Re: [gentoo-dev] validity of manifest signing key

2011-06-26 Thread Marc Schiffbauer
* Dane Smith schrieb am 25.03.11 um 12:35 Uhr: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 03/25/2011 05:47 AM, Thomas Kahle wrote: > > Hi, > > > > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > > the validity should be <6 month. What is the protocol when

Re: [gentoo-dev] validity of manifest signing key

2011-06-25 Thread Michał Górny
On Sat, 25 Jun 2011 09:37:55 +0200 justin wrote: > I was signing my commits since I am a dev, but I just discovered that > I only do sha1 signing. How do I switch to sha256 signing? $ grep digest ~/.gnupg/gpg.conf personal-digest-preferences sha256,sha512,sha1,ripemd160,md5 -- Best regards, M

Re: [gentoo-dev] validity of manifest signing key

2011-06-25 Thread justin
Hi, I was signing my commits since I am a dev, but I just discovered that I only do sha1 signing. How do I switch to sha256 signing? justin signature.asc Description: OpenPGP digital signature

Re: [gentoo-dev] validity of manifest signing key

2011-03-26 Thread Paweł Hajdan, Jr.
On 3/25/11 8:00 PM, Mike Frysinger wrote: > i wasnt aware you could extend the expiration date of a key. that > sort of defeats the purpose of having an expiration date doesnt it ? > then someone could steal your expired key, extend the date, and keep > using it. I think that's one more reason fo

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 12:35 PM, Robin H. Johnson wrote: > Also, I propose we change the suggested validity time to 1 or 2 years, sounds reasonable to me. ive been 1 year for a while anyways as the 6 month one got to be annoying. -mike

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Andreas K. Huettel
> > -) Extend expiry date and upload again? > > i wasnt aware you could extend the expiration date of a key. that > sort of defeats the purpose of having an expiration date doesnt it ? > then someone could steal your expired key, extend the date, and keep > using it. The expiration date is a pro

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Robin H. Johnson
On Fri, Mar 25, 2011 at 10:47:19AM +0100, Thomas Kahle wrote: > Hi, > > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > the validity should be <6 month. What is the protocol when the expiry > date is approaching? > > -) Extend expiry date and upload again? Extend it and

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 5:47 AM, Thomas Kahle wrote: > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > the validity should be <6 month.  What is the protocol when the expiry > date is approaching? > > -) Extend expiry date and upload again? i wasnt aware you could extend

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 10:53 AM, Andreas K. Huettel wrote: >> > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 >> > that the validity should be <6 month.  What is the protocol when the >> > expiry date is approaching? >> >> I'd say that should be changed. With keys changing eve

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Andreas K. Huettel
> > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 > > that the validity should be <6 month. What is the protocol when the > > expiry date is approaching? > > I'd say that should be changed. With keys changing every half a year, > we're soon going to have a tree spammed with M

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Michał Górny
On Fri, 25 Mar 2011 10:47:19 +0100 Thomas Kahle wrote: > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 > that the validity should be <6 month. What is the protocol when the > expiry date is approaching? I'd say that should be changed. With keys changing every half a year, w

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Dane Smith
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/25/2011 05:47 AM, Thomas Kahle wrote: > Hi, > > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > the validity should be <6 month. What is the protocol when the expiry > date is approaching? > > -) Extend expiry date an

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Christoph Mende
On Fri, 2011-03-25 at 10:55 +0100, Antoni Grzymala wrote: > Thomas Kahle dixit (2011-03-25, 10:47): > > > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > > the validity should be <6 month. What is the protocol when the expiry > > date is approaching? > > “After size com

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Antoni Grzymala
Thomas Kahle dixit (2011-03-25, 10:47): > it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that > the validity should be <6 month. What is the protocol when the expiry > date is approaching? “After size comes the expiration date. Here smaller is better, but most users can go fo

[gentoo-dev] validity of manifest signing key

2011-03-25 Thread Thomas Kahle
Hi, it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be <6 month. What is the protocol when the expiry date is approaching? -) Extend expiry date and upload again? -) Create new key (and sign with ?? ) ? Cheers, Thomas -- Thomas Kahle http://dev.gent