W dniu pią, 06.07.2018 o godzinie 07∶43 +0200, użytkownik Ulrich Mueller
napisał:
> > > > > > On Thu, 5 Jul 2018, Michał Górny wrote:
> > Replace the disjoint 'minimum' and 'recommendation' for expiration
> > with a single requirement. Make it 2 years. Also, remove disjoint
> > expiration recommendation for the primary key and subkeys since many
> > developers fail at implementing that anyway.
> 
> Still NACK. If expiration is exactly 2 years and renewal must happen
> 2 weeks before the expiry date, then it is not possible to keep the
> same date.

Did you even read the text?  It's 'at most 2 years'.  If you renew it
every year, you can achieve the desired effect while keeping far ahead
of the required schedule.

> Example: The key will expire at 2018-12-31, so it must be renewed at
> 2018-12-17 or earlier. This will make it impossible to keep the same
> month and day (unless one would reset it to 2019-12-31, which is only
> one year though).
> 
> So please, make it something like 2 years + 3 months.
> 

I really see no point in added complexity just so that someone could
bend the standard to the limits.

-- 
Best regards,
Michał Górny

Attachment: signature.asc
Description: This is a digitally signed message part

Reply via email to