in

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Vít Ondruch
Dne 29.1.2015 v 15:08 Paul Wouters napsal(a): > On Thu, 29 Jan 2015, Vít Ondruch wrote: > >> Dne 28.1.2015 v 21:34 Paul Wouters napsal(a): >>> openpgpkey --fetch pwout...@fedoraproject.org >> >> $ openpgpkey --fetch pwout...@fedoraproject.org >> Error: query data is not secured by DNSSEC - use --in

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Paul Wouters
On Thu, 29 Jan 2015, Vít Ondruch wrote: Dne 28.1.2015 v 21:34 Paul Wouters napsal(a): openpgpkey --fetch pwout...@fedoraproject.org $ openpgpkey --fetch pwout...@fedoraproject.org Error: query data is not secured by DNSSEC - use --insecure to override It's time for you to start using DNSSEC

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Vít Ondruch
Dne 28.1.2015 v 21:34 Paul Wouters napsal(a): > openpgpkey --fetch pwout...@fedoraproject.org $ openpgpkey --fetch pwout...@fedoraproject.org Error: query data is not secured by DNSSEC - use --insecure to override Vít -- devel mailing list devel@lists.fedoraproject.org https://admin.fedoraproj

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-29 Thread Petr Spacek
On 28.1.2015 21:34, Paul Wouters wrote: > Hi, > > Fedora is probably the First to use OPENPGPKEY at a large scale. > > https://tools.ietf.org/html/draft-ietf-dane-openpgpkey-01 Paul, thank you for doing this experiment! I definitely support it. For people who do not watch dane-list closely, ple

Re: NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-28 Thread Till Maas
On Wed, Jan 28, 2015 at 03:34:02PM -0500, Paul Wouters wrote: | Note that during FAS processing I found out that: | | 1) there are many nonsense values instead of keyid's in the fas field | (some put in their fingerprint, which is not useful without a key, | some had multiple keyids, and

NowpPublishing fedora developer PGP keys in DNSSEC

2015-01-28 Thread Paul Wouters
Hi, Fedora is probably the First to use OPENPGPKEY at a large scale. https://tools.ietf.org/html/draft-ietf-dane-openpgpkey-01 Everyone[*] who added a GPG keyid in FAS has their key published now using the OPENPGPKEY specification. You can obtain a key using the openpgpkey command of the hash-