[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: Resignation and uploads



Op zo, 13-11-2005 te 15:06 +0100, schreef Thijs Kinkhorst:
> On Fri, November 11, 2005 17:10, Christian Perrier wrote:
> > From what I know of him, he will take care of these Debian tasks as
> > soon as he'll be able to do so....just like any of us would after coming
> > back from a conference we were at as part of our paid work.
> 
> I think many other people would take good care to provide backup for our
> tasks in case we're away for longer than a couple of days. There's no
> reason at all that on some key positions in Debian there's only one
> person.

There's one thing people are constantly overlooking here:

The job of maintaining the keyring is far more sensitive and takes a lot
more than just 'throwing the key in' if it remotely looks good.

Rember that 'having a key in the Debian keyring' is, for all practical
matters, equivalent to 'having root on all Debian installations'. A
number of things about the keyring can be (and are!) automated; the
things that cannot be automated are done manually, and they require an
admin who does his job carefully and concisely.

I for one am _happy_ that James does not 'just' throw in the key if the
name is remotely similar, but does indeed verify why this new key is
necessary, if it is properly signed by the active key of at least one
(but preferably more) other developer(s), whether the old key is still
valid (and if so whether it should have been revoked), why the old key
was revoked (if it has been revoked), and a number of other things that
probably only experience can tell you how to do them right.

As always, weighing security against usability is not an easy job; one
that requires a lot of time, responsability, and the guts to say "no"
when it's necessary. The Debian project should be proud that their main
sysadmins are more than up to the job, rather than complaining about how
long it always takes; because, try as you might, adding more sysadmins
doesn't necessarily make the job go faster. And yes, I speak out of
experience here.

-- 
.../ -/ ---/ .--./ / .--/ .-/ .../ -/ ../ -./ --./ / -.--/ ---/ ..-/ .-./ / -/
../ --/ ./ / .--/ ../ -/ ..../ / -../ ./ -.-./ ---/ -../ ../ -./ --./ / --/
-.--/ / .../ ../ --./ -./ .-/ -/ ..-/ .-./ ./ .-.-.-/ / --/ ---/ .-./ .../ ./ /
../ .../ / ---/ ..-/ -/ -../ .-/ -/ ./ -../ / -/ ./ -.-./ ..../ -./ ---/ .-../
---/ --./ -.--/ / .-/ -./ -.--/ .--/ .-/ -.--/ .-.-.-/ / ...-.-/



Reply to: