Re: [gentoo-dev] validity of manifest signing key

2011-06-26 Thread Marc Schiffbauer
* Dane Smith schrieb am 25.03.11 um 12:35 Uhr: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/25/2011 05:47 AM, Thomas Kahle wrote: Hi, it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry

Re: [gentoo-dev] validity of manifest signing key

2011-06-25 Thread justin
Hi, I was signing my commits since I am a dev, but I just discovered that I only do sha1 signing. How do I switch to sha256 signing? justin signature.asc Description: OpenPGP digital signature

Re: [gentoo-dev] validity of manifest signing key

2011-06-25 Thread Michał Górny
On Sat, 25 Jun 2011 09:37:55 +0200 justin j...@gentoo.org wrote: I was signing my commits since I am a dev, but I just discovered that I only do sha1 signing. How do I switch to sha256 signing? $ grep digest ~/.gnupg/gpg.conf personal-digest-preferences sha256,sha512,sha1,ripemd160,md5 --

Re: [gentoo-dev] validity of manifest signing key

2011-03-26 Thread Paweł Hajdan, Jr.
On 3/25/11 8:00 PM, Mike Frysinger wrote: i wasnt aware you could extend the expiration date of a key. that sort of defeats the purpose of having an expiration date doesnt it ? then someone could steal your expired key, extend the date, and keep using it. I think that's one more reason for

[gentoo-dev] validity of manifest signing key

2011-03-25 Thread Thomas Kahle
Hi, it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? -) Extend expiry date and upload again? -) Create new key (and sign with ?? ) ? Cheers, Thomas -- Thomas Kahle

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Antoni Grzymala
Thomas Kahle dixit (2011-03-25, 10:47): it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? “After size comes the expiration date. Here smaller is better, but most users can go for a

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Christoph Mende
On Fri, 2011-03-25 at 10:55 +0100, Antoni Grzymala wrote: Thomas Kahle dixit (2011-03-25, 10:47): it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? “After size comes the

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Dane Smith
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 03/25/2011 05:47 AM, Thomas Kahle wrote: Hi, it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? -) Extend expiry date and

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Michał Górny
On Fri, 25 Mar 2011 10:47:19 +0100 Thomas Kahle to...@gentoo.org wrote: it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? I'd say that should be changed. With keys changing every

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Andreas K. Huettel
it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? I'd say that should be changed. With keys changing every half a year, we're soon going to have a tree spammed with Manifests

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 10:53 AM, Andreas K. Huettel wrote: it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month.  What is the protocol when the expiry date is approaching? I'd say that should be changed. With keys changing every half a

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 5:47 AM, Thomas Kahle wrote: it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month.  What is the protocol when the expiry date is approaching? -) Extend expiry date and upload again? i wasnt aware you could extend the

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Robin H. Johnson
On Fri, Mar 25, 2011 at 10:47:19AM +0100, Thomas Kahle wrote: Hi, it says here http://www.gentoo.org/doc/en/gnupg-user.xml#doc_chap2 that the validity should be 6 month. What is the protocol when the expiry date is approaching? -) Extend expiry date and upload again? Extend it and make

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Andreas K. Huettel
-) Extend expiry date and upload again? i wasnt aware you could extend the expiration date of a key. that sort of defeats the purpose of having an expiration date doesnt it ? then someone could steal your expired key, extend the date, and keep using it. The expiration date is a property

Re: [gentoo-dev] validity of manifest signing key

2011-03-25 Thread Mike Frysinger
On Fri, Mar 25, 2011 at 12:35 PM, Robin H. Johnson wrote: Also, I propose we change the suggested validity time to 1 or 2 years, sounds reasonable to me. ive been 1 year for a while anyways as the 6 month one got to be annoying. -mike